Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

8/30/2019
10:30 AM
Ori Eisen
Ori Eisen
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
50%
50%

To Navigate a Sea of Cybersecurity Solutions, Learn How to Fish

Three steps for relieving the pressure of picking the right tools.

In their classic rock song, Queen and David Bowie defined the feeling of being "Under Pressure" as "the terror of knowing what this world is about." Chief information security officers (CISOs) can relate: They must confront relentless threats that the hackers of the world create to trigger panic and bring down organizations — but they often struggle to find and deploy the products that will best protect the enterprise. This certainly puts them under pressure.

Much of the challenge stems from the overwhelming volume of products to consider: The global security solutions market is projected to grow to $133.8 billion in 2022, up from $103.1 billion this year, according to a forecast from International Data Corporation. CISOs are also dealing with more security vendors than ever, with 46% of organizations using more than 10 — up from just 28% that used that many in 2016, according to research from Cisco.

As a result, CISOs are constantly wading through an endless sea of solutions and vendors as they try to make the right choices. If they fail, they may be blamed for deployments that either introduced productivity-sapping friction (such as the unintended shutdown of a key app or system); killed legitimate, business-critical files and connections; or could not meet security requirements (such as ability to scale). These outcomes frequently cost CISOs their credibility, if not their jobs.

When I see firsthand what CISOs experience, I am often reminded of the old saying, "Give a man a fish, and you feed him for a day. Teach a man to fish, and you feed him for a lifetime." In this case, a "fish" is a security product. But learning how to catch that fish translates into evaluating new solutions that empower CISOs to take command of their security posture instead of simply buying a bunch of fish at the market and hoping for the best. This knowledge enables them to both effectively evaluate new ideas within the current no-margin-for-error climate, while reviewing tried-and-true solutions and vendor relationships to gauge whether they still provide enough value to keep in the mix.

In my more than two decades as a practitioner developing system infrastructure and implementing solutions, I've found it's worthwhile to continuously weigh the following three considerations:

Are your longtime vendors still innovating? In deciding between "new" and "tried and true," you need to assess whether longtime vendor relationships are still producing new advancements that will keep you ahead of cyberattackers. Vendors often get acquired because they've lost their original direction/focus. When this happens, it may be time to start looking for the next, hungry vendor. A sound cybersecurity strategy, after all, is as much about your vendor's state of mind as it is about products.

Are you holding vendors accountable? If you have a dozen businesses trying to get you to buy something, challenge them to validate their product performance claims. Ask vendors to invest their time and people into proving their capabilities and delivering tangible value, instead of sending out tools out of a box and leaving it up to you to get the most out of them. If they sincerely believe in what they're selling, they'll agree to this. If not, then you're better off moving on.

Are you testing products in a real environment? You can't find out if something will work if you're only testing it in a petri dish. Authentic environments bring authentic results. Vendors may push you to put a product into operation immediately, pointing to its successful performance in what the vendor considers a production environment. But results achieved in a managed setting don’t always provide a full picture of a solution's effectiveness. Press your vendors to relate as much real-world production insight as possible, but when you do deploy new technologies, try them out in a phased approach beginning with relatively less mission-critical users more tolerant of disruption. Be transparent and up-front with vendors about users' experience, and oblige them to resolve discrepancies where feedback differs from expectations before embedding products into strategic and indispensable business functions where reliable performance is vital.

Conclusion
In navigating the large sea of cybersecurity solutions, CISOs may often feel like they're drowning. That's understandable, and it underscores why they need to transition from a product-centric model to a strategy-driven one. By picking vendors that continue to innovate while they stand behind their offerings — and proving that they work by testing in real-life environments — they build confidence in the many choices they must make, now and in the future. That's when they can tackle anything that attackers throw at them. In other words, they take control of the pressure instead of letting the pressure control them.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "The Right to Be Patched: How Sentient Robots Will Change InfoSec Management."

Ori Eisen has spent the last two decades fighting online crime and holds more than two dozen cybersecurity patents. Prior to founding Trusona, he established online financial institution and e-commerce fraud prevention and detection solution 41st Parameter, acquired by ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
HackerOne Drops Mobile Voting App Vendor Voatz
Dark Reading Staff 3/30/2020
Limited-Time Free Offers to Secure the Enterprise Amid COVID-19
Curtis Franklin Jr., Senior Editor at Dark Reading,  3/31/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11547
PUBLISHED: 2020-04-05
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.
CVE-2020-11548
PUBLISHED: 2020-04-05
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
CVE-2020-11542
PUBLISHED: 2020-04-04
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.
CVE-2020-11533
PUBLISHED: 2020-04-04
Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material).
CVE-2020-11529
PUBLISHED: 2020-04-04
Common/Grav.php in Grav before 1.6.23 has an Open Redirect.