Dark rubik cube

Infiltrating the dark side

Uncategorized
(Source: Stockfresh)

11 June 2014

Two weeks ago I wrote about Shadow IT in connection with the phenomenon of business units and individual workers bypassing IT departments to go straight to the cloud. At HP Discover 2014 in Las Vegas I learned of another form of shadow IT. To put it more accurately, I learned of a shadow IT market.

In an interesting presentation at the event, Art Gilliland, SVP & general manager at HP Enterprise Security said companies were asking why they were spending so much money on security and it wasn’t getting any better. He stated that billions had been spent on security last year but there had been a 20% increase in breaches and a 30% increase in cost.

Gilliland suggested this was partly the result of a change in the adversary landscape, an evolution in the bad guys from individuals in their basements doing something for kicks to organised and sophisticated gangs seeking to steal things for money. Or, if they were government organisations, for espionage purposes.

Then he went on to offer a more interesting perspective when he spoke about participants in the adversary landscape working together and buying and selling services from each other in the market place. Gilliland suggested the market was a driving force for what was happening in the adversary landscape. “Market forces are organising all the actors around the value chain or process,” he said.

In other words, the adversary landscape was evolving into a shadow IT market (although he never used that term) and behaving exactly as any market would. Gilliland said the market was “motivating individuals to specialise in one of those steps” because “if you specialise in the market you make more money”. He added that this was “driving complexity for our customers”.

Through the mirror
I found the argument that the forces on the dark side were essentially coalescing around a mirror market fascinating. Like much of the IT market, anti-security has grown from the preserve of hobbyists and geeks doing something to prove they can into a much more disciplined and structured market. In that light, it was intriguing to view that market from a channel perspective and to see the parallels with the legitimate market.

In much the same way as channel partners play a defined part in the overall IT market and they do so by choosing what role they wish to play in that structure, so those players in the anti security market make a decision about the role they play based on whether it is viable for them to do so. We have heard vendors exhorting resellers to specialise or to ensure they can add value and to move away from trying to be all things to all men. It’s not just confined to channel partners.

The vast majority of vendors have also taken the decision not to try and cover all the parts of the market but to collaborate with other actors in the supply chain because they are better at what they do and they can do it more cheaply and efficiently. Which is another reason why channel partners exist.

It helps our understanding of the forces seeking to damage legitimate organisations if we can view them in terms that are familiar to us. Everybody talks about the market and market forces, it’s part of their everyday vocabulary. So if they can see the players in the anti security sphere through the prism of the market, they can start to understand how that market operates.

The one big difference, of course, is that the companies seeking to protect organisations against security threats have to get it right all the time whereas, as Gilliland pointed out during his presentation, the bad guys only have to get it right one time. And because the anti security market, (or the shadow IT market) has become more efficient by splitting into separate constituent parts and, in the process, underlining the viability of specialisation, those bad guys have become very good at what they do. The ones who aren’t have been flushed out of the market.

Sound familiar?

Read More:


Back to Top ↑