Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Cisco Swallows Securent for $100M

Reveals plans to tie storage, network, and SAAS security together

Nov 01, 2007 | 07:37 AM

By DarkReading
DarkReading

By James Rogers, November 1, 2007, 3:00 PM

Cisco threw down $100 million in cash to acquire privately held database security startup Securent earlier today.

The deal, which will be Cisco's 125th acquisition, will see Securent's core technology extend into other parts of the networking vendor's product line, according to Joe Burton, CTO of unified communications at Cisco.

"We will keep selling their product as it is [but] we really see the possibility of growing Securent into something bigger and richer," he says, explaining that this could encompass security for voice and instant messaging applications.

Securent's flagship product is its Entitlement Management Solution (EMS), which uses SQL agents to intercept requests for data from users before they reach the Oracle databases and Microsoft Sharepoint servers.

EMS can then either deny or allow access to the data according to the security policies put in place by each organization.

Cisco is now planning to tie the code behind EMS to other parts of its portfolio. "We primarily see this working by building connectors to other products," he says, explaining that the startup's technology could be integrated with Cisco's Network Admission Control (NAC) offerings, IP Phones, and its Software as-a-Service (SAAS) products.

"We do see some opportunities over time to integrate Securent's policy management with our other SAAS offerings such as IronPort and WebEx," adds Burton.

Cisco has been making a song and dance about Web 2.0 technologies for some time now, snapping up messaging security specialist IronPort for $830 million earlier this year and throwing down $3.2 billion for WebEx in March.

Although Securent is a minnow compared to IronPort and WebEx, the startup will nonetheless form the basis of a new unit, called policy business, located within Cisco's Collaboration Services Group.

This unit will be headed by Securent's CEO and former HP exec Rajiv Gupta, who will be joined by the rest of the startup's management team and workforce, according to Burton.

The startup has a total of 57 employees on its staff, split between its headquarters in Mountain View, Calif., and its R&D base in Hyderabad, India.

"We're keeping both their Mountain View and Indian employees, [but] sometime over the next few months, as appropriate, the Mountain View employees will move to the nearby Cisco campus," says Burton.

Securent is not the only vendor playing in security policy space, and the startup is up against CA's Embedded Entitlements Manager, and BEA, which also offers "entitlement" software as part of its Aqualogic product.

Cisco's Burton told Byte and Switch that Securent was not the only security specialist that Cisco looked at prior to this acquisition. "This was our number one pick by far," he says, but would not say which other vendors were in the frame.

Securent has managed to rack up about 15 customers since it launched its software since late 2005. These include Qualcomm, Credit Suisse, First American Corporation, and the Ontario Teachers' Pension Plan.

The Securent acquisition is expected to close in the second quarter of Cisco fiscal year 2008.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Byte and Switch's editors directly, send us a message.

  • BEA Systems Inc. (Nasdaq: BEAS)
  • CA Inc. (NYSE: CA)
  • Cisco Systems Inc. (Nasdaq: CSCO)
  • Credit Suisse
  • Hewlett-Packard Co. (NYSE: HPQ)
  • IronPort Systems
  • Qualcomm Inc. (Nasdaq: QCOM)
  • Securent
  • WebEx Communications Inc. (Nasdaq: WEBX)


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)