13
BEST PRACTICES RESEARCH © Frost & Sullivan 1 “We Accelerate Growth”

BEST PRACTICES RESEARCH - Verizon Enterprise · BEST PRACTICES RESEARCH © Frost & Sullivan 2 “We Accelerate Growth ... or external resources (use of outsourced or managed security

  • Upload
    duongtu

  • View
    216

  • Download
    2

Embed Size (px)

Citation preview

BEST PRACTICES RESEARCH

© Frost & Sullivan 1 “We Accelerate Growth”

BEST PRACTICES RESEARCH

© Frost & Sullivan 2 “We Accelerate Growth”

Contents

Background and Company Performance ........................................................................ 3

Industry Challenges .............................................................................................. 3

New Product Attributes and Customer Impact .......................................................... 3

Conclusion........................................................................................................... 6

Significance of New Product Innovation ......................................................................... 7

Understanding New Product Innovation ......................................................................... 7

Key Benchmarking Criteria .................................................................................... 7

Best Practice Award Analysis for Verizon ....................................................................... 8

Decision Support Scorecard ................................................................................... 8

New Product Attributes ......................................................................................... 9

Customer Impact ................................................................................................. 9

Decision Support Matrix ...................................................................................... 10

The Intersection between 360-Degree Research and Best Practices Awards ..................... 11

Research Methodology ........................................................................................ 11

Best Practices Recognition: 10 Steps to Researching, Identifying, and Recognizing Best Practices ................................................................................................................. 12

About Frost & Sullivan .............................................................................................. 13

BEST PRACTICES RESEARCH

© Frost & Sullivan 3 “We Accelerate Growth”

Background and Company Performance

Industry Challenges

The cyber threat landscape has become increasing perilous and more sophisticated.

Advanced Persistent Threats (APT), botnets, zero-day attacks, and countless malware

variants have caused significant monetary damage on a global scale.

As the threat landscape has changed, it is not a secret that the manner in which people

interact and communicate via the Internet has also changed with social media and other

forms of communication, computing, and collaboration. Gone are the days in which a Web

browser was used as one-way tool to obtain information from the Internet and interactive

information was only exchanged via e-mail. Web browsers and customized applications

are now the interface for a number of communication channels including Facebook,

LinkedIn, Twitter, Skype, and many others.

To address the new cyber threat reality and the growing breadth of the cyber

environments that need to be secured, organizations are aggressively investing in

protective measures. Whether the investments are in security technologies (security tools

including software and hardware appliances), security professionals including training &

education, certification, or external resources (use of outsourced or managed security

services and professional security services), spending on all categories is projected to

grow.

Despite the aggressive approach to cyber security that many organizations are taking, The

2015 (ISC)2 Global Information Security Workforce Study reported that more than half of

the almost 14,000 security professional respondents believed that their organizations did

not improve their positions against security adversaries. Additionally, remediation time

following a system or data compromise is lengthening.

Frankly, all organizations live in a world of finite resources. Every opportunity needs to be

taken to be smarter and more strategic in cyber security investments, improving the yield

achieved from such investments.

Verizon Enterprise Solutions has delivered a solution that does just that. Essentially,

Verizon Enterprise Solutions DBIR Splunk application is an application that can be

downloaded from the Splunkbase Web site and allows organizations to work smart and

more strategic in applying cyber security.

New Product Attributes and Customer Impact

Match to Needs

The DBIR app for Splunk is currently a Beta release. Verizon is actively updating

and enhancing the tool, and will continue to publish updated versions with

BEST PRACTICES RESEARCH

© Frost & Sullivan 4 “We Accelerate Growth”

increased functionality and usability features. The application is an easy-to-use

tool that leverages:

two powerful tools: (1) the research underlying the annual Verizon Data Breach

Investigation Reports, and (2).Splunk data collection and analysis software.

The Verizon Data Breach Investigations Report (DBIR) is the cyber security’s preeminent

source of research on the topic of data breaches. For organizations looking to improve

their cyber security posture, the report filters the almost infinite number of possible

breach causes to actual, real-world vetted list, allowing organization to focus their cyber

security investments, and get maximum return on investments.

