Splunk Addressing Organizations’ Biggest Issues
CF: What are the biggest issues organizations face when it comes to cybersecurity and how is Splunk addressing those?
JW: The biggest threats are getting broad visibility end to end across your landscape. Threats can be very evolved and if they’re successful and an organization gets breached, there could be lateral movement across the organization. There could be more compromised accounts. There could be implanted malware across multiple systems.
To really get that full, visible picture on what happens post-breach, Splunk can be hugely helpful because we have logs from all of the systems that may have been impacted. So we can help put together that big picture of an attack. Security tools that are more focused on prevention try to stop those threats getting in. But Splunk is very good if those tools have failed at figuring out what attackers did, how they did it and where they did it, giving that picture. So I think that’s really important. I think then response, when you get that new understanding of here we had a weakness, this is how they got in and this is what they did next. Now I’m going to change my infrastructure to prevent that from happening in future. So both the full visibility and then the fast response when something’s happened, I think are the key pieces.