Hello everyone,
written communication is a waste of time, no one reads anymore – this is the quintessence of a very successful PR consultant who specializes in the external presentation of top managers.
Understandable in a time of hyperinflation not only of assets, but also of empty words on our screens.
So welcome to the club of incorrigible readers, a dying species!
I can only hope that a countertrend will set in again at some point. A career on TikTok and Instagram will be Mission Impossible with my charisma.
To take it to a new extreme today, I have 2 book recommendations with me! Namely from Barak Engel: “Why CISOs Fail” and “The Security Hippie“:
Both are written in an entertaining way, in 2-3 concentrated afternoons each (soon there will be Christmas holidays again) you can get through well even as a non-native speaker.
Reading a book requires, among other things, a quiet environment, time and concentration, i.e. a significantly higher personal commitment to the content than is usual in everyday work.
In the end, my experience of taking more from it is usually at least a few new ideas, arguments and puzzle pieces in the worldview.
Barak worked for an Israeli ISP, was responsible for the security of Webex (yes) at the turn of the millennium, and then successfully started his own business as a virtual / fractional CISO (company: EAmmune)
In the books he writes very openly (of course without naming names) about his experiences, e.g.
- Board communication with boards of Fortune 500 companies (“reduce undue tech risks to help businesses win“)
- Cooperation with in-house lawyers and sales managers (very exciting – the first time I saw this constructively addressed)
- PCI audits of credit card processing companies including fraud at an online marketplace
- Several cases of criminal insiders
- Incorrectly implemented encryption algorithms
- The difficult initial phase of the leap into self-employment, including the insolvency proceedings in the wake of the financial crisis in 2008: All customers lost except one, all employees dismissed, then rebuilt
Interesting footnote: The average length of employment of CISOs (based on the same job) in the USA is probably < 2 years. Probably sounds more dramatic than it is – job changes are more normal there anyway, many companies haven’t had a CISO for that long, and various career primers also suggest job hopping every 2-3 years.
Feel free to write to me (or send me a reel 😉) if you can recommend other books with unembellished testimonials .
Of which there are already enough: Dog & Pony shows and regulations compendia (“Organizations should…”).
At this point, the further escalation level or a confession: I, too, have started a new modest book project , which is mainly about anonymized “war stories” from the unvarnished everyday life of security .
Topics include career killers, conflict communication, budget negotiations, bonus systems + performance evaluation of CISOs / security teams, organizational structures, behavior in real incidents, bad buys / failed implementations, dealing with security providers and of course the lessons learned from all this.
100% anonymized and off the record without traceability in order to get the most honest answers possible. Focus on the DACH region. 360 degree perspective: From CISOs, employees, superiors, contractual partners.
The first interviews have already been conducted, and excerpts of the content will be included here in the market commentary in the future. As usual, in an edutainment style instead of a sermon format.
So prepare yourself mentally for me to ask you for an interview – of course I need your support, otherwise it will be a very short book.
And feel free to let us know which questions you are interested in.
Panther is still quite unknown as a SIEM in the DACH region among major customers, Tines as a SOAR is already more common (e.g. in combination with Elastic), Wiz and Okta . All the more interesting is a field report from the Figma Security Team on this tech stack, esp. on the use of AI agents as support for security staff:
- So far, ~70% time savings have been achieved when investigating complex incidents and, for example, ~25% fewer user requests for new software (agents recognize the user request and suggest existing alternatives)
- Wesentlicher Erfolgsfaktor: 3-teilige Architektur für Kontext („Memory ended up being the thing that had the most impact on how useful the system became over time”):
- RAG based on AWS Bedrock + Kendra contains an archive of alerts with associated case summaries from Slack and Asana, which is the first to be consulted and analyzed for similar alerts (semantic comparison with alert description + username)
- Control context for analysis agents, e.g. “Planned maintenance work on system X in the period…, disruptions to be expected”
- interpretation context for sub-analyses of certain log/event sources, esp. data schemas. This has apparently led to dramatic improvements in the quality and speed of analysis
- All 3 context stores are updated by agents themselves
- Centralized configuration for agents
- Deterministic guardrails at the tool level, i.e. it is generally assumed that agent actions cannot be trusted 100%
Adobe has published a field report on virtual patching using WAF, in order to cope with the ever-shrinking time window between vulnerability and exploit, and to bridge the waiting time for an official working patch:
- For this purpose, no less than 7 WAF products are used (of course not all one after the other, but each for specific systems), including AWS, Azure, Cloudflare, Akamai, Wallarm and ModSecurity (open source)
