Report | IDC MarketScape: Worldwide Modern Endpoint Security for Enterprises, 2021

Report | IDC MarketScape: Worldwide Modern Endpoint Security for Enterprises, 2021

Download the IDC MarketScape report on Worldwide Modern Endpoint Security for Enterprises 2021 to gain valuable insights into the top vendors in endpoint security, including Check Point. Access key evaluations and market trends to inform your security strategy. Download now to learn more!

Report | IDC MarketScape: Worldwide Modern Endpoint Security for Enterprises, 2021

November 2021, IDC #US48306021e

IDC MarketScape

IDC MarketScape: Worldwide Modern Endpoint Security for Enterprises 2021 Vendor Assessment

Michael Suby

THIS IDC MARKETSCAPE EXCERPT FEATURES CHECK POINT

IDC MARKETSCAPE FIGURE

FIGURE 1

IDC MarketScape Worldwide Modern Endpoint Security for Enterprises

Vendor Assessment

Source: IDC, 2021

©2021 IDC #US48306021e 2

Please see the Appendix for detailed methodology, market definition, and scoring criteria.

IN THIS EXCERPT

The content for this excerpt was taken directly from IDC MarketScape: Worldwide Modern Endpoint

Security for Enterprises 2021 Vendor Assessment (Doc # US48306021). All or parts of the following

sections are included in this excerpt: IDC Opinion, IDC MarketScape Vendor Inclusion Criteria,

Essential Guidance, Vendor Summary Profile, Appendix and Learn More. Also included is Figure 1.

IDC OPINION

The criticality of effective endpoint security has never been greater for enterprises. A principal reason

is enterprises' evolving IT footprint. Spurred by the COVID-19 pandemic, millions of office workers

changed locations from onsite to work from home (WFH). While workers are gradually returning to the

office, the workplace landscape for many organizations is unlikely to return to its pre-pandemic state.

In addition, the usage of cloud applications surged during the pandemic as business leaders sought

flexibility to support their immediate needs and to better compete in a digitally transformed future.

This dual shift of workers and applications to off premises has been a gift to threat actors. The

exploitability of personal computers (PCs) of WFH employees increased. In addition to being situated

outside office-based perimeter defenses, these devices were now on a full-time basis connecting

through unmanaged home networks and with increasing potential, used for nonbusiness purposes and

by other family members. The viability for threat actors to infect remote PCs, in essence, multiplied.

And since users of these devices required access to cloud-based applications (custom and software

as a service) and on-premises applications through a VPN to remain productive, the attractiveness of

PCs as targets rose. Moreover, as worker remoteness increased along with access to both cloud and

on-premises applications, business networks became flatter. Legacy approaches to use network

segmentation as a security mechanism became less effective. Also a benefit to threat actors, their

lateral movement from the first infected PCs to other PCs and connected IT systems encountered

fewer barriers.

Not only have threat actors intensified their focus on endpoints, but they have also advanced their

tradecraft. A decade ago, signature-based antivirus software was considered an adequate defense in

identifying and removing malware from end-users' devices. Times have radically changed. Threat

actors no longer rely exclusively on dropping malware onto devices to carry out their attacks. Instead,

they are more apt to manipulate legitimate software programs, tools, and files (i.e., living off the land

attacks). Subsequently, identifying behaviors of malicious intent has become a requirement in

mounting an adequate defense.

Identifying malicious behaviors, however, is no simple task. The varied, wide ranging, and complex

nature of what end-user devices (PCs and smartphones) are equipped to do blurs the distinction

between malicious and legitimate behaviors. In addition, threat actors will orchestrate a series of

actions, each seemingly benign, to further disguise their presence. Assembling the trail of related

actions has become essential in uncovering active attacks and then responding with speed and

precision to blunt them.

Building up endpoint security is crucial. Modern endpoint security (MES) products, the combination of

endpoint protection platforms (EPPs) for deterministic prevention and endpoint detection and response

©2021 IDC #US48306021e 3

(EDR) for post-compromise reaction, are the latest evolution in endpoint security designed to combat

threats aimed at endpoints. It is confirmed through IDC research that the demand for modern endpoint

security is on the rise.

A modern endpoint security product, however, is not an island. Rather, it is a component in a

constellation of complementary security technologies and operations that function together to fortify

the security posture of endpoints and the resiliency of business functions. Given this more holistic view

of modern endpoint security, enterprises should not limit their assessment of the independent merits of

modern endpoint security products. They should also examine integration and workflow streamlining

with and across other technologies that fortify security and enhance security and IT operations. A list of

these technologies includes but are not limited to hardware-based device integrity checks and

restoration, endpoint/IT hygiene management, file and data backup and recovery, and the evolution of

EDR to eXtended Detection and Response (XDR).

