Blog

Yet another acronym is about to change how we do cybersecurity, and it’s SIEM’s fault.

Yet another acronym is about to change how we do cybersecurity, and it’s SIEM’s fault.

Note: this blog was first published on Smarter Cyber: Automation & AI

First, before the dawn of time there was IDS. The Intrusion Detection System. Was it the first cybersecurity acronym? I don’t know. I wasn’t around. Since then, too many have followed.

  • 1986–1987 — IDS (Intrusion Detection System)
  • late 1990s–early 2000s — IPS (Intrusion Prevention System)
  • late 1990s–early 2000s — SIM (Security Information Management)
  • 2005 — SIM -> SIEM (Security Information & Event Management)
  • 2006–2007 — DLP (Data Loss Prevention)
  • early 2000s (BYOD era) — MDM (Mobile Device Management)
  • 2009/2010 — ZT (Zero Trust)
  • 2012 — CASB (Cloud Access Security Broker)
  • 2013 — EDR (Endpoint Detection & Response)
  • 2013 — SDP (Software-Defined Perimeter)
  • 2015 — UEBA (User & Entity Behavior Analytics)
  • 2015–2017 — SOAR (Security Orchestration, Automation & Response)
  • 2017 — CWPP (Cloud Workload Protection Platform)
  • 2018 — EDR -> XDR (Extended Detection & Response)
  • 2019 — SASE (Secure Access Service Edge)
  • ~2019 — ZTNA (Zero Trust Network Access)
  • 2019 — CSPM (Cloud Security Posture Management)
  • 2020 — NDR (Network Detection & Response)
  • 2021 — CNAPP (Cloud-Native Application Protection Platform)
  • 2021 — EASM (External Attack Surface Management)

And the next one has arrived, at last. Surely this will be the last, and we can finally be a boring industry that has its architectures figured out and an acronym list that grows on a nice 3-5 year cadence. Perhaps one day.

But that day is not today.

So let’s talk about the new acronym Gartner has added to the soup.

Cybersecurity Mesh Architecture (CSMA).

I’ve spent the past few months studying this (with bias) since joining Mesh Security. In this article, my first in quite some time, I’ll share my take, not just on CSMA as an architecture, but what it looks like when implemented as a platform.

SIEM today does a few things pretty well: Store and query logs and sprinkle some detections on top. Maybe SIEM vendors will add autonomous investigation into the mix with AI SOC features, but already many teams are looking for cheaper solutions, moving to data lakes and using federated search on top of that, then getting detections from a layer on top.

CSMA is basically what I think SIEM could have aspired to become a decade ago to really unify the context of all SecOps data into one place. That’s what we all want right? One dashboard to rule them all?

The formula to pull such a platform off is probably no surprise to anyone (though easier said than done):

👉 Integrate into all the different acronym soup tools and infra to gather more data on demand to reduce log aggregation requirements.

👉 Unify and enrich data into a graph for de-duplicated, efficiently queryable and pivotable data. Way faster to query and better for detections (less noise to begin with).

👉 Include continuous posture management controls so we have proactive visibility of how our various framework controls are being complied with, agnostic to what data sources inform the compliance.

👉 Layer on response actions (with the integrated acronym soup).

👉 Yes, of course sprinkle in some AI investigation for any triggered detections.

Then you can have all your acronym solutions, including SIEM and/or data lake. You can mix and match vendors. Whatever underlying flexibility you want or need. The CSMA platform doesn’t care. It just federates whatever you give it into one normalized, unified graph of your entire IT apparatus.

Cool idea, right?

Instead of growing toward that cheaper, faster, and more comprehensive architecture over time as I hypothesize it could have, SIEM sort of sat in its lane as a reactive tool and left the posture management, most parts of enrichment, response, and investigation to other tools and manual work by the SecOps team. It even lagged behind in terms of automating investigation in the AI era. AI SOC products popped up to do that part, but SIEMs were and are still best positioned to do that, and are (I think) late to the party on some of the features and functionalities that CSMA is finally bringing to the table as a new way to practice cybersecurity.

It’s cybersecurity unified into one fabric, agnostic to whether the underlying data comes from SIEM, data lake, XDR, CSPM, (I’m not listing them again, you get the idea).

I won’t do a technical deep dive here (yet), just the idea behind it and what it looks like as a platform.

So here it is, plain and simple:

Migrate some or all of your log storage from SIEM to a data lake to reduce cost, query the rest where it sits as-needed for enrichment, and use APIs for all of your various tools to build a big graph of all the noteworthy stuff…

👉 identities

👉 endpoints

👉 configurations

👉 policies

👉 actions

👉 etc

…normalized into fundamental entities, and just query that graph. It’s fast to query (light weight and de-duplicated), and really easy to pivot through for investigation. Then you can build:

👉 detections

👉 access controls

👉 posture reqs

…in one abstract layer that doesn’t care about what sources feed the graph it sits on top of, just that the necessary data and permissions are there between all your tools. Swap your tools out all you want, the CSMA platform doesn’t care.

So then you can query faster than via SIEM or data lake, since the CSMA platform just queries your SIEM or DL and assorted APIs as-needed to keep data fresh, but beyond that you’re just querying a graph, which is a lot smaller of a structure to search through.

So, that’s coming to a SOC near you. We’re stuck with a new acronym. And this time it’s SIEM’s fault.

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Ready to see Mesh
in action?

See your real security exposure across identity, cloud, SaaS, and endpoints – and eliminate it in minutes.

Mesh video