Firewall Automation Best Practices and How Opinnate Upgrades Security Management

In the contemporary fast-paced cybersecurity world, managing firewalls manually is no longer enough. Networks are growing more complex, threats evolve by the hour, and security teams are under constant pressure to maintain visibility and control. Firewall automation has become a vital strategy to strengthen security, remove repetitive manual work, and ensure consistent policy enforcement across all environments. Further, in this blog, you will gain insight on what firewall automation really means, why it matters, the best practices to follow, and how Opinnate brings a new level of intelligence and efficiency to modern network security. What Is Firewall Automation? Firewall automation refers to the use of software and intelligent tools to automate the process of managing, configuring, and monitoring firewalls. Instead of relying on manual rule updates and policy changes, automation ensures that firewalls operate according to predefined policies and templates across multiple devices and vendors. With automation, organizations no longer struggle with inconsistent configurations or time consuming manual reviews. Automated tools streamline everything from rule creation to policy updates, making it easier to maintain secure and well optimized environments. Why Firewall Automation Is Essential Today? Today’s cybersecurity challenges demand speed, accuracy, and real time responsiveness. Firewall automation provides all three by transforming the way organizations handle their security operations. Stronger Security with Fewer Errors Human error remains one of the most common causes of firewall misconfigurations. Automation ensures policies stay up to date and consistent while minimizing mistakes that could expose the network to attacks. Faster Threat Detection and Response Automated systems identify threats and unusual activity instantly and can trigger responses far faster than manual processes. Better Resource Utilization Instead of spending hours reviewing rules and deploying changes, security teams can focus on strategic, high value work. Firewall Automation and Rule Analysis: How They Differ Automation and rule analysis serve different purposes but work best when used together. Automation handles the execution of changes and policy enforcement at scale. Rule analysis ensures the rules remain efficient, organized, secure, and relevant. Combining the two creates a strong, agile, and well maintained security posture. Automation reacts quickly to operational needs, while analysis maintains long term policy quality. What Can Be Automated? A wide range of tasks can be fully or partially automated, including: Creation and management of firewall rules Policy management and compliance validation User access authorization Threat detection workflows Firewall log review and reporting Configuration backups and updates These automated functions reduce risk, speed up operations, and create a more controlled security environment. Best Practices for Effective Firewall Automation To get the most value from firewall automation, organizations should follow these key practices: Define Clear and Unified Policies Establish organization wide rules for how firewall changes are created, reviewed, and updated. Consistency ensures better long term security. Test Every Change Before Deployment A testing environment helps prevent disruptions and ensures new rules do not negatively impact production systems. Use Templates and Standardized Configurations Templates simplify large scale policy management and reduce inconsistencies across devices and vendors. Monitor and Audit Changes Continuously Visibility is essential. Monitoring tools track all configuration changes and highlight unusual or non compliant updates. Automate Routine Tasks Aggressively Automate processes such as rule creation, approval, modifications, and removal to reduce manual effort and human error. Apply Version Control Version control improves traceability and makes it easy to roll back misconfigurations. Integrate with Other Security Tools Linking automation tools with SIEMs, vulnerability scanners, and other systems enhances threat detection and policy enforcement. The Real Gains of Firewall Automation Significant Time Savings and Higher Operational Efficiency Manual rule reviews and multi vendor firewall management consume countless hours. Automation enables security teams to: Remove manual auditing by automatically analyzing rules Accelerate policy updates with guided workflows Deploy rule changes faster with automated validation The result is a leaner and far more productive security team. Enhanced Security and Reduced Exposure to Risks Misconfigurations often lead to security breaches. Automation helps prevent this by: Identifying risky or overly permissive rules Detecting unused or redundant rule entries Maintaining policy consistency across the entire network With automated checks, organizations significantly strengthen their security posture. Improved Compliance and Simplified Auditing Compliance with ISO 27001, PCI DSS, NIST, and GDPR becomes far easier with automation. Tools like Opinnate can: Generate audit ready compliance reports Enforce standards consistently Flag non compliant rules with recommended fixes This reduces audit frustration and minimizes the risk of penalties. Faster Incident Response and Better Threat Mitigation Every second counts during a cyberattack. Automated systems enhance response speed by: Offering real time visibility Adjusting policies proactively based on detected threats Quickly identifying misconfigurations that may worsen incidents This reduces downtime and helps organizations stay resilient under pressure. How Opinnate Upgrades Firewall Automation Opinnate is designed to transform the way enterprises manage, analyze, and enforce their network security policies. It provides intelligent automation, deep rule analysis, and centralized management across multi vendor environments. Here is how Opinnate stands out. Intelligent Firewall Rule Analysis Opinnate continuously reviews rules across all firewalls and identifies: Unused or stale rules Conflicting or redundant rules Overly permissive policies Rules that create performance or security risks By offering clear and actionable insights, Opinnate keeps firewall policies optimized at all times. Automated Policy Enforcement and Change Management Opinnate removes the complexity of manual changes through: Automated configuration updates Streamlined approval workflows Complete change tracking with version history Teams gain speed, accuracy, and a clean audit trail. Seamless Multi Vendor Integration Opinnate works with a variety of leading firewall providers including: Fortinet Check Point Palo Alto Networks Cisco Sophos No extra controllers or managers are required. Everything is handled from one unified platform. Real Time Compliance Monitoring Opinnate automates compliance tasks by offering: Continuous assessments Instant security reporting Recommendations to enforce compliance Organizations maintain regulatory alignment with almost zero manual intervention. Risk Based Policy Recommendations Opinnate goes beyond detection. It recommends the best actions using: Real time traffic insights Industry standard best practices Risk scoring and impact prediction This helps teams fix vulnerabilities before they evolve into threats. Centralized and
Firewall Rule Analysis: Importance and Challenges