IDC MARKETSCAPE VENDOR INCLUSION CRITERIA

Participating vendors met the following criteria:

▪ From a single endpoint software agent, the vendor's modern endpoint security product

supports both endpoint protection platform and endpoint detection and response.

▪ End-user personal computing device platforms supported by the modern endpoint security

product must, at minimum, include the latest versions of Windows and macOS.

▪ Vendor began selling modern endpoint security products to customers from January 2019 or

earlier.

▪ Sales to commercial and governmental customers of EPP (also referred to as antivirus or

next-generation antivirus), EDR, and modern endpoint security products must, at minimum,

totaled $30 million (following generally accepted accounting principles [GAAP]) in calendar

year 2020.

▪ At year-end 2020, the vendor's percentage of customers with 2,500 or more protected

endpoints exceeded 5%.

ADVICE FOR TECHNOLOGY BUYERS

Just as the threat landscape has evolved so too has the endpoint security market.

As the threat landscape has evolved with intensified focus on compromising endpoint devices, so too

has the landscape of modern endpoint security vendors included in this IDC MarketScape. With this,

enterprise endpoint security buyers have greater choice and opportunity to select a vendor that is best

aligned with their circumstances and requirements. Our overarching advice is to evaluate vendors from

the perspective of strategic fit. Selecting a vendor and its MES product is not only for combating the

threats of today as they will be different tomorrow. Rather, the selection should be made from a long-

term perspective on whether the vendor can adapt to the threats of the future while also reducing the

cost and complexity of security operations.

More tactically, IDC offers this advice to enterprise MES buyers:

▪ Focus first on MES fundamentals:

©2021 IDC #US48306021e 4

▪ Protection efficacy. IDC buyer analysis revealed enterprises' top consideration in choosing

a MES vendor is its research into never-before-seen threats and attack tactics. But buyers

are not content with just research, they want results. There is no better result than

automatically and deterministically blocking new forms of attacks. Independent

evaluations on protection efficacy are useful guides in this regard but are not the panacea.

IDC recommends conducting proof of concepts (POCs). We further recommend that EPP

POCs should become a routine activity. With existing vendors evolving their EPP

capabilities and new vendors emerging with "next generation" approaches, comparative

analysis in your environment is the best litmus test. Avoid the trap of being the enterprise

that started its search for a more effective MES product after it suffered a serious security

incident.

▪ EDR automation. Second on the list of buyers' vendor selection criteria is incident

investigation speed and ease. The unfortunate reality is some attacks will evade the

immediate preventions of EPP and establish a footprint on endpoints. Security teams need

to be prepared. But just having EDR functionality is not enough, human engagement is

required. Concentrating human engagement more on decision making and less on

investigatory processes is vital in lessening threat actors' dwell time and the time required

of your security personnel. Therefore, automation is essential and is present in various

forms, such as assembling and cross-correlating relevant data, visualizing attack

sequence, devising risk-rated responses, and executing on the chosen response(s). In

addition, enterprises cited automated threat hunting as an important factor in considering a

MES vendor. Conducting a proof of concept is the most effective means for evaluating the

vendor's level of automation and usability fit with your security personnel.

▪ Device support. MES products can only deliver EPP and EDR capabilities on endpoint

device types and operating systems (OS) that their software agents support. Obviously,

you will want to confirm support for the device types and OS platforms that are in your

environment. All vendors in this IDC MarketScape support recent OS versions of Windows

and Mac. But Windows and Mac PCs are not the only device types attacked. Mobile

devices, physical and virtual servers, and cloud workloads are also targeted. While

vendors' datasheets list supported device types and OSs, IDC recommends digging

deeper into feature parity and feature distinction to ensure the vendor's product is

adequately equipped for all of your devices and provides unified management.

▪ Examine cross-function integration. Endpoint security and endpoint management functions are

intertwined. Unpatched and out-of-date software applications and OS versions are targets of

exploitation by threat actors. When exploited, EPP and EDP become the next two layers of

compensating security. Quite likely, your organization has a dedicated patch management

solution in place. If that is the case, cross-vendor integrations should be examined for time-

saving enhancements in workflows and acceleration in risk reduction. Alternatively, an

increasing number of vendors offer patch management as part of their product suite. This too

can be a suitable option if the feature set meets the varied needs of your IT estate. In addition,

patch management is one of several functions that reduce an endpoint's attack surface and,

consequently, exploitability. Other functions include device control, host firewall management,

vulnerability assessment, micro-segmentation, and application blacklisting, whitelisting, and

process-level allow listing. In your consideration of MES vendors, comparing their collection of

attack surface reduction capabilities with those of dedicated products may reveal an effective

and possibly a more affordable approach to strengthening your security posture.

