Industry Innovators: Security infrastructure
Industry Innovators: Hall of Fame
Risk management is a tough nut to crack in the IT world. Traditionally, organizations have avoided identifying IT risk as a separate and actionable risk area, folding it in with other forms of risk and often ignoring it completely. However, today, IT risk is a major issue for several reasons. First, and most visible, is compliance. Regulatory requirements force organizations to call out IT risk and address it explicitly.
Second, we finally are in that information age that people have been talking about for decades, and information is the life-blood of most organizations. In fact, even money itself is little more than data under certain circumstances. Finally, that status of data as the underpinning for the entire organization demands that risk be managed explicitly. Far fewer organizations than in years past are submitting to the “check-in-the-box” syndrome where compliance is all that matters and security comes a distant second, as long as the compliance report reads properly.
Modulo has addressed the challenge of compliance and real risk management by developing a platform that works on the premise of command and control. The Modulo Risk Manager links the organization's assets and infrastructure directly to governance, risk and compliance (GRC) requirements and, using the most comprehensive knowledge base in the industry – 21,454 individual controls addressing technology, people and processes, views the entire organization from a risk management perspective.
The key to this company's innovation is that it collects and harmonizes threat, vulnerability, operational, vendor and business risks – IT, operational and physical data – and matches this to business processes. The system is based on a MetaFramework on which one deploys the appropriate modules for the organization. The system integrates with many third-party products – more than 3,145 data collector possibilities, for example – to provide both front- and backend services and data sources.
This rich set of integration possibilities covers just about any business or IT configuration imaginable. The Modulo Risk Manager, then, becomes a central control point for addressing, managing and mitigating risk holistically throughout the organization. Hence, the notion of command and control. In part, because of its comprehensive command-and-control approach, Modulo is one of a small handful of risk management products used extensively in managing risk within national security organizations.
|
AT A GLANCE Vendor: Modulo Security Flagship product: Modulo Risk Manager Cost: $28,500 depending on number of assets for SaaS deployment; contact vendor for on-premises pricing. Innovation: Provides an aggregated view of risk in a command-and-control environment. Greatest strength: Customer relationship. |
