Exploring the Convergence of Observability and Security - Part 7: Advantages
June 14, 2023

Pete Goldin
APMdigest

Share this

With input from industry experts — both analysts and vendors — this 8-part blog series will explore the convergence of observability and security, the challenges and advantages, and how it may transform the IT landscape.

Start with: Exploring the Convergence of Observability and Security - Part 1

Start with: Exploring the Convergence of Observability and Security - Part 2: Logs, Metrics and Traces

Start with: Exploring the Convergence of Observability and Security - Part 3: Tools

Start with: Exploring the Convergence of Observability and Security - Part 4: Dashboards

Start with: Exploring the Convergence of Observability and Security - Part 5: Teams

Start with: Exploring the Convergence of Observability and Security - Part 6: Challenges

Ultimately the experts believe convergence of observability and security delivers several benefits.

"My research has identified two major benefits: Faster resolution of security issues and reduced overall risk of security incidents," says Shamus McGillicuddy, VP of Research, Network Infrastructure and Operations, at Enterprise Management Associates (EMA). "We've also identified four secondary benefits: Operational efficiency (do more with less), faster resolution of performance issues, improved overall network uptime, and enhanced business influence over IT strategy. That last one refers to the fact that ITOps and security use their combined influence to get a seat at the table when major things are happening, such as migration to the cloud."

Use the player or download the MP3 below to listen to EMA-APMdigest Podcast Episode 2 — Shamus McGillicuddy talks about Network Observability, the convergence of observability and security, and more.

Click here for a direct MP3 download of Episode 2 - Part 1

The following are more advantages of observability and security convergence , as the experts see it:

More essential information for security

Mike Loukides, VP of Emerging Tech Content at O'Reilly Media: "The big advantage of convergence between security and observability is that security is an activity that always needs more data. An attacker who knows what they're doing is going to be able to rewrite your log files and be stealthy enough that your metrics will look normal. But it will be very difficult for them to hide the paths they take through your system, which is what tracing will give you. Observability provides more information on your system. That's invaluable for security."

Simplifying Data Processing and Distribution

Buddy Brewer, Chief Product Officer at Mezmo: "Converging security and observability simplifies data processing and distribution, allowing organizations to collect and share the right information with the right teams."

Uncovering security issues and vulnerabilities

Spiros Xanthos, SVP and General Manager of Observability at Splunk cites recent research showing the benefits of convergence, according to survey respondents, include:

■ More effective uncovering of security issues thanks to intelligence and correlation capabilities (59%).

■ The ability to uncover and assess more security vulnerabilities (55%), thanks to the visibility afforded by observability solutions.

■ More granular and precise threat detection — 59% uncover security issues more effectively, thanks to intelligence and correlation capabilities native to observability solutions.

■ A more comprehensive view — 55% uncover and assess more security vulnerabilities, thanks to the visibility afforded by observability solutions.

Faster resolution of security problems

Gregg Ostrowski, CTO Adviser at Cisco AppDynamics: "Security and application teams often operate in silos, which can increase the time it takes to identify and resolve security threats. To speed up the process, the combination of security and observability enables IT teams to identify the source of vulnerabilities, likelihood of exploitation and potential impacts on the business."

Jam Leomi, Lead Security Engineer at Honeycomb explains, "There are many advantages of converging the two, one of the greatest being the cross-organizational collaboration it affords teams using the same tools and language. Less context switching alleviates the cognitive load on engineers so they can find and fix issues faster."

"With robust visibility across systems as well as the entire software development lifecycle, observability helps organizations reduce the time it takes to find vulnerabilities from days or weeks to as little as minutes and enables teams to be more effective and strategic in their resolution strategies, rather than being mired in days of firefighting," adds Amit Shah, Director of Product Marketing at Dynatrace.

Citing the same research above, Spiros Xanthos of Splunk says 51% of respondents reported being able to take action on security issues faster, thanks to the remediation capabilities of observability solutions.

Eliminating security and performance blind spots in the cloud

Chaim Mazal, Chief Security Officer at Gigamon: "The key advantage of converging security and observability is to provide technology organizations with real-time actionable intelligence across all layers of their hybrid and multi-cloud infrastructure. Having this level of deep observability arms teams with the tools and resources they need to deliver defense in depth while containing the spiraling cost and complexity of securing and managing their hybrid environment. This ultimately helps to eliminate security and performance blind spots across cloud environments, complementing logging tools with network-derived intelligence to significantly fortify the organization's overall security posture."

Ensuring Resilience

Take the 2023 SRE Survey

Leo Vasiliou, Director of Product Marketing at Catchpoint: "Security and observability will meet at the resilience intersection of what you control and what you don't control, which is really what we're talking about. The set of observability capabilities for your application stack (what you control) can also be applied to e.g., your security or internet stack (what you don't control) to ensure resilience supporting the needs of multiple teams. Part of these capabilities already exist in various information and event management forms, so normalizing the capabilities makes sense."

Uncovering Observability unknowns

Jam Leomi from Honeycomb: "Security provides an advantage to observability tools as it can really dig into the unknowns, something that comes up often when tracking abnormal behavior and malicious incidents with observability."

Building Higher quality applications

Buddy Brewer from Mezmo: "Security and observability teams share a common goal—to rid the world of software defects. By converging security and observability, organizations can adopt a more holistic approach to shipping high-quality software that users and businesses can trust."

More time for innovation

Gregg Ostrowski from Cisco AppDynamics: "The combination of security and observability offers organizations unified visibility into complex and evolving IT stacks. With this line of sight across both multi-cloud and on-premises platforms, organizations can detect security threats and quickly remediate them before they have the chance to disrupt performance. This means organizations can dedicate more time for innovation and equip themselves for the future."

Shifting left

Amit Shah from Dynatrace: "Observability allows organizations to shift security left — that is, to identify security vulnerabilities in development through testing — as well as to shift right by identifying vulnerabilities in production through real-user monitoring, performance tracking, and other methods.

Making Security Pervasive

Prashant Prahlad, VP of Cloud Security Products at Datadog: "The main benefit of converging security and observability is that it makes security pervasive throughout an organization and shifts the responsibility of security to the DevOps teams that own and operate critical services for the business. The convergence brings about organizational changes that create a DevOps-oriented security ambassador for the aspiring security professionals of the future."

Saving money

Ajit Sancheti, GM, Falcon LogScale at CrowdStrike says with the convergence of observability and security, organizations only need to store the data in one place consequently reducing opex and capex by consolidating tools.

Check back tomorrow for: Exploring the Convergence of Observability and Security – Part 8, the final installment in the series, with tips on how to make convergence happen.

Go to: Exploring the Convergence of Observability and Security - Part 8: Getting There

Pete Goldin is Editor and Publisher of APMdigest
Share this

The Latest

May 09, 2024

App sprawl has been a concern for technologists for some time, but it has never presented such a challenge as now. As organizations move to implement generative AI into their applications, it's only going to become more complex ... Observability is a necessary component for understanding the vast amounts of complex data within AI-infused applications, and it must be the centerpiece of an app- and data-centric strategy to truly manage app sprawl ...

May 08, 2024

Fundamentally, investments in digital transformation — often an amorphous budget category for enterprises — have not yielded their anticipated productivity and value ... In the wake of the tsunami of money thrown at digital transformation, most businesses don't actually know what technology they've acquired, or the extent of it, and how it's being used, which is directly tied to how people do their jobs. Now, AI transformation represents the biggest change management challenge organizations will face in the next one to two years ...

May 07, 2024

As businesses focus more and more on uncovering new ways to unlock the value of their data, generative AI (GenAI) is presenting some new opportunities to do so, particularly when it comes to data management and how organizations collect, process, analyze, and derive insights from their assets. In the near future, I expect to see six key ways in which GenAI will reshape our current data management landscape ...

May 06, 2024

The rise of AI is ushering in a new disrupt-or-die era. "Data-ready enterprises that connect and unify broad structured and unstructured data sets into an intelligent data infrastructure are best positioned to win in the age of AI ...

May 02, 2024

A majority (61%) of organizations are forced to evolve or rethink their data and analytics (D&A) operating model because of the impact of disruptive artificial intelligence (AI) technologies, according to a new Gartner survey ...

May 01, 2024

The power of AI, and the increasing importance of GenAI are changing the way people work, teams collaborate, and processes operate ... Gartner identified the top data and analytics (D&A) trends for 2024 that are driving the emergence of a wide range of challenges, including organizational and human issues ...

April 30, 2024

IT and the business are disconnected. Ask the business what IT does and you might hear "they implement infrastructure, write software, and migrate things to cloud," and for some that might be the extent of their knowledge of IT. Similarly, IT might know that the business "markets and sells and develops product," but they may not know what those functions entail beyond the unit they serve the most ...

April 29, 2024

Cloud spending continues to soar. Globally, cloud users spent a mind-boggling $563.6 billion last year on public cloud services, and there's no sign of a slowdown ... CloudZero's State of Cloud Cost Report 2024 found that organizations are still struggling to gain control over their cloud costs and that a lack of visibility is having a significant impact. Among the key findings of the report ...

April 25, 2024

The use of hybrid multicloud models is forecasted to double over the next one to three years as IT decision makers are facing new pressures to modernize IT infrastructures because of drivers like AI, security, and sustainability, according to the Enterprise Cloud Index (ECI) report from Nutanix ...

April 24, 2024

Over the last 20 years Digital Employee Experience has become a necessity for companies committed to digital transformation and improving IT experiences. In fact, by 2025, more than 50% of IT organizations will use digital employee experience to prioritize and measure digital initiative success ...