Reducing The Risk Of Weak Links With Consolidation

The breadth of tools that IT teams have at their disposal to protect their organisations can be both a blessing and a curse. On the one hand, having a diverse array of products and technologies to detect threats and help protect the organisation can be seen as a good thing; but on the other, it raises the risk that there could be a weak link somewhere within this array of tools.

As the SolarWinds attack and the Log4j vulnerability make all too clear, the old adage about a chain only being as strong as its weakest link has never been more relevant. 

Consolidation of security technologies presents a way to “remove” weak links and blunt the impact of this risk. However, this approach needs to be carried out in a carefully planned manner if cybersecurity professionals hope to reduce their overall risk without creating a new set of security challenges that need to be managed.

Identify Opportunities For Consolidation - But Be Smart About It

How best to get started? Organisations need to evaluate their existing security vendors by performing a Know Your Third-Party assessment. Security vendors that were once “best of breed” might not have been keeping pace with the rapidly evolving threat landscape over the years; alternately, they might not have been consistently investing in the ongoing development of their product or the people they hire.

Once a potential “weak link” vendor has been identified, the next step is to see if there is a vendor who can provide similar functionality as part of a consolidated platform. There has been a fair amount of consolidation in the technology space in recent years - Cisco’s purchase of Splunk, for example – so this task is more easily accomplished today than it would have been ten or even five years ago.

Before moving forward with this type of consolidation, however, organisations should make sure that the vendor services that will be connecting with internal systems comply with the security requirements specified by the organisation.

If your organisation embraces zero trust principles that eliminate implicit trust, for instance, then the services need to leverage these principles as well. 

Additionally, the vendor services should only be accessing the specific resources necessary to carry out their function; providing full access to network resources increases risk. Again, the idea is not to swap out one weak link and inadvertently create a different weak link.

Another consideration: even if a single vendor provides multiple security products, do those different products seamlessly integrate with one another? To our earlier point about companies growing through acquisition and buying up smaller companies, this isn’t always a foregone conclusion. Organisations should seek out vendors that have done the work to make sure their various acquired technologies all work with one another so that security teams can easily gain a comprehensive view across them. Careful evaluation is required in this case.

The Goal: Less Complexity, Less Risk 

It can be tempting to view technology consolidation solely as a cost-cutting exercise – particularly if there is a lot of input coming from the finance side of the house. This is the wrong lens through which to view a consolidation exercise. 

There can certainly be financial benefits if an organisation chooses to consolidate multiple products or services with one vendor, but that shouldn’t be the primary consideration. The focus should be on looking at the supply chain and identifying areas to remove complexity and reduce overall risk. 

This means that CIOs and CISOs should be actively involved in any technology consolidation activities - the process should not be left solely in the hands of the finance team, who might only have a cost reduction mindset rather than the fuller security and risk management mindset.

Ultimately, supply chain complexities – and the inadvertent loopholes that they offer to bad actors – make a consolidation strategy to evaluate and adopt best-of-breed technologies more important than ever.

By taking a well thought out approach to eliminating weak links in their supply chain through consolidation, CIOs, CISOs, and other cybersecurity professionals will be able to bolster their overall security posture, allowing them to better navigate today’s challenging threat landscape. 

Manuel Sanchez is Information Security and Compliance Specialist at iManage

Image: Fill

You Might Also Read:

Misconfigured Cloud Applications Are Putting Your Data At Risk:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« The Importance Of Cloud Access Security In Today's Cyber Landscape
Fast Forward - Technology Developments By 2040 »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Axence

Axence

Axence provides professional solutions for the comprehensive management of IT infrastructure for companies and institutions all over the world.

Araxxe

Araxxe

Araxxe delivers Revenue Assurance, End-to-End Billing Verification and Interconnect Fraud Detection solutions to communication companies worldwide.

SYSGO

SYSGO

SYSGO is the leading European provider of real-time operating systems for critical embedded applications in the Internet of Things (IoT).

Sadoff E-Recycling & Data Destruction

Sadoff E-Recycling & Data Destruction

Sadoff E-Recycling and Data Destruction protect the environment and your data with proven and trusted electronics recycling and data destruction services.

Echosec Systems

Echosec Systems

Echosec Systems is a data discovery company delivering social media and dark web threat intelligence. Our web based security software delivers critical information for situational awareness.

SecureThings

SecureThings

SecureThings focus is to provide guidance and technology to secure connected vehicles in order to build end-to-end security for the automotive industry.

AUREA Technology

AUREA Technology

The photon counter SPD_OEM_NIR from AUREA Technology is designed for quantum key distribution at telecom wavelengths.

Cyberport

Cyberport

Cyberport is focused on facilitating the growth of major technology trends such as FinTech and cybersecurity as well as the emerging technologies of AI, big data and blockchain.

Pyxsoft PowerWAF

Pyxsoft PowerWAF

Pyxsoft PowerWAF responds to the problem of business cybersecurity. We protect our clients' websites and data against attacks and exploitation of all kinds of vulnerabilities.

Internet Security Research Group (ISRG)

Internet Security Research Group (ISRG)

ISRG's mission is to reduce financial, technological, and educational barriers to secure communication over the Internet.

Labaton Sucharow

Labaton Sucharow

Standing on the horizon of law and technology, our Cybersecurity and Data Privacy Practice helps to protect consumers who have been harmed by businesses’ failures to safeguard their customers' data.

Miggo Security

Miggo Security

Miggo is the first Application Detection and Response (ADR) platform on a mission to stop application breaches.

Synergy ECP

Synergy ECP

Synergy ECP has a talented, dedicated staff to provide a broad range of services to the defense and intelligence industries.

WIIT Group

WIIT Group

WIIT Group are focused on a single goal: securing our clients’ critical processes and enabling them for digital transformation.

Nicos AG

Nicos AG

Nicos AG specializes in secure, global data communication.

Foresights

Foresights

Foresights is a Nordic company utilizing advanced intelligence tradecraft and extensive cyber security capabilities to deliver services and advisory tailored to our client’s critical requirements.