Friday | 10 July, 2009
CSO
SMB - Apps security testing companies ride wave
IBM and HP are working to integrate apps testing into their development platforms, but vendors of stand-alone security solutions still find business booming
Matt Hines (InfoWorld) 04/04/2008 09:11:18

HP executives conceded that large, diversified IT vendors haven't always kept their promises to stay committed to the products they acquire. They said their long-term goal is to make SPI's Web applications tools an integral piece of the company's Mercury development platform.

But in the meantime, HP is seeing continued growth in demand for SPI's existing technologies, and executives said the company will continue to market the tools in a standalone fashion.

"It's true that acquisitions sometimes don't work out as promised, but we are totally committed to furthering SPI while we integrate the technology into the development process," said Chris Whitener, chief strategist of the Secure Advantage business at HP. "Clearly our vision is that security testing will become a requirement of software developers, but there's a market for these products as they exist today, and we're still seeing strong demand."

Industry analysts said the process of driving security testing deeper into the development lifecycle remains nascent, while predicting that it may very well become the norm in the future.

However, there should be opportunities for both the independent providers and for their larger rivals as applications security continues to prove itself as a growth market, said Paul Roberts, an analyst with the 451 Group.

"Whenever big acquisitions happen, you always hear the business model validation argument from those left standing. I don't disagree that it's taking a long time for HP to fully digest SPI, and it's the same with IBM and Watchfire," Roberts said. "And even when they do, there's likely still a role for stand-alone tools at later points in the development cycle."

The analyst pointed out that the move to push security responsibilities onto developers may not be welcomed by some of those highly sought-after professionals.

"The larger question is, will there always be a role for smaller venture-funded companies to provide [applications security testing], or will it also get rolled up into larger diversified companies selling the development platforms," said Roberts.

"Both arguments are right, and it's not a zero-sum game; clearly HP and IBM bought those companies because they see a need for testing to move down the chain. But people who say that most code-writing shops aren't there yet are right, and there's also a dearth of development talent out there," he said.

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

Extensible Threat Management

Unified threat management (UTM) spawned a new era of IT security. The promise of these integrated security appliances proved to be an exceptional and efficient way of securing commercial networks. However, businesses today face an inflection point, dictated by changing market trends and new technologies that demand more of today’s UTM. Hence the need is for eXtensible threat management (XTM) solutions, the next generation of UTM appliances.

Sponsored Links