09:16 AM
Dark Reading
Dark Reading
Products and Releases
Connect Directly

Tufin Survey Reveals 91% Of Security Managers Are Under Pressure To Deliver Applications And Services Faster

More than three-quarters of respondents believe virtualization will have the biggest impact on security operations during next 12 to 18 months

Morristown, New Jersey, February 25, 2014: Tufin Technologies, the market-leading provider of Security Policy Orchestration solutions, today announced the results of a survey of169 security professionalson the current state of security operations. Conducted at Cisco Live! in Milan, Italy in January 2014, morethan 90% of the respondents reported that the on-demand nature of virtualization and the cloud has increased pressure on them to deliver applications and services faster. With more than three quartersof respondents believing virtualization will have the biggest impact on Security Operations over the next 12-18 months, the pace will only accelerate, underscoring the need for increased automation. In order to ensure security teamsremain agile and effective in light of the accelerated pace, Tufin, in separate releases also issued today,announcednew security,automation and orchestration capabilities and a partnership with IT automation software leader Puppet Labs.

Thesesurvey results complement the findings of a larger October 2013Tufin-commissioned survey in which 71% of more than 500 senior IT professionals found themselves having to adopt new processes, learn new technologies and interact with new people because of these same trends. TheCisco Live! attendeeresponses pointed toadditional problems being caused by the intense pace of change, highlighting several opportunities to improve Security Operations:

• Almost 90%felt that organizations rely too heavily on network security products and tools at the expense of good network architecture and design in order to deliver the optimum level of network security.

• Almost 40% reported that the biggest barrier to effective network security is network complexity while25% cited a lack of collaboration and another 20% cited the constant change occurring in today's networks as their biggest barriers.

• With this being the case, it comes as no surprise thatabout 89% of the respondents reported that between 20-60% of security policy changes in their organization need to be corrected after the fact.

• Another one-sixth reported that as much as60-80% of their organizations' security policy changes need to be redone.

"As previous surveys have confirmed, the role of security within Operations is expanding in order to deal with the network security challenges brought on by the cloud and virtualization," said Ruvi Kitov, Tufin CEO. "Thisleads to more and deeper collaboration with other IT groupsin order to integrate and automate security into areas such as network design, change processes and operational performance. Our customers tell us this is the best way to ensure next generation networks are efficient, agile and equipped to deal with next generation security concerns. We agree and believe intelligent change and process automation will become standardsas virtualization and the cloud become more pervasive."

Survey respondentsalso made it emphatically clear thatthe threat landscape itself is changingjust as quickly as corporate networks. When asked to name the three developments that will most greatly impact security operations over the next 12-18 months, advanced threats were the number one answer, nosing ahead of virtualization (number two) and the transition of mission critical enterprise apps to the cloud (number three).

However, the survey revealed that Security Operations teams are rising to the challenge. More than three-quarters believed their networks were more secure (55%) or just as secure (22%) than they were five years ago. Plus security teams identifiedthat automation would positively affect the accuracy of policy changes (33%), the lack of consistent processes across departments (25%), and the lack of network control(20%). This underscored the need for a complete automation suite designed to handle these issues with features such as topology mapping and one-click repair.

"It is clear that virtualization and the cloud deliver great benefits but also introduce greater complexity and unforeseen risks that must be addressed," said Kitov. "Our customers know that automation is necessary to properly safeguard today's networks and support the needs of the business. Tufin continues to add capabilities to our product suite to providethebest-of breed automation and orchestration solutions needed to deliver the efficiency, agility and collaboration required for their ongoing success."

About Tufin Technologies

Tufin® is the leader in Security Policy Orchestration, automating and accelerating network infrastructure changes while maintaining security and compliance. By improving network change processes, organizations using the Tufin Orchestration Suite&trade will have a positive impact on the business by reducing the time and cost spent implementing network changes by up to 80 %. Taking a holistic view of IT, the Tufin Orchestration Suite helps organizations automate security and efficiency into day-to-day operations, enabling them to be more agile and leverage technology to gain a competitive advantage. Founded in 2005, Tufin serves more than 1,300 customers in industries from telecom and financial services to energy, transportation and pharmaceuticals. Tufin partners with leading vendors including Check Point, Cisco, Juniper Networks, Palo Alto Networks, Fortinet, F5, Stonesoft, Blue Coat, McAfee and BMC Software, and is known for technological innovation and dedicated customer service.

For more information visit, or follow Tufin on:

• Twitter:

• Facebook:

• LinkedIn:

• BrightTalk:

• YouTube:

• The Tufin Blog:

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2014-10-24
adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX allows local users to read arbitrary files with root privileges by leveraging improperly protected setuid functionality.

Published: 2014-10-24
The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic.

Published: 2014-10-23
Untrusted search path vulnerability in Hamster Free ZIP Archiver allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

Published: 2014-10-23
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.

Published: 2014-10-23
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.