Risk

7/12/2007
03:30 AM
50%
50%

Consolidate This

The M&A bug bites proactive security, but convergence will have to wait

Everyone's talking about consolidation in the security market, and with good reason – lots of M&A activity has occurred. So what’s going on behind the scenes financially, and where will this trend leave us? Will security practitioners be left holding the bag? Most importantly, what impact will consolidation have on the nascent proactive security market?

Convergence versus consolidation
Two distinct threads run through the security market: consolidation and convergence. The first involves the unremitting development of energetic, innovative startups. These little guys are often the targets of consolidation, especially in the form of rollups. One quintessential example of a security rollup is Cybertrust, which bought a number of little companies (and some medium-sized ones like TruSecure) and assembled them into something bigger than the parts alone. In the end, Cybertrust built a company with annual revenues just north of $200 million.

Another rollup-like example is EMC Corp. (NYSE: EMC), with its acquisitions in the data security market, buying up little companies like Authentica and Documentum in order to bolster its data protection capabilities. Of course, EMC has bigger fish to fry, what with its recent $2.1 billion purchase of RSA Security Inc. (Nasdaq: EMC) It seems EMC has become a convergence point.

You see, eventually companies the size of Cybertrust and RSA themselves become targets for mega-corporations. Case in point: Verizon Business ’s $400 million purchase of Cybertrust, which closes this week. (See Verizon Grabs Cybertrust.) Cybertrust was acquired with a multiple on revenue of around 2 – the kind of valuation typical for a services company, even one where the services are heavily commoditized.

The Cybertrust/Verizon deal is more of a convergence than a consolidation. Similarly, the BT Counterpane deal is what I would call a convergence deal. (See BT Buys Counterpane.)

So what exactly is converging in these situations? The convergence involves network security as a commodity service being packaged together with other network-related utilities. If you are a large company, you need certain utilities such as Internet bandwidth and telephone services – and you need security as well. Convergence with the telecom sector makes great sense in the network security market of firewalls, intrusion monitoring, and extrusion detection. Incidentally, that’s why managed security services make a great deal of sense when it comes to network operations and monitoring. These are reactive security solutions.

Probably the two top convergence plays going strong now are IBM Corp. (NYSE: IBM), which bought Internet Security Systems Inc. last August for $1.3 billion, and Symantec Corp. (Nasdaq: SYMC), which bulked up and shifted toward the enterprise with its record-breaking $13.5 billion merger with Veritas. (See IBM Up-Ends Security Services Market.) Convergence is good for the overall security market, because it helps to spread the security “meme” far and wide. If decent network security becomes as ubiquitous as the telephone, that will be a great development for reactive security.

Proactive security is different
The real problem is that the computer security disaster we have created for ourselves looms as large as ever, even as the security market grows to gargantuan proportions and security companies rake in billions of dollars. At the heart of the problem is an emerging conundrum: The kinds of services ripe for convergence are not the kinds of services that can solve the security problem. Reactive network security can only go so far. If we want to get a handle on the unmitigated growth of the computer security problem, we have to build better software.

Software security has certainly come a long way since I wrote Building Secure Software with John Viega way back in 2000. The security market is maturing, demand is very high, and people are beginning to realize how much work remains to be done. A broad realization of the importance of software security is dawning, especially in the financial services market.

The first generation of tools created for the software security market (proactive security) is the Web application security testing tools. I call these tools badness-ometers – affectionately, of course. Black-box testing tools are great because they can help the clueless or the overly optimistic to understand that there is indeed a huge software problem... with their own software! Black-box testing tools are also dangerous, however, because passing all of the tests built into one of these tools does not mean your Web app is secure.

The upshot is that as long as badness-ometers are treated as badness-ometers and not security-meters, we’re OK.

Interestingly, the top two software badness-ometer companies were recently acquired: SPI Dynamics was bought by Hewlett-Packard Co. (NYSE: HPQ) for around $100 million (a multiple on revenue of 5.5), and Watchfire Corp. was bought by IBM for around $85 million (a multiple on revenue of 2.8). (See Want Turns to Need.)

The question is just what impact the consolidation bug will have on the proactive security market. Both HP and IBM are probably counting on Web app security testing tools to be mature enough for use by QA people (that is, non-security people who focus on software testing for a living). If that were true, then every QA department out there would need a few copies. We’ve debated the question of whether these tools are ready to be wielded by QA long and hard at Cigital, and the jury is still out.

There are pros and cons. If QA people could effectively use badness-ometers, awareness of the magnitude of the software security problem would grow, which would be excellent. However, if QA people find themselves over their heads in security nonsense, not much will come of the first wave of consolidation, at least for HP and IBM. What would be really interesting is if the large security services organizations at HP and IBM started applying badness-ometers in all of their projects. Demand for solutions to solve the problems that these tools find would skyrocket.

In the end, it's nice to see software security – the proactive security market – continuing to grow. Expect more consolidation as this trend continues. Convergence will have to wait.

— Gary McGraw is CTO of Cigital Inc. Special to Dark Reading

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
2019 Attacker Playbook
Ericka Chickowski, Contributing Writer, Dark Reading,  12/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
[Sponsored Content] The State of Encryption and How to Improve It
[Sponsored Content] The State of Encryption and How to Improve It
Encryption and access controls are considered to be the ultimate safeguards to ensure the security and confidentiality of data, which is why they're mandated in so many compliance and regulatory standards. While the cybersecurity market boasts a wide variety of encryption technologies, many data breaches reveal that sensitive and personal data has often been left unencrypted and, therefore, vulnerable.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20201
PUBLISHED: 2018-12-18
There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly unspecified other impact via a crafted js file.
CVE-2018-20194
PUBLISHED: 2018-12-18
There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy l...
CVE-2018-20195
PUBLISHED: 2018-12-18
A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVE-2018-20196
PUBLISHED: 2018-12-18
There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled.
CVE-2018-20197
PUBLISHED: 2018-12-18
There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy l...