Business Insider

VMware's CEO has a vision that should terrify the security industry: 'Start getting rid of products'

VMware CEO Pat Gelsinger
VMware CEO Pat Gelsinger VMware
Read in app

The problem with the security industry, says VMWare CEO Pat Gelsinger, is that companies are using too many security products. If you want to be more secure, he says, "start getting rid of products."

Indeed, Gelsinger's big idea for disrupting cybersecurity is to get companies using fewer security products, and rely more on products that already have security baked in, he said in an interview with CRN on Monday at the 2018 Best of Breed conference in Philadelphia.

About two years ago, VMWare used 30 security products to protect its own employees and systems from cyberattack, but now it uses fewer than 20. The lesson, he says, is that VMware is now both more secure, and less reliant on piling on new tools from outside vendors.

“Your customers are looking for more and just giving them another warm blanket, expecting that’s going to stop bullets doesn’t do it,” Gelsinger said. “Your customers want less products, they want more value — and particularly in the security area that’s true. We think VMware is a critical component of that as you’re building those capabilities.”

Gelsinger says the goal is to reduce VMware's usage of security products even further, down to 15 security solutions, which the company will do by building more basic security functions and encryption directly into its own products, including NSX, vSan and AppDefense. That vision could be bad news for the very many security startups out there, who are all selling to a finite number of businesses in the world. 

Having fewer security products may seem counterintuitive as a way to fight cyberattack, but too many security products can create opportunity for attackers. A complicated, patchwork security infrastructure can slow down the detection of threats and makes it easier for attackers to find and exploit any software vulnerabilities. The average enterprise deploys 75 different security products, according to SafeBreach, an internet security company. Gelsinger also cited a meeting he had with a CIO of a top bank, who said that his company uses 250 security vendors.

"How do you make all that work, right? The patches of the patches, and integration—it's just nuts and that has got to get much simpler," Gelsinger said.

It may take a few years before Gelsinger and VMware successfully reduce their reliance on dedicated security tools —  but ultimately, the company hopes to have fewer external vendors and platforms to rely on, while making its own infrastructure platform more secure. In the meanwhile, he urges companies to encrypt their data, so it can't be cracked even in the event of a security incident.

“You should always have data encrypted,” Gelsinger said. “There’s still lots of breaches, but this dramatically reduces the attack surface.”

Read the full interview with CRN here.

Read next

Rosalie Chan headshot
Rosalie Chan
Rosalie Chan is a senior editor for Business Insider's tech team. Previously, she covered cloud computing and enterprise tech, reporting on companies like Google Cloud, Amazon Web Services, Microsoft, Intel, Alibaba Cloud, Atlassian, GitHub, VMware, Broadcom, and more. She has written extensively on topics including cloud computing, developer companies, open source, and sexism and sexual harassment in the tech industry. She has received the San Francisco Press Club award for continuing coverage for her reporting on sexism and sexual harassment in Silicon Slopes and the Excellence in Business / Consumer / Tech Reporting award from the Asian American Journalists Association for her investigation into the coding boot camp Holberton School. Most recently, she was an editor on the Business Insider investigative package, The True Cost of Data Centers, which received a George Polk Award and an honorable mention from SABEW.Rosalie joined Business Insider after working as a software engineer and freelance journalist. She studied journalism, computer science, and technology and business law at Northwestern University. Her work has previously appeared in TIME, the Huffington Post, VICE, Pacific Standard, Inverse, Chicago magazine, the Chicago Reporter, and more. She's based in San Francisco.