2023 Gartner® Market Guide for Cloud-Native Application Protection Platforms (CNAPP)

Contributed by Sysdig

To date cloud security has been fragmented. It’s been built from many different categories, with different acronyms, which has been challenging for teams trying to navigate their cloud-native security needs. The industry needed a consolidated approach to cloud, containers, and workload security. With the 2023 Gartner Market Guide for Cloud-Native Application Protection Platforms (CNAPP), Gartner has provided key findings and recommendations to get there.

According to Gartner, when considering a CNAPP solution, you need to “Build a team for the evaluation and selection of CNAPP offerings with skills spanning cloud security, workload security (including containers), application and middleware security, development security and developers.

Dig into the 2023 Gartner Market Guide for CNAPP to learn:

  • The state of the cloud security market and how it has become more integrated
  • The types of capabilities available today and how offerings are likely to evolve
  • How to make a decision for selecting CNAPP vendors that best suit your business needs in today’s market
  • Strategic Planning Assumptions for the market in the next 2 years

Download & Read Gartner’s Market Guide report here

About Sysdig 

Sysdig secures and accelerates cloud innovation. Powered by Runtime Insights, our platform stops threats in real time and reduces vulnerabilities by up to 95%. Our roots are in runtime as the creators of Falco, the open standard for cloud threat detection. We apply Runtime Insights across the software lifecycle to prioritize vulnerabilities and instantly detect attacks. From shift left to shield right, customers rely on Sysdig to prevent, detect, and respond at cloud speed.

Bernie Cowens, Chief Information Security Officer at TJX Companies Keynotes Our Transformational CISO Assembly!

The Millennium Alliance is excited to announce Bernie Cowens, Chief Information Security Officer at TJX Companies will keynote our Transformational CISO Assembly August 22-23 at The Line in Austin!

Interested in joining this Assembly? Click here to request an invite.

About Bernie Cowens

Bernie Cowens has more than 30 years of security and technology leadership experience. He previously served as Vice president and Chief Security Officer for PG&E responsible for leading company-wide efforts to identify and manage physical and cybersecurity risks. Mr Cohen’s served as Chief Information Security Officer for first American Financial, where he oversaw all aspects of cybersecurity for the company and its global business units. He has held senior security executive positions at PricewaterhouseCoopers, Experian, PLC and the Automobile Club of Southern California. He served as Vice President and Chief Information Officer for SafeNet, a global encryption technology manufacturing company. Mr Cohen’s has a Master of Science egree and Management Information Systems from Bowie State University and a Bachelor of Arts degree in Information Systems Management from the University of Maryland.

Conquering the 5 Biggest Hurdles of Third-Party Access with Cyolo

Contributed by Cyolo

What do the high-profile breaches at Uber, Kaseya, and SolarWinds have in common?

They all demonstrated the risks posed by third-party access and revealed just how much we don’t know about our vendors’ security posture.

At the same time, these and other attacks have exposed the tremendous extent to which modern businesses depend on other businesses. Third-party partnerships are simply too valuable to give up, so the only answer is to make access less risky for third-party users.

This paper explores the top challenges associated with third-party access and how they can be overcome with a zero-trust access solution that reduces risk while preserving business efficiency and productivity.

Read the full report here.

About Cyolo

Cyolo’s unified platform securely connects local and mobile users to the tools and data they need, in the organizational network, cloud or IoT environments and even offline networks, regardless of where they are or what device they are using. Cyolo provides users access to all the assets they need including, applications, resources, workstations, servers and files, without granting risky network access to information assets.

To learn more, visit cyolo.io.

Theft by a Thousand Clicks: Behavioral Cybersecurity Statistics with Hoxhunt

Contributed by Hoxhunt

Email-originated cyber attacks account for roughly 90% of all data breaches, which in total exacted a $6 trillion toll on the global economy in 2021 at a clip of over $14 million-and-climbing per company per successful phishing attack, according to reports by the Ponemon Institute and Cybersecurity Ventures. Collectively, those little clicks would add up to the GDP of the third largest nation in the world behind the US and China. Understanding employee behavior in relation to cybersecurity as well as effective behavior change methodology is a critical step towards protecting individuals and organizations from phishing attacks and data breaches.

