logo
Symantec

Predicts 2015: Infrastructure Protection

Analysts are looking ahead to notable trends in network sandboxing, cloud services, enterprise protection platforms, the supply chain and country-specific buying restrictions. CISOs should monitor these near-term events to adapt buying and risk management processes or evolve security practices.

Key Findings
  • CASBs help enforce security policies in the data path between the user and multiple SaaS applications by focusing on a single console that can support four key pillars: visibility, compliance, data security and threat prevention.
  • Sandboxing-from-a-platform solutions are being rapidly adopted.
  • Supply chains demand an improved way to link users and physical assets more effectively and more securely.
  • Where point security products emerge for endpoints, the majority of enterprises will wait for incumbent EPPs to incorporate that feature rather than deploy an additional product.
  • For most enterprises, avoiding products from the U.S. and China will not greatly reduce their vulnerability to a motivated nation-state attack.
Recommendations
  • Leverage the visibility functions of CASBs to better understand user behavior in authorized and unauthorized SaaS applications.
  • Evaluate your organization's breach detection capabilities, and decide whether you need sandboxing.
  • Establish cybersecurity requirements for the supply chain, and incorporate the necessary steps in contracts and in integration with partners to ensure that those requirements are met.
  • Prioritize deploying a single endpoint agent where possible.
  • Analyze the impact of reduced availability of support when purchasing or renewing products from a competing geography depending on where your IT security operations are located.
Strategic Planning Assumptions

By 2018, 50% of organizations using multiple SaaS applications for business-critical workloads will use CASBs, up from 5% today.

By 2018, 85% of new deals for network sandboxing functionality will be packaged with network firewall and content security platforms.

Through 2020, supply chain security failures will force 50% of digital businesses to negotiate partner contracts to share risk and liability.

Through 2020, fewer than 5% of network security vendors will gain traction in the EPP market because of buying center boundaries.

By 2020, more than 10% of RFPs for network security products and services will exclude vendors from China and the U.S.

Analysis

Every year, Gartner analysts offer their predictions on the key issues facing the markets they cover. Gartner's security analysts have developed a set of predictions in the infrastructure protection space for 2015 and beyond. Chief information security officers (CISOs), network security managers, and other cloud and supply chain decision makers should consider these forward-looking Strategic Planning Assumptions when allocating resources and selecting products and services.

What You Need to Know

In this document, Gartner's risk management and security analysts are looking ahead of present day markets for notable trends in cloud services, network sandboxing and enterprise protection platforms (EPPs) that will influence future buying or will consolidate major security capabilities from what is now found in disparate functionality or services. Analysts are also looking ahead to areas where security is underrepresented, such as within the supply chain, and to the potential for the Internet of Things to simultaneously shape and adversely affect present-day security practices. Additionally, analysts are closely watching the evolution of specific, security-buying restrictions between countries where mistrust is accelerating.

Strategic Planning Assumptions

Strategic Planning Assumption: By 2018, 50% of organizations using multiple SaaS applications for business-critical workloads will use cloud access security brokers (CASBs), up from 5% today.

Analysis by: Sid Deshpande and Craig Lawson

Key Findings:

End-user spending on SaaS is estimated to grow from $26.6 billion in 2014 to $55.5 billion by 2018. As SaaS usage becomes common for business-critical workloads, there is a clear need for additional controls to administer security controls across multiple SaaS platforms. Although many SaaS providers offer assurances around data availability, the end user is ultimately accountable for the confidentiality and integrity of data stored in and accessed via a SaaS platform. CASBs offer IT security leaders the opportunity to be seen as positive contributors to the cloud adoption conversation, instead of a perceived roadblock to business units that seek to adopt SaaS applications.

