Brand digital risk protections cannot really help you with legal enforcement. They don't let you fix the legal issues you have. Or they do not, most of the time, they do not check the product authentication. They do not scan e-commerce websites or they do not check the counterfeit products. Like for example, someone selling a very famous shoe brand on eBay, but they are fake. So these brand protection tools are able to monitor and alert the companies so that they can secure their brand reputation. Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth.
I'm analyst and advisor with KuppingerCole Analysts. Today, we want to learn new topics that we have not yet covered here in the analyst chat. And for that, I have invited the respective research analysts who will cover the topics.
And first, before we go to the author and to the expert, we want to talk about three topics that are related, closely related, somewhat different, and they are important when you are really a larger corporation that wants to protect your digital assets on the web or just your brand. So we want to talk about attack surface management. We want to talk about digital risk protection and about brand protection, what they are and how they are different and where they overlap.
For that, I have invited Osman Celik. He is a research analyst and he has covered all of this and he hasn't told me about that. So we need to wrap up a lot that has happened in the last half year or so.
Hi, Osman. Good to have you.
Hi, Matthias. I'm doing good. I hope you are doing well too. And thanks for inviting me for today's call.
And yeah, like you mentioned, I've been covering attack surface management and brand protection and also DRP as part of ASM. A little over three years, but specifically brand protection, I think a little over one year.
And yeah, I'm looking forward to today's discussion and I hope that I can be in help for those who are needing guidance on these topics. Absolutely. And to mention that in the beginning, if you have any questions regarding these topics, which are new to this podcast, please reach out to Osman, to myself, leave a comment below this video on YouTube, or you will find a way to reach out to us maybe on LinkedIn. We are both there. Just let us know if you have any questions, because this is an interesting market.
Something, as Osman mentioned, is already covered for quite a while and it's an evolving market. And I think it's getting more and more important, although it's not directly IAM, which we are usually famous for. It's not directly cybersecurity, but somewhere it is. So let's start with one of these three topics. Let's start with attack surface management. And you cover that as a separate research topic. Can you give an explanation, a definition of what this is and how that is structured, that market, and what actually can you do with it?
Yeah, that's a good question. So I've been covering the attack surface management since 2023.
Actually, right now, I'm writing my third edition to be released August this year. And I have kept an eye on what's going on in the market. And to sum it up, what attack surface management tools are, very briefly, these are proactive or preemptive cybersecurity solutions that let you mitigate the risks targeting your organization proactively. And for this purpose, I have come up with my own market definition and subcategories of the markets.
And today, I think that we can briefly talk about ASM, but focus on the DRP and the brand protection solutions instead. But you have to promise me that you will invite me again once the ASM report is out in August.
So there, maybe we can cover more in detail. Because if I start talking about the attack surface management, this is my main area, then it will take some time. I would say that first, we clarify that I see digital risk protection, DRP tools, as a subcategory of attack surface management, ASM. But brand protection, as I mentioned in the beginning, I covered this since last year, and I kind of recreated this market from my existing ASM research. Don't get me wrong, I did not create this market. But as a separate research topic, I focused on it separate from ASM.
So brand protection tools were for me, to give it a start also to the conversation, were slightly different than DRP solutions. They were more comprehensive, they were providing more tools, also non-core cybersecurity tools and functionalities.
Therefore, I thought maybe we should separate these two markets, ASM and brand protection, and keep the DRP within the ASM market. And that's how it all began. And actually, this thought of mine paid off when I did my research. I saw many good solutions out there for brand protection. And since one year, I see these two markets separate, and I also talk to vendors. When I have a chance to talk with them, I also explain my point of view on this. And most of the time I get positive feedback. I did not come across with any vendors complaining about this research method.
But I think as an analyst, you always get this kind of positive and negative feedbacks in your daily life. Okay, that sounds interesting. So starting with brand protection, as you suggested, what actually does it do? The name actually is quite clear. I have a brand, I'm a large corporation, I'm a large international corporation. And of course, I want to protect my brand. So where do these solutions support me in that?
I would say that to make a distinction, maybe I should better first explain my subcategories in ASM and very briefly explain DRP, digital risk protection solutions, because I see them as a foundation of brand protection. And then I also explain if that's fine for me. All right. So when I was doing my attack surface management report last year for the second edition, I came up with this methodology. The market is very broad, although it is not mature, because I think that the foundation of ASM, at least technologically speaking, it dates back to 2020s.
