{"id":3654,"date":"2024-05-20T17:14:45","date_gmt":"2024-05-20T22:14:45","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/google-pitches-workspace-as-more-secure-option-to-microsoft-email-citing-csrb-report"},"modified":"2024-05-20T17:14:45","modified_gmt":"2024-05-20T22:14:45","slug":"google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/20\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report\/","title":{"rendered":"Google Pitches Workspace as Microsoft Email Alternative, Citing CSRB Report"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt2aff2bc2dd98879a\/664bb11799440869cdebe6b1\/workspace_monticello_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Google is using a recent report from the US Cyber Safety Review Board (CSRB) that was critical of Microsoft&#8217;s security practices to make a case for its own Google Workspace suite of cloud-hosted email and office productivity apps.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In two separate blogs \u2014 and without once referring to Microsoft by name \u2014 company executives cited the CSRB report as reason why enterprise organizations should consider moving away from Microsoft Exchange Online hosted email to Google Workspace.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The company has launched a new <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/workspace.google.com\/blog\/identity-and-security\/securealternative\" rel=\"noopener\">Secure Alternative Program<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> with special pricing on its Google Workspace Enterprise Plus offering and on Mandiant&#8217;s incident response service for organizations that make the switch. Google will also offer migration and change management support for enterprises that need help transitioning from Exchange Online to Workspace.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Risks of a Monoculture\">The Risks of a Monoculture<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;For years, security experts have warned of the risks of government overreliance on a single technology vendor,&#8221; Google Cloud senior director of global risk and compliance Jeanette Manfra and Charley Snyder, the company&#8217;s head of security policy, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blog.google\/technology\/safety-security\/csrb-report-google-recommendations\/\" rel=\"noopener\">wrote this week<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &#8220;The recent U.S. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/resources-tools\/groups\/cyber-safety-review-board-csrb\" rel=\"noopener\">Cyber Safety Review Board (CSRB) report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> detailing significant security failures and systematic weaknesses in a longstanding vendor reaffirms these risks.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The report that Google has brandished in its new campaign is based on the CSRB&#8217;s investigation of two incidents over the past year where two separate nation-state actors breached Microsoft&#8217;s Exchange Online environment. One of the intrusions happened last June and involved Chinese cyberespionage group <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/chinese-apt-cracks-microsoft-outlook-emails-government-agencies\" rel=\"noopener\">Storm-0558 gaining access to email accounts<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> belonging to some 25 entities. The victims included several senior US government officials managing US-China relations, prompting the CSRB to describe the attackers as striking the &#8220;espionage equivalent of gold.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The second intrusion happened last November and involved Russia&#8217;s &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/microsoft-falls-victim-russian-midnight-blizzard-cyberattack\" rel=\"noopener\">Midnight Blizzard<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8221; gaining access to email accounts belonging to Microsoft executive leadership and also to some source code repositories and other internal systems. Microsoft disclosed the email breach in January and the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/russia-sponsored-cyberattackers-infiltrate-microsoft-s-code-base\" rel=\"noopener\">source code leak two months later<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in March.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cascade of Security Failures\">Cascade of Security Failures<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The CSRB report blamed a &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/feds-microsoft-clean-up-cloud-security-act\" rel=\"noopener\">cascade of security failures<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8221; at Microsoft for the breaches, concluding that &#8220;Microsoft&#8217;s security culture was inadequate and requires an overhaul, particularly in light of the company&#8217;s centrality in the technology ecosystem and the level of trust customers place in the company to protect their data and operations.&#8221; In response, Microsoft has promised to make <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/microsoft-will-hold-executives-accountable-for-cybersecurity\" rel=\"noopener\">sweeping organizational changes<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and hold senior leadership directly accountable for meeting cybersecurity goals.