Cybersecurity categories such as SIEM, SOAR, EDR and XDR are beginning to lose their importance as standalone buying categories. This is more than product consolidation. The security stack itself is being reorganized around the work required to move from raw evidence to an executed outcome.

The category model has reached its limit

The current stack was built for a world in which machines produced signals and people made sense of them. Enterprises buy separate products and ask analysts to connect the pieces. Each product supplies part of the answer, but the analyst still assembles the final one.

The human analyst has become the hidden integration layer holding the cybersecurity stack together.

A new stack organized in layers

Six connected responsibilities are emerging: Security Data, Security Context, Security Detection, Security Investigation, Security Decision Intelligence and Security Execution. Governance operates across the architecture, while outcomes feed back through it so the system can improve.

The exact product boundaries will evolve. The important shift is that responsibility becomes explicit. Who owns the data? Who adds context? Who detects? Who investigates? Who provides decision intelligence? Who decides? Who executes?

The missing Security Decision Intelligence Layer

Data supplies evidence. Context explains what it means. Detection identifies a possible threat. Investigation determines what happened. Execution carries out an action. Yet the responsibility for deciding what the organization should do still sits largely with people.

The Security Decision Intelligence Layer fills the intelligence gap. It reconciles evidence with business priorities, evaluates competing actions, explains the trade-offs and changes when the underlying conditions change—giving people what they need to make the final decision.

The layered era has begun

The market may continue using familiar category names for some time. But the underlying responsibilities are already reorganizing. Once you stop asking which legacy category a company belongs to and start asking which part of the security outcome it intends to own, the market looks completely different.

Originally published by Obbe Knoop on LinkedIn.

Read the original article