Press Releases

IBM launches open technology to speed response to cyber threats across clouds

November 20, 2019

Posted by: Anasia D'mello

Mary O’Brien of IBM Security

IBM announced Cloud Pak for Security, featuring industry-first innovations to connect with any security tool, cloud or on-premise system, without moving data from its original source. The platform includes open-source technology for hunting threats, automation capabilities to help speed response to cyberattacks, and the ability to run in any environment.

Cloud Pak for Security is the first platform to leverage new open-source technology, says IBM, which can search and translate security data from a variety of sources, bringing together critical security insights from across a company’s multicloud IT environment. The platform is extensible, so that additional tools and applications can be added over time.

As businesses move further into cloud maturity, applications and data are frequently spread across multiple private and public clouds and on-premise resources. Attempts to protect this fragmented IT environment often require security teams to undertake complex integrations and continuously switch between different screens and point products. In a recent SANS Institute report, sponsored by IBM Security, more than half of security teams surveyed said they struggle to integrate data with disparate security and analytic tools and combine that data across their cloud environments to spot advanced threats.

Three initial capabilities of Cloud Pak for Security include:

“As businesses move mission-critical workloads to hybrid multicloud environments, security data is spread across different tools, clouds and IT infrastructure. This can create gaps that allow threats to be missed, leading security teams to build and maintain costly, complex integrations and manual response plans,” said Mary O’Brien, general manager, IBM Security. “With Cloud Pak for Security, we’re helping to lay the foundation for a more connected security ecosystem designed for the hybrid, multicloud world.”

IBM collaborated with dozens of clients and service providers during the design process, developing a solution to address critical interoperability challenges that permeate the security industry. The Cloud Pak for Security includes connectors for pre-built integrations with popular security tools from IBM, Carbon Black, Tenable, Elastic, BigFix, Splunk, as well as public cloud providers including IBM Cloud, Amazon Web Services and Microsoft Azure. The solution is built on open standards so that it can connect additional security tools and data from across a company’s infrastructure.

“Organisations have rapidly adopted new security technologies to keep up with the latest threats, but are now juggling dozens of disconnected tools which don’t always work well together,” said Jon Oltsik, senior principal analyst, Enterprise Strategy Group. “The industry needs to solve this issue for customers by shifting to more open technologies and unified platforms that can serve as the connective glue between security point tools. IBM’s approach aligns with this requirement and has the potential to bring together every layer of the security stack within a single, simplified interface.”

To further accelerate industry migration toward open security, IBM is also spearheading open-source projects to make security tools work together natively across the security ecosystem. As a founding member of the Open Cybersecurity Alliance, IBM and more than 20 other organisations are working together on open standards and open source technologies to help enable product interoperability and reduce vendor lock-in across the security community.

Designed for the hybrid, multicloud world

76% of organisations surveyed report they are already using between two and 15 hybrid clouds, and 98% forecast they will be using multiple hybrid clouds within three years. IBM’s Cloud Pak for Security is built on open source technologies that support companies’ cloud environments – including Red Hat OpenShift.

Creating Cloud Pak for Security on these open, flexible building blocks allows for easy “containerised” deployment across any cloud or on premise-environment. As companies continue adding new cloud deployments and migrations, Cloud Pak for Security can adapt and scale to these new environments – allowing clients to bring their sensitive and mission-critical workloads into the cloud while maintaining visibility and control from within a centralised security platform.

Cloud Pak for Security also provides a model to help Managed Security Services Providers (MSSP) efficiently operate at scale, connect security silos and streamline their security processes. Organisations can also hire IBM Security for a wide range of additional services, such as on-demand consulting, custom development and incident response.

Comment on this article below or via Twitter @IoTGN