
Endpoints Accelerating Cybersecurity Innovation
CIO Review APAC | Thursday, January 19, 2023

Mining attack data to identify new threat patterns and correlations, then fine-tuning machine learning (ML) models and new products, is the goal.
FREMONT, CA:Endpoint attacks are delivering an increasing amount of data, which DevOps teams need to improve current products and create new ones. The objective is to analyse attack data to find new threat patterns and correlations, then hone machine learning (ML) models and new products. The data assets available for developing new platforms and apps are richer the more complicated and numerous the endpoint assault attempts are. For market leaders, extracting new insights from endpoint attack data is a top strategic priority.
On the Hunt for Innovation and Market Growth
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Enterprise expenditure on endpoint protection platforms will increase globally from a base of USD 9.4 billion in 2020 to USD 25.8 billion in 2026, at a 14.4 per cent compound annual growth rate (CAGR), the most recent Information Security and Risk Management projection from Q4 2022. Attackers' constant search for novel ways to sneakily infiltrate endpoints is a key market driver.
Intruders had switched to malware-free intrusions which accounted for 71 per cent of all detections indexed by the CrowdStrike Threat Graph. By detecting even the smallest new signals that previous-generation endpoint security technologies would entirely miss, CrowdStrike sees a chance to assist its customers in preventing a breach.
They can accept weak signals from many endpoints, which is one of the areas in which they've made significant advances. And by connecting these, can discover brand-new detections. Now, expanding it to third-party partners so that they can examine additional weak signals across endpoints and domains and develop a novel detection, at the company's annual Fal.
In the endpoint security industry, there is little sustained competitive parity. Enterprises are purchasing startups in AI and ML as well as well-established businesses with extensive knowledge to stay up with the inventive and deadly new breach strategies that attackers are coming up with.
In the endpoint security industry, there is little sustained competitive parity. Enterprises are purchasing startups in AI and ML as well as well-established businesses with extensive knowledge to stay up with the inventive and deadly new breach strategies that attackers are coming up with. Selling the advantages of consolidation is effective when there is a large product portfolio to package and a consistent stream of new goods.
Endpoint security product buyers are looking for integrated solutions. In response, providers are reorganising their partners and products around XDR platforms. Capabilities include managed service delivery, enhanced threat intelligence, and identity threat detection and response. The most recent study on the competitive environment for endpoint protection platforms is written by Rustam Malik and Dave Messett. Over 60 per cent of businesses will have swapped out their outdated antivirus software for EPP and EDR systems that integrate prevention with detection and response.
Five of the several cutting-edge cybersecurity applications, platforms, and solutions to which endpoint security has contributed are shown to have the greatest influence. These include self-healing endpoints, unified endpoint management (UEM), cloud-native platforms, remote browser isolation (RBI), and identity threat detection and response (ITDR).
Cloud-native Platforms that Advance Enterprise Endpoint Security
Cloud-native endpoint protection technologies allow for more individualised user experiences since they can more quickly adapt to how their teams work. Application programming interfaces (APIs) for cloud-native EPP, EDR, and XDR platforms are frequently more dependable and facilitate easier interaction with cybersecurity tech stacks.
The capacity of cloud platforms to expand to meet fluctuations in computation, processing, and storage is another aspect influencing how cloud-native endpoint platforms are advancing innovation in the broader cybersecurity sector.
In addition to managing real-time protection and response, cloud-native endpoint platforms also provide telemetry data that is helpful for behaviour-based detection and analytics. This can assist in locating and addressing fresh and developing risks.
Cloud-native endpoint protection platform (EPP) solutions continue to see an increase in acceptance as they shift the administrative burden from product maintenance to more fruitful risk-reduction operations. AWS, Carbon Black, CrowdStrike, and Zscaler are top suppliers of cloud-native endpoint security.
Unified Endpoint Management (UEM) that Drives Greater Endpoint Visibility Regardless of Device
When hybrid work became the norm and controlling numerous endpoints on the same platform became a top priority, UEM proved to be vital. CISOs tell VentureBeat that companies are constantly searching for new approaches to deploy, patch, and provision endpoint devices for remote workers while simultaneously streamlining, streamlining, and increasing visibility.
Additionally, CISOs desire enhanced endpoint security without compromising user experience, a problem that several UEM providers are attempting to address in their most recent and upcoming releases. To deliver greater reliability and better insight into endpoint performance, advanced UEM systems combine analytics, ML, and automation.
To increase productivity, there is a tendency toward centralising endpoint support personnel, tools, and procedures. The potential of cyberattacks is growing, necessitating a speedier patch distribution process as well as better control and compliance in configuration management.
The UEM industry is consolidating on its own, in part due to CISOs' focus on increasing endpoint security at a reduced cost while enhancing network effectiveness. IBM, Ivanti, ManageEngine, Matrix42, Microsoft, and VMWare are notable companies that are all putting themselves in a position to profit from the current market consolidation.
Ivanti and VMWare are the only two providers to obtain a neutral-to-positive evaluation for their zero-trust capabilities, according to Gartner's most recent Magic Quadrant for Unified Endpoint Management Tools.
Remote Browser Isolation that Solves the Challenge of Protecting Every Browser Session from Attack
In many businesses that are pursuing zero trust network access (ZTNA) efforts, including small, medium, and large-scale enterprises (including government agencies), remote browser isolation (RBI) is being widely adopted. Although RBI assumes that no web material is secure, it does not call for significant changes to technology stacks.
Because RBI executes all browser sessions in a safe, isolated cloud environment, applications can be accessed with the least amount of privileges during a browser session. Endpoint agents or clients no longer need to be installed or monitored on managed or unmanaged devices as a result. Additionally, it permits third-party contractors to utilise their own devices in a BYOD (bring your device) environment and provides simple, secure access.
Broadcom, Forcepoint, Ericom, Iboss, Lookout, NetSkope, Palo Alto Networks, and Zscaler are some of the top RBI providers. Ericom stands out for its zero-trust RBI strategy, which protects endpoints against sophisticated online threats while maintaining the performance and user experience of the native browser.
Additionally, RBI can shield data stored in programmes like Office 365 and Salesforce from potentially harmful unmanaged devices that may be used by partners or contractors. Users and data can be protected with Ericom's solution in virtual meeting spaces like Zoom and Microsoft Teams.
Self-healing Endpoints that Free the IT team’s Time while Securing Networks
Self-healing endpoints will turn off by themselves, check the versions of their OS, programmes, and patches, and then restart into the most effective configuration. Numerous more companies, including Absolute Software, Akamai, Ivanti, Malwarebytes, Microsoft, SentinelOne, Tanium, and Trend Micro, offer endpoints that can self-heal on their own.
The approach taken by Absolute Software is distinctive in that it uses firmware-embedded persistence as the cornerstone of self-healing. Every PC-based endpoint has an undeletable digital connection according to the company's strategy. The Resilience platform from Absolute stands out for offering accurate asset management data together with real-time visibility and control of any device, whether it is connected to a network or not. The platform's other features include asset management, device and application control, endpoint intelligence, incident reporting, resilience, and compliance. It is also the first self-healing zero-trust platform in the sector.
Forrester describes the four trends that will shape the future of endpoint management, as well as the endpoint management problems and six features of modern endpoint management. CISOs tell VentureBeat that they frequently use the cost and time savings for IT service management, the decreased workload for security operations, the possible losses from damaged assets, and the advancements in audit and compliance to argue for self-healing endpoints.
More in News