CISOs and other security leaders should pay attention to the following emerging trends:

  • Enterprise end-user computing is shifting rapidly toward more mobile usage, such as smartphones and tablets. SaaS applications are a natural companion to this computing model, which is fueling the growth in enterprise SaaS.
  • Gartner's 2014 cloud adoption survey revealed that 90% of respondents who indicated that they are currently making use of SaaS expect it to constitute more than half of their enterprise application spending by 2018.
  • Security features offered by individual SaaS providers are useful, but are restricted to the SaaS offering in question and are of limited value in containing risks associated with behavior of approved SaaS users.
  • CASBs allow IT security professionals to enforce security policies in the data path between the user and multiple SaaS applications by focusing on a single console that can support four key pillars: visibility, compliance, data security and threat prevention.
  • As CASB solutions evolve, threat prevention capabilities will support a wider range of cloud applications and infrastructure, so enterprises will view spending on CASB to be synonymous with cloud spending.

Market Implications:

The level of importance assigned to each of the four CASB pillars (visibility, compliance, data security and threat prevention) depends on the types of SaaS use cases implemented by an organization. The biggest market impact will be made by those CASB platforms that are able to function as a single point of control across multiple SaaS applications. As business-critical SaaS use cases become more common, CASB platforms that are able to better integrate with existing security infrastructure will benefit the most from enterprise spending on SaaS security.

Recommendations:

For CISOs and security managers:

  • Develop a strategy for the controlled use of SaaS that includes mechanisms such as CASB that can flexibly provide a growing set of controls across multiple SaaS services simultaneously.
  • Leverage the visibility functions of CASBs to better understand user behavior in authorized and unauthorized SaaS applications.
  • Proactively recommend SaaS applications that are business ready, appropriate to your use cases, and help meet security and governance standards.
  • Deploy data security (encryption or tokenization) to protect the most sensitive data and to meet data residency and compliance issues.
  • Deploy threat-prevention features of CASB to provide coverage where the use of traditional technologies is not effective, and when desired SaaS applications lack sufficient security and control functionality.

Strategic Planning Assumption: By 2018, 85% of new deals for network sandboxing functionality will be packaged with network firewall and content security platforms.

Analysis by: Adam Hils

Key Findings:

For the past three years, lean-forward organizations have been rightly wary of an advanced threat environment in which bad actors innovate faster than traditional blocking mechanisms such as firewalls, intrusion prevention systems (IPSs) and secure Web gateways can react. In response, a few privately funded startup vendors introduced advanced threat detection approaches. The most widely adopted advanced threat detection technique deployed is network malware sandboxing.1 Potential malicious files are pulled off the wire and detonated in a virtual environment where the effects on "real" endpoint traffic destinations are observed. So far, this approach has appealed to well-staffed incident response teams.

Recently, several very high-profile breaches have broadened the perceived need for zero-day malware detection in a sandbox, but it can increase costs for the midsize- or understaffed security client. Incumbent security platform vendors introduced less costly, often cloud-based, malware detonation sandboxes as platform extensions. CISOs and security managers should be aware of the following emerging trends:

  • When comparing platform extensions to pure-play appliances, the appliance solutions often offer a wider range of file types analyzed, a superior ability to identify malicious traffic and finer-grained identification of infected endpoints.
  • Platform vendors often offer a subset of the pure-play capabilities, providing a "good enough" solution at a lower cost.
  • Sandboxing-from-a-platform solutions are being rapidly adopted. In a very fast-growing market, platform solutions are gaining faster than pure-play solutions.
  • SMBs and late adopters will move toward adopting sandboxing features associated with their incumbent platforms.

Near-Term Flags: By the close of 2015, at least two publicly held platform vendors will announce greater than 50% attach rates on new deals for their sandbox offerings.

By 2016, all pure-play sandboxing vendors remaining in the market will have diversified their portfolios to include such complementary techniques as network forensics, endpoint forensics, endpoint infection containment, botnet detection, IPSs and incident response.

Market Implications:

As platform extension adoption increases, buyers with flat or limited IT security budget may be forced to choose between established security controls such as IPSs or sandboxes. Customers could include sandboxing as a requirement in firewall and secure Web gateway RFPs. The entire market will continue to grow rapidly. However, as cybercriminals and attackers develop sophisticated sandbox evasion techniques, buyers could require complementary approaches. Pure-play sandboxes without complementary functionalities could diversify or begin to exit the market– sometimes via acquisition. Platform vendors without sandboxing features in-house may find partnering or API strategies ineffective, and will white-label solutions or acquire them.

Recommendations:

For CISOs:

  • Assess your organization's main threat vectors, and decide whether targeted malware justifies an investment in sandboxing.
  • Determine whether you need best of breed for a premium price or "good enough" for a 15% to 30% cost uptick to existing platforms.
  • Demand that existing platform vendors reveal their road maps around sandboxing and other advanced threat approaches.
  • If considering pure-play solutions, investigate prospects for long-term vendor viability and planned road maps for product diversification.

For security managers evaluating sandboxes:

  • Decide where in the network it makes sense to implement sandboxes: at network ingress/egress points? At the Web gateway? At the email gateway?
  • Investigate the sandboxing capabilities of your existing platform vendors versus alternative platform vendors and pure-play solutions.
  • Perform proof of concept (POC) exercises with a shortlist of candidates to compare results and justify potential cost increases.
  • Strategic Planning Assumption: Through 2020, supply chain security failures will force 50% of digital businesses to negotiate partner contracts to share risk and liability.

    Analysis by: Earl Perkins

    Key Findings:

    An enterprise's resource transport, logistics and service systems, and its myriad supplier partners introduce complexity for cybersecurity planning and management. Organizations have their own risk and security management teams with the authority to establish secure practices and infrastructure. However, they have little authority or influence over their supply chain partners' ongoing risk and security management – particularly when integrating process, networking and services across the chain. Organizations may depend on partners that also depend on additional partners. In IT, this multipartner dependency can often be found in security and risk management that is spread across a variety of cloud service providers. When combined with physical brick-and-mortar providers across the supply chain, the problem becomes acute. The complexity of supply chain relationships increases the risk CISOs face in managing across these partners. CISOs should expect the following trends to emerge:

    • With the Internet of Things (IoT), improved and dynamic monitoring and control across the supply chain will be possible, but a means to coordinate that capability must be created where needed.
    • Supply chains demand an improved way to link users and physical assets more effectively. Physical assets must be digitized and incorporated into a digital business strategy if supply chain management is to evolve.
    • Without a means to deploy a holistic risk and security program that takes transport, logistics and services programs into account, businesses with extended supply chain requirements remain at risk.

    Market Implications:

    Future supply chains must integrate and secure the digital and physical worlds of customers to be competitive. Major initiatives for supply chain cybersecurity must secure tracking of assets, loss prevention, inventory management, transportation, logistics, payment systems, traffic management, and transportation asset tracking and control.

    The business value of cybersecurity will vary per the needs of various industry segments, proposed uses, or business solutions and regions. A new style of cybersecurity negotiation will identify common gaps and weaknesses between buyer and supplier, and attempt to create an integrated and mutually beneficial approach to protecting the buyer/supplier relationship.

    Recommendations:

    • End users should establish cybersecurity requirements and standards for their supply chain that reflect the suppliers' digital risk and liability and incorporate the necessary steps in contracts and in integration with partners to ensure that those requirements are met.
    • Suppliers should evaluate their transport, logistics and services in the light of cybersecurity to determine weaknesses in process, infrastructure and connectivity, and to take early steps to correct in preparation for negotiations with their customers.
    • Government agencies should seek to enable a business environment that encourages buyer/supplier collaboration and provide timely threat information and advice to enhance such collaboration.

    Strategic Planning Assumption: Through 2020, fewer than 5% of network security vendors will gain traction in the EPP market because of buying center boundaries.

    Analysis by: Neil MacDonald and Greg Young

    Key Findings:

    EPPs exemplify the desire by organizations to have as few agents as possible on endpoints. Those enterprises willing to deploy multiple endpoint security agents are niche or are a minor segment of the market. Additional agents incur greater risk of interfering with applications, complicating support resolution with additional alerts and having to update and deploy products. Those exceptions are usually characterized as having a very low risk acceptance, a standard desktop and mobile image and platform, and other use cases where security trumps functionality. Financial organizations such as banking and military defense industries are examples.

    In most cases, EPP and network security have unique buying and operations centers with different selling channels. Historically, there are few exceptions of vendors having success that crosses the endpoint/network operations line (other than VPN agents), but there are many examples of vendors retracting from the other market. CISOs and network security buyers should understand the following technology and buying trends:

    • There is an advantage to having visibility shared between the endpoint and network security safeguards. Having knowledge of the state or activities of an endpoint can make for better efficacy and level of confidence in alerts.
    • Those endpoint agents from network vendors (other than VPN clients) that have been in the market for some time have not had any meaningful traction.
    • Where point security products emerge for endpoints, the majority of enterprises will wait for incumbent EPPs to incorporate that feature rather than deploy an additional product.
    • Network security vendors are not usually versed in the issues of delivering or supporting products that address the endpoint.

    Market Implications:

    Network security vendors will likely not have any meaningful market success unless they develop a full, pure-play EPP that replaces incumbent EPP rather than only adding an additional agent. Gartner does not believe that the cost of entry and economics of the EPP market will be acceptable to the focus and balance sheets of most network security vendors.

    Enterprises will likely continue to seek a single EPP and may look to their network security vendors to share intelligence through third-party ecosystems, rather than deploy additional endpoint agents or seek an EPP from their network security vendors.

    Recommendations:

    • Continue to prioritize, deploying a single endpoint agent where possible.
    • Evaluate additional EPP agents only in special circumstances or when having accounted for the impact on operations and support.

    Strategic Planning Assumption: By 2020, more than 10% of RFPs for network security products and services will exclude vendors from China and the U.S.

    Analysis by: Greg Young

    Key Findings:

    Gartner market share data indicates an increasing bifurcation in international sales of security products, services and managed services between the United States and China.2 Gartner believes this prediction extends to countries such as the Russian Federation, Brazil and Germany, where legislation has been passed or considered, protecting data sovereignty.

    Organizations in each country increasingly buy made-at-home security solutions. Such market activity is normal in IT, because localization has advantages such as language support. However, the market share shift in security is becoming more evident as a result of concerns over state-sponsored surveillance. The Edward Snowden revelations allege supply chain integrity compromises by governments, fueling suspicions already aroused by public accounts of state-sponsored cyberattacks and infiltrations. Those organizations with particular national sensitivities such as governments, defense contractors and critical infrastructure – which already have procurement limitations – are experiencing deeper buying restrictions. CISOs and other security solution buyers should watch the following emerging trends:

    • There are already passive supply chain and procurement impediments in both U.S. and China to procuring security products for use in governments and some industries, such as requirements for specific certifications. Less explicit or soft bias is already observed by Gartner in procurement when vendors are excluded via subjective criteria. However, the motivation is to exclude certain countries of origin.
    • Many revelations have shown that the state-sponsored product compromises have been done later in the supply chain. A motivated state can place a Trojan horse into products notwithstanding the origin. Advanced nation states have been shown to compromise products no matter the origin.
    • State surveillance via lawful intercept and other practices impact cloud providers, telecommunications and related service offerings. State surveillance based on country of operation – even when the target has broken no laws and no warrants have been issued – can also affect security products, such as those found when back doors are installed in products.
    • Avoiding products from the U.S. and China for most enterprises will not greatly reduce your vulnerability to a motivated nation-state attack.

    Market Implications:

    Network security market share for products and services is likely to continue to bifurcate along national lines in each country. Brazil, for example, is a country that has reacted strongly to intelligence-gathering reports and is imposing some of the most stringent data residence protection measures for federal agencies that will benefit Brazilian security, cloud and service providers. The new law, Marco Civil, extends law enforcement access to data outside of Brazil's borders.3

    No matter the country of origin, most organizations will not be highly impacted, as the risks of state-sponsored threats are akin to those posed by general threats and stopped by the same practices.

