It’s Not The Breach, It’s The Spread: Strengthening Cyber Resilience
Cyberattacks are becoming more sophisticated, and the real damage often comes not from the initial breach, but from how far it spreads. As a result, customers are increasingly focused on resilience, not just prevention. And they’re turning to trusted partners to help make that happen.
In a recent CRNtv webinar, Garrett Weber, senior director of solutions engineering at Akamai, joined CRNtv host Sydney Neely to explore how microsegmentation can help partners reduce risk, prevent lateral movement, and deliver stronger, more resilient security strategies to their customers.
The discussion also featured insights from Ellen Daniel, senior content strategist at The Channel Company, who shared findings from a survey of 100 IT decision-makers, including chief information officers, chief technology officers, IT directors and cybersecurity leads, on their current security challenges, outsourcing trends and confidence in their providers.
Ellen: We surveyed 100 IT decision-makers, and 51 percent said they outsource some element of their security operations. The most commonly outsourced services were penetration testing, threat intelligence and managed detection and response.
The top reasons for outsourcing were a lack of internal expertise, cited by 65 percent, and the desire for better security capabilities, cited by 61 percent. When asked to rate their confidence in their service provider’s ability to improve cyber resilience, the average score was 7.5 out of 10. Satisfaction is generally high, but there’s still room for improvement.
Sydney: Garrett, if most customers feel their providers are “good but not great,” what can partners do to strengthen that trust?
Garrett: The first thing that partners can do is help translate technology and its impact into business value. Right now, organizations are seeing much more stringent controls on the checkbook. They need to justify what they’re purchasing and what the return on that investment is.
The ability to tie it back to business value ultimately gives customers a stronger partnership with the provider.
The other part is understanding the customer well enough to proactively anticipate their needs and become a source of insight. For example, if they’re talking about moving to the cloud or modernizing apps for Kubernetes, partners should say, “Here are some of the threat vectors you need to look at, and here are some technologies you may want to include in that stack.”
Knowing what they’re going to need and making good recommendations helps build a roadmap for the future. That builds trust, and trust leads to recurring business.
Sydney: Ellen, the research also looked at how organizations are responding to breaches. What stood out?
Ellen: Seventy-four percent of respondents said it would take them two days or less to fully recover from a cyberattack. That’s encouraging, but more than a quarter said it would take over three days. Eighty-one percent said lateral movement had not occurred during a cyberattack at their organization, but 14 percent were unsure.
Sydney: Garrett, a lot of organizations said they believe they would be able to recover from a breach in just a few days. That’s a good sign, but it doesn’t always mean the attack was fully contained. How can microsegmentation help partners and customers stay in control and limit lateral movement during and after a breach?
Garrett: A few days is definitely better than a few weeks, which is what we’ve seen in the past, when organizations were working on pencil and paper while trying to bring business back online.
But wouldn’t it be better if recovery took just a few hours, or if the breach didn’t escalate into a full incident? That’s where microsegmentation helps. It creates a security blanket that limits lateral movement, which is where breaches become most damaging.
If an attacker gets in, but access is restricted based on how they entered or the credentials they compromised, the impact is minimized. You might only need to reimage a few workstations, reset a password or block a connection at the firewall, not recover the entire environment.
Microsegmentation reduces risk, controls access to sensitive resources and triggers alerts for the SOC and incident response teams. It’s a strong complement to EDR or MDR solutions.
Sydney: With all these segmentation tools out there, what sets Akamai apart, and how does your approach help partners earn trust and grow their business?
Garrett: I’d boil it down to breadth of coverage and ease of use. Akamai supports a wide range of environments and operating systems, and we’ve invested heavily in making the product intuitive and scalable.
We’ve also built strong services and support teams to help customers implement use cases at scale. That’s important for organizations that haven’t done this before and are asking, “How do I implement it? What’s the impact going to be?”
Partners benefit because customers want completed projects, not shelfware. They want to know their investment is worthwhile. Our teams focus on delivering value and completing the work, not just filling hours. That means we support both customers and partners until the job is done and the use case is fully implemented.
To learn more about how Akamai is helping partners bring modern microsegmentation and Zero Trust solutions to customers, visit akamai.com/partners/overview.