Reducing The Risk Of Weak Links With Consolidation

The breadth of tools that IT teams have at their disposal to protect their organisations can be both a blessing and a curse. On the one hand, having a diverse array of products and technologies to detect threats and help protect the organisation can be seen as a good thing; but on the other, it raises the risk that there could be a weak link somewhere within this array of tools.

As the SolarWinds attack and the Log4j vulnerability make all too clear, the old adage about a chain only being as strong as its weakest link has never been more relevant. 

Consolidation of security technologies presents a way to “remove” weak links and blunt the impact of this risk. However, this approach needs to be carried out in a carefully planned manner if cybersecurity professionals hope to reduce their overall risk without creating a new set of security challenges that need to be managed.

Identify Opportunities For Consolidation - But Be Smart About It

How best to get started? Organisations need to evaluate their existing security vendors by performing a Know Your Third-Party assessment. Security vendors that were once “best of breed” might not have been keeping pace with the rapidly evolving threat landscape over the years; alternately, they might not have been consistently investing in the ongoing development of their product or the people they hire.

Once a potential “weak link” vendor has been identified, the next step is to see if there is a vendor who can provide similar functionality as part of a consolidated platform. There has been a fair amount of consolidation in the technology space in recent years - Cisco’s purchase of Splunk, for example – so this task is more easily accomplished today than it would have been ten or even five years ago.

Before moving forward with this type of consolidation, however, organisations should make sure that the vendor services that will be connecting with internal systems comply with the security requirements specified by the organisation.

If your organisation embraces zero trust principles that eliminate implicit trust, for instance, then the services need to leverage these principles as well. 

Additionally, the vendor services should only be accessing the specific resources necessary to carry out their function; providing full access to network resources increases risk. Again, the idea is not to swap out one weak link and inadvertently create a different weak link.

Another consideration: even if a single vendor provides multiple security products, do those different products seamlessly integrate with one another? To our earlier point about companies growing through acquisition and buying up smaller companies, this isn’t always a foregone conclusion. Organisations should seek out vendors that have done the work to make sure their various acquired technologies all work with one another so that security teams can easily gain a comprehensive view across them. Careful evaluation is required in this case.

The Goal: Less Complexity, Less Risk 

It can be tempting to view technology consolidation solely as a cost-cutting exercise – particularly if there is a lot of input coming from the finance side of the house. This is the wrong lens through which to view a consolidation exercise. 

There can certainly be financial benefits if an organisation chooses to consolidate multiple products or services with one vendor, but that shouldn’t be the primary consideration. The focus should be on looking at the supply chain and identifying areas to remove complexity and reduce overall risk. 

This means that CIOs and CISOs should be actively involved in any technology consolidation activities - the process should not be left solely in the hands of the finance team, who might only have a cost reduction mindset rather than the fuller security and risk management mindset.

Ultimately, supply chain complexities – and the inadvertent loopholes that they offer to bad actors – make a consolidation strategy to evaluate and adopt best-of-breed technologies more important than ever.

By taking a well thought out approach to eliminating weak links in their supply chain through consolidation, CIOs, CISOs, and other cybersecurity professionals will be able to bolster their overall security posture, allowing them to better navigate today’s challenging threat landscape. 

Manuel Sanchez is Information Security and Compliance Specialist at iManage

Image: Fill

You Might Also Read:

Misconfigured Cloud Applications Are Putting Your Data At Risk:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« The Importance Of Cloud Access Security In Today's Cyber Landscape
Fast Forward - Technology Developments By 2040 »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

CipherPoint Software

CipherPoint Software

CipherPoint Software provides data-centric auditing and protection solutions for securing unstructured information

Aptive Consulting

Aptive Consulting

Aptive is a cyber security consultancy providing Penetration Testing and Vulnerability Assessment services.

Ground Labs

Ground Labs

Ground Labs is a security software company dedicated to making sensitive data discovery products that help organisations prevent sensitive data loss.

NetExtend

NetExtend

NetExtend services include backup and recovery, endpoint protection, network monitoring, cloud portal and billing and payment solutions.

Apricorn

Apricorn

Apricorn provides hardware-based 256-bit encrypted external storage products to companies and organizations that require high-level protection for their data at rest.

Raz-Lee Security

Raz-Lee Security

Raz-Lee Security is the leading security solution provider for IBM Power i, otherwise known as iSeries or AS/400 servers.

X4 Technology

X4 Technology

X4 Technology is a leader in finding the very best technology talent for some of the world’s most innovative start-ups and globally recognised brands.

Guardian Data Destruction

Guardian Data Destruction

Guardian Data Destruction provides a comprehensive suite of onsite e-data destruction services.

CyberLab

CyberLab

CyberLab (formerly Chess) is a specialist cyber security company that provides a wide range of security solutions and services.

Future Planet Capital

Future Planet Capital

Future Planet is the impact-led, global venture capital firm built to invest in high growth potential companies from the world's top research centres.

Schneider Downs

Schneider Downs

Schneider Downs & Co. provides accounting, tax and business advisory services through innovative thought leaders who deliver their expertise to meet the individual needs of each client.

Xalient

Xalient

Xalient is an IT consulting and managed services business, specialising in modern, software-defined networking, security and communications technologies.

Cyber Legion

Cyber Legion

Cyber Legion Ltd is a UK-based Cyber Security as a Service (CSaaS) start-up that provides IT security testing services to various organizations around the globe.

Splashtop

Splashtop

Splashtop’s cloud-based, secure, and easily managed remote access solution is increasingly replacing legacy approaches such as virtual private networks.

Endor Labs

Endor Labs

Endor Labs gives developers and security teams the context they need to prioritize open source risk.

Mantodea Security

Mantodea Security

Mantodea Security is an industry-agnostic powerhouse backed by extensive experience and expertise in the realm of IT security.