The Evolving Cybersecurity Landscape – Nayaki Nayyar, Securonix
Securonix CEO Nayaki Nayyar dives into how the cybersecurity ecosystem is evolving in the wake of a wave of consolidation driven by mergers and acquisitions.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Nki N who is CEO for Securonix, and we're talking about the current state of the cybersecurity marketplace, which is radically different.
Nki, welcome the show. Thank you, Mike. Glad to be here.
Look forward to our conversation today. Thank you. One of the things we've seen is, for a while there, it seemed like organizations were, if they could find somebody to manage it, were buying just about any point product and tool they could find.
But, um, these days it seems like a lot of organizations have pulled in their horns. We're starting to see some mergers and acquisition activity in the security space as a result. How different is the market as you understand it today as ACEO who plays in this space and what should people be paying attention to?
Yeah, Mike, it's, it's a great question. I will say this, you know, cybersecurity as a category and as a market is a highly fragmented market. The number of tools, technologies, and products that, uh, customers need to put in place to be able to, uh, detect, uh, all their threats and respond to that is, uh, a large number of products that they have to do.
So, you know, this market is, uh, very, very, uh, prime for consolidation. You will see a lot of, uh, consolidation happening, uh, in the coming years, even as recent as, uh, a few weeks back when we saw the announcement of Splunk getting acquired by Cisco. Right?
So, um, that's how we see it. But another big thing, Mike, I would say, uh, cybersecurity as a topic is no longer just ACIO or a CISO issue or a tech issue anymore. Uh, it has become a board topic.
Uh, given the cybercrime has reached catastrophic hides every board, uh, including audit committees. I'm on couple of public boards, myself, Mike, I'm a part of our committee also, and they are now required to disclose if there's any significant incident within four business days. Right.
So, given the importance of this, given the, uh, oversight that every board is now required to provide on this, this has really gone beyond just ACIO CSO or tech issue to become a more board level, business level conversation across every large organization. Do you think organizations need to look a little deeper at the security vendors they're working with to make sure they're gonna be around? It seems like a lot of venture capital money that went into this space is harder to come by.
So, um, how do I know who's gonna be in this for the long haul? Well, I would say, uh, vendors who have, uh, been at it for a long time, uh, have, uh, very, very strong products are going to be the winners in the long run. No question about Itron.
As you know, uh, we have been a leader in the entire, uh, sim space for four quarters in a row, four years in a row in the KA magic quadrant. Uh, so absolutely, I would say vendors with strong products, strong capabilities, strong vision and strategy for future of where the market is heading, uh, will be the winners. And we feel very, very excited about where securonics is today and what the future holds for us.
And I can go into the, a lot more details on what we are doing on the product front As we kind of think about this whole category. Um, are more people investing in this space nowadays? Because it seemed like for a while there was a, a lull.
And then are people rediscovering sims as we go along here? Or what's going on? Well, absolutely Mike.
We sit at the heart of this problem of helping customers detect, uh, the threats, investigate them and respond, you know, without having a strong sim when you don't have a strong, uh, convergence point, right? We collect all the data from all sources across the entire organization into our data lake. And then, uh, the biggest, I would say, differentiation that we as secureonix bring to the market, uh, is the threat content, the autobox threat content that we deliver of the box, very similar to what I call, uh, a Netflix analogy, uh, analogy where, you know, Netflix doesn't differentiate because of the platform.
They differentiate because of the content that they deliver. Similarly, um, this market sim as a category is not just the data and the platform that helps differentiate the vendors. It's really the threat content that helps us differentiate.
So we have very, very strong, what we call threat content as a service, um, that we deliver out of the box for customers to be able to deploy out of the box and get it up and running. And the speed at which they can detect those threats, respond to those threats is what are big differentiation is. Absolutely.
Yeah. Is the rise of AI also bringing more attention to this space? 'cause at the end of the day, AI is about the data, right?
Oh, absolutely. In fact, uh, fast forward, I would say, uh, year, year and a half, uh, this world will look very, very different. The, what we call the future of soc, uh, by 2025.
