By Tony Palmer, Principal Validation Analyst
NOVEMBER 2022
How will your organization’s spending in each of the following areas of cybersecurity change – if at all – over the next 12 months? (Percent of respondents, N=344)
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Almost half (48%) of organizations report a problematic shortage of cybersecurity skills. This ongoing cybersecurity skills shortage has two major implications. The most obvious is a shortage of talented cybersecurity professionals, with simply more cybersecurity job openings than qualified candidates to fill them. The second implication is at least as important: Many members of the current cybersecurity workforce lack the advanced skills necessary to safeguard critical business assets or to counteract sophisticated cyber adversaries. Combine this with the unabated increase in security threats, and security professionals—no matter how qualified—will struggle with an incomplete visualization of what their most urgent risks are.
ESG is impressed with the way Microsoft Defender for Cloud identifies and prioritizes vulnerabilities and threats across an organization’s cloud configuration. Attack path visualizations and Cloud Security Explorer’s easily customizable graph-based queries enable security professionals to focus their attention on what is most important: strengthening the overall security posture of the environment with fast and efficient investigation and response.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
With the problematic shortage of cybersecurity skills, organizations need security tools that are effective and easy to use and that require little investment in training or time.
DevSecOps initiatives improve agility, can be deployed at every phase of the software lifecycle, and help enable security and compliance capabilities to be consumed as a service. By developing security as code, organizations can frontload security remediation and shift security posture management left earlier in the development cycle, so issues can be resolved sooner, wasting less effort working on flawed code and easing the burden on security administrators.
New features and capabilities can be quickly integrated into the software and applications that support data privacy and compliance programs.
ESG validated that Defender for DevOps provided comprehensive visibility into the overall security posture of a modern DevOps environment, providing deep context into the interaction and dependencies of code, entities, and infrastructure across multi-pipeline and multi-cloud environments. Most importantly, Defender for Cloud integrates this functionality seamlessly into recommendations, empowering organizations to instantly identify and remediate their most critical issues.
Microsoft has demonstrated a synergy between DevOps platforms—Github, Azure DevOps, and Visual Studio code—cloud platforms—Azure and multi-cloud support—and the Defender for Cloud security platform. ESG confirmed that Defender for Cloud can share visibility and improve communication between development and security teams, so security issues can be identified and resolved faster, reducing the burden on Security teams.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
Source: ESG, a division of TechTarget, Inc.
The ability to prevent, detect and respond quickly to modern threats is essential to ensure security for organizations’ workloads in hybrid cloud environments. How organizations respond to threats over time determines how well they can secure critical workloads across virtual machines, containers, databases, storage, and application services.
ESG validated that Defender for Cloud helps organizations focus on the most critical threats across the entire workload stack to protect workloads across hybrid cloud and multi-cloud environments from evolving threats.
ESG confirmed that the Microsoft end-to-end multi-cloud security portfolio provides unified visibility and a single control plane across multiple, diverse clouds. In addition, Microsoft combines agent-based and agentless approaches providing customers with broad and deep workload protection. This is a distinct advantage when compared to offerings that only focus on either an agentless OR agent-based approach.
This ESG Technical Validation was commissioned by Microsoft and is distributed under license from TechTarget, Inc.
All product names, logos, brands, and trademarks are the property of their respective owners. Information contained in this publication has been obtained by sources TechTarget, Inc. considers to be reliable but is not warranted by TechTarget, Inc. This publication may contain opinions of TechTarget, Inc., which are subject to change. This publication may include forecasts, projections, and other predictive statements that represent TechTarget, Inc.’s assumptions and expectations in light of currently available information. These forecasts are based on industry trends and involve variables and uncertainties. Consequently, TechTarget, Inc. makes no warranty as to the accuracy of specific forecasts, projections or predictive statements contained herein.
This publication is copyrighted by TechTarget, Inc. Any reproduction or redistribution of this publication, in whole or in part, whether in hard-copy format, electronically, or otherwise to persons not authorized to receive it, without the express consent of TechTarget, Inc., is in violation of U.S. copyright law and will be subject to an action for civil damages and, if applicable, criminal prosecution. Should you have any questions, please contact Client Relations at cr@esg-global.com.
The goal of ESG Validation reports is to educate IT professionals about information technology solutions for companies of all types and sizes. ESG Validation reports are not meant to replace the evaluation process that should be conducted before making purchasing decisions, but rather to provide insight into these emerging technologies. Our objectives are to explore some of the more valuable features and functions of IT solutions, show how they can be used to solve real customer problems, and identify any areas needing improvement. The ESG Validation Team’s expert third-party perspective is based on our own hands-on testing as well as on interviews with customers who use these products in production environments.
TechTarget's Enterprise Strategy Group is an IT analyst, research, validation, and strategy firm that provides market intelligence and actionable insight to the global IT community.