Remember when CheckPoint were just firewalls, Symantec were just AV, and security companies could just provide consultancy?
Neither do I, it’s been too long.
Security has now become too complex, and too important to play the mix-and-match game with individual vendors, it’s only integrated, multi-function, solutions that will now make the cut. But there are so few of them out there. Well, so few that actualy do what they say they do anyway.
As security became a multi-billion £/$/€ a year industry, hundreds of companies started up to bring us the silver bullet appliances that will end our problems forever. Not only do silver bullets not exist in security – and you should be shot for using the phrase in any way that’s non-derogatory – but where are those companies now?
They either failed, or have been bought up by larger companies who have tried to duct-tape the disparate products into silver-bullet SOLUTIONS.
Which have also failed.
It’s not that the products don’t work, some of them actually do, it’s that;
- Businesses threw technology at problems without knowing WHY they were doing it
- The big companies that collected the smaller ones tried to integrate the individual products together under one GUI, instead of unifying the functionality under a single code base
- There has never been, and there never will be, a one-size-fits-all solution to security
But the market is still ripe for innovation, and there will continue to be companies starting up with the goal of bringing a single product to market that will catch the latest security hype/wave/buzz and make them their fortunes (MDM for example). They may even succeed, but only if they make their impact in the first year or two, otherwise the market will have moved on.
If they’re VERY lucky, the larger companies that collect little ones will be naive / ignorant enough to buy them and save them the trouble.
I am not against combining single products into a larger solutions, in fact it’s the only way to go, but only if it’s done correctly. Single product companies have 100% focus, which gives them drive, goals, and a dedication to making their one product the best. The second you absorb that company, every one of those attributed that put them on (or near) the top, is lost in the larger mix. The functionality is diluted, innovation ceases, and the the whole thing quickly becomes obsolete.
True integration of functionality can only be accomplished with a single code base, and a single platform, which means that any organisation that absorbed the smaller companies better have a plan in mind to migrate not only the applications over to their growing solution, but they will need to consider all of the clients who bought the product prior to the M&A. These guys often suffer from a total lack of customer service and support, and there’s no way they’ll buy into the larger programme.
From what I have heard, the due diligence necessary to combine product companies is not overly abundant, and until it is, we should all be VERY careful when we look to resolve our security issues with multi-function solutions.
That’s why I call these ‘collage companies’, as the picture might be pretty, but it’s in no way whole.
Here are a few questions you might want to ask your potential providers;
- Can your solution replace some / most of my current functionality?
- Do you provide a consultancy ‘wrapper’ around these solutions to help us manage them against our business goals?
- Will the output from your solution feed into my current collection mechanism, or can my current output feed into yours?
- Are the various aspects / functions of your solution ‘home grown’, or obtained through acquisition? If acquisition, how have you unified the back end code and platforms?
- How do you ensure that the different functions of the solution receive a similar attention to what the single product vendors provide?
- Do you have a single customer support process to handle all functionality questions?
Regardless of the shenanigans going on in the security product market, your choice of vendor should only be driven by what your risk assessment and gap analysis said you need, and your due diligence should cover any requirements you may have regarding integration and ongoing maintenance.
If is doesn’t, don’t expect the collage companies to help, they have enough problems keeping their own houses in order.
Choose wisely.
