Google to Acquire Mandiant
mandiant.com
mandiant.com
Their APT-1 report (https://www.mandiant.com/resources/apt1-exposing-one-of-chin... they released in 2013 was at the time unprecedented and brought awareness to nation-state sponsored hacking to a much broader audience than ever before.
As someone who worked there in the early days (a little over 100+ employees) as an entry-level peon, I always felt I had the ability to walk into Kevin's office at anytime and tell him something I thought was important and get attention and respect back.
While much of the organization has changed in the last 3 years, the constant has always been Kevin and the amount of work they put in to recover from the disastrous FireEye acquisition, preserve the brand's integrity, and to parlay that into such a positive acquisition for the employees and shareholders is an incredible outcome.
Congratulations to both Google and Mandiant.
Microsoft Corp. is in talks to acquire cybersecurity research and incident response company Mandiant Inc... Mandiant shares surged 18% in New York, bringing its market value to almost $4.3 billion.. A deal might also push cloud rivals Amazon.com Inc. and Alphabet Inc.’s Google to pursue their own similar acquisitions
https://www.bloomberg.com/news/articles/2022-02-08/microsoft...
And from the current event:
..acquired by Google LLC for $23.00 per share in an all-cash transaction valued at approximately $5.4 billion
Also, it's very unlikely Google wants to be in the incident response consulting space: Google entirely hates any line of business that can't be automated into a smooth profit paste. Flying security professionals out to clients isn't in their DNA.
That hasn't been my experience with security services companies. Sure, people matter, but the processes, technology, and leadership can keep a good one on track regardless of who leaves.
As much as Investment Bankers maybe be a drain on society, they DO provide value to certain capital-holders.
Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes."
Isn't a primary responsibility of government to protect its citizens and businesses from other states' militaries?
Government is not an abdication of responsibility.
Not petty crime and local burglary.
I suspect you'll find that the state does involve itself in organised crime, smuggling, consumer and securities fraud, and the like.
Organizations do bear responsibility for their security posture--and many have spectacularly failed in this responsibility--but let's not pretend that an employee being phished is equivalent to something on the level of the SolarWinds hack or any one of the many nasty bits of malware coming out of Russia.
State sponsored attacks are well funded and leverage one more or 0-days, which by definition cannot be defended against. The only way to stay ahead of a 0-day is to find it first, and that requires resources and expertise even large organizations are hard pressed to find in the numbers required.
What a shocking idea!
Do you really want the TSA on the internet? Because that's what you're asking for...
Every company's IT looks different, it's hard to tell whether an attack is private or state sponsored, often where or who it is originating from, and how to defend against it varies from case to case.
So it's hard to imagine what exactly it is that the government is supposed to do at a company level. Of course at an ISP level or when it comes to national infrastructure the government can do things, but I don't see how the government protects a middle-sized business from cyber attacks.
The government could probably do a lot of preventative things like sponsoring and funding security audits of open source software, but when some hackers exploits my broken config or some API it's not clear to me how the government is supposed to prevent that. They can't read every line of source code in the country.
Currently those layers are roughly provided by the big tech companies, and the government's involvement in making those more secure is PhD students and curious professors from (public) universities. It would be nice if that was a more directly employed org in the government.
I think we take for granted that they are clearly defined now because nation-states worked very hard to define, create, and enforce that concept. As I understand it, for most of human history there was no real notion of a well-bounded state and even today sovereignty is hotly debated in some areas.
So, it's not that enforcing land borders is intrinsically easy. It's that it appears easy because nations adopted it as their responsibility and do the work. Look at how much political energy was expended around Trump's wall between the US and Mexico to get a sense of how complex and effortful land borders are.
I don't see any reason that Internet sovereignty couldn't be equally well-defined and defended... except countries simply aren't doing it.
The inter-net as the name suggests is a network, not a perimeter and runs across boundaries. If you want Trump's border wall on the internet you're talking about handing the government sole access and control to all information going in and out.
That's way beyond cyber defense of private business. And looking at some countries engaging in this right now you better be careful what you ask for.
Countries try to enforce their borders. And they normally regulate traffic through a custom, the rest is deemed unlawful.
More on the point: the current internet is a mess. Hopefully it collapses and a new network is built, with security in mind this time.
I think those boundaries are a lot less natural than you think when you take into account things like embassies, extradition treaties, etc.
But there's also a perverse incentive. Offensive capabilities hidden and not patched.
And there's also issues with responding on US soil or assets.
Like would it be legal for NSA to proactively go into Google's networks or some internet infrastructure device without permission or court order? Even to do something good?
Meanwhile, the high risk basic R&D spend that underpins many US businesses (including most grad student salaries and research grants) is from the US Government. Every time one of those fails (Solyndra) the press points it out as a failure of government. Every time it succeeds (SpaceX) it’s attributed to the scrappy entrepreneur and the government subsidy be damned.
The risk is socialized onto the taxpayer and the gains are privatized to the very rich. Look at the iPhone: internet (DARPA), cellular (developed to Army requirements based on Vietnam radio problems), GPS (DoD), multitouch (University of Delaware on an NSF grant). How about the Sand Hill boys spend some of that money on security instead of inflating Atherton real estate prices and laundering money through modern art auctions?
I wonder what will happen to the engineers; there is definitely a lot of expertise at that company, specifically in the IR/security side.
