Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

9/20/2017
11:55 AM
50%
50%

SecureAuth to Merge with Core Security

K1 Investment Management, which owns Core Security, plans to acquire the identity management and authentication company for more than $200 million.

K1 Investment Management plans to acquire SecureAuth for more than $200 million and merge it with its portfolio company Core Security, SecureAuth CEO Jeffrey Kukowski told Dark Reading.

The merger, announced today, is expected to close within a matter of days pending US government regulatory approval, says Kukowski, who will be CEO of the as-yet-unnamed combined company.

SecureAuth is the sixth company K1 Investment Management plans to merge with Core Security, which last year became an amalgamation of Courion, Core Security, SecureReset, Bay 31, and Damballa.

The merger will bring SecureAuth's laser focus on authentication to the table and round out Core Security's offerings, said Frank Dickson, IDC research director, in the announcement.

Core Security has three product lines: Core Network Insight, for advanced threat detection; Threat and Vulnerability Management, for vulnerability testing and assessment; and Identity and Access Management & IAM, a suite of governance tools for identity management and access.

"What is exciting to me is that this merger is not just complementary but it completes the view. It finishes that picture," says Chris Sullivan, CTO and CISO of Core Security.

Core Security has technology to address the network, endpoint and vulnerabilities but lacked an identity piece.

SecureAuth IdP performs single sign-on, multi-factor authentication, and behavior-based authentication. 

Under the merger, the combined companies will address vulnerabilities, identities, networks and endpoints with an identity-based security automation platform, which aims to shorten the time it takes for enterprises to see, respond to and remediate attacks.

When cybercriminals attack, they don't remain just within one security silo such as a secured network, says Keith Graham, SecureAuth CTO. However, SOCs are not designed to peer into multiple silos to respond to a breach. As a result, the merger's platform is designed to bring greater visibility to threats.

Customer Expectations

The combined company will have over 1,500 customers, some of which are already customers of both SecureAuth and Core Security. Sullivan says Core and SecureAuth were already familiar with one another prior to the merger announcement. Some of Core's customers would request identity access technology and, as a result, the sales teams for both companies would jointly meet with those customers.

Little overlap exists between the two companies in products and markets, say Kukowski and Sullivan. They pointed to some duplication in password protection offerings and noted each company has a presence in the healthcare and financial services industries.

The companies will begin integration in the fourth quarter, and over the next three-to five-months a decision will be made as to the name of the merged company and its products, Kukowski says.

SecureAuth's main product, SecureAuth IdP, will be integrated with Core Network Insight, followed by Core's Threat and Vulnerability Management, and, then, Core's Identity and Access Management & IAM, Graham says.

"There is consolidation occurring in the security industry where vendors are looking to add new product categories to their portfolio in order to deliver a more complete product suite for their customers," says Joseph Blankenship, a senior analyst with Forrester Research. "This can be an advantage for the customers who are dealing with product sprawl and multiple vendor solutions."

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
martin.george
50%
50%
martin.george,
User Rank: Apprentice
9/25/2017 | 11:14:23 AM
Nice post
That is really interesting theme, what can I say) 
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9405
PUBLISHED: 2020-02-26
IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.
CVE-2020-9406
PUBLISHED: 2020-02-26
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
CVE-2020-9407
PUBLISHED: 2020-02-26
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.
CVE-2020-9398
PUBLISHED: 2020-02-25
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
CVE-2015-5201
PUBLISHED: 2020-02-25
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows r...