    Recommendations:

    • CISOs should analyze the impact of reduced availability of support when purchasing or renewing products from a competing geography, depending on where their enterprise IT security operations are located.
    • IT security product and service providers should tune business planning to modify their RFP "bid/no-bid" processes and business expansion plans, recognizing changes in national buying tendencies for certain verticals.
    • CISOs should be consistent in their strategies: They should not limit the source of equipment procurement, but should not restrict cloud hosting of their data.
    • CISOs should differentiate between protection from warrantless surveillance by any state, and that of avoiding products from foreign countries to avoid a flawed strategy.
    • Agencies and enterprises with state-based sensitivities should use encryption, monitoring and a consistent cloud data security strategy as the best risk reduction mechanisms.
    A Look Back

    In response to your requests, we are taking a look back at some key predictions from previous years. We have intentionally selected predictions from opposite ends of the scale – one where we were wholly or largely on target, as well as one we missed.

    On Target: 2011 Prediction – By 2015, more that 50% of enterprises will have instituted "default deny" policies that restrict the applications users can install.

    A recent Gartner survey4 revealed that 22% of organizations do not allow users to have admin rights, and 30% already use dedicated tools from Bit9, Kaspersky Lab, McAfee or others to lock at least some machines down to known good applications. Therefore, roughly 50% of organizations already have a default deny policy for at least some PCs. Furthermore, in the same survey, 18% of respondents indicated that they were actively considering a default deny policy.

    The dedicated application control market, which represents the purest form of a default deny environment, has been hampered by a lack of awareness, a lack of solutions and a perception by IT departments that it is difficult to implement. However, recent highly publicized breaches and the failure of antivirus vendors to keep up with new malware are accelerating interest in application control. Availability of the solution is also improving as the EPP vendors add this capability and Windows 10 introduces native "enterprise lockdown" capability. Finally, adoption pioneers are contributing to the quality of implementation guidance, making deployments less of an exploration.

    Missed: 2012 Prediction – By 2014, a worm exploiting cloud-based personal file synchronization services will cause massive, costly enterprise data loss and service disruption.

    Although the usage of enterprise file synchronization and sharing (EFSS) has grown significantly, it has not proven to be a significant point of malware entry. Commercial file synchronization and sharing products, including those based in the public cloud, have provided reliable and secure service. A dramatic security failure attacking a large number of desktops simultaneously remains a purely hypothetical form of incident.

    The security failures that have been experienced have been of relatively minor impact, and have mostly been experienced by organizations that allow ad hoc use of EFSS. These include the inadvertent placement of sensitive data into publicly shared directories visible to the entire Internet, an account takeover by obtaining a customer's password, and the placement of regulated data (particularly personally identifiable information) into the personal accounts of services that have not been approved and contracted for by the enterprise. A small rate of these sorts of security failures is virtually inevitable if end users are not provided any support, and failures are most likely to occur when users are allowed to obtain their own cloud-based file-sharing service. The best way to reduce the rate of EFSS security incidents is to choose an enterprise-ready service, manage accounts and service configuration, and provide appropriate use guidelines to your employees.

    Evidence

    1 W. Shanks, "Enhancing Incident Response Through Forensic, Memory Analysis and Malware Sandboxing Techniques," SANS Institute paper, 25 March 2014.

    2 J. de Jong-Chen, "U.S.-China Cybersecurity Relations: Understanding China's Current Environment," Georgetown Journal of International Affairs, 15 September 2014.

    3 A. Edgerton, "Brazil House Passes Internet Bill as Rousseff Drops Data Demand," Bloomberg News, 25 March 2014.

    4 Online survey of 140 EPP reference customers conducted by Gartner in 3Q13.

    Source: Gartner Research, G00264103, Ray Wagner, Neil MacDonald, Adam Hils, Greg Young, Earl Perkins, Sid Deshpande, Craig Lawson, Jay Heiser, Peter Firstbrook, 13 November 2014