Splunk produces software for searching, monitoring, and analyzing machine-generated big

data. In network security, Splunk is well known for its customizability and usability. As

log management and SIEM platforms serve the compliance needs of organizations,

security professionals are finding value in using Splunk as a security analytics tool layered

on top of SIEM and other data sources. Splunk has a strong reputation for being able to

support heavy data loads and has strong application integrations with Hadoop and NoSQL

to handle “big data.”

The Verizon DBIR app for Splunk takes the rich breach intelligence from the DBIR and

makes it actionable within Splunk, using applied analytics to make focused

recommendations for organizations to deter and detect breaches based on real intelligence.

-The application contains dashboards and views for the recommendations

encompassing credential use, phishing, malware, DNS and Proxy log review,

and vulnerability management including:

Authentication tracking

Credential-based lateral movement

“Impossible journey” VPN connections

Data exfiltration flagging through email

Vulnerable system identification

Malicious outbound communication detection

Quality

The quality of the intelligence is beyond question. The “2015 Data Breach Investigation

Report” analyzes more than 2,100 confirmed data breaches and approximately 80,000

reported security incidents. Over its eight annual versions, the report addresses more

than 8,000 breaches and nearly 195,000 security incidents that have occurred over more

than 10 years. Additionally, the DBIR also includes security incidents that do not result in

BEST PRACTICES RESEARCH

© Frost & Sullivan 5 “We Accelerate Growth”

breaches, in order to offer a better survey of the cybersecurity landscape. Verizon is

among 70 global organizations that contributed data and analysis to this year’s report.

Price/Performance Value

Much like the Verizon Data Breach Investigations Report, the Verizon DBIR app for Splunk

is free. The application can be downloaded with no fees at

https://splunkbase.splunk.com/app/2708/. For Verizon, the application is simply part of

the public service that Verizon provides in providing breach intelligence.

Using the application is not totally without cost. Splunk handles many data feeds “out of

the box” but the application will require some basic configuration work. For example, the

user credential monitoring requires that the proper systems are providing the required

information to Splunk, certainly not a challenging task but one that needs to be

accomplished. At the end of the day, there is not a better value and return on investment

anywhere within the security industry.

Customer Ownership Experience

The choice to use Splunk for the DBIR application was a good one. Common across all

Splunk platforms is the concept of operational intelligence:

Business insights correlate data traffic and apply business analytics to create

alarms.

Operational visibility is the idea that applications, endpoint activity, and all data

traffic can be monitored and acted upon centrally.

Proactive monitoring means Splunk can detect anomalies before pre-set rules are

applied.

Search and investigation occur in real-time and across multiple platforms.

Splunk has a rich constellation of security ecosystem partners. Key apps/partnerships

include Splunk for Palo Alto Networks, Splunk for Blue Coat ProxySG, Splunk for F5

Networks, FireEye, Splunk for Symantec Endpoint Protection, Splunk for Juniper SRX

firewalls, Oracle Audit Trail, Splunk Add-on for McAfee, etc.

Additionally, Splunk has architectural advantages as compared to many SIEM products.

Splunk collects raw data feeds easily and does not need custom collectors or parsers.

Splunk stores flat files without normalization and is schema agnostic. Splunk’s search

language creates several advantages including ability to initiate searches over multiple

data and file types and advanced correlation and anomaly recognition.

One practical example of how the DBIR application leverages the strength of Splunk

involves location data. Splunk collects and indexes data from just about any source

BEST PRACTICES RESEARCH

© Frost & Sullivan 6 “We Accelerate Growth”

imaginable, such as network traffic, Web servers, custom applications, application servers,

hypervisors, GPS systems, social media, and preexisting structured databases. Splunk

handles the ingesting of telemetry data easily, allowing the DBIR application to provide

utilities such as “impossible journey” VPN connection monitoring.

Conclusion

The creation of complex solutions requires ordinary inspiration. Genius is required for

solutions that are powerful yet simple to implement. Verizon Enterprise Solutions DBIR

application is genius, creating an easy to implement and use application that applies rich

and unparalleled real-world breach research to an organization’s unique network

environment. The result is actionable intelligence that can make measurable and tangible

improvements to an organization’s cyber security posture.

For its new, innovative, and distinctive DBIR application, Verizon Enterprise Solutions has

earned Frost & Sullivan’s 2015 New Product Innovation Award.

