Opens in a new tab
vmblog logo 2024 wht (updated)

Lookout 2023 Predictions: Cybersecurity Outlook 2023 – Out with Siloed Security Solutions, In with Automation

Share: 

David Marshall | Published: December 15, 2022

vmblog-predictions-2023 

Industry executives and experts share their predictions for 2023.  Read them in this 15th annual VMblog.com series exclusive.

Cybersecurity Outlook 2023: Out with Siloed Security Solutions, In with Automation

By Sundaram Lakshmanan, CTO, Lookout

Historically, security has often been labelled as a drain on enterprise resources. But the reality is that data breaches are happening more frequently than ever. To tackle the new threat landscape ushered in by hybrid work, security needs to modernize and become a business enabler.

The fact of the matter is that a strong cybersecurity posture is essential not only for protecting sensitive data, but also for the overall resilience of the business itself. CISOs must adjust their security strategy to reflect the latest evolutions in the cyber threat environment so that they are able to confront security threats while simultaneously enhancing productivity and efficiency.

Siloed security technologies will become the weakest link

Specialized point products will become the Achilles’ heel of enterprise security. Put aside the problems or the breaches of the future for a moment. Even the current breaches we are seeing now cannot be prevented or responded to or remediated unless organizations start thinking about cloud-delivered, integrated security platforms. Without this, the problem will be harder and harder for companies using siloed point products- regardless of whether they’re hosted on-premises or in the cloud.

The warning signs are everywhere: data security best practices sometimes fall through the cracks and breaches are becoming incredibly complex. As data, devices, and users continue to become more interconnected, IT and security teams need to consolidate their security solutions to avoid the complexities of trying to secure data with multiple tools. The platform approach will help ensure that all data- regardless of whether it lives in the cloud, on-prem, or in a private app – is being protected under uniform data security policies.

For the next few years, this issue should be top-of-mind: there is simply no other way for enterprises to easily stop breaches or troubleshoot a breach or respond to a breach or understand the breach without the visibility and control that a platform approach can provide.

The secure services edge (SSE) market is proving that a combination of cloud access security broker (CASB), zero-trust network access (ZTNA), and secure web gateway (SWG) in a single platform is the most forward-looking approach to securing remote workers and protecting data across the modern enterprise infrastructure. A recent survey by Gartner, Inc. found that 75% of organizations are pursuing security vendor consolidation in 2022, up from 29% in 2020.

Security automation will be a massive differentiator (You need SASE for a real XDR)

DLP is one critical piece to the puzzle that lies before us, but the visibility and controls it provides are useless without security automation in place. To do a better job of protection, you need to have better network visibility (CASB, Endpoints, SWG, Internal Apps w/ ZTNA). One thing that we see that is currently missing is the SSE telemetry being an integral part of a real XDR.

Just about everyone has slapped the label of Extended Detection and Response (XDR) onto their Endpoint Detection & Response (EDR) solution, including SIEM vendors. This trend will no doubt continue. Nonetheless, XDR is still a valuable tool to have in place to address the security challenges of the future. After all, if you look at the kill chain of a ransomware attack, the organization’s EDR region is one of the first things bad actors will attempt to turn off.

XDR is more than endpoints and more than understanding your logs/visibility. Of course, you need both of the above, but more importantly, you need to put a “brain” behind it to predict breaches in real-time.

The status quo is no longer enough

To protect data while supporting work from anywhere, security operations need to untether themselves from the traditional siloed approach to deploying security products By taking advantage of cloud-native solutions and leveraging automation appropriately, CISOs will be in the best possible position to proactively protect their organizations while also distinguishing cybersecurity as an enabler of productivity and profitability.

##

ABOUT THE AUTHOR

Sundaram-Lakshmanan 

Sundaram brings more than 20 years of network and security product development experience to Lookout. As CTO and Head of Engineering for SASE products at Lookout, he is responsible for SASE cloud service, product vision and development. He joined Lookout through acquisition of CipherCloud, Inc. where he was the CTO and Head of Engineering and Product organizations. He joined CipherCloud through acquisition of Anicut Systems, the company he founded and lead as CEO to build Next-Gen Firewall-as-a-Service to help detect breaches with advanced ML. Prior to starting Anicut Systems, Sundaram was a Distinguished Engineer at Juniper Networks. Before that, he was a Software Architect at Blue Coat Systems (now Broadcom) and there he architected and delivered Secure Web Gateway (SWG)-as-a-Service. He has a successful track record of delivering multiple innovative first-to-market and market-leading security products, as well as building global engineering teams. Sundaram holds multiple patents in the space. He received a MS from the National University of Singapore in CIS with specialization in networking and cryptography, as well as a BE in Electrical Engineering from Regional Engineering College (NIT) Trichy, India.