MSSP, MSP, Managed Security Services, AI/ML, SIEM

Securonix Looks to Partnerships to Expand Security, Global Reach

The end of legacy SIEMs

In the past few months, Cybersecurity firm Securonix has rolled out a series of partnerships with tech vendors, MSSPs, MSPs, and other channel players to expand its global footprint and navigate a competitive and rapidly evolving SIEM space.

This week, the Texas-based vendor revealed a new customer partnership with Banyax, a managed detection and response (MDR) company, that will use Securonix’s AI-powered user and entity behavior analytics (UEBA) platform to improve insider threat detection across its customer base, including MSSPs.

The partnership will allow Banyax to integrate Securonix’s technology in its Banyax Service Delivery Platform, unifying the behavior analytics with its own threat detection workflows. Securonix’s tools use machine learning models to run through massive volumes of security telemetry for behavioral anomaly detection. Banyax will be able to ingest data through open APIs, run deep threat analysis in its platform, and send high-confidence alerts to Banyax analysts and customers.

The result is faster root cause analysis, fewer false positives – a growing problem in the cybersecurity field and a key cause of alert fatigue among security pros – and streamlined workflows, according to Securonix officials.

A 'Model' for Partnerships

“Our work with Banyax is a model of what strong partnerships should look like, built on technical trust, shared innovation, and a relentless focus on customer outcomes,” Securonix CEO Kash Shaikh said in a statement.

The collaboration with Banyax comes after a number of other partnership announcements. In June, Securonix said it was working with Prophecy International Holdings, the organization in Australia behind the Snare log collection and management solution.

The combination of Snare Solution’s log agents offering with Securonix’s UEBA platform is aimed at helping enterprises and government agencies standardize telemetry intake, reduce the complexity of infrastructure, and enhance threat detection across hybrid environments, including those running Windows, Linux, or macOS, and whether they’re in the cloud or on premises.

By streamlining telemetry flow from endpoint to SIEM solution, the partnership will let security logs flow easily into the Securonix platform. Work with early customers found that there was 30% to 50% faster onboarding of logs, lower SIEM storage and processing costs, improved compliance, and improved accuracy and precision for machine learning and threat modeling, according to the companies.

Taking a Worldview

Other partnerships with MSSP Skyone and security tech distributor ITSDI will help Securonix expand its reach in the Latin American and the Philippines, respectively. In addition, the vendor last month said it was collaborating with LA Technologies, a MSSP with expertise in operational technology (OT) security and AI-powered threat detection and a direct presence in seven countries and operational support in more than 30.

All this comes around at a time when Securonix is making waves with its acquisition of TheatQuotient, a deal that will combine behavioral analytics and agentic AI with curated external threat intelligence. It also grows Securonix’s reach beyond SIEM into a threat detection, investigation, and response (TDIR) platform for both enterprises and MSSPs.

Securonix and other vendors are adapting to changes in the SIEM space that has evolved quickly since first being introduced in 2005 when companies began combining log management and event management systems. SIEM platforms then started handling big data, which cloud-native security firm Exabeam wrote meant large volumes of historical logs. Later, SIEM capabilities were combined with UEBA and anomaly identification, which included SOAR.

The Pressure is On

“The traditional SIEM model is under pressure due to the sheer volume of alerts, the complexity of hybrid-multi environments, and the need to respond in near-real time to sophisticated and quickly evolving threats,” Krista Case, research director with The Futurum Group, told MSSP Alert. “The SOC (security operations center) needs more intelligent, integrated, and automated detection and response capabilities.”

In response, SIEM vendors are responding with a greater platform-driven approach, such as bringing together UEBA, SOAR, and traditional SIEM capabilities, Case said, adding that they’re also under pressure to ensure they can reliably consumer, enrich, and analyze data from a broad array of sources while maintaining fidelity and compliance.

“Complementing this data ingestion, rich machine learning, analytics, and AI are becoming table stakes in order to address insider threats, lateral movement, and low-and-slow attacks that often slip past rule-based detection,” she said. “The Securonix and Banyax partnership points to the need for behavior analytics-driven detection of anomalous activity in a more contextual and risk-prioritized way.”

Case also pointed out that “Securonix’s alliances with Skyone and LA Tech point to the need for regionalization. As cyber threats grow more global and as regulatory demands become more localized, in-region support and compliance expertise becomes more important.”

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds