NCC Group Taps Qualys to Extend Managed Security Service into Shadow IT Realm
好的,我现在需要帮用户总结一篇文章,控制在100字以内。用户的要求是直接写文章描述,不需要以“文章内容总结”之类的开头。 首先,我快速浏览文章内容。文章主要讲NCC Group与Qualys合作,扩展其攻击面管理服务,以应对影子IT的问题。影子IT指的是未经批准的IT资产,可能带来安全风险。Qualys提供了实时资产发现工具,帮助NCC持续监控IT环境。此外,文章还提到AI时代数据共享的问题和MSSP市场的增长。 接下来,我需要提取关键点:合作双方、服务扩展、解决影子IT、实时监控工具、AI带来的挑战、MSSP市场的增长。 然后,我组织语言,确保在100字以内涵盖这些要点。避免使用复杂的术语,保持简洁明了。 最后,检查字数是否符合要求,并确保信息准确无误。 </think> NCC Group与Qualys合作扩展攻击面管理服务,帮助识别和监控企业环境中的影子IT资产。通过实时资产发现工具,NCC能够更有效地检测未授权设备和数据共享风险。随着AI的普及,企业对MSSP的需求增加,但完全依赖AI仍需人工协调防御。未来需平衡内部任务与外包服务以降低安全风险。 2025-12-19 21:24:54 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

Avatar photo

NCC Group this week revealed it has allied with Qualys to expand the scope of its managed attack surface management (ASM) services to address instances of shadow IT.

Amber Mitchell, lead product manager for ASM at NCC Group, said the managed security service provider (MSSP) already provides a managed attack surface service, but aligning with Qualys makes it simpler to surface IT assets that internal cybersecurity teams are not aware of in their IT environments.

At the core of that capability is a set of real-time asset discovery tools from Qualys that now enable NCC Group to continuously monitor those IT environments, said Mitchell.

Shadow IT has, of course, been a long-standing issue for cybersecurity teams. Many devices, for example, that are connected to corporate networks without approval lack the controls needed to protect the rest of the organization from malware that an end user may have inadvertently downloaded.

That issue is becoming even more problematic in the age of artificial intelligence. End users are now routinely sharing sensitive data with external large language models (LLMs) without fully appreciating how that data might also be used to train the next iteration of that model. Cybersecurity teams will need to move beyond detecting assets to also discovering how data is being shared with external services.

It’s not clear to what degree organizations are now relying on MSSPs to help secure IT environments but there has definitely been an increase largely because most organizations have found it difficult to hire and retain cybersecurity professionals on their own. In theory, AI tools should help close that skills gap but as the tactics and techniques employed by cybercriminals continue to evolve there will still be a need for a human to orchestrate cybersecurity defenses. The upside is there should be less toil for cybersecurity professionals as more tedious tasks are handled by AI agents.

Ultimately, each cybersecurity team will need to determine which tasks to assign to themselves or to an AI versus outsourcing to an MSSP. In fact, according to the research firm MarketsandMarkets, the global managed security services (MSS) market is projected to grow from $39.5 billion in 2025 to $66.8 billion by 2030, representing an 11% compound annual growth rate (CAGR).

The truth is there are very few organizations that have the resources required, even with the help of AI, to fully secure an IT environment on their own. More challenging still, with the addition of AI agents, the overall size of that attack surface that needs to be defended is only going to continue to increase.

Cybersecurity teams heading into the New Year would be if they have not already to rethink their overall strategy. There is never going to be such a thing as perfect security so the focus needs to be on minimizing risks to the organizations as much as reasonably possible. Invariably, achieving that goal is always going to start with understanding the full scope of the IT environment that needs to be defended.

Recent Articles By Author


文章来源: https://securityboulevard.com/2025/12/ncc-group-taps-qualys-to-extend-managed-security-service-into-shadow-it-realm/
如有侵权请联系:admin#unsafe.sh