So it's around there for a while now, but it's not mature. So I looked at the solutions and then I identified four main subcategories of ASM. What are they?
CASM, cyber asset attack surface management, EASM, external attack surface management, TPRM, third party risk management, and DRP, digital risk protection tools, solutions. And these subcategories actually were the basis of my research and analysis, vendor hunt, everything. So I was looking for solutions, offering either one of them or a combination of them or all of them. And then once I say that, yeah, they offer this for one of these subcategories at least, then for me, they were ASM solutions. This is how I conducted my research. And I can also go and explain them a bit for clarification.
I think that we should say that the CASM tools are generally focused on giving visibility to internal assets. And then they work closely with your configuration management databases, your unified endpoint management tools and mobile device management tools. These are tools that are providing internal scans. Long story short, EASM is more popular and is, to be honest, covering most of the market, ASM market.
These are the solutions that are monitoring your external digital assets and aiming to monitor exposed systems, websites, domains, subdomains, IPs, generally an organization's external attack surface. TPRM, very briefly, these are scanning your supply chain, your partners. And sometimes these are also called vendor risk management solutions. Then they tip you basically as an organization, you go most of the time, unfortunately, manually enter the organizations between your supply chain.
And then these tools let you scan and monitor their attack surfaces and warn you in case there is a vulnerability or threat emerging from them. The final category that I think that I should give more explanation before we start with the protection is digital risk protection. So these tools are, first of all, powered by threat intelligence or cyber threat intelligence, however you call it. These tools are monitoring dark deep web, social media forums, hacker groups, the social messaging platforms like Telegram, and then they find out what is exposed.
Credentials, brand abuse, infringements or impersonations, phishing attacks, also targeting companies, impersonating another company or another person, in general brand abuse. So for me, they also provide brand protection if you're going to use it as a daily life term. Brand protection, yes. But there is another category that I noticed when I was doing this research, and most of the vendors are defining it as brand protection. So I stick to the wording. Sorry guys, it's not a very cool name when we think about the other solutions in the cybersecurity landscape.
So yeah, brand protection tools are one step forward compared to DRP solutions. So I can kind of summarize like this, the ASM part. And for the brand protection tools, as I said, DRP solutions were not really providing that comprehensive solutions that some large organizations might need. What are they? For example, brand digital risk protections cannot really help you with legal enforcement. They don't let you fix the legal issues you have. Or they do not, most of the time, they do not check the product authentication. They do not scan e-commerce websites, or they do not check the products.
Like for example, someone selling a very famous shoe brand product on eBay, but they are fake. So these brand protection tools are able to monitor and alert the companies so that they can secure their brand reputation. So if I got it correctly, so we have ASM as the umbrella term with capabilities inside there, which are CASM, EASM, TPRM, and DRP. And brand protection is somewhat similar, but not the same, but it really aims at what the name says, brand protection, really going really broad into the attack surface that a brand could actually endanger on a daily basis.
So where do we want to continue? Should we focus on DRP now to look at the capabilities or brand protection, or why would an organization actually choose one of those? What is the distinction between and the selection criteria to say, okay, I go for DRP or I go to for brand protection?
Yeah, when you first contacted me, let's do a podcast or a video about this topic, I suggested that let's do DRP versus brand protection. I think it's very straight to the point.
So quick, maybe I give you a spoiler. You need one of these solutions at the end. That's why I used versus. It's not like you should get both of them if you want a broader cybersecurity. No. In my opinion, after doing a research, of course, there are suitable markets for DRP and for brand protection. And I would say that I started with DRP and then how they are offered and then how do they differentiate in the market, and then spent a bit more time on the brand protection tools. Is that fine? Absolutely, absolutely.
So DRP tools are not always, by the way, it should not be taken granted that they are offered with ASM tools. Like I described in the beginning, DRP solutions are mostly often compounded in the broader ASM platforms. This is what I've seen in the market. And they provide lightweight brand protection, and then they utilize cyber threat intelligence. And these are alternative for brand protections solutions as well. But in case you have budget constraints, or if you have limited resources, or if you just need an entry-level protection for your brand, then you can go with DRP.
But brand protection, on the other hand, these solutions are covering more comprehensive use cases. And then they also have more functionalities when it comes to protecting your brand. So on the other hand, we have the brand protection tools, and these tools are providing you with a more comprehensive functionality set. First of all, they come with takedown services almost as a market standard, because most ASM solutions do not come with takedown services. What are they? So you report infringement case or impersonation, for example, on social media, or a type of squirting domain.
