SYS-CON MEDIA Authors: Pat Romanski, Jnan Dash, Elizabeth White, Yeshim Deniz, Nikita Ivanov

Blog Post

AlgoSec Security Management Suite Allows Viewing and Remediating IT Risk

RSA preview interview with Yuval Baron, Chairman, President & CEO, AlgoSec

Hi Yuval, Thank you for taking the time to answer my questions. First of all, please tell us, what is AlgoSec all about and what do you do?

Yuval Baron: AlgoSec enables organizations to manage security at the speed of business. Enterprise networks and data centers are highly complex, oftentimes consisting of vast numbers of networking and security devices, which use thousands of security policies and hundreds of critical business applications. All of these must be managed across multiple vendors, stakeholders and locations. This rising complexity, plus evolving cyber threats and increasing business demands makes it hard to keep up if you're manually managing the security policy. Additionally, traditional security management efforts are siloed across different IT organizations such as network operations, security operations, and application teams.  All of this comes at the cost of a major loss of productivity.

AlgoSec's automated and application-centric approach orchestrates the management of complex policies across all of these networking and security devices and aligns the different teams to achieve the best of both worlds - improving security and enabling a faster response to dynamic business needs.

I'm happy to share that today, more than 1000 of the world's leading organizations, including 15 of the Fortune 50, rely on AlgoSec for faster security provisioning of business applications, simplified operations and improved protection against cyber-attacks. AlgoSec customers typically report significant and quantifiable improvements in operational efficiency - up to 80% reduction of time spent on audits and 60% less time spent processing firewall changes - while also reducing the attack surface and ensuring networking and security devices are configured properly.

What are you going to launch at RSA?

Baron: At RSA we will be announcing the latest version of the AlgoSec Security Management Suite, which now enables organizations to view and remediate IT risk with the business in mind. The AlgoSec Suite integrates with vulnerability scanners from Qualys and Nessus to display vulnerabilities associated with data center applications and their associated physical or virtual servers. With this integration, the AlgoSec Suite delivers unprecedented visibility into the risk levels of data center applications - even as they change - enabling IT and security teams to more effectively communicate with business stakeholders so they can "own their risk". AlgoSec will have a booth (#427) at RSA where you can see also see a live demo of the new capabilities.

The biggest challenge is that this is a new way of managing IT risk, but we have data from a survey we conducted last fall, plus research from Gartner, that shows the demand is there for this concept of viewing and prioritizing risk from the perspective of a business application.

Who is your target audience and how do you intend to reach them? What is the biggest challenge you face right now in telling your story and winning over new clients?

Baron: An enterprise solution sale spans multiple stakeholders in networking, security, application development, architecture groups, and involves from the administrators all the way up to CSO or CIO sometimes. So while we have a good story and can bring tremendous, quantifiable value, the pain points for each of these groups is a bit different - we have evolved from a "tool" to a solution that ties into your business processes.

I'd be curious to hear any general thoughts you have on market trends...

Baron: There are 4 market trends that we see impacting our space:

  1. Next-generation firewalls are becoming more mainstream - they're no longer "next-gen" per se. Adoption rates are on the rise, every firewall vendor is now touting next-generation firewall capabilities and organizations are becoming more mature in terms of their expertise with managing these devices. That's not to say that the traditional firewall is dead, but the firewall as we know it is evolving as it has since its inception. From a security management perspective this means finding ways to take advantage of the granular control without adding overhead from additional changes and managing next-gen policies alongside traditional ones.
  1. We're seeing more interest in our solution as part of data center consolidation and cloud migration projects. The "cloud" is disruptive to networks and data centers because of the significant financial and operational value that can be derived, but getting there takes a real commitment that involves many aspects, one of which plays right into a strength of ours - managing application connectivity.
  1. We are seeing a shift in how security is viewed, from where security owns the risk to where security consults the business, but ultimately the business owns the risk.
  1. Software-defined networking is definitely on the radar of senior management. Within the next several years we'll start seeing deployments in enterprise production environments.

What's the business model? How will you make money?

Baron: AlgoSec's primary source of revenue is through software licenses of its product suite delivered on a physical or virtual appliance or as stand-alone software to Enterprise customers, Managed Service Providers and consultants. Additionally, AlgoSec also provides professional services, primarily around integrating and aligning its solutions with the customer's existing environment.

Who are your competitors?

Baron: Depending on the geographies and the required business solution we may compete with companies such as Skybox, Tufin, and FireMon.

How do you differentiate from your competitors?

