Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Is Bharosa Acquisition Bait?

Authentication specialist may be for sale, but its CEO is not looking to pair up with another security pure-play

Jan 28, 2007 | 08:00 AM

By James Rogers
DarkReading

Whether authentication specialist Bharosa is just flirting or looking for a more lasting commitment, speculation is afoot about the startup's future.

"I happen to know that they are for sale, they have hired bankers," said an industry analyst, who asked not to be named. "The whole notion of authentication is heating up, particularly around these financial services breaches."

Bharosa is a bit more coy. "I have no comment about being in play," says CEO Jon Fisher, while admitting that his firm has received acquisition overtures. But he does not want to see the company fall "into the wrong hands."

What does he mean by that? "Selling the company to another pure play security vendor is not what I envision," he says. "I don't want to make a wrong move where the technology can't be leveraged around the world."

Bharosa essentially offers two products: "Tracker" verifies the device a user is coming from and assesses the threat the user poses; "Authenticator" is a virtual token to protect sensitive data, such as passwords or PINs. (See Bharosa Launches 3.5 and National City Taps Bharosa.)

"To our knowledge, they are the only pure-play vendor doing strong authentication and fraud detection," said Nick Selby, a senior analyst at The 451 Group, highlighting a recent burst of activity in this space, in a note last week. "The last acquisition was Entrust's acquisition of Business Signatures for $50 million," he noted, adding that RSA also bought security startups PassMark and Cyota. (See Entrust Bags Business Signatures, RSA Snatches Up Competition Passmark, and Add Another Bolt to the Cyber Door.)

The analyst adds that Bharosa's technology could dovetail nicely with any number of large vendors: "It could fit nicely into the portfolios of a number of companies, including Verisign, RSA, IBM, and even, conceivably, Oracle."

Bharosa claims 30 enterprise customers, which include three of the top 10 U.S. banks and five of the country's top 25 credit unions. Notable clients include Wells Fargo, the U.S Air Force, and the Desert Federal Credit Union. (See Banking on Multifactor Authentication.)

CEO Fisher says the 50-employee company, which has racked up $2 million in funding, has been profitable for a year. "We're south of $20 million in annual revenue, but certainly north of $5 million," he adds.

Our anonymous source thinks that even if Bharosa gets bought, it is not likely to involve mega-bucks: "It would be a modest valuation –- if they get taken out for $30 million, they would be dancing in the halls."

For a big-name vendor, a deal of that size would hardly break the bank, according to the analyst. "For a company like EMC, a $20 million acquisition doesn't have to go through a lot of approvals," he says. "Cisco is making all kinds of acquisitions in the security space, so it would not be a stretch for them to buy someone in authentication."

— James Rogers, Senior Editor Byte and Switch

  • Bharosa Inc.
  • Cisco Systems Inc. (Nasdaq: CSCO)
  • EMC Corp. (NYSE: EMC)
  • Entrust Inc.
  • The 451 Group
  • IBM Corp. (NYSE: IBM)
  • RSA Security Inc. (Nasdaq: EMC)
  • VeriSign Inc. (Nasdaq: VRSN)


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)