Uh, what takes a SOC analyst today, maybe days or weeks to detect a threat and respond to it will take minutes or seconds. Uh, as we embed ai, and we have already started that journey, Mike give embedded, uh, gen AI charge capabilities to truly help what we call the level one, level two SOC analyst, to be able to, um, uh, drastically transform the experience that they have in detecting and responding to the threats. But the speed at which they can do will be a lot different as we bring more, uh, gen AI capabilities to the platform.
So stay tuned. That's a big part of our innovation journey that we are gonna be releasing come early 2024. And, uh, keeping at it and getting to what we call the SOC of 2025 would be very different than what it's today.
What impact is that gonna have on the current cybersecurity skill shortage that we've been dealing with forever and a day? Is that gonna shrink or will it just kinda change and evolve? Yeah, look, I mean, every customer, every large, um, uh, organization that we talk to, their number one challenge is, is a significant shortage.
Uh, they have in the skills, the cybersecurity skills, especially the shortage that they have for staffing their soc, their, uh, security operations control and AI will dramatically change it. The level one, level two SOC analyst would no longer be needed. I would say that work would be done by, um, AI enabled, um, SIM capabilities and the customers, they would just have to evolve towards having more advanced, like level three and level four kind of SOC analysts versus having to stock, um, for level one and level two.
So that's how I see it, uh, with the shortage customers have, with the significant gap there is, they'll be very, would say the low hanging fruit of level one, level two would be handled by the system, would be handled by AI embedded into our platform. And then customers will evolve their skills and their personnel and their resources to more, I would say more advanced level of threat hunting capabilities. The relationship between the security teams and the rest of it, we see IT operations folks getting more involved.
We see developers being asked to assume more responsibility. How is the whole space evolving from your perspective? Yeah, I mean, there's a lot more convergence.
Uh, security is not, you know, there was a time when security was detached from it or separate from it, uh, but now they are, I would say, uh, one team and they're all coming together. The whole concept of dev SecOps, it's not DevOps and SecOps DevSecOps and security is part and parcel of the entire value chain and very, very tightly integrated with entire, uh, IT area. So, uh, and you see, you know, a CSO that was never a part of CIO's, ELT, is now in the board meetings, right?
So the elevation of a CSO to, uh, not just A-C-I-O-C-L-T, but also to the entire company, CLT, and then of course at the board level now has really elevated that role and has merged the IT and, uh, security a lot more tighter and a lot more integrated. I would say Most security folks that I know are somewhat, shall we say, born optimist in the sense that up until there's that breach gets discovered, they think that, you know, things are gonna be secure. And I think deep in their hearts, they probably know differently.
But, um, the question I would have is, you know, how do we validate what we're doing versus what the breach might be, or the threats may be because the board wants to know and the board listens to the CISO and the IT people, but ultimately, how are we gonna be? Sure, Yeah. It all comes down to, which is why you see pretty much, especially at the board level, Mike, uh, the boards now require the CISOs to come to the table with the framework, whatever framework they use, right?
Whether they use NIST as a framework, or Mitra as a framework come with a framework and what the coverage is, uh, across that framework and being able to very clearly articulate where the gaps are and how the, uh, the CSOs or the IT team are planning on fixing those gaps. So it's very important to have that very open, transparent conversation with the board to say, this is a framework you're using, these are the areas that you have full coverage for, and the areas that you don't have coverage for and investments that are needed for you to be able to get to that full coverage. And, uh, a plug with securonics on it.
We have what we call a threat coverage analyzer, Mike, in our platform where customers can see what the coverage is. We do, uh, leverage Mitre, uh, cover, uh, framework quite a lot and being able to provide that visibility to not just, uh, cso, but also the board level for them to see the full coverage and see where the gaps are and being able to monitor that and address those gaps in a real time fashion. We have seen, of course, you refer to the SEC rules, but um, it seems like there's a lot more regulation coming down the pike.
It's a little more stringent, a little stricter. It seems to be holding people accountable for how they manage data spans, everything from data privacy to data governance. But, you know, should we all be gearing up for some new era of regulation?
Well, absolutely. I think this is one area, uh, that is seeing a lot of change and lot of, uh, updates to the entire SEC rules and regulations that are coming up on a very, very frequent basis. Um, I can't, I can't predict what's gonna happen in future, Mike.
