Hacking, viruses, megabreaches and
other cybercriminal activity are on the increase, and cybersecurity
specialists Bit9, which works with 30 of the Fortune 100 companies, has
today announced a significant round of funding, $34.5 million, to help
fight it. The Series D investment, the biggest yet for Bit9, was led by
new investor Sequoia Capital, with participation from existing
investors Atlas Venture, Highland Capital Partners, Kleiner Perkins
Caufield & Byers, and .406 Ventures.
The growth of cybercrime has massively increased the need for
companies to protect their data, and that is giving rise to a number of
new approaches for how to do that most effectively. Bit9′s
approach plays on a new trend among cybersecurity companies: traditional
protection is based around the concept of a blacklist of forbidden
sites, but Patrick Morley, the CEO of Bit9, notes that his company turns
this on its head to focus not on what shouldn’t be allowed in, but only
on what should — the so-called “whitelist” approach to the problem.
The idea, he says, is to trust only sites that are known, rather than
trying to account for the ones that are not. The reason for this, he
says, is because viruses, worms and the people who create them are
regularly changing what they are doing, so to try to account for all
that is bad and new is virtually impossible. “The challenge with
security is that it is hard because to create new threats is so easy
that they pass right through” an existing blacklist security wall, he
tells me.
Think of the old approach as a flu shot: these tend to only account
for the most common strains, and so that means you can still catch a flu
if its a new one that hasn’t been included in the seasonal shot.
Up to now, this approach has given Bit9 some significant accolades.
Morley notes that Bit9, which says it works with some 700 organizations
in total (although it doesn’t name any of them) and says it’s growing at
100 percent annually in terms of business, was the only company in the
world to date that has been able to stop the Flame virus (or at least
publicly state that it has…), and it was the only one that stopped the
RSA breach. On Flame, he notes that the block was almost inadvertent. It
simply was not on its whitelist for a particular customer: “We stopped
it not because it was Flame, but because it was not trustworthy,” he
says.
Morley says that the changes in cybersecurity have really started to
take place in the last 24 months — not just in terms of attacks being
ramped up, but also because enterprises have become much more aware of
the issue of breaches. He says that these days the conversation is
happening at board level, with companies increasingly away of “how risky
things are.”
As we heard earlier this year in Verizon’s big cyber security report,
the biggest threats today, he says, come from organized crime, nation
states looking for IP from other countries and hacktivists like
Anonymous.
Going forward, Morley says that Bit9 plans to extend its whitelist
approach to cover more platforms than it does today, with some of those
developments to come in the next two quarters. He says the company
already sees success covering security on laptops and desktops, as well
as data centers and infrstructure, “but if you think about it the move
to mobile, bring your own device and cloud” are also becoming
increasingly significant areas, he says. These are also areas that Bit9
will seek to further incorporate into its support.
The cost for cybercrime attacks — according to the Ponemon Institute,
which interviewed 50 companies — is now at $5.9 million, with the
highest now $36.4 million.