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A Microsoft spokesman pointed to that effort in response to a Dark Reading request for comment. &#8220;Microsoft is making security our top priority, above all else,&#8221; the spokesman said in an emailed comment. &#8220;Our <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-cloud\/resources\/secure-future-initiative\" rel=\"noopener\">Secure Future Initiative (SFI)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> brings together every part of Microsoft to advance cybersecurity protection across our platforms and products, benefiting customers around the world, including commercial and government enterprises, small businesses and individuals.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Rik Turner, an analyst with Omdia, perceives Google&#8217;s new offering as a bid to try to wean customers away from Microsoft while memories of the CSRB report are still fresh. &#8220;This move by Google is an opportunistic one on the coattails of the CSRB&#8217;s report, and why not?&#8221; Turner asks. &#8220;While Google has some very good and often innovative technology, the fact is the company still is not the obvious choice for enterprise organizations on many fronts, and certainly not in office productivity,&#8221; he adds. &#8220;So why not grab some of the media attention on what the CSRB has said, and potentially even drive some more?&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"An Opportunistic Move\">An Opportunistic Move<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Google&#8217;s pitch to customers with its new campaign is that Workspace offers a safer alternative to Microsoft&#8217;s email because it is cloud native and architected with modern threats in mind, and that organizations won&#8217;t have to deal with desktop clients and instances of on-premises software that they need to patch and maintain. &#8220;This means a smaller attack surface and less work for your IT teams,&#8221; Google vice president of product management Yulie Kwon Kim said. &#8220;The fully cloud hosted model also means organizations do not have to worry about securing emails and files stored on end user devices.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Omdia&#8217;s Turner says the general market perception is that Google has garnered some success with its Google Workspace offering. But most of that success has largely been confined to the cloud-native start-up community rather than mainstream corporate America. Google will find that market harder to crack because of Microsoft&#8217;s near ubiquity in that segment and the fact that it has been there for decades.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There&#8217;s also the issue of Google having its own security problems, Turner says, pointing to a security vendor&#8217;s report last year on a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/vendor-claims-design-flaw-in-google-workspace-is-putting-organizations-at-risk\" rel=\"noopener\">design weakness in Workspace<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that Google denied was a weakness. &#8220;It&#8217;s too early, in my opinion, to gauge how effective the combination of the CSRB report and this Google initiative will be in prising major customers away from Microsoft, but I am somewhat skeptical,&#8221; he notes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Guy Rosenthal, vice president of product at DoControl, says that Google&#8217;s arguments about the risks associated with using a single vendor for operating systems, email, office productivity tools, and security has merit. But that&#8217;s a risk organizations take when using many major technology vendors. &#8220;Take, for example, a company utilizing Google&#8217;s ecosystem,&#8221; Rosenthal says. &#8220;They might use Google Chrome to access all Google services, effectively creating a monoculture similar to Microsoft&#8217;s environment.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At the same time, he says Google&#8217;s claim of a more secure-by-design offering, leveraging AI-based defenses and robust threat data analytics, is compelling. The reduced need for on-premises software indeed minimizes the attack surface, he admits, but adds, &#8220;However, it is essential to consider that no system is impervious. Both Google and Microsoft have experienced security incidents, and both invest heavily in securing their environments.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/google-pitches-workspace-as-more-secure-option-to-microsoft-email-citing-csrb-report\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google is using a recent report from the US Cyber<\/p>\n","protected":false},"author":12,"featured_media":3655,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3654","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?fit=1000%2C510&ssl=1",1000,510,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?fit=300%2C153&ssl=1",300,153,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?fit=640%2C327&ssl=1",640,327,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?fit=640%2C326&ssl=1",640,326,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?fit=1000%2C510&ssl=1",1000,510,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?fit=1000%2C510&ssl=1",1000,510,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?fit=1000%2C510&ssl=1",1000,510,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?resize=825%2C510&ssl=1",825,510,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/google-pitches-workspace-as-microsoft-email-alternative-citing-csrb-report.jpg?fit=1000%2C510&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3654","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3654"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3654\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3655"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3654"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3654"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3654"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}