▪ Evaluate XDR frameworks. Reaching a complete and speedy understanding of attacks

affecting endpoints may require more than telemetry gathered from endpoints running a MES

software agent. Telemetry from other sources (e.g., network sensors, perimeter defenses,

©2021 IDC #US48306021e 5

email and web gateways, cloud access security brokers, and identity management services)

can bring in beneficial context. Many of these sources can also be control points for applying

attack-mitigating responses and in refining security policies. An oversimplified description, this

is the realm of eXtended Detection and Response. Nearly all vendors in this IDC MarketScape

have an XDR framework that encompasses their non-endpoint security product portfolios,

ecosystem partners, or a combination of both. As part of your assessment of MES products,

evaluate the vendor's current state of XDR, future developments, and incremental security

value and what a transition from EDR to XDR will entail (e.g., additional cost, technology

upgrades, and staff training and augmentation).

▪ Question ransomware defenses and recovery options. The consequences of ransomware

incidents are a top-of-mind concern for business leaders, and for good reason. According to

IDC's July 2021 Future Enterprise Resiliency and Spending Survey, Wave 6, 75% of IT

decision makers with organizations that experienced one or more ransomware incidents in the

past 12 months indicated that significant extra resources beyond what internal staff handled

were required to rectify. Ransomware, like other forms of malware, frequently enter business

networks through endpoint devices. Subsequently, endpoint security products, like MES, are a

vital line of defense. But just as ransomware has evolved to evade detection, and ultimately,

increased the likelihood of payment and amount of ransom payment, MES products must also

evolve to detect ransomware and prevent its execution (e.g., data exfiltration and file

encryption) and propagation to other endpoints and critical systems. IDC recommends that

you query MES vendors about their ransomware defenses and incident recovery options for

returning affected files and endpoint configurations (e.g., changes to registry keys) to their

previous known good state. As you do, assess these capabilities within the context of your

overall business cyber-resiliency plans.

▪ Gain perspective on incorporation of built-in device security capabilities. Worth repeating,

threat actors will evolve how they conduct attacks. They will continuously probe for new

avenues to enter and takeover endpoints. While not yet mainstream, attackers compromising

the device's firmware is a possibility. Rather than react to this possibility once it becomes

reality, ask MES vendors about their approach to confirming firmware integrity and restoration.

Also ask about leveraging the device's chip-based processing features in conducting or

augmenting MES functions. Eventually, the measuring stick for endpoint security solutions will

entail the collaboration of built-in device security with overlay on-device security software

augmented with cloud-powered features. To make security-maximized decisions on device

and MES product purchases, ask MES vendors about their current and planned approaches to

leveraging built-in device security features.

▪ Consider managed services options. Although MES vendors have and will continue to

automate and simplify the use of EDR, experienced security professionals are needed to

produce maximum return on EDR's capabilities. IDC recommends that you consider the

managed service options offered by MES vendors and/or their channel partners. As service

needs vary by level of engagement (e.g., from on-demand collaboration to around-the-clock

outsourcing) and tasks performed (e.g., threat monitoring, threat hunting, and threat

response), seek a managed services arrangement that best aligns with your current needs

and budget but is also flexible to adjust for changing circumstances.

VENDOR SUMMARY PROFILES

This section briefly explains IDC's key observations resulting in a vendor's position in the IDC

MarketScape. While every vendor is evaluated against each of the criteria outlined in the Appendix,

the description here provides a summary of each vendor's strengths and challenges.

©2021 IDC #US48306021e 6

Check Point

Check Point is positioned in the Major Players category in the 2021 IDC MarketScape for modern

endpoint security for enterprises.

Pivoting from its lengthy and storied history in endpoint security and aligning its product strategy with

growing customer appetite for integrated product suites over independent point products, Check Point

rebranded its SandBlast Agent endpoint security product as Harmony Endpoint in 2020. Harmony

Endpoint Basic, the narrowest but functionally robust Harmony Endpoint package, includes anti-

malware, anti-ransomware, zero-day phishing, advanced threat prevention, and EDR. The next

package size, Harmony Endpoint Advanced, augments Basic with threat emulation (sandboxing) and

threat extraction (file content disarm and reconstruction). The most comprehensive package, Harmony

Endpoint Complete, adds data security (full disc and media encryption) to Advanced. All technologies

in Harmony Endpoint are originally designed or acquired by Check Point.

