Synack delivers crowdsourced security for government, snags IRS contract

News Analysis
Nov 15, 20163 mins

Another play on the crowdsourced security theme, Synack manages to snag a customer not usually seen on such approaches

security thinkstock
Credit: Thinkstock

Government departments tend to be seen as “top shelf” IT customers. They tend to use larger providers, use more traditional delivery mechanisms and have a conservative approach towards newer ways of working. So, when Synack, a crowdsourced cybersecurity vendor, told me it secured a contract with the IRS, I was intrigued.

+ Also on Network World: How the government can help businesses fight cyber attacks +

First, a little bit about what Synack does: The company is following something of an ongoing trend in the security space in that it wrangles a bunch of “ethical hackers” to essentially try and break a client’s IT systems. The idea being that those hackers can ply their trade, but instead of intruding onto organizations’ IT systems out of malice, they can do so as a service (and, it must be added, for a payment). Founded in 2013 by former NSA security experts Jay Kaplan, CEO, and Dr. Mark Kuhr, CTO, Synack feels very similar to HackerOne, a company now headed by Marten Mickos of MySQL fame.

Anyway, Synack plays the intermediary role between hacker and large organization, and it provides a sort of a Chinese wall whereby the client pays for a top-shelf, robust and professional service, and Synack takes the lead in managing operatives who, it must be admitted, are sometimes not the most savory of characters.

And that shielding of the “riff raff” seems to be working, at least when it comes to making clients feel comfortable with their service. Synack claims customers across banking and financial services, healthcare, consumer goods and retail, manufacturing, and technology.

Synack Government unveiled

And today the company adds another market: the U.S. government. It unveiled Synack Government, a new line of business dedicated to serving the needs of federal, state and local agencies. This product announcement follows Synack’s winning the U.S. government’s largest, crowdsourced vulnerability-discovery contract ever through the Hack the Pentagon program.

Not just words, however, the company also unveiled its $2 million contract with the U.S. IRS to pioneer a model in the government that proactively protects sensitive government and taxpayer data on the irs.gov domain. Synack is now officially unveiling an optimized solution, Crowd Security Intelligence Federal, to provide an adversarial perspective on the security of agencies’ sensitive, mission-critical IT assets.

“We are excited to see vital government bodies, like the IRS and [Department of Defense], move even more quickly than many enterprises to implement our innovative crowdsourced security approach,” Kaplan said. “As attackers and threats become savvier, the federal agencies are recognizing that advanced security is paramount. We’re rolling out our Synack Government solution to protect some of the most sensitive transactional data and mission-critical IT assets in the country.”

Of course, many will ask how this is different from any of the other numerous bug-bounty programs out there. Synack says it is different in that its model consists of the most rigorous vetting and tracking in the industry, ensuring the customer has continuous visibility and management over all Synack Red Team activities.

It’s certainly a real vote of confidence that the IRS is going this way. I don’t think for a minute that Synack replaces more traditional approaches to hacker protection. But as an additional tool, it looks very useful.

benkepes

Ben Kepes is a technology evangelist, an investor, a commentator and a business adviser. His business interests include a diverse range of industries from manufacturing to property to technology. As a technology commentator he has a broad presence both in the traditional media and extensively online. Ben covers the convergence of technology, mobile, ubiquity and agility, all enabled by the cloud. His areas of interest extend to aviation technology, enterprise software, software integration, financial/accounting software, platforms and infrastructure as well as articulating technology simply for everyday users.

He is a globally recognized subject matter expert with an extensive following across multiple channels. His commentary has been published on Forbes, ReadWriteWeb, GigaOm, The Guardian and a wide variety of publications – both print and online. Often included in lists of the most influential technology thinkers globally, Ben is also an active member of the Clouderati, a global group of cloud thought leaders and is in demand as a speaker at conferences and events all around the world.

As organizations react to the demands for more flexible working environments, the impacts of the economic downturn and the existence of multiple form-factor devices and ubiquitous connectivity, Cloud computing stands alone as the technology paradigm that enables the convergence of those trends -- Ben’s insight into these factors has helped organizations large and small, buy-side and sell-side, to navigate a challenging path from the old paradigm to the new one.

Ben is passionate about technology as an enabler and enjoys exploring that theme in various settings.

The opinions expressed in this blog are those of Ben Kepes and do not necessarily represent those of IDG Communications, Inc., its parent, subsidiary or affiliated companies.

More from this author