Cisco’s incident-response response

Contact: Adrian Sanabria

In its $2.7bn acquisition of Sourcefire last year, Cisco obtained significant threat detection and prevention capabilities but still had difficulties showing customers the big picture and integrating into the incident-response process. Now it’s adding those capabilities by picking up ThreatGRID, an anti-malware analysis vendor and threat intelligence provider.

Cisco obtains a popular threat intelligence source, with its feeds already baked into at least a half-dozen popular SIEM and anti-malware products. The twist here is that Cisco’s Sourcefire division already has an anti-malware detection and analysis offering. Our take is that this is partially a complementary deal, much like how Bit9’s pickup of Carbon Black filled in many of the vendor’s coverage and functionality gaps. The move is also a competitive one, better positioning Cisco against other firms such as FireEye and Palo Alto Networks. Both have been diversifying their product portfolios through several acquisitions this year.

The purchase of ThreatGRID is all about context and getting the big picture. Most anti-malware offerings are focused on identifying and stopping malware, but don’t provide insight into what’s happening and why. Given the importance to CISOs to shrink the time from malware detection to recovery, improved visibility and incident response are becoming key ingredients of any broad security portfolio and we expect any company in the incident-response and next-generation anti-malware categories to be potential acquisition targets this year.

For more real-time information on tech M&A, follow us on Twitter @451TechMnA.

Posted in M&A