A couple of recent trends and predictions for cybersecurity for the coming year.
🛡️ 2024 - The Year of Security Data Lake? Security Data Lakes are rapidly emerging as an influential force in cybersecurity. Data Lake has a scalable architecture and seems to be a more suited approach to log processing compared to similar applications. Will this be the year we see a widespread adoption? Time will tell but the signs are promising. We’ve already delivered a few Security Data Lake/Lakehouse integrations and are consistently seeing more. To get in-depth understanding, go through our guide on how AWS Security Lake is architected to ingest data from multiple sources.
🔺 OCSF is on the rise: As the Open Cybersecurity Schema Framework (OCSF) gains traction, security companies are increasingly embracing its standardized approach to data representation and sharing. Adoption has expanded to include more than 145 organizations and 435 individual contributors — an 8x increase between 2022 and 2023.
📈 ServiceGraph Connectors are making strides with Operational Technology: Service Graph Connector integration with the OT Security application automates critical data from: sensor appliances, OT assets, and network connections using the ServiceNow Common Service Data Model (CSDM). The other popular integrations for ServiceNow include Vulnerability Response and SecOps.
🚀 Palo Alto ups the ante in cybersecurity with advanced Cortex platform upgrades: Palo Alto Networks recently announced Platformization, a strategy to consolidate their product offering into a single, unified platform. One of the major SOC platforms, Cortex, released important updates to enhance your existing Cortex integration. Their latest advancements and versions in their platforms include:
Cortex XSIAM 2.1: Improved visibility, security, and platform usability. Highlights: drill-down dashboards, user risk analysis with OS/location data, and BYOK (Bring Your Own Key) encryption.
Cortex XDR 3.9 & Agent 8.3: New threat protection: on-write malware blocking and pre-boot attack detection.
Cortex XSOAR 8.5: Enhanced user experience, SOC efficiency, and collaboration. Highlights: multi-tenant incident investigation, secure custom Docker images, and new content packs.
Cortex Xpanse 2.4: Leverage MITRE ATT&CK framework to gain deeper insights into vulnerabilities, enabling more effective prioritization and remediation. Enhanced incident response through improved capabilities and increased visibility into user activity.