This inaugural Behavioral Cybersecurity Report by Hoxhunt analyzed email data of 1.6 million Hoxhunt participants and their 24.7 million simulations. This analysis indicates that user email behavior can vary significantly depending on their industry, type of job, and geographical location. More importantly, user behavior, skill and progress over time indicates robust improvement. Global phishing simulation failure rates and missed simulations clearly decline, while rates of skill acquisition, threat reporting, and phishing simulation success increase. Employees and their mailboxes constitute the greatest cybersecurity risk factor for enterprises and other organizations. 2021 saw record-setting venture capital and PE activity in cybersecurity. But investment into security awareness solutions lagged behind technical solutions, as has effective innovation in security awareness models. Traditionally, improving employee cybersecurity awareness has been seen as Email-originated cyber attacks account for roughly 90% of all data breaches, which in total exacted a $6 trillion toll on the global economy in 2021 at a clip of over $14 million and climbing per company per successful phishing attack, according to reports by the Ponemon Institute and Cybersecurity Ventures. Collectively, those little clicks would add up to the GDP of the third largest nation in the world behind the US and China. Understanding employee behavior in relation to cybersecurity as well as effective behavior change methodology is a critical step towards protecting individuals and organizations from phishing attacks and data breaches.

A lost cause in terms of actually reducing risk. Awareness has thus been relegated to a compliance-based approach, which is more check-a-box than actual risk reduction. But with next-gen training solutions, which combine advanced technology with a people-centric approach, a truly riskbased approach can and will offer high ROI in terms of risk reduction. The results section of this report will show how a global sample of 1.6 million Hoxhunt users performed with millions of highly realistic phishing simulations of varying difficulty over time. Users are segmented by their geography, industry, and job role. Their behavior is segmented by their failure, success, and missed email rates. There are many intriguing findings that bear further inquiry as we seek to understand why users behave the way they do with emails. But, more importantly: so what?

Read Hoxhunt’s full report here

About Hoxhunt

Hoxhunt is a human risk management platform that goes beyond security awareness to drive behavior change and measurably lower risk. We combine AI and behavioral science to create individualized micro-training experiences people love. Employees learn to detect and report advanced phishing attacks. Operations teams respond fast with limited resources. And security leaders gain outcome-driven metrics to document reduced cybersecurity risk.

Hoxhunt works with leading global companies such as Airbus, IGT, DocuSign, Nokia, AES, Avanade, and Kärcher and partners with leading global cybersecurity companies such as Microsoft and Deloitte.

To learn more, visit https://www.hoxhunt.com/

GJP Group’s Customer Success Story with Digibee

Contributed by Digibee

👉 80% Reduction in wait time for guests
👉 $300,000 savings in operating costs after one year

Find out how our partners at Digibee are helping GJP Hotels & Resorts integrate 10 times faster than traditional integration models, and improve their customer experience.

Read the GJP Group Customer Success Story here.

About Digibee

Digibee is an eiPaaS Solution that bridges the gap between current systems and new technologies. They help you connect data and platforms that have never been connected before. By leveraging their platform on top of their customer’s legacy systems, Digibee’s ustomers modernize and evolve their data services into modern, API based, microservices architecture, without breaking the bank or taking forever to accomplish their digital transformation efforts. Digibee connects enterprise apps and internet services using its #NOCODEINTEGRATION approach. Digibee enables less technical users to connect its own services to deliver new products to the market. It is as simple as drag and drop!

To learn more, visit digibee.com.

#MillenniumLive on Cybersecurity as a Team Sport with Netskope

Cloud transformation and work from anywhere have changed how security needs to work. Netskope understands these changes and works to protect people and data anywhere they go, no matter what.

Gerry Plaza, Field CTO in the Chief Strategy Office at Netskope, joined the Millennium Live podcast to discuss the best way businesses can stay ahead of cloud, data, and network security challenges. In his time as a CTO, Gerry shares ways you’re able to work cross-functionally within an organization to help reduce friction and ways he’s currently working to promote better digital citizenship at Netskope.

Netskope empowers the largest organizations in the world with the right balance of protection and speed they need to enable business velocity and secure their digital transformation journey.

Gerry’s career trajectory has taken him through every IT functional role of increasing responsibilities, throughout his 25+ years in the IT Industry. This expansive experience has allowed him to build a deep expertise in Enterprise Architecture allowing him to have a positive impact in every functional area of Infrastructure and Operations from 3-Tier Architecture to Hyperconverged, Virtualization, IP & FC Networking, Network Security, Cyber Security, Cloud, IaaS, and everything in-between throughout Design, Engineering and Operations teams.

Listen on Spotify, Apple, Amazon Music, and Google Podcasts.