With an objective of providing customers with choice and combinability across endpoint, devices, and

access, Harmony Endpoint is one product set within the broader Harmony suite. Other product sets in

the Harmony suite are: Harmony Connect (Secure Access Service Edge), Harmony Browse (web

gateway functionality delivered within the end-user's browser via a nano agent), Harmony Email and

Productivity Suite (email and phishing security specifically for Office 365 and G Suite), and Harmony

Mobile (mobile threat management).

Harmony, itself, is one of three suites in Check Point's full product portfolio of SMB and enterprise

products. The other two suites are Quantum (network security) and CloudGuard (cloud security). Like

Harmony, there are multiple product sets in the Quantum and CloudGuard suites. Check Point also

sells an endpoint protection product named ZoneAlarm, which is targeted at the consumer market.

Bringing all suites and product sets together into unified management is Infinity-Vision. Combined with

access to Check Point's library of threat intelligence and equipped with similar SOC tools used by

Check Point analysts, Infinity-Vision is Check Point's answer to XDR.

Strengths

With a limited number of exceptions, Check Point is in the upper tier of MES vendors in all of our

comparisons. Key strengths for Check Point include:

▪ Profitable. A consistently profitable company for over 15 years, Check Point has a history of

reinvestment in core security technologies, threat research, new and enhanced products,

system management, and sales channel.

▪ Broad and integrated product portfolio. As outlined previously, Check Point has a

comprehensive and integrated portfolio of security products that it has assembled into mix-

and-match suites and product sets. From those, Check Point is well positioned to engage with

customers as they seek to reduce their vendor relationships while strengthening their security

readiness.

▪ Distinctive MES product capabilities. Check Point is in a limited subset of MES vendors with

rollback remediation and hardware security integration features. Threat emulation and threat

extraction are also distinctive MES product features.

▪ Consumer business. Check Point is active in the consumer segment through its ZoneAlarm

brand. In addition to threat intelligence gathered from millions of consumer endpoints,

©2021 IDC #US48306021e 7

ZoneAlarm provides Check Point with an additional segment to test its core endpoint security

technologies.

Challenges

Compared with the MES vendors included this IDC MarketScape, Check Point's participation in

independent product evaluations is modest. Check Point is similar to other MES vendors that have

long-term customers using their non-endpoint products. As an incumbent vendor, the need to

participate and promote independent product evaluations from multiple testing firms and through a

variety of tests is not as great in gaining consideration of its MES product.

Check Point's range of attack surface reduction features is modest but not as expansive as a subset of

MES vendors. Support for patch management is currently missing, although we are aware that Check

Point is working with a third-party vendor to address this within the next year.

Consider Check Point When

While Harmony Endpoint is a viable solution for new Check Point customers, it should be an instinctive

consideration for enterprises that are already customers of Check Point's non-endpoint security

products. The reason is twofold. First, Check Point's Harmony Endpoint product has an extensive

range of security functionality and, depending on the other vendors' MES products being considered,

distinctive capabilities. Second, Check Point's broad product portfolio and Infinity-Vision's unified

management supports enterprises in their quest to reduce vendor relationships, lower overhead in

security operations, and improve security readiness.

APPENDIX

Reading an IDC MarketScape Graph

For the purposes of this analysis, IDC divided potential key measures for success into two primary

categories: capabilities and strategies.

Positioning on the y-axis reflects the vendor's current capabilities and menu of services and how well

aligned the vendor is to customer needs. The capabilities category focuses on the capabilities of the

company and product today, here and now. Under this category, IDC analysts will look at how well a

vendor is building/delivering capabilities that enable it to execute its chosen strategy in the market.

Positioning on the x-axis, or strategies axis, indicates how well the vendor's future strategy aligns with

what customers will require in three to five years. The strategies category focuses on high-level

decisions and underlying assumptions about offerings, customer segments, and business and go-to-

market plans for the next three to five years.

The size of the individual vendor markers in the IDC MarketScape represents the market share of each

individual vendor within the specific market segment being assessed.

IDC MarketScape Methodology

IDC MarketScape criteria selection, weightings, and vendor scores represent well-researched IDC

judgment about the market and specific vendors. IDC analysts tailor the range of standard

characteristics by which vendors are measured through structured discussions, surveys, and

interviews with market leaders, participants, and end users. Market weightings are based on user

interviews, buyer surveys, and the input of IDC experts in each market. IDC analysts base individual

©2021 IDC #US48306021e 8

vendor scores, and ultimately vendor positions on the IDC MarketScape, on detailed surveys and

interviews with the vendors, publicly available information, and end-user experiences in an effort to

provide an accurate and consistent assessment of each vendor's characteristics, behavior, and

capability.