BEST PRACTICES RESEARCH

© Frost & Sullivan 7 “We Accelerate Growth”

Significance of New Product Innovation

Ultimately, growth in any organization depends upon continually introducing new products

to the market, and successfully commercializing those products. For these dual goals to

occur, a company must be best-in-class in three key areas: understanding demand,

nurturing the brand, and differentiating from the competition.

Understanding New Product Innovation

Innovation is about finding a productive outlet for creativity—for consistently translating

ideas into high quality products that have a profound impact on the customer.

Key Benchmarking Criteria

For the New Product Innovation Award, Frost & Sullivan analysts independently evaluated

two key factors— New Product Attributes and Customer Impact—according to the criteria

identified below.

BEST PRACTICES RESEARCH

© Frost & Sullivan 8 “We Accelerate Growth”

New Product Attributes

Criterion 1: Match to Needs

Criterion 2: Reliability

Criterion 3: Quality

Criterion 4: Positioning

Criterion 5: Design

Customer Impact

Criterion 1: Price/Performance Value

Criterion 2: Customer Purchase Experience

Criterion 3: Customer Ownership Experience

Criterion 4: Customer Service Experience

Criterion 5: Brand Equity

Best Practice Award Analysis for Verizon

Decision Support Scorecard

To support its evaluation of best practices across multiple business performance

categories, Frost & Sullivan employs a customized Decision Support Scorecard. This tool

allows our research and consulting teams to objectively analyze performance, according to

the key benchmarking criteria listed in the previous section, and to assign ratings on that

basis. The tool follows a 10-point scale that allows for nuances in performance evaluation;

ratings guidelines are illustrated below.

RATINGS GUIDELINES

The Decision Support Scorecard is organized by New Product Attributes and Customer

Impact (i.e., the overarching categories for all 10 benchmarking criteria; the definitions

for each criteria are provided beneath the scorecard). The research team confirms the

veracity of this weighted scorecard through sensitivity analysis, which confirms that small

changes to the ratings for a specific criterion do not lead to a significant change in the

overall relative rankings of the companies.

The results of this analysis are shown below. To remain unbiased and to protect the

interests of all organizations reviewed, we have chosen to refer to the other key players

as Competitor 2 and Competitor 3.

BEST PRACTICES RESEARCH

© Frost & Sullivan 9 “We Accelerate Growth”

DECISION SUPPORT SCORECARD FOR NEW PRODUCT INNOVATION AWARD

Measurement of 1–10 (1 = poor; 10 = excellent)

New Product Innovation

New Product

Attributes

Customer

Impact Average Rating

Verizon Enterprise Solutions 10 10 10

Competitor 2 8 6 7

Competitor 3 7 6 6.5

New Product Attributes

Criterion 1: Match to Needs

Requirement: Customer needs directly influence and inspire the product’s design and

positioning

Criterion 2: Reliability

Requirement: The product consistently meets or exceeds customer expectations for

consistent performance during its entire life cycle

Criterion 3: Quality

Requirement: Product offers best-in-class quality, with a full complement of features and

functionality

Criterion 4: Positioning

Requirement: The product serves a unique, unmet need that competitors cannot easily

replicate

Criterion 5: Design

Requirement: The product features an innovative design, enhancing both visual appeal

and ease of use

Customer Impact

Criterion 1: Price/Performance Value

Requirement: Products or services offer the best value for the price, compared to similar

offerings in the market

Criterion 2: Customer Purchase Experience

Requirement: Customers feel like they are buying the most optimal solution that

addresses both their unique needs and their unique constraints

Criterion 3: Customer Ownership Experience

Requirement: Customers are proud to own the company’s product or service, and have a

positive experience throughout the life of the product or service

Criterion 4: Customer Service Experience

Requirement: Customer service is accessible, fast, stress-free, and of high quality

BEST PRACTICES RESEARCH

© Frost & Sullivan 10 “We Accelerate Growth”

Criterion 5: Brand Equity

Requirement: Customers have a positive view of the brand and exhibit high brand loyalty

Decision Support Matrix

Once all companies have been evaluated according to the Decision Support Scorecard,

analysts can then position the candidates on the matrix shown below, enabling them to

visualize which companies are truly breakthrough and which ones are not yet operating at

best-in-class levels.

