Welcome to the KuppingerCole Analysts Chat. I'm your host. My name is Matthias Reinwarth. I'm an advisor and analyst with KuppingerCole Analysts.
Today, we are going to dive into an emerging concept in security architecture that's gathering attention across the industry. We are joined for that by Jonathan Care, who is a bit behind that concept. He is developing the concept of a cybersecurity fabric, a comprehensive approach to unifying security controls and capabilities. So let's talk about this and welcome to the show again, Jonathan. Hi. Thanks for having me on again, Matthias. It's great to be here. Great to have you. And cybersecurity fabric, let's start with the basics.
The term fabric is not really new to KuppingerCole and to IT in general. We've seen network fabrics, data fabrics, and of course, very close to my heart, the KuppingerCole Identity Fabric together with the reference architecture. What exactly do you mean by a cybersecurity fabric and what do we mean?
Well, this is based on a conversation with my colleagues here in KuppingerCole, including Martin Kuppinger. And the idea is that the cybersecurity fabric is an architectural approach that connects our disparate security technologies into a cohesive integrated system. And where I guess where I'm going is that our traditional security setup, if you like, has siloed security tools. And we've heard the phrase, many panes of glass, but of course, it's much deeper than that. And this is to try and remedy that.
The fabric should provide seamless communication, automation, and orchestration between components. So if you like, we have four key pillars, visibility, integration, automation, and adaptability. And if you will, think of it as a mesh where security capabilities are woven together with clear information flows and coordinated responses. And think as well of the, if you like, the vertical dimension as well. This fabric should span infrastructure, applications, endpoints, cloud, data, and of course, will integrate with the identity layers of the environment as well.
It's a really, really fascinating approach. And again, it's less about technology in general or introducing new technologies, but it's more about rethinking how we can combine this, integrate that and orchestrate what we already have. And maybe also as we use it in the identity fabrics to evolve existing landscapes towards a next generation cybersecurity framework.
Yeah, absolutely. Where I'm going, I think, is I'm not asking anyone to buy anything necessarily. I believe that every organization has the necessary security tools. They have Ascent, they have Endpoint, they have an EDR, they have NDR, they have what the tools that they already feel are necessary. The challenge, the problem I see is that these tools don't talk to each other. And so you have gaps, you have inefficiencies. And as we know, the gaps and inefficiencies are the cracks in the armor through which attackers can penetrate.
And so the idea of this fabric approach is making sure that there are connections and communication between existing technologies. And therefore, because we have communication, we have a force multiplier effect, because we are integrating and automating our tool set. And so instead of saying, well, we need another tool. And I remember once when I was out in the Middle East, I had an IT manager very worried saying, how many antiviruses do I need to be safe and secure?
Of course, you only need one Endpoint tool. But it needs to be able to integrate with your SIM, needs to be able to integrate with your firewalling, needs to integrate with your application security controls. And that way, we maximize the value of our existing investments. And that's saying that we usually only leverage 20% of the capabilities of the solutions we buy, and maybe that can also contribute to that. But from the platform approach, how does that differ from existing approaches like Zero Trust or other security frameworks? There are lots around.
Is this complementary or replacement or coexisting? How does it work?
Well, I like to think of it as complementary. I'm not trying to reinvent Zero Trust. I'm certainly not trying to replace NIST or the work of ISO. And those are all standards and governance and control frameworks that have great value. And take Zero Trust as an example. It provides principles and it provides a philosophy. What we're saying is with a fabric, we're providing the architectural implementation. And so these frameworks that we talk about like ZT, like NIST, like ISO, provide the what and the why. And then as architects, this is the how. This is how you build the house.
And for example, Zero Trust requires continuous validation, which is arguably a good thing. And the fabric provides the infrastructure to make that possible. So this is an enabler for implementation of these best practices that we know well, and it's not intended to be a replacement for them. You mentioned the what, the why and the how. The question is, why now? The question is, what is the business case? What are the benefits for an organization to leverage that approach and to adopt the concept of a cybersecurity fabric? Why should they do that?
And what is the starting point then, the business case? It's a great question again. And I have come to realize that in cybersecurity, we must be highly cognizant of how what we're doing fits in and align to the business case and indeed the business strategy of the organization. So what do we get? We get faster detection and response times because we have this automated information sharing and orchestration of response. What else does that give us? Reduced manual effort for security teams.
So our precious human resources in the SOC, in the application support teams, in the incident response teams, kind of focus on high value activity. We also, because we have integrated telemetry, and again, we look across our friends in infrastructure and service operations, and we know integrated telemetry gives us that better visibility. And for us, we can see across the entire attack surface. This leads us to improved resilience through coordinating our defensive measures.