Market Definition

Modern endpoint security products protect personal computing devices (PCDs, such as workstations

and laptops) from cyberattacks through the detection of malicious code and behaviors present or

operating within the PCD and then facilitate a counteracting response (e.g., block, remove, or isolate).

Modern endpoint security products contain two detect and response mechanisms differentiated based

on elapsed time and human involvement. Endpoint protection platforms (EPP) reach detection verdicts

and initiate responses in real time and autonomously (i.e., without human involvement). Endpoint

detection and response (EDR) is a second stage of detection and response for cyberattacks that have

evaded EPP detection. With EDR, the time to reach detection verdicts and initiate responses can span

minutes to days. How fast the cyberattack unfolds, its sequence of steps, and its sophistication and

uniqueness are factors that affect the elapsed time in detection and response. Automation and

predefined workflows assist in reducing the elapsed time. Security analysts (humans) are typically

involved, at minimum, to confirm detection and/or authorize response.

LEARN MORE

Related Research

▪ Top Technology Integration Opportunities for Unified Endpoint Management (IDC

#US48266821, September 2021)

▪ Market Analysis Perspective: Worldwide Tier 2 SOC Analytics, 2021 — Where the Puck Is

Going (IDC #US47394921, September 2021)

▪ Market Analysis Perspective: Worldwide Corporate Endpoint Security, 2021 (IDC

#US48208121, September 2021)

▪ IDC's 2021 Ransomware Study: Where You Are Matters! (IDC #US48093721, July 2021)

▪ Which Criteria Rank Highest in the Evaluation of Modern Endpoint Security Products? (IDC

#US48053021, July 2021)

▪ Worldwide Corporate Endpoint Security Forecast, 2021–2025: On a Higher Growth Trajectory

(IDC #US47957021, June 2021)

▪ Worldwide Corporate Endpoint Security Market Shares, 2020: Pandemic and Expanding

Functionality Propelled Market Growth (IDC #US47768021, June 2021)

▪ Insights from IDC's EDR and XDR 2020 Survey: Operational Challenges and Initiatives Are

Abundant (IDC #US47357921, January 2021)

Synopsis

This IDC study represents a vendor assessment of modern endpoint security for enterprises through

the IDC MarketScape model.

"Modern endpoint security products have evolved from point solutions to multifunction security

platforms," according to Michael Suby, research vice president, Security and Trust at IDC. "The

principal reason for this evolution is time. Threat actors are finding and exploiting vulnerabilities and

weakness in security defenses at a faster pace. Conversely, enterprise security professionals have

©2021 IDC #US48306021e 9

zero spare time. They must operate faster and more efficiently across a broader IT estate if they ever

hope to change circumstances from primarily reacting to threats to getting ahead of threats. The

trajectory of modern endpoint security products is reassuring. First by integrating endpoint protection

and endpoint detection and response together, vendors are weaving in additional security and IT

hygiene functionality into a cohesive risk reduction and breach avoidance platform."

About IDC

International Data Corporation (IDC) is the premier global provider of market intelligence, advisory

services, and events for the information technology, telecommunications and consumer technology

markets. IDC helps IT professionals, business executives, and the investment community make fact-

based decisions on technology purchases and business strategy. More than 1,100 IDC analysts

provide global, regional, and local expertise on technology and industry opportunities and trends in

over 110 countries worldwide. For 50 years, IDC has provided strategic insights to help our clients

achieve their key business objectives. IDC is a subsidiary of IDG, the world's leading technology

media, research, and events company.

Global Headquarters

140 Kendrick Street

Building B

Needham, MA 02494

USA

508.872.8200

Twitter: @IDC

blogs.idc.com

www.idc.com

Copyright and Trademark Notice

This IDC research document was published as part of an IDC continuous intelligence service, providing written

research, analyst interactions, telebriefings, and conferences. Visit www.idc.com to learn more about IDC

subscription and consulting services. To view a list of IDC offices worldwide, visit www.idc.com/offices. Please

contact the IDC Hotline at 800.343.4952, ext. 7988 (or +1.508.988.7988) or sales@idc.com for information on

applying the price of this document toward the purchase of an IDC service or for information on additional copies

or web rights. IDC and IDC MarketScape are trademarks of International Data Group, Inc.

Copyright 2021 IDC. Reproduction is forbidden unless authorized. All rights reserved.


Item Type: pdf