DECISION SUPPORT MATRIX FOR NEW PRODUCT INNOVATION AWARD

High

Low

Low High

Cu

sto

mer I

mp

act

New Product Attributes

Verizon

Enterprise Solutions

Competitor 2

Competitor 3

BEST PRACTICES RESEARCH

© Frost & Sullivan 11 “We Accelerate Growth”

The Intersection between 360-Degree Research and Best

Practices Awards

Research Methodology

Frost & Sullivan’s 360-degree research

methodology represents the analytical

rigor of our research process. It offers a

360-degree-view of industry challenges,

trends, and issues by integrating all 7 of

Frost & Sullivan's research methodologies.

Too often, companies make important

growth decisions based on a narrow

understanding of their environment,

leading to errors of both omission and

commission. Successful growth strategies

are founded on a thorough understanding

of market, technical, economic, financial,

customer, best practices, and demographic

analyses. The integration of these research

disciplines into the 360-degree research

methodology provides an evaluation

platform for benchmarking industry players and for identifying those performing at best-

in-class levels.

360-DEGREE RESEARCH: SEEING ORDER IN

THE CHAOS

BEST PRACTICES RESEARCH

© Frost & Sullivan 12 “We Accelerate Growth”

Best Practices Recognition: 10 Steps to Researching, Identifying, and Recognizing Best Practices

Frost & Sullivan Awards follow a 10-step process to evaluate award candidates and assess

their fit with select best practice criteria. The reputation and integrity of the Awards are

based on close adherence to this process.

STEP OBJECTIVE KEY ACTIVITIES OUTPUT

1 Monitor, target, and screen

Identify award recipient candidates from around the globe

Conduct in-depth industry research

Identify emerging sectors Scan multiple geographies

Pipeline of candidates who potentially meet all best-practice criteria

2 Perform 360-degree research

Perform comprehensive, 360-degree research on all candidates in the pipeline

Interview thought leaders and industry practitioners

Assess candidates’ fit with best-practice criteria

Rank all candidates

Matrix positioning all candidates’ performance relative to one another

3

Invite thought leadership in best practices

Perform in-depth examination of all candidates

Confirm best-practice criteria Examine eligibility of all

candidates Identify any information gaps

Detailed profiles of all ranked candidates

4

Initiate research director review

Conduct an unbiased evaluation of all candidate profiles

Brainstorm ranking options Invite multiple perspectives

on candidates’ performance Update candidate profiles

Final prioritization of all eligible candidates and companion best-practice positioning paper

5

Assemble panel of industry experts

Present findings to an expert panel of industry thought leaders

Share findings Strengthen cases for

candidate eligibility Prioritize candidates

Refined list of prioritized award candidates

6

Conduct global industry review

Build consensus on award candidates’ eligibility

Hold global team meeting to review all candidates

Pressure-test fit with criteria Confirm inclusion of all

eligible candidates

Final list of eligible award candidates, representing success stories worldwide

7 Perform quality check

Develop official award consideration materials

Perform final performance benchmarking activities

Write nominations Perform quality review

High-quality, accurate, and creative presentation of nominees’ successes

8

Reconnect with panel of industry experts

Finalize the selection of the best-practice award recipient

Review analysis with panel Build consensus Select winner

Decision on which company performs best against all best-practice criteria

9 Communicate recognition

Inform award recipient of award recognition

Present award to the CEO Inspire the organization for

continued success Celebrate the recipient’s

performance

Announcement of award and plan for how recipient can use the award to enhance the brand

10 Take strategic action

Upon licensing, company may share award news with stakeholders and customers

Coordinate media outreach Design a marketing plan Assess award’s role in future

strategic planning

Widespread awareness of recipient’s award status among investors, media personnel, and employees

BEST PRACTICES RESEARCH

© Frost & Sullivan 13 “We Accelerate Growth”

About Frost & Sullivan

Frost & Sullivan, the Growth Partnership Company, enables clients to accelerate growth

and achieve best in class positions in growth, innovation and leadership. The company's

Growth Partnership Service provides the CEO and the CEO's Growth Team with disciplined

research and best practice models to drive the generation, evaluation and implementation

of powerful growth strategies. Frost & Sullivan leverages almost 50 years of experience in

partnering with Global 1000 companies, emerging businesses and the investment

community from 31 offices on six continents. To join our Growth Partnership, please visit

http://www.frost.com.