Tuesday, June 25, 2019

So, Why Did I Join Chronicle Security?

As I mentioned a few days ago, I recently joined Chronicle, the Alphabet security company. Now I’d like to share a bit more of my thinking…


near new Chronicle office

As I mentioned a few days ago, I recently joined Chronicle, the Alphabet security company. Now I’d like to share a bit more of my thinking and reasoning for this.

What I see in Chronicle is an amazing technology platform, transparent business model, stellar team and huge potential for changing how we do security. Now, this sounds absurdly enthusiastic, so let me qualify with some context.

During my years as an analyst, I was exposed to many hundreds of security vendors (such as via vendor briefings). While many had interesting technology (at least for some use cases), the effective mixture of technology, business model and, for lack of a better term, timing is really rare. One can have decent technology, good people — and be too early (or late) for the market. One can have great technology and then kill it with a predatory business model. Or, one can have an amazing marketing message that technology just does not deliver operationally.

Here I do see all the success components in place. Let me handle those one by one.

  1. Technology platform — let’s start by saying that few people (and by “few” I really mean “nobody” :-)) over here are surprised by 250 millisecond data searches over trillions of logs and other telemetry records, but many of Chronicle Backstory characteristics are hard if not impossible to replicate elsewhere. Scale, performance, clean and enriched data combined with threat intelligence (TI) matching today deliver benefits for both incident response and threat hunting (if not threat detection yet)
  2. Business model — Chronicle Backstory has no per event (per EPS) or per gigabyte pricing. One year data retention is included (more about this in the near future — a lot of fun can be had with an immediately accessible year-worth of logs). This makes the business model clear and transparent, as well as predictable. A higher-level reason I like this, therefore, is that our model is thus more customer-centric. Believe it or not, a chance to load up chatty logs like DNS and web proxy without any agonizing over numbers makes such a model quite disruptive for security operations.
  3. Team — in brief, I really liked the caliber of people at Chronicle and the overall company culture. Culture really matters if you are trying to envision and build a new product, with unique capabilities, and I think a separate company with its own culture is the right way to do it.
  4. Vision and potential — now, some of you may already blame me for being overly enthusiastic, but frankly this item is perhaps the most exciting of all. Given the platform of such scale and performance, the application of many analytic methods (such as those from other Alphabet companies) may deliver insights that are just not possible elsewhere. Some vendors may have the data, others may have analytics, perhaps some would have the scale, but I do not see anybody who has the combination.

Finally, keep in mind that I am writing this only a few months after Chronicle launched at RSA 2019. If some things seem unfinished to you, guess what? We barely just started! Hence a big part of my excitement (a very fact-based excitement, if I may call it that) is about what is possible in the future, given what we have today…


Originally published at Medium.

Tuesday, June 11, 2019

Sorry, yes, I was told my “departure messages looked like a DoS and IT turned it off for some…


Sorry, yes, I was told my “departure messages looked like a DoS and IT turned it off for some time”, let me fix the text..


Originally published at Medium.

Friday, June 07, 2019

The Last Blog Post — Redux

This is a slightly modified farewell letter that I posted to my now-defunct Gartner blog [and, no, I have no idea why it is defunct, this…


This is a slightly modified farewell letter that I posted to my now-defunct [correction: it is back] Gartner blog

— start —

It is with some sadness and much excitement that I write this final post for my Gartner blog.

If you recall, I joined Gartner in 2011, so it has been nearly 8 years. So far, this has been my favorite job, the best I ever had in my life, by a wide margin. I’ve been very good at it too, making it all the way to VP Distinguished Analyst.

In fact, I loved nearly every moment of it. Hundreds, possibly thousands, of client inquiry calls over the course of 8 years. Many dozens of papers, most with such amazing partners like Augusto Barros and more recently Anna Belak. Dozens of conference presentations. Nearly 500 Gartner blog posts. Many topics like SIEM, EDR (hey, I coined the term!), DLP, UEBA, VA/VM, SOAR, NTA / NDR, SOC, MSSP / MDR, TI, DDoS, deception, IR / DFIR and other security operations, detection and response topics. Hours of intellectual banter about technology trends around virtual Gartner watercooler, with new ideas flowing and new research created.

All in all, a lot of fun!

And now all of this comes to an end. However, note that my move is not about leaving Gartner, but about pursuing literally a once in a lifetime opportunity! Continuing my unwritten policy of not mentioning vendors on my blog, I won’t mention where I am going (see LinkedIn, if you are that curious).

My security blogging will certainly continue! and my new security blog is here! Also, please follow me on Twitter.

Now, onwards to CHANGE THE WORLD!!!

My published Gartner research:


Originally published at Medium.

Thursday, June 06, 2019

The Last Blog Post!

After nearly 8 years at Gartner, publishing hundreds of blog posts, research notes, and Magic Quadrants on SIEM, EDR, and SOC operations, today is my last day as a Gartner analyst.

Thank you to all the readers, clients, and colleagues who engaged in debates, challenged assumptions, and contributed to defining security analytics over this transformative decade.

The journey continues elsewhere, and my writing will persist on my personal blog and other platforms.

Dr Anton Chuvakin