About Netskope

Netskope, a global cybersecurity leader, is redefining cloud, data, and network security to help organizations apply Zero Trust principles to protect data. The Netskope Intelligent Security Service Edge (SSE) platform is fast, easy to use, and secures people, devices, and data anywhere they go. Netskope helps customers reduce risk, accelerate performance, and get unrivaled visibility into any cloud, web, and private application activity. Thousands of customers, including more than 25 of the Fortune 100, trust Netskope to address evolving threats, new risks, technology shifts, organizational and network changes, and new regulatory requirements.

To learn how Netskope helps customers be ready for anything on their SASE journey, visit netskope.com.

 

How AES Fueled Security Vigilance and Measurably Lowered The Human Factor in Cyber-Risks

Contributed by Hoxhunt

Where did the winding 5-year journey to human risk reduction take CISO, Ryan Boulais and Fortune 500 energy company, The AES Corporation?

🚀 Like all great  #securitybehaviorchange and #humanriskmanagement journeys, this one started with legacy awareness training tools. But the journey led to Hoxhunt, and a:

📈 2,533% improvement in resilience ratio (#phishing simulation reporting rate divided by the failure rate)
📈 500% improvement in training engagement
📈 79% reduction in the failure rate
📈 Massive upswell in real threats detected and reported
📈 Reduction in resources needed to analyze threats and escalate incidents

1) The AES security team tried to improve security culture with three of the biggest SAT tools on the market for five years. But SAT engagement actually fell over time to 10%.
2)  That led to Hoxhunt. Recognizing that the traditional awareness model was flawed, AES launched an innovative security behavior change and human risk management program, leveraging the capabilities of Hoxhunt.
3) And that led to results. Read how they did it. This is an incredible success story given its time and scope.

“…With phishing simulation engagement rates reaching above 60 percent and failure rates dropping below 2 percent, Hoxhunt has helped us push our resilience into new territory, with our resilience ratio jumping by over 2,500 percent in just a few months. Hoxhunt has helped us surpass anything our legacy SAT tools could deliver.” — Ryan Boulais, VP & Chief Information Security Officer

The resilience ratio score of 38 is astonishing given the industry, size, and scope of AES. Similar companies will strive for scores of 10-15, and typically topout at 20. The resilience ratio is calculated by dividing the engagement rate by the failure rate, yielding a more accurate metric for risk than either engagement or failure alone.

“We focus on engagement. We aren’t beholden to click rate. Previously, we’d had a click rate of 7% with our awareness training solution, but we had a low reporting rate of only 10%. No matter what awareness tool we tried, engagement remained stagnant. We needed a new model to gain better visibility into our human risk and manage that risk, and Hoxhunt enabled that. Now we have a reporting rate of 70% and a click rate of like 2%. We’ve measurably reduced risk and improved security culture in a way that aligns with our cultural values, and people seem to really like it.” — David Badanes, Director of Cybersecurity Strategic Initiatives, AE

Read Hoxhunt’s full report here 

About Hoxhunt

Hoxhunt is a human risk management platform that goes beyond security awareness to drive behavior change and measurably lower risk. We combine AI and behavioral science to create individualized micro-training experiences people love. Employees learn to detect and report advanced phishing attacks. Operations teams respond fast with limited resources. And security leaders gain outcome-driven metrics to document reduced cybersecurity risk.

Hoxhunt works with leading global companies such as Airbus, IGT, DocuSign, Nokia, AES, Avanade, and Kärcher and partners with leading global cybersecurity companies such as Microsoft and Deloitte.

To learn more, visit https://www.hoxhunt.com/

#MillenniumLive: Helping Global Enterprises on Their Digital Journey

We’re honored to be joined by Matt Durham, Head of Market Strategy at Digibee on the #MillenniumLive podcast for a discussion on how Digibee’s solutions are allowing enterprises to compete and excel in today’s rapidly changing digital environment. 

Listen on Spotify, Apple, Amazon Music, and Google Podcasts.

About Digibee

Digibee is an eiPaaS Solution that bridges the gap between current systems and new technologies. They help you connect data and platforms that have never been connected before. By leveraging their platform on top of their customer’s legacy systems, Digibee’s customers modernize and evolve their data services into modern, API-based, microservices architecture, without breaking the bank or taking forever to accomplish their digital transformation efforts. Digibee connects enterprise apps and internet services using its #NOCODEINTEGRATION approach. Digibee enables less technical users to connect its own services to deliver new products to the market. It is as simple as drag and drop!

