March 2, 2016 By Douglas Bonderud 2 min read

When the king of antivirus says it’s time for a burial, there’s a problem. Last year, John McAfee of the eponymous antivirus solution penned a piece for SiliconANGLE and argued that the time had come — it was no longer possible for antivirus tools to keep up with emerging attack vectors and offer reliable defense of corporate systems. But what takes their place?

Next-gen endpoint security tools are the new kids on the block. As noted by Network World, this market doubled last year and the year before, and it is on track for 67 percent compound annual growth rate over the next half decade. But are these next-gen tools really up to the challenge of pulling the plug on antivirus?

Changing of the Guard?

So what has to happen for endpoint tools to surpass the still-alive-and-kicking antivirus industry? Market growth is critical. Network World reported that the antivirus market comes in at around $9 billion, while the next-gen market sits at just $500 million this year. Growth can be misleading, however, since many endpoint vendors are startups with minimal overhead and limited staff — meaning even small revenue increases translate to big growth percentages.

Beyond investment and product deployment, however, endpoint tools can also get ahead if they’re certified as antivirus replacements. Right now, these new tools are novelties; they might provide ironclad protection or merely stop a few odd bits of code from cracking enterprise networks. But certification from vendors licensed to evaluate compliance with standards such as PCI DSS could give these next-gen solutions the boost they need to close the revenue gap or drastically lower investment in traditional antivirus solutions.

The Next Generation of Endpoint Security

But what does a next-gen solution do, exactly? Some offerings look at kernel-level processes to identify suspicious behavior, while others rely on application white-listing to keep company servers clean. Dark Reading suggested other approaches such as containerization, binary runtime inspection and a combination of traditional antivirus offerings to handle known malicious vectors with application control using a default-deny approach to ensure only good software is deployed.

According to McAfee, however, this won’t be enough in isolation. Endpoint security-makers, IT admins and app developers must all acknowledge the one area where advancements in technology have little to no impact: human behavior.

Oh, Behave

Despite more intelligent antivirus tools and the addition of real-time monitoring solutions, socially engineered attack efforts consistently make it through corporate endpoints. Why? Because users are hardwired to act in ways that undermine IT security. McAfee cited the emergence of a culture where each tech pro is assigned a partnered hacker who attempts to break code before it goes live.

But this is just the beginning. For endpoint tools to truly usurp their antivirus cousins, they need to account for the human condition — the predisposition to be nice or social instead of being safe. Think of it like building in support for unstructured big data. It’s no easy task to reconcile this massive, ever-changing resource, but it is absolutely worth the potential insight.

For endpoint security tools, it’s the same challenge: Getting certified is the first step. Managing the human condition puts them on the road to long-term success.

More from

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Protecting your digital assets from non-human identity attacks

4 min read - Untethered data accessibility and workflow automation are now foundational elements of most digital infrastructures. With the right applications and protocols in place, businesses no longer need to feel restricted by their lack of manpower or technical capabilities — machines are now filling those gaps.The use of non-human identities (NHIs) to power business-critical applications — especially those used in cloud computing environments or when facilitating service-to-service connections — has opened the doors for seamless operational efficiency. Unfortunately, these doors aren’t the…

Communication platforms play a major role in data breach risks

4 min read - Every online activity or task brings at least some level of cybersecurity risk, but some have more risk than others. Kiteworks Sensitive Content Communications Report found that this is especially true when it comes to using communication tools.When it comes to cybersecurity, communicating means more than just talking to another person; it includes any activity where you are transferring data from one point online to another. Companies use a wide range of different types of tools to communicate, including email,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today