Metropolitan Water District of Southern California

Evolution of the Cybersecurity Tech Landscape: Challenges, Opportunities and Both

It has been said that over two hundred million years ago, the supercontinent of Pangea began to break apart approximately 135 million years after its formation. Imagine the multitude of ecosystems that existed during the lifespan of the continent. Once the changes in the land mass began, many ecosystems would have ended, many would have evolved, and there were opportunities for new environments to emerge over the millions of years that followed. The cyber and information technology landscape is analogous to the dynamic planet we call home. One only needs to look at recent high-profile acquisitions and mergers to see how dynamic the technology landscape can be. Major technology staples—the dominant species—like VMWare, Splunk, and IBM are undergoing changes that are in some ways comparable to the extinction-level events faced by the various species that have thrived, changed, or died over the eons the Earth has existed. Each dominant species has ever existed has left its mark on Earth’s environment.

In November 2023, Broadcom completed its acquisition of VMware, marking a significant step in transforming its cloud and hybrid solutions with a strong emphasis on subscription-based models​​. Similarly, Cisco finalized its acquisition of Splunk in March 2024, aiming to integrate Splunk’s data analysis and security tools to bolster its network, security, and observability offerings​​. Additionally, Palo Alto Networks announced the acquisition of IBM’s QRadar cloud assets in May 2024, a move designed to enhance its Cortex XSIAM platform and strengthen its AI-powered cybersecurity capabilities​. Furthermore, in May 2024, LogRhythm and Exabeam announced their merger, combining their strengths in SIEM and AI-driven security operations to deliver enhanced threat detection, investigation, and response capabilities. These strategic acquisitions reflect the growing emphasis on AI, security, and cloud solutions in the technology landscape.

These acquisitions and mergers may cause concern among chief information officers (CIOs) and chief information security officers (CISOs). Resiliency, security data observability, and cyber threat response capabilities such as those provided by these transforming products have long since become core to many organizations’ business continuity strategies. However, security leaders should not be apprehensive about the evolution of these technology giants. The shift in the technology landscape will create challenges, but opportunities will also be created in almost, if not equal, proportion to the challenges.

The Challenges

Transition to Subscription Models: Acquisitions or mergers of technology companies may change the licensing model to which an organization has become accustomed. For example, an acquisition or merger may change from a perpetual license model or maintenance agreement to a subscription-based one. This is the case with Broadcom's acquisition of VMWare.  

"In the near term, a shift from perpetual licensing to a subscription model could present a financial pain point. However, as consolidation of vendors improves communication efficiency, the assumption of a subscription model also creates an opportunity for organizations to have access to the latest software updates and innovations."

Vendor and Partner Management: The evolution of these technology giants naturally creates challenges for CIOs and CISOs' current relationships with the vendors and partners. These changes may necessitate renegotiation of contracts, adjustment to service level agreements, and modifications to agreements to ensure support and services continue uninterrupted. Additionally, service disruptions should be planned for instances where another acquires a company’s technology to obtain the acquired company’s customers.

The Opportunities

Enhanced Capabilities: Recent mergers and acquisitions, such as Cisco/Splunk, Exabeam/LogRhythm, or Palo Alto/IBM, highlight the creation of significantly enhanced observability capabilities. Blending these technologies presents an opportunity for advanced AI-driven capabilities to emerge and thrive in the marketplace. Thus, Security leaders will be provided with companies that produce products with excellent threat detection, investigation, and response capabilities.

Innovation and AI Integration: Combining advanced threat detection capabilities with AI-driven analytics creates environments where cyber risks can be managed comprehensively and proactively. In merging SIEM technologies, we may see integrations that provide enhanced real-time monitoring, automated response, and predictive analytics, allowing organizations to be ahead of the curve against cyber threats.

Both

Streamlined Vendor Management: CIOs and CISOs may face challenges in the early days of these tech company mergers, but they may realize significant benefits in the long term. Consolidation of vendors may reduce procurement complexities and reduce administrative overhead. Additionally, reduced vendors to work with for the same level of resiliency and security coverage will likely translate into more efficient communication and coordination with vendor partners, leading to product and service improvements.

Shift to Subscription Models: In the near term, a shift from perpetual licensing to a subscription model could present a financial pain point. However, as consolidation of vendors improves communication efficiency, the assumption of a subscription model also creates an opportunity for organizations to have access to the latest software updates and innovations. Furthermore, Subscription models provide predictable costs over time instead of large upfront expenses.

What Does it All Mean?

Just as with the Earth's constant evolution, some species win and thrive while others die off as the Earth’s environment shifts and changes with the moving of the continents. Similarly, the evolution of the cybersecurity technology landscape through mergers and acquisitions means some companies will thrive while others die or transform into something else altogether. Accept that the technology one has deployed will likely be changed, the impact of which will at least have some short-term, if not long-term, detrimental impact on the status quo.

Therefore, it is important at the announcement of a merger or acquisition, security leaders at least begin to plan for and even, if possible, test (in small use cases) replacement technology(ies) to proactively prepare for an inevitability that technology through the merger or acquisition process simply dies off or becomes a non-viable option for the organization. A transition process will likely take some time, and deployments may last for some time in another fiscal year. Thus, if a deployed technology is removed from the market when a merger or acquisition occurs or is transformed so that the financial or operational impact proves to be burdensome, leaders are ready to deploy a replacement to minimize the disruption to the business. However, if the risk is appropriate, a leader can take the challenges head-on to reap any benefits from the transformation of the technology, vendor partner, or both through the acquisition or merger process.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.