A modern company may possess hundreds, or even thousands, of security data sources.

Examples include:

Infrastructure

  • Windows servers
  • Linux servers
  • Active Directory
  • domain controllers
  • DNS
  • DHCP
  • file servers
  • databases
  • hypervisors
  • virtualization solutions.

Network

  • firewalls
  • routers
  • switches
  • VPN
  • proxy
  • Wi-Fi
  • IDS
  • IPS
  • SD-WAN equipment.

Endpoints

  • antivirus
  • EDR
  • XDR
  • Windows machines
  • Linux machines
  • macOS
  • servers.

Identify

  • Active Directory
  • Entra ID
  • identity providers
  • MFA
  • SSO
  • IAM/PAM solutions.

Cloud

  • Microsoft Azure
  • AWS
  • Google Cloud
  • Kubernetes
  • containers
  • SaaS.

Applications

  • ERP
  • CRM
  • financial applications
  • HR applications
  • web applications
  • API
  • e-commerce platforms.

Messaging and collaboration

  • Microsoft 365
  • Exchange
  • Teams
  • SharePoint
  • Google Workspace
  • third-party messaging solutions.

Security

  • EDR
  • antivirus
  • WAF
  • IDS/IPS
  • DLP
  • CASB
  • vulnerability solutions
  • scanners
  • attack protection systems.

The problem is therefore generally not the lack of information.

The problem is their fragmentation.

Categories: