Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

9/20/2017
11:55 AM
50%
50%

SecureAuth to Merge with Core Security

K1 Investment Management, which owns Core Security, plans to acquire the identity management and authentication company for more than $200 million.

K1 Investment Management plans to acquire SecureAuth for more than $200 million and merge it with its portfolio company Core Security, SecureAuth CEO Jeffrey Kukowski told Dark Reading.

The merger, announced today, is expected to close within a matter of days pending US government regulatory approval, says Kukowski, who will be CEO of the as-yet-unnamed combined company.

SecureAuth is the sixth company K1 Investment Management plans to merge with Core Security, which last year became an amalgamation of Courion, Core Security, SecureReset, Bay 31, and Damballa.

The merger will bring SecureAuth's laser focus on authentication to the table and round out Core Security's offerings, said Frank Dickson, IDC research director, in the announcement.

Core Security has three product lines: Core Network Insight, for advanced threat detection; Threat and Vulnerability Management, for vulnerability testing and assessment; and Identity and Access Management & IAM, a suite of governance tools for identity management and access.

"What is exciting to me is that this merger is not just complementary but it completes the view. It finishes that picture," says Chris Sullivan, CTO and CISO of Core Security.

Core Security has technology to address the network, endpoint and vulnerabilities but lacked an identity piece.

SecureAuth IdP performs single sign-on, multi-factor authentication, and behavior-based authentication. 

Under the merger, the combined companies will address vulnerabilities, identities, networks and endpoints with an identity-based security automation platform, which aims to shorten the time it takes for enterprises to see, respond to and remediate attacks.

When cybercriminals attack, they don't remain just within one security silo such as a secured network, says Keith Graham, SecureAuth CTO. However, SOCs are not designed to peer into multiple silos to respond to a breach. As a result, the merger's platform is designed to bring greater visibility to threats.

Customer Expectations

The combined company will have over 1,500 customers, some of which are already customers of both SecureAuth and Core Security. Sullivan says Core and SecureAuth were already familiar with one another prior to the merger announcement. Some of Core's customers would request identity access technology and, as a result, the sales teams for both companies would jointly meet with those customers.

Little overlap exists between the two companies in products and markets, say Kukowski and Sullivan. They pointed to some duplication in password protection offerings and noted each company has a presence in the healthcare and financial services industries.

The companies will begin integration in the fourth quarter, and over the next three-to five-months a decision will be made as to the name of the merged company and its products, Kukowski says.

SecureAuth's main product, SecureAuth IdP, will be integrated with Core Network Insight, followed by Core's Threat and Vulnerability Management, and, then, Core's Identity and Access Management & IAM, Graham says.

"There is consolidation occurring in the security industry where vendors are looking to add new product categories to their portfolio in order to deliver a more complete product suite for their customers," says Joseph Blankenship, a senior analyst with Forrester Research. "This can be an advantage for the customers who are dealing with product sprawl and multiple vendor solutions."

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
martin.george
50%
50%
martin.george,
User Rank: Apprentice
9/25/2017 | 11:14:23 AM
Nice post
That is really interesting theme, what can I say) 
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19071
PUBLISHED: 2019-11-18
A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19072
PUBLISHED: 2019-11-18
A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.
CVE-2019-19073
PUBLISHED: 2019-11-18
Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config_pipe_credits() function, the htc_setup_complete() function, ...
CVE-2019-19074
PUBLISHED: 2019-11-18
A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.
CVE-2019-19075
PUBLISHED: 2019-11-18
A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c in the Linux kernel before 5.3.8 allows attackers to cause a denial of service (memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.