Baron: AlgoSec has four primary advantages:

  1. Our profound, application-centric technology specifically focuses on business agility and delivering application-centric visibility. The solution ensures that application owners, network operations and security teams are aligned and it enables risk to be viewed and prioritized by business application.
  2. AlgoSec automates more business processes than any other solution, resulting in greater productivity and a quantifiable ROI.
  3. AlgoSec provides more breadth and depth of policy analysis. AlgoSec's patented Deep Policy InspectionTM technology taps on more data sources and conducts more rigorous analysis to present to the most accurate and comprehensive results for risk analysis, policy optimization and performance improvements.
  4. Lastly, AlgoSec is dedicated to customer satisfaction. I liken AlgoSec as "the Zappos of enterprise software." We back everything up as the only company in its domain to offer money-back guarantee. Within 9 years only two AlgoSec customers out of more than 6,000 transactions have ever returned the solution, resulting in a 99.97 percent satisfaction rate.

How does your technology differentiate from the competition and can you elaborate on the different technology deployed?

Baron:

  1. AlgoSec delivers a business-centric approach to security policy management that focuses on maximizing the availability of critical business applications as well as operational agility.
  2. With our latest release, we now provide visibility of risk per business application, enabling business owners to make smarter risk remediation decisions and ultimately "own the risk".
  3. AlgoSec comes out-of-the-box with robust and highly flexible change workflows that can be tailored to meet the real-life needs of our customers.
  4. AlgoSec provides rich, accurate and actionable security policy analysis for simplifying compliance, reducing risk and optimizing the rulebase.
  5. The AlgoSec Suite consists of three products, but they are truly integrated. One example I can give is looking at a business application, adding a new server to a "flow" and automatically triggering the change request with full risk and compliance check to ensure that the change won't introduce more risk.
  6. AlgoSec is proven to scale in the most demanding environments. This may not seem different considering many vendors say this, but the fact is many cannot prove it when put into an enterprise environment. I'm happy to share that AlgoSec is built to scale.

What business or technology could yours disrupt?

Baron: AlgoSec's technology doesn't replace an existing solution because there really is no other solution. The disruption is shifting organizations from a manual security policy management approach that is fraught with risk, non-compliance and inefficiency to an automated and application-centric approach that aligns different stakeholders and is ultimately baked into business processes. At the simplest level, this technology enables organizations to achieve significant time and cost savings, while ensuring a more secure and agile business.

Who founded the company, when? What can you tell me about the story of the company's founding?

Baron: I founded the company along with our co-founder and CTO Avishai Wool back in 2003 and we are self-funded.

What is your distribution model? Where to buy your product?

Baron: We sell primarily through the channel and have resellers and distributors throughout the world.

What's next on your product roadmap?

Baron: We will continue to build upon our mission of enabling security to be managed at the speed of business. This means expanding upon our business application-centric approach, continuing to integrate with and support other network and security devices and continuing to focus on automating more security management processes.

Are you targeting a first VC round? If yes when and what will you use the funds for? How much money is being sought?

Baron: AlgoSec has never needed to raise money from external investors as the company generates a positive cash flow. With our cash flow increasing over the years and our ability to sustain our own growth we are not currently looking into raising funds.

What else would you like to add?

Baron: I would like my team to wake up in the morning with a smile on their faces. We hire very bright people who are also team players all focused on the goal of serving our customers and ensuring we are doing everything within our realm to make them happy. AlgoSec's financial success is a result of implementing such an approach.

Other information if applicable:

Partnerships, collaborations or affiliations: We have technology partnerships with Baron: Check Point, Cisco, Fortinet, Juniper, McAfee, Palo Alto Networks, Blue Coat, HP, VMware, and we just announced our partnership with Qualys

Federal or state grants, contracts or awards received:

Market size being pursued: We focus on the enterprise market

Who are the likely competitors, direct or indirect?

Is the company profitable? Yes, we've been profitable since 2007

Current annual revenue: We do not disclose our revenue numbers though I can share that we have a 3 year CAGR of 55%

AlgoSec is the market leader for security policy management, enabling organizations to simplify and automate security operations in evolving data centers and networks. More than 1000 of the world's leading organizations, including 15 of the Fortune 50, rely on AlgoSec for faster security provisioning of business applications, streamlined change management, continuous compliance and tighter security.

AlgoSec's application-centric approach orchestrates the management of complex policies across firewalls and related network devices, aligning IT teams for improved business agility.

AlgoSec is committed to the success of every single customer, and offers the industry's only money-back guarantee. For more information, visit www.AlgoSec.com.

More Stories By Xenia von Wedel

Xenia von Wedel, Tech blogger and SVP of Transform PR/San Francisco- Mountain View. She mainly writes about B2B solutions, social media and open source software. Transform Public Relations is a full-service PR agency, serving clients in a variety of industries worldwide. The agency is focused on thought leadership content creation and syndication, media outreach and strategy. Buy her a coffee if you like her article: http://xeniar.tip.me

Latest Stories
SYS-CON Events announced today that Gridstore™, the leader in hyper-converged infrastructure purpose-built to optimize Microsoft workloads, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Gridstore™ is the leader in hyper-converged infrastructure purpose-built for Microsoft workloads and designed to accelerate applications in virtualized environments. Gridstore’s hyper-converged infrastructure is the ...
There's Big Data, then there's really Big Data from the Internet of Things. IoT is evolving to include many data possibilities like new types of event, log and network data. The volumes are enormous, generating tens of billions of logs per day, which raise data challenges. Early IoT deployments are relying heavily on both the cloud and managed service providers to navigate these challenges. In her session at Big Data Expo®, Hannah Smalltree, Director at Treasure Data, discussed how IoT, Big D...
DevOps Summit 2015 New York, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that it is now accepting Keynote Proposals. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete...
The 4th International DevOps Summit, co-located with16th International Cloud Expo – being held June 9-11, 2015, at the Javits Center in New York City, NY – announces that its Call for Papers is now open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's large...
The Internet of Things promises to transform businesses (and lives), but navigating the business and technical path to success can be difficult to understand. In his session at @ThingsExpo, Sean Lorenz, Technical Product Manager for Xively at LogMeIn, demonstrated how to approach creating broadly successful connected customer solutions using real world business transformation studies including New England BioLabs and more.
WebRTC defines no default signaling protocol, causing fragmentation between WebRTC silos. SIP and XMPP provide possibilities, but come with considerable complexity and are not designed for use in a web environment. In his session at @ThingsExpo, Matthew Hodgson, technical co-founder of the Matrix.org, discussed how Matrix is a new non-profit Open Source Project that defines both a new HTTP-based standard for VoIP & IM signaling and provides reference implementations.
DevOps Summit 2015 New York, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that it is now accepting Keynote Proposals. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete...
Explosive growth in connected devices. Enormous amounts of data for collection and analysis. Critical use of data for split-second decision making and actionable information. All three are factors in making the Internet of Things a reality. Yet, any one factor would have an IT organization pondering its infrastructure strategy. How should your organization enhance its IT framework to enable an Internet of Things implementation? In his session at Internet of @ThingsExpo, James Kirkland, Chief Ar...
Scott Jenson leads a project called The Physical Web within the Chrome team at Google. Project members are working to take the scalability and openness of the web and use it to talk to the exponentially exploding range of smart devices. Nearly every company today working on the IoT comes up with the same basic solution: use my server and you'll be fine. But if we really believe there will be trillions of these devices, that just can't scale. We need a system that is open a scalable and by using ...
The Internet of Things is tied together with a thin strand that is known as time. Coincidentally, at the core of nearly all data analytics is a timestamp. When working with time series data there are a few core principles that everyone should consider, especially across datasets where time is the common boundary. In his session at Internet of @ThingsExpo, Jim Scott, Director of Enterprise Strategy & Architecture at MapR Technologies, discussed single-value, geo-spatial, and log time series dat...
"SAP had made a big transition into the cloud as we believe it has significant value for our customers, drives innovation and is easy to consume. When you look at the SAP portfolio, SAP HANA is the underlying platform and it powers all of our platforms and all of our analytics," explained Thorsten Leiduck, VP ISVs & Digital Commerce at SAP, in this SYS-CON.tv interview at 15th Cloud Expo, held Nov 4-6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
SAP is delivering break-through innovation combined with fantastic user experience powered by the market-leading in-memory technology, SAP HANA. In his General Session at 15th Cloud Expo, Thorsten Leiduck, VP ISVs & Digital Commerce, SAP, discussed how SAP and partners provide cloud and hybrid cloud solutions as well as real-time Big Data offerings that help companies of all sizes and industries run better. SAP launched an application challenge to award the most innovative SAP HANA and SAP HANA...
Connected devices and the Internet of Things are getting significant momentum in 2014. In his session at Internet of @ThingsExpo, Jim Hunter, Chief Scientist & Technology Evangelist at Greenwave Systems, examined three key elements that together will drive mass adoption of the IoT before the end of 2015. The first element is the recent advent of robust open source protocols (like AllJoyn and WebRTC) that facilitate M2M communication. The second is broad availability of flexible, cost-effective ...
What do a firewall and a fortress have in common? They are no longer strong enough to protect the valuables housed inside. Like the walls of an old fortress, the cracks in the firewall are allowing the bad guys to slip in - unannounced and unnoticed. By the time these thieves get in, the damage is already done and the network is already compromised. Intellectual property is easily slipped out the back door leaving no trace of forced entry. If we want to reign in on these cybercriminals, it's hig...
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is now open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.