To learn more visit https://www.digibee.com/

A Look Back At The Millennium Alliance’s Record Q1 Growth & Looking Ahead To Q2

NEW YORK – April 18, 2023The Millennium Alliance has come out of the gates at a record-breaking pace in 2023 after experiencing the strongest Q1 in its nine-year existence. Across the board, they experienced a tremendous level of success, from the highest-quality delegations in company history to cultivating partnerships with some of the most innovative technology providers, to putting on ten massively successful events since the beginning of this year, to growing its team by 15%.

Millennium is now looking to build off this positive momentum in Q2 with its versatile portfolio of offerings, including its packed calendar of Two-Day Invite Only Assemblies, with eleven taking place in the second quarter alone, a world-class #MillenniumLive Podcast Series which is approaching its 200th episode and has been gaining thousands of new subscribers annually, along with industry-leading Executive Education Opportunities.

“The fact that as we begin to close in on a full decade as an organization and we have already built so much positive momentum in the early part of this year is amazing to see. We’ve firmly positioned ourselves to exceed the lofty goals that we’ve set out as a company to achieve in 2023 which is a fantastic feeling. This is a testament to the outstanding team that we’ve put together, as well as to the continued support of our members and partners. It’s safe to say that Millennium is pleased but never satisfied with what we’ve been able to accomplish and plans to set many more records as we continue with our journey to be the leaders in digital transformation for our community.” – Alex Sobol, Co-Founder, The Millennium Alliance  

For more information or to get in contact with The Millennium Alliance directly, contact info@mill-all.com

About The Millennium Alliance

The Millennium Alliance is a leading technology and business educational advisory firm with the sole mission of helping to transform the digital enterprise. Through our executive education platform, peer-to-peer learning model via our senior-level Assemblies, exclusive research projects conducted with Ivy League academic institutions, and our numerous digital properties, we have become a trusted source for real-world tangible learning and engagement opportunities for senior executives and their technology partners.

This all started in 2014 when our founders, Alex Sobol & Rob Davis decided to create the most intimate, high-level & exclusive in-person and online think tank for leaders in a wide variety of industries within both the private and public sectors: The Millennium Alliance. Since its founding, Millennium has built a strong reputation nationwide, now with thousands of engaged Members, and was recently featured on the Inc. 5000 list of fastest-growing companies. The Millennium Alliance is headquartered in Midtown Manhattan.

Building upon its award-winning conference and executive education businesses, today, The Millennium Alliance continues to stay connected with its C-Suite Members and partners through intimate In-Person Assemblies, industry-leading Executive Education Opportunities, and by providing exclusive industry insights from the nation’s leading academics, business leaders, and technology providers via our 50+ annual events and The Digital Diary Content Platform, as well as the rapidly growing #MillenniumLive Podcast Series.

#MillenniumLive 200th Episode: Painless Infrastructure Visibility with Galileo

Every day, the pressure is on for IT teams to keep systems running efficiently to fuel business growth. Last week, Millennium Live wrapped up a successful Digital Enterprise CIO Transformation Assembly with Galileo, a technology partner to help you resolve challenging IT issues and promote the growth of your organization. Tim Conley, Galileo Founder & Principal of The ATS Group, joined the podcast to discuss how on-prem and cloud infrastructure is growing in complexity. Most IT teams are paying a hefty price for multiple, redundant monitoring tools that delay incident resolution, contribute to silos within the IT organization, and slow down your business. Tim discusses challenges large data centers are facing today, and how Galileo is helping companies combat the rising cost of going to the cloud. Since 2007, Galileo has saved customers money and time by consolidating technology resources, preventing downtime, and providing end-to-end visibility across your entire IT landscape.

Listen on Spotify, Apple, Amazon Music, and Google Podcasts.

About Galileo

Galileo is more than a monitoring tool. With Galileo, IT teams can increase uptime, pinpoint usage trends, forecast demands, right-size environments and accurately plan for the future.

The reliability of your infrastructure takes on a new level of importance with today’s data-intensive workloads. Through Galileo, organizations can streamline support and develop realistic roadmaps for growth and transformation through data visualization, trending and tagging capabilities. Intuitive multi-vendor monitoring for servers, storage, systems, database, SAN, networking and cloud allows users to anticipate and adapt to usage needs and avoid bottlenecks.

To learn more about Galilio visit https://galileosuite.com/