skip to main content
Close Icon We use cookies to improve your website experience.  To learn about our use of cookies and how you can manage your cookie settings, please see our Cookie Policy.  By continuing to use the website, you consent to our use of cookies.
Global Search Configuration

Ovum view


This year’s RSA Conference in San Francisco saw the IT security sector moving on in a couple of ways. Firstly, there were a multitude of vendors proposing technology to go beyond security incident and event management (SIEM), and secondly, detection and response capabilities are now offered as a managed service.

Going beyond SIEM and managed xDR were new trends

Some ongoing trends from previous years included the use of artificial intelligence and, more specifically, machine learning (ML) to improve threat detection.

This can be in platforms such as endpoint detection and response (EDR), where ML algorithms are applied to network traffic, or in user and entity behavioral analysis, where a system learns what constitutes normal behavior, then watches to detect anomalies that may indicate that a security exploit is underway.

In identity services, an ongoing trend is the zero trust model in privileged access management, where privileged users such as sysadmins must authenticate every time they start a new task and are therefore granted access rights only for the specific task they are performing, rather than gaining general access rights across the organization.

This year Ovum investigated the emerging sector of managed detection and response (MDR) in particular, where EDR and/or network detection and response (NDR) are offered as a service. We see this as an important development that can broaden the “xDR” market beyond the large enterprise market.

We also tracked the evolution of SIEM. Either the SIEM vendors themselves will address the shortcomings of their technology by adding functions, or newer players will enter the market with products that are initially complementary but may ultimately replace SIEMs altogether. These shortcomings include the fact that they

  • don’t work well across hybrid on-premises/cloud environments

  • cannot address the requirement for integrated detection and response

  • charge customers to store data, making their cost more onerous as the amount stored increases.



Rik Turner, Principal Analyst, Infrastructure Solutions

Recommended Articles

  • Consumer & Entertainment Services

    US pay TV: Is it facing an existential threat?

    By Adam Thomas 28 Mar 2018

    With US pay TV having endured the worst year in its history, thoughts have inevitably turned to the future. The likelihood remains that the immediate future will remain highly uncomfortable for everyone except the scaled multinational digital platforms.

  • Enterprise Decision Maker, Enterprise IT Strategy and Select...

    2017 Trends to Watch: Big Data

    By Tony Baer 21 Nov 2016

    The breakout use case for big data will be fast data. The Internet of Things (IoT) is increasing the urgency for enterprises to embrace real-time streaming analytics, as use cases from mobile devices and sensors become compelling to a wide range of industry sectors.

    Topics Big data and analytics IoT

  • Enterprise Services

    5G: Another technology in search of enterprise use cases

    By Evan Kirchheimer 26 Apr 2018

    Service provider interest in justifying 5G investment through its potential to open new revenue streams from the enterprise segment is growing ever greater.


Have any questions? Speak to a Specialist

Europe, Middle East & Africa team - +44 (0) 207 017 7700

Asia-Pacific team - +61 (0)3 960 16700

US team - +1 646 957 8878

Email us at

You can also contact your named/allocated Client Services Executive using their direct dial.
PR enquiries - Call us at +44 788 597 5160 or email us at

Contact marketing -

Already an Ovum client? Login to the Knowledge Center now