As an engineer I would be stoked. The resources that Google can bring in terms of data, compute and depth of analytical skills would be very appealing. It’s probably going to be a disaster for the product folks but i think the engineers will be happy. At least for a little bit.
This could be a way to improve their offering and remove the "security argument" showstopper for cloud migrations.
Hey team, so this is Steve from another department in another company. He's been assigned to our team, so. Of course we're handling text in the Chromium engine and Steve's backgound is in threat analysis, but I guess we'll figure something along the way. Welcome, Steve
Interviewing happens with startups. When there aren’t interviews the assumption is that Perf will take care of non-performers.
The engineers probably would need to be re-interviewed. Heh.
In reality: your product will be sunsetteded and replaced with a Google-created version of the same thing within two years; your key management (and other) talent will pace around for 3-4 years in frustration waiting for their stocks and acquisition bonuses to fully vest, and eventually most of the talent that can get a competing offer that is close to Google's proverbial buckets of cash will take that and leave.
That said, it might be different in Google Cloud where more of the infrastructure is closer to industry standard infrastructure instead of Google's bespoke creations. And there's a focus on the needs of what people outside of Google do and how they do it.
> Mandiant’s more than 600 consultants currently respond to thousands of security breaches each year. Paired with research from more than 300 intelligence analysts, these resulting insights are what power Mandiant’s dynamic cyber defense solutions – delivered through the managed multi-vendor XDR platform, Mandiant Advantage.
This reads like they are a PR company covering everything computer.
I take a tiny bit of issue with that.
Cryptography consulting is a higher labor rate, and higher end pen-testing w TS SCI+full poly, and application security gurus are above, or equal to IR.
There are currently poaching wars going on around talented IR folks. A fortune 500 recently hired away an IR colleague with whom I collaborated around tap & agg with a FAANG type offer, RSUs, the whole shebang
Have seen labor rates across Fireye, and a host of others.
Even high end appsec, seceng, and legit reversing pays below crypto and IR. We just can’t charge as much for it for all but the most niche and demanding environments, which is not the bulk of what’s out there.
I am thinking averages here. I know there is high paying work in each domain, but the skills used are also highly developed, etc. If you wanted to build a high end consultancy with a lot of work IR is a great choice. I know ToB has done awesome in crypto (blockchain/contracts) space, etc. but I think IR work is a little easier to get into and build a business on without having really advanced and niche skills.
IR is a huge practice area, lots and lots of people do it, and the line-level consulting work here is stuff that isn't at all difficult or specialized (log file analysis, imaging). There's specialty work in IR too, of course (there are firms that specialize in memory forensics, for instance), and that bills higher.
Mandiant is like the PwC of IR firms; Mandiant can get contracts that bill basic log file analysis out at $3k/day, because they're Mandiant. That doesn't mean the person doing that work is seeing proportionally more income themselves, or that a team of people striking out on their own from Mandiant are going to be able to bill comparably.
On the other hand, a team of cryptographers or hardware reversers at a big firm probably could expect to see comparable bill rates after starting up their own firm.
In other words, it is the company that detected a breach of its own systems via dogfooding, that turned out to be the only detection that occurred of a breach of the entire US govt more or less - Solarwinds.
Mandiant got the jump on every US govt agency in detecting arguably the largest espionage event of the digital age.
I’m genuinely surprised by this acquisition, however. Mandiant’s business model (consulting services) was successful despite the pressures and operational dissonance from the product side. When I left, they were well-poised for natural growth and to capture a larger market share of managed security services. I’m sure there is a model for success under Google, but I doubt many of the employees below the C-level wanted to go this direction.
We really are a privileged bunch aren't we =)
Those popups are all cookie-hidden if the cookies are set. Easy for an engineer working regularly on the product to accrete the cookies necessary to hide most of them over time.
(Concretely in this case, I bet 99% of the engineers on that site have forgotten GDPR is a thing, especially since their compliance is being handled by third-party provider TrustArc. Easy for a frequent visitor to forget that every new visitor will get asked about the cookie use permission on the first visit).
Google has a reputation for taking in a lot of data about user behaviour for targeting ads. That's pretty well defined data though, from well-defined sources, with well-defined semantics. Things like page views.
How would Google ever be able to "hover up all your data" and get any benefit from it? What is the data? Where did it come from? What are the semantics? How are users identified? How is that mapped to users Google knows about?
It's just entirely impractical to do anything with it, and that's leaving aside the fact that I imagine it would violate the terms of service, the contracts Google may have with businesses, and may constitute a significant legal issue with regards to data misuse.
How exactly do you imagine that Google could do this, and what exactly would their motivation be to do so?
Mandatory disclaimer: I work at Google, but not on any of the above and I only just started. My feelings on this are only informed by my previous time as a customer of Google Cloud.
So as long as they have amazing handcuffs on the CEO, it's probably more like $1M per employee and $100M+ for the CEO (if real handcuffs) + brand.
An independent Mandiant is amazing for the ecosystem, but so goes. Over all though, probably still net win for folks involved + community - Google getting even more serious here is great!
Maybe we should bet on a wave of other big acquisitions by companies with big cash reserves as well?
Why does Big Tech get a pass? Is it because they feed the government free data on every single American and foreign national?