And again, these are automated and orchestrated. And thus, we achieve lower operational costs, not by cutting, but by maximizing the existing investments we already have. And that really rings a bell for me, because I did some episodes around, for example, the management of NHI, of non-human identities, just in the recent weeks. And automation orchestration was a key component because of the sheer number of identities there. And you've mentioned it just right now as well. So automation as a key component.
So how mature does an organization security program need to be before they can effectively implement this Fabric approach? Because if you automate something that's not mature, you're maybe automating a problem, not a solution. Indeed. And one of the things I think it's very easy to deceive ourselves into just, as you say, admiring or even automating the admiration of a problem. Why is this Fabric approach different?
Well, it's adaptable to whatever maturity level you're at. So the Fabric can meet you where you are. And you can start with fundamental capabilities, asset inventory, vulnerability management, basic monitoring.
That's a, if you like, a ground level maturity. You can then say, well, again, don't run before you can walk. Focus on building visibility before implementing complex automations. And that's okay, because building visibility leads you towards what automations are the most value for your business. And indeed, what do we automate? Repetitive, low-risk tasks. They are the low-hanging fruit, and a lot of them. So you can get a lot of wins with those. And as the security maturity grows, the Fabric grows organically.
So you can also really have some kind of transition architectures where you move from one step to the next and really improve over many steps and get to a better, more mature process framework and implementation in terms of a cybersecurity Fabric. I think that's the way that we do it in general with our advisory as well. So really to identify what is the next step that can be achievable? And that sounds like that's playing very well there as well. We're already almost out of time. This is just a sneak peek at what we're doing, and there's more to see and to hear from you very soon.
But I still want to look ahead. How do you see such a concept, this concept of the Kuppinger Coal Cybersecurity Framework evolve over the next three, five years? I don't think there's any surprises, certainly, that we'll see AI becoming the central nervous system of the cybersecurity Fabric. And that means we're going to see more adaptive and self-healing capabilities built into the Fabric. It means that we're able to integrate cloud security and on-premises security through common Fabric interfaces.
And therefore, we can then extend beyond our enterprise into one of the most problematic areas, our supply chains and our ecosystem partners, which means, again, we can get automation to move from reactive to predictive, and we can get to be addressing threats before they impact. Right. And this really sounds promising. So before we wrap up, to move that from that, at that moment in time, still theoretical approach, what's one piece of advice that you would like to give security leaders to make that more tangible for them when they are intrigued by this concept? What would be step one?
Well, I think step one, know where you are. Begin with a clear assessment of your current security architecture and integration points. And identify the most painful manual processes or visibility gaps. These are your initial targets.
Next, I think we can focus on building a foundation of common data models and integration standards. And everyone says common data models, oh, you're trying to boil the ocean.
No, I want us to start small, but design with scale in mind. Ensure pilot projects have clear success metrics. And the other thing is this fabric, it's a journey, not a destination. As we evolve, as our posture evolves, as the threats and the technologies change, the fabric can and will evolve with us. That sounds really, really fascinating and really like a great way to move forward with an existing infrastructure because it really gives you guidance along the long-term planning as well.
Listeners who want to learn more about the cybersecurity fabric concept, where can they find additional resources? Of course, they can drop questions on YouTube below this video. And I'm sure you, Jonathan, will answer them or I, but there should be more research that is more available, right? Absolutely. So we're going to be launching this and publishing a white paper and I'll be presenting at EIC 2025 in Berlin from the 6th to the 9th of May. And I'll be also walking and talking.
Please, if you are there and this interests you, then please do stop me and we'll have a chat. As this rolls out, I'm going to be speaking at several upcoming industry conferences on the topic.
So again, we've had interest from some conferences and we'll be building more in because we want to spread this. It's something that Cuppingill wants to share with the community. As we grow this, we'll be offering, as you said, similar to the identity fabric, we'll offer reference architectures and integration patterns for some common security tools. And we'll be encouraging, of course, the community to contribute to this as well. And for those who wish, I'm always available to connect on LinkedIn to discuss specific implementation questions. That sounds good. Really sounds good.
So I'm looking forward to learning more from you about the cybersecurity fabric, maybe to integrate that seamlessly with the identity fabric and the reference architecture that we are working on there right now. As I say, cybersecurity is always best when you do it collaboratively. And I think the fabric does that for the architecture and Cuppingill does this for the practitioners and the vendors and all those who are using that. That's really interesting. I'm really looking forward to learning more. Thanks again, Jonathan, for being my guest today. That concludes today's analyst chat.
Drop your questions if you have any. If you're interested in specific aspects, let us know. We'll follow up with a new episode on that. And thank you for listening to that episode and your questions will be valuable in evolving that for Jonathan as well. So until next time, thank you, Jonathan. For everybody, stay secure and see you maybe in Berlin. And if you're watching that later, just reach out to us or find out what's been published from EIC then. See you then. Bye-bye.