- The block rules are initially very narrow in order to filter as little legitimate traffic as possible. The basic assumption behind this is that attackers will not make any clever modifications to the exploit at first, but rather quickly try out the same approach with many potential victims
- 2-stage tests – in the first approach, until the confidence level of a successful defense reaches approx. 80%. Entire test phase until the rules go live only approx. 1 hour incl. audit mode (recording of the accesses that would be blocked without actually blocking)
- The whole pipeline and control context for this is mapped in a harness, the agents are model-agnostic, different models are used for creation and testing (apparently higher quality)
M&A (long list due to holidays):
- VISA acquires BioCatch (fraud detection via signals such as mouse/button inputs) for $2.4 billion
- Cyera buys Oasis (NHI Mgmt.) for $1 billion
- MunichRe buys At-Bay (US MSSP with its own cyber insurance => “all-round carefree” package for clients) for ~EUR 500m
- Tata buys MHP from Porsche for EUR 320 million (= approx. EUR 70 thousand per employee, or ~0.5*turnover)
- Fortinet Acquires Virtue AI (AI Governance for Enterprise Environments, Including Agentic Identity, Security Tests, Guardrails, and Runtime Monitoring)
- Overall, Fortinet is benefiting extremely strongly from the trend towards more segmentation / AI containment – ~33% growth in order intake (OT Sec even > 50%), highly profitable
- Networking and SD WAN were summarized in the investor conference as “SASE Firewalls”, the segment accounts for ~90% of the business
- Okta buys Permiso (ITDR) for allegedly ~$200 million
- Brinqa buys competitor PlexTrac (RBVM)
- Cribl buys Radiant (AI SOC) => A new SIEM competitor may emerge here
- Cloudflare issues ~$2 billion worth of bonds
- Horizon3 (automated pen tests) gets another US$ 250 million in funding at a 2 billion valuation
- Spur (IP-based TI, e.g. to prevent fraud at banks) receives USD 200 million in funding
- Threatlocker (EPP / MDR) will be provided with an additional ~$190 million
- Zenity (AI Agent Governance) raises $125 million in Series C
- Onyx (also AI Agent Governance) gets ~110 million USD
- Groundcover (Observability, Performance + Log Mgmt.): +100 Mio. USD
- Obsidian (SSPM) receives another USD 85 million and Oligo (AppSec) USD 60 million
- I guess there’s never been a better time to raise VC funding with a Cybersec startup in the US
Vendor Briefings:
N-Able:
- US manufacturer of security software such as remote access, endpoint management and backup & recovery (focus of the conversation)
- In addition, partnerships with Bitdefender and SentinelOne to offer packages for MSSP
- So far, we have had little contact, although > 500,000 SMEs have already had over 16,000 MSPs (including in-house IT service providers) as customers
- Backup solution:
- Cloud first (own data center – also in Germany or Switzerland, SOC2 certified)
- Technical approach: SW package on each server to record changes between incremental backups as accurately as possible and thus keep the volume of backups low (realistically, 0.1% of the full backup is achievable, factor 10-50 better than with usual snapshots). In addition, native connection of M365
- Immutable copy included (in the same data center, but logically separated and no longer modifiable by customers)
- Storage frequencies + data retention can be adjusted granularly of course
- Additional local storage optional
- Recovery tests / restore automated for Azure, ESXi, HyperV (Proxmox on roadmap)
- Disaster Recovery as a Service: Hosted at N-Able, as an alternative to standby images
Hush:
- Israeli startup for NHI / AI Agent Governance, currently ~40 MA
- Approx. 20 enterprise customers (including Kyndryl, Swimlane, Salesforce, also 1 customer in EU)
- For common coding + enterprise agents like Claude, MS Foundry, Agentforce, and custom agents (honestly, I’m not sure if this really works well for the latter, I’m happy to hear your feedback on practical experience)
- Centralized SaaS engine with API-based integrations + eBPF sensors on the servers running workloads
- Discovery, Inventory + Posture / Config-Mgmt
- Identity + MCP Mgmt.: Registration with assignment to human user, gateway function with integration with Entra ID to deterministically restrict rights in connected applications, ephemeral/JIT credential management, automated deletion. Similar to AWS IAM
- Runtime monitoring, esp. Accesses
Onyx:
- Israeli AI Gateway + Governance solution, funding of cyberstarts, among others, currently > 200 employees
- ~60 customers (including Revolut), customers + GTM team in the EU (Belgium)
- AI Gateway similar to LiteLLM, Portkey or similar, connection of different models with cost control + load balancing, for A/B tests, logging, rules
- Architecture: Script in MDM = > Monitoring + Forwarding of Network Traffic of Endpoints + Browser Extension + SaaS AI/MCP Gateways
- Discovery of common SaaS tools, agent foundries, MCP servers with connection to data sources and risk assessment. Access can also be restricted directly in the interface
- Probably used by most customers so far by the SOC team
As always, nothing in the market commentary is AI-generated. Questions, suggestions, comments, experience reports, topic requests and also opposing opinions or corrections are welcome by email. Ditto for unsubscribing from the mailing list.
For the people who have received the market commentary for the first time: Here you can register if you are interested or convert the archive into book form with an AI agent, edit it, publish it as a hardcover and then transfer the sales proceeds to me.
Best regards,
Jannis Stemmann