I can't say what exactly is coming down the pipe, but even with what's required now of companies to be able to think of it, to be able to provide, uh, have a eight K release, if there's any significant incident within four business days, that's a pretty, uh, a lot of pressure on organizations, right? Being able to do that in a very timely manner is, is not easy. And for that, companies do require a very, very solid, um, framework for them to be able to provide that kind of data and have a eight K release, right?
So, uh, I can't really predict what's coming further down the road, but even with what's required right now, I feel it's a lot of pressure for organizations to be able to do that in near dear time, compassion, Understandably, security folks are a little stressed out and maybe more stressed out in the future is, and that of course leads to turnover. But, um, are there things to be done that kind of reduce the stress? Oh, exactly.
Absolutely. Um, which is where we as Securonics, what we have done, Mike, and we talked about SIM little bit, we have been a pioneer in new EBA user behavior analytics. A few years back we came out with what we call the NextGen sim, the cloud native version of sim, and very recently we released what we call a unified defense sim.
It has got like a holistic framework for customers to start their journey. It starts with the data lake. We did announce a partnership with, uh, snowflake where customers can now, um, uh, have a full 365 days of hot search, which was never available before.
Most sim vendors used to only provide seven days of hot search, and everything else was warm or cold. Uh, with this partnership with Snowflake, we now provide customers a full 365 days of hot search so they can, uh, leverage the entire 12 months of data to be able to, um, hunt for those threats and respond to those threats, right? So that's, I would say, a big differentiation.
We have customers can leverage that. And then, like I said, threat content, uh, which is a, a key differentiator. We have threat content as a service, the autobox threat content, threat coverage analyzer, like I talked about, being able to get a full understanding of what your coverage is, especially if you're using mitta coverage and having a, a full view and end-to-end view from an analyst to ACXO.
It's not just a capability for a, a SOC analyst to be able to leverage a platform, but also having a dashboard for ACXO who can take it to the board to have the conversation to say, Hey, where, what my coverage is, where the gaps are, and how they plan on addressing it, right? So it's a full holistic platform for them to start, uh, the entire data lake, have full three and 65 day support search with threat content out of the box, and leverage that threat content as a service, the full threat coverage analyzer and a full TDIR experience, I call it threat detection and investigation response, uh, all the way from a SOC analyst to ACXO. There seems to be a lot more talk these days about reducing the total cost of security by standardizing on one single platform.
Is is that what you're seeing people do or is that more of a, you know, an interesting conversational point, but probably not as practical as people might think? I would say, uh, it's somewhere in the middle. Uh, there's definitely consolidation happening.
Um, even for us, we do have one platform for UEBA SIM and so, right, so instead of having different tools for products and platforms for sim, SOAR and UEBA, we have one platform. So customers are definitely looking for vendors who have more holistic platform and they can consolidate that, uh, onto one of those vendors versus having too many platforms and too many products and vendors. Now, will there be a lot more consolidation than what we have today, Mike, that needs to be seen?
Absolutely. I think there'll be a lot more consolidation, but time will tell where these consolidations are gonna happen. Yeah.
So what's your best advice to folks then? As you kinda look at the landscape right now and you're talking to CISOs and CIOs and business leaders, I mean, is there something that they should be doing more proactively than they currently or not? Look, I, uh, like I said, I fundamentally believe this world is gonna move very, very fast with Gen AI and LLM capabilities.
The SOC of future is gonna be very different, uh, which uh, requires every CISO and every security, uh, leader out there to work with vendors who are thinking ahead, who are thinking about what that future of SOC looks like, and, uh, partnering very closely with them because the threat actors, uh, are gonna be very different too. They're gonna be leveraging all these technologies also to be a lot more intense, a lot more frequent, and a lot more malicious. And every organization has to be, uh, very ready and prepared to be able to handle that kind of, um, volume and intensity that's gonna happen in 2025 and beyond, uh, which is where, um, I would advise everyone to truly be ready for that and start working with vendors who can help you get, uh, into that future world.
And Secureonix is absolutely on that journey. So stay tuned for what we call a sock of 2025. They'll be releasing, uh, very, very shortly.
All right, folks. You heard it here. You ain't seen nothing yet, so buckle up 'cause it's gonna be an interesting year for sure.
Niha, thank you for being on the show. Thank you, Mike. Thanks so much.
It was great talking to you. Thanks so much. All right.
Back to you guys in the studio.