You have to deal with legal enforcement, right? So brand protection tools are also helping you with that process. Another thing is, for example, let's say product authentication. You search for the products in the e-commerce website, and then brand protection tools can scan and then find these products. Whereas DRP solutions are very limited in this sense.
And also, you can also do a better policy governing with the brand protection tools. So they are more comprehensive. And why I wanted to talk about brand protection, especially, is because I covered this as a separate topic since last year, and I wrote also a virus compass on this. And I noticed that there are certain skill sets, function sets that the brand protection offers, but DRP doesn't. That's why I use the term lightweight for DRP and heavyweight for brand protection tools. For example, let's talk about some similarities and some of the differences.
For example, I have just a list of functionalities here. Just forgive me, I cannot remember everything, but let's go over this and then I will tell you what brand protection does and what DRP does and what both of them can do. For example, let's talk about brand intelligence. Both of these solutions work with threat intelligence. So both of them have this capability. But on the other hand, you have the intellectual property rights management, for example, embedded to brand protection tools, whereas DRP most of the time doesn't offer such capability.
Dark deep web monitoring, these are kind of very much standard in the market for DRP and brand protection tools, because this is how everything begins in most cases. You can also go and monitor the ads and contents of websites and this is mostly done with brand protection tools.
Brand abuse and brand reputation management are offered in both of the solutions, but when we are talking about brand reputation, and if you are very worried about your brand reputation, then you should go and seek for a brand protection tool, because they have a more full-spectrum brand protection plus cybersecurity support when you need. Yeah, this could be the summary of the differences between them and some of the similarities.
Other than that, both solutions are offering with alerting mechanism, reporting mechanisms, executive summaries, or they do scans in multiple languages, or even today defect detection, any sort of AI-generated content or assets. But the main difference is, for me, brand protection support for legal cases, plus e-commerce, marketplace, app store support when it comes to detecting the counterfeit products, either digital or physical products.
So, the physical products, if we talk about physical products, we are kind of leaving the realm of cybersecurity, if you get the sense. So, for me, brand protection is going beyond the traditional cybersecurity, we understand, and is also going a bit on the legal way.
Right, and from what you described, I think, from what I've got, is really that brand protection really looks more, in the end, at the customer and how a customer could be distracted from a brand with a counterfeit product, with wrong messaging out of unexpected channels. So, it really goes beyond cybersecurity, but it really does what the name says, it really looks at the customer and their interaction and their relationship and their trust into a brand. Exactly. Right.
So, could there be a good reason to have both, to have DRP and brand protection out of the same hand of a vendor or from different vendors even? This is a very good question, and I kind of answered, gave a spoiler in the beginning for our audience who are a bit impatient.
So, the answer is simply no, you don't need them separately. But there might be some exceptions, and I also told about these cases as well.
So, the DRP solutions are lightweight brand protection tools, in a nutshell. If you're, let's say, an SMB, and if you have already an ASM tool, a tech service management tool, most of the time, your vendor also provides you with DRP capabilities. And you already have a lightweight brand protection already. And if that's enough for you, you don't need a brand protection tool. But let's think about another large enterprise, and this company also needs ASM, separate than brand protection.
And in case their ASM vendor provider is already offering a digital risk protection module within the ASM license for no extra cost, let's assume, then yes, hypothetically, you have DRP included in ASM, plus you need a better brand protection tool. So, in that case, you might need both of them. But if we ignore these exceptions, now, if you're a large organization, you should go with the brand protection. If you are not really concerned about attack vectors related to your brand, then you should be fine with DRP solutions because they already also provide a good coverage.
Is there any good reason to have none of them? Or would you say, okay, every organization with a substantial footprint towards customers, towards the market should use this? This is a no-brainer.
Well, this is a very interesting question for me. Yeah, I think that there should be some cases where both of them are needed, especially if you're very small. And like I mentioned earlier, some of the ASM solutions offer only EASM or only Chasm or Chasm plus EASM. And if I think about the organizations now today, they can be fine without DRP unless they have some concerns about their brand reputation. If they are in, let's say, a B2B business where they do not have so much touch with the customers, then they don't really think about the brand reputation because it's a B2B business.
But still, when I think about it, I think that the exceptions should not be that much. I would say that the organization should have at least a DRP solution and that should be working well, orchestrated well with the ASM tools if they have any. And I think even the size does not really matter. If you are a startup and you live by your brand, by your product, if you live by what you do different, I think you really want to protect yourself from false messaging, from false information, from counterfeit products, depending on what you actually deliver.
