Google Cloud’s Chronicle will now offer curated threat detection as part of its analytics initiative in the Chronicle SecOps suite. Credit: Magdalena Petrova Google Cloud Wednesday announced the general availability of what it calls “curated detection” for its Chronicle security analysis platform. The new detection feature leverages the threat intelligence that Google gains from protecting its own user base into an automated detection service that covers everything from ransomware, infostealers and data theft to simple misconfigured systems and remote access tools.The new product will integrate authoritative data sources like MITRE ATT&CK to help organizations contextualize and better understand potential threats, as well as providing constantly updated threat information from Google’s own security team.Google Cloud has made two recent security updates to its own products—including built-in DDoS protection and API security—but it’s important to recognize that, while curated detection builds on the company’s in-house expertise, Chronicle is very much a product to be sold to everyone, including non-Google Cloud customers. Chronicle’s new features don’t make it a full-fledged managed detection and response (MDR) service—where vendors manage detection and response for customers in their infrastructure—but the market for threat detection in general is growing, according to Gartner vice president and distinguished analyst Neil MacDonald. Gartner projects the MDR market to grow at 49% year-over-year, on an already sizeable $2.5 billion in annual revenue. The technology’s popularity is largely a function of the ever-increasing complexity of modern security, and the increasing knowledge gap among in-house security teams, he says.“Every organization is under attack, every organization wants to do a better job detecting and responding to these events and every organization struggles with finding staff to handle it,” MacDonald says. “So the idea of turning to a third party to handle it on their behalf makes a lot of sense.” The announcement for the revamped Chronicle announcement is also likely a response to rival Microsoft, which introduced a similar set of managed detection and response services earlier this year. With independent companies like CrowdStrike, Arctic Wolf and Red Canary making major headway in the sector, it’s no surprise that powerhouses like Microsoft and Google want to follow suit and claim a piece of the pie.“It’s important to understand that when Google brought in Chronicle [out of its X research subsidiary], their intention was to enter the broader security information and event management space to compete with Microsoft’s Sentinel.”(This story has been updated to clarify the scope of Chronicle’s curated detection service.) Related content news analysis Thousands of servers hacked due to insecurely deployed Ray AI framework Ray deployments are not intended to connect to the internet, but AI developers are doing so anyway and leaving their servers vulnerable. By Lucian Constantin Mar 28, 2024 4 mins Vulnerabilities news Cisco: Security teams are ‘overconfident’ about handling next-gen threats Tooling complexity and generative AI may harm many companies’ security posture. By Jon Gold Mar 28, 2024 3 mins Security brandpost Sponsored by Microsoft Security Iran’s evolving influence operations and cyberattacks support Hamas Understanding how Iranian and Iran-affiliated threats traverse 3 distinct phases may help identify vulnerabilities and attack vectors. By Microsoft Security Mar 28, 2024 5 mins Security news Report suggests cybersecurity investment, board involvement linked to better shareholder returns The study by Diligent and Bitsight points to advanced security and strong risk or audit committees as good predictors of an enterprise’s financial success. By sascha _brodsky Mar 28, 2024 4 mins CSO and CISO Business Business IT Alignment PODCASTS VIDEOS RESOURCES EVENTS SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe