Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

Security's Sea Change

The security boom is over... Long live the security boom

WASHINGTON -- Gartner IT Security Summit 2007 -- Security's rise to the top of the IT priority list -- and the top of the IT budget -- has peaked, and a gradual fall has begun, experts said at a Gartner conference here. But the technology and business challenges remain, and in many cases they will be assimilated into broader corporate, market, and product initiatives that will continue to grow.

"What we've been doing up until now has been a gigantic game of whack-a-mole," said John Pescatore, vice president and distinguished analyst at Gartner, in his keynote. "A problem pops up, and we try to push it back down. Then another one comes up, and we push that one down, often with a different hammer," he said, referring to the broad array of point products on the market.

"We're about to transition to a game that's a lot more like chess," Pescatore said. "The bad guys are like the white pieces -- they always get to move first. But just because they go first doesn't mean they always win. We need to create a situation where we are forcing them onto parts of the board where we know we're strongest."

In a lunch presentation, security expert Bruce Schneier of BT Counterpane also predicted a sea change. "Long term, I don't really see a need for a separate security market," he said, calling for greater integration of security technology into everyday hardware, software, and services.

"You don't buy a car and then go buy anti-lock brakes from the company that developed them," Schneier quipped. "The safety features are bought and built in by the company that makes the car." Major companies such as Microsoft and Cisco are paving the way for this approach by building more and more security features directly into their products, he noted.

"That doesn't mean that security becomes less important or that there won't be innovation," Schneier said. "But in 10 years, I don't think we'll be going to conferences like these, that focus only on security. Those issues will be handled as part of broader discussions of business and technology."

Gartner's numbers support the bold predictions of the speakers. Security, which had been Gartner clients' top priority in 2005 and number two in 2006, dropped to number six this year, Pescatore reported. And after breaking into the top 10 business priorities for the first time last year (it was number seven), security has once again fallen out of clients' top 10 lists.

The change in priorities will necessarily bring about a change in security spending practices, Pescatore predicted. Security organizations in coming years will be encouraged to cut spending and "operationalize" security practices to increase automation and improve efficiency, he said.

For the last couple of years, security spending has been growing twice as fast as overall IT spending, reflecting a broad, "reactive" trend that was spurred by news of security breaches, Pescatore observed. "Unfortunately, most organizations have found that there's very little correlation between spending and actual security, and a lot of businesspeople are now asking where the benefit is." Gartner is predicting a 9.3 percent increase in security spending for 2007, but the spree is cooling off from previous years, he said.

As attacks become more targeted, there is a drop in the number of wide-ranging attacks, such as worms and spam-based phishing exploits, that attract the media's attention, Pescatore noted. "This makes some people believe that the threat is decreasing, when in fact, the actual damage caused [by security breaches] is increasing."

But security spending is becoming harder to track as well, Pescatore said. For example, many companies are now building more spending into their application development process, "so the money is coming out of the app dev budget, not the security budget."

Regulatory compliance, which has been a key driver for security technology spending over the last couple of years, is also cooling off, at least on the IT side. "What we've seen recently is that nearly half of the compliance deficiencies that companies encounter are on the accounting side, while less than 5 percent are IT systems related," Pescatore said. That auditing experience may help break the wave of companies spending heavily on security technology in order to speed compliance, he predicted.

But unlike Schneier, Pescatore rejected the notion that the security industry will consolidate into a few large players or disappear altogether. He showed a graph of security-related mergers and acquisitions over the past six years, and it shows valleys and peaks, culminating with almost 30 deals in 2006.

"What that tells us is that the market is very cyclical," Pescatore said. "We think the activity will level off this year, and there will continue to be startups that come in with new products."

Consolidation at the enterprise level is overrated, he stated. "In reality, very few companies would be better off if they only had one security vendor," Pescatore said. "They might save some time because they wouldn't have so many vendors to call, but a lot of the innovation continues to come from smaller vendors."

— Tim Wilson, Site Editor, Dark Reading

  • BT Counterpane
  • Cisco Systems Inc. (Nasdaq: CSCO)
  • Gartner Inc.
  • Microsoft Corp. (Nasdaq: MSFT) Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    How Attackers Could Use Azure Apps to Sneak into Microsoft 365
    Kelly Sheridan, Staff Editor, Dark Reading,  3/24/2020
    Malicious USB Drive Hides Behind Gift Card Lure
    Dark Reading Staff 3/27/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Write a Caption, Win a Starbucks Card! Click Here
    Latest Comment: This comment is waiting for review by our moderators.
    Current Issue
    6 Emerging Cyber Threats That Enterprises Face in 2020
    This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
    Flash Poll
    State of Cybersecurity Incident Response
    State of Cybersecurity Incident Response
    Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-10940
    PUBLISHED: 2020-03-27
    Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.
    CVE-2020-10939
    PUBLISHED: 2020-03-27
    Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.
    CVE-2020-6095
    PUBLISHED: 2020-03-27
    An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
    CVE-2020-10817
    PUBLISHED: 2020-03-27
    The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress allows SQL Injection. NOTE: this product is discontinued.
    CVE-2020-10952
    PUBLISHED: 2020-03-27
    GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.