I think these are interesting markets that really should be monitored also by our audience, right? Yeah, I remember many years ago, I was using WhatsApp. Is it okay if I say WhatsApp? I don't know.
But yeah, it's a very big brand. And then I heard somewhere that there are only 50 employees they have, but the impact they have and vice versa. This understanding of their customers was huge. If something bad happened with WhatsApp, for example, if they leak data, if they let hackers communicate in the, let's say WhatsApp channels, like the Telegram has the bad reputation. If the WhatsApp had the same situation, although they had only 50 employees, I'm talking about five to 10 years ago, but WhatsApp was still, WhatsApp was again WhatsApp.
So for me, the size of the organization doesn't really matter. For me, it's their reach. Forgive me, maybe I made a mistake. When I said large enterprise, I directly assumed that they touch with the customers will be even bigger. It's in most of the cases like this. But when we think about smaller vendors, smaller organizations working with millions of people, yes, I think that the right wording should be here and not the organization size, but their reach, their touch points with the customers.
So, and in most of the time, cyber criminals are targeting the companies that are more popular, right? Or they would target the brands that they could actually ask more ransomware or they could maybe create bigger impact. So if they were aiming also smaller market, smaller organizations, I would say that they would still create an impact, but the size of the impact wouldn't be similar to the larger enterprise or larger reach enterprises. So what we understood is that it is a huge market, that there are different focuses of the different products and how they are cut.
When it comes to your research, what is already available? And I know the ASM will be out in August, if I remember correctly, but there is existing research already available for those who are interested in finding the differences and understanding which organization or which vendor shines in which market. What can you recommend? What should they look for on our website? All right. So for the DRP solutions, I include them in my ASM research. The best idea would be go check my BIOS Compass from last year first, and if possible, my Leadership Compass, if you're watching this in June, July period.
But if you're watching this after August, then my ASM Reports third edition will be released. So if you have a chance, go read it. It is the most comprehensive report out there when it comes to ASM solutions. And the DRP is also analyzed there, and you will see the vendors offering DRP solutions. Speaking of grant protection, I released a BIOS Compass only as of today, and it's from November or December last year, if I'm not wrong. It's recent, yes. And I'm also in touch with many vendors.
I actually released another BIOS Compass vendor's edition with another vendor, which kind of shows that there's a demand for this in the market. But I think that our audience should be staying tuned for more research for the grant protection tools that I will do in the coming months and years. So let's make a deal. You will come back when the ASM Leadership Compass is out, so then we can discuss the newest results here. We've laid the groundwork for today to distinguish what the individual market segments actually deliver and where they shine. And for the time being, there is existing research.
And for everybody who's interested, just go to our website. If you have direct questions to Osman and me, please let us know. Leave a comment below this video on YouTube or wherever you are catching up with our podcast, and we are happy to take that into consideration. And if you have questions for the ASM Edition for the Leadership Compass in August, let us know. I will ask the questions to Osman, so you get the results and the feedback that you're actually looking for. And that would be a good idea. Right. So leave your questions.
And yeah, great to have you back on the podcast again, Osman. And then we have a deal. We will meet in August and talk about the Leadership Compass. Up until then, thank you very much for being my guest today.
Yeah, you're welcome. And yes, I am looking forward to making another video with you, because I know that our audience would probably watch that video as well, or they would be interested at least if they're interested in brand protection, DRP, then ASM should be also in their radar. And one spoiler, I am still in the writing phase for the Tax Service Management Report. By the way, it's much more comprehensive than brand protection and then DRP when we speak about ASM. And it's more important that when we think about the tax services, just a quick information.
I was thinking about the physical attack services, human attack services, cloud attack services, digital attack services, when I thought about the attack services in general. But this year, all we talk about is AI attack service. And I see vendors are bringing new functionalities in this field. And that was also an eye opener for me, although I am analyzing this over three years now. So I would say that stay tuned for that leadership compass as well. And we will do webinars, videos about that as well, hopefully. And I will definitely join you, Matthias. If you invite me. Absolutely.
And it's good to have this outlook, because it's really a much bigger topic. And maybe it's interesting for those who thought, oh, maybe I just need brand protection. Maybe the bigger solution provides more value. So we give you then the option to decide what is the right market segment to look at. And we provide the research.
Thanks, Osman, again. And great to have you here.
Yeah, you're welcome, Matthias. Thank you. See you. Bye-bye. Bye-bye.