Firewall rule analysis is the process of reviewing and analyzing the rules in a firewall to ensure that they are effective and meet the security requirements of an organization. Firewalls are network security devices that are used to prevent unauthorized access to a network or a system. Firewall rules define what traffic is allowed or denied by the firewall. Firewall rule analysis involves examining these rules to ensure that they are correct, complete, and appropriate for the network environment. The goal of rule analysis is to identify any security vulnerabilities or misconfigurations in the firewall rules. This can include identifying rules that are too permissive, rules that conflict with each other, or rules that are no longer necessary. Firewall analysis can also help to identify areas where the firewall rules can be optimized to improve network performance. Importance of Firewall Rule Analysis Firewall rule analysis is of paramount importance in ensuring the robustness of an organization’s cybersecurity infrastructure. These analyses involve the careful examination of firewall configurations and rules to identify vulnerabilities, misconfigurations, and potential security gaps. Here’s why it should be a top priority: Challenges in Rule Analysis In today’s dynamic and perilous digital environment, rule analysis is not just a good practice; it’s a necessity for safeguarding sensitive data, maintaining compliance, and fortifying your cybersecurity defenses. Firewall rule analysis can be a time-consuming and complex task, particularly in large networks with a significant number of devices and complex configurations. There are various tools and techniques available to assist with rule analysis, including firewall log analysis, automated firewall rule analysis tools , and manual rule analysis techniques. Firewall analysis can be challenging due to several reasons. Some of the difficulties in rule analysis are: Overall, firewall rule analysis requires a deep understanding of the network architecture, security policies, and the intent of the rules. It can be a time-consuming and challenging task that requires attention to detail, patience, and expertise.
Firewall Change and Best Practices for Change Management

Change management is an important part of any IT organization. To make people about what will be happening, to make it in a controlled manner and decrease unplanned downtime every organization must be working on a good change management process. As to firewalls, firewalls are an essential security tool for protecting networks and systems from unauthorized access and malicious activity. Implementing and managing firewall changes can be a complex task, and there are some best practices that organizations can follow to ensure their firewalls are effective and secure: By following these best practices, organizations can effectively manage their firewall changes and maintain a strong security posture.
Firewall Audit – The Control of Firewall Operation

A firewall audit is a process that evaluates the effectiveness and efficiency of a firewall implementation in protecting an organization’s network from unauthorized access and other security threats. A firewall is a network security device that monitors and controls incoming and outgoing network traffic based on predetermined security policies. During a firewall audit, an auditor typically evaluates the configuration, policies, and logs of the firewall to ensure that it is properly configured and functioning as intended. The audit aims to identify any weaknesses or vulnerabilities in the firewall implementation that could be exploited by attackers to gain unauthorized access to the network. The audit may involve reviewing documentation of the firewall configuration and policies, analyzing firewall logs for signs of unauthorized access or other security incidents, and conducting vulnerability assessments or penetration testing to identify potential weaknesses in the firewall implementation. The Importance of Firewall Audit for Firewall Control Firewall control through audits is paramount for maintaining robust cybersecurity. Audits provide a systematic examination of firewall configurations, rule sets, and access controls to ensure they align with security policies and compliance standards. By regularly scrutinizing firewall settings, organizations can identify vulnerabilities, unauthorized access, or misconfigurations that may expose them to cyber threats. This proactive approach not only strengthens the network’s security posture but also ensures that it evolves with emerging threats. Additionally, firewall audits are essential for meeting regulatory requirements, instilling confidence in stakeholders, and preventing costly data breaches, making them a cornerstone of effective cybersecurity practices. The goal of a firewall audit is to provide an objective assessment of the firewall implementation’s security posture and to identify areas for improvement. By conducting regular firewall audits, organizations can ensure that their networks are protected against evolving security threats and that their sensitive data and assets are secure. Here are some additional details regarding firewall audits: In summary, a firewall audit is a comprehensive assessment of an organization’s firewall implementation that aims to identify potential security risks and vulnerabilities, ensure compliance with regulations and best practices, and provide recommendations for improvement. By conducting regular firewall audits, organizations can maintain the security and integrity of their network infrastructure and protect against evolving security threats.
Firewall Analyzers in Modern Networks

Firewall analyzers are one of the essential components in modern networks. They are important tools for managing and maintaining the security of network firewalls. They provide detailed information and insights into firewall activity, which can help network administrators identify potential security threats and vulnerabilities. Here are some specific reasons why firewall analyzer in modern networks is necessary: Network visibility: They provide visibility into network traffic by monitoring and analyzing firewall logs. This information is critical for identifying potential threats, as well as troubleshooting network issues. Firewall analyzers play a pivotal role in enhancing network visibility. These tools monitor and scrutinize network traffic, providing in-depth insights into data flows, user activity, and potential security threats. By analyzing firewall logs and traffic patterns, they offer a clear view of network behavior, helping organizations identify anomalies, unauthorized access attempts, and vulnerabilities. This heightened visibility empowers administrators to make informed decisions, enforce security policies, and respond promptly to emerging threats, ultimately bolstering network security and overall operational efficiency. Threat detection: They can help detect and block suspicious activity, such as unauthorized access attempts, malware downloads, and phishing attacks. By monitoring firewall logs in real-time, administrators can quickly identify and respond to potential threats before they can cause significant damage. Compliance: They can help organizations comply with regulatory requirements and industry standards by providing detailed reports and audits of firewall activity. This information can be used to demonstrate compliance with regulations such as PCI DSS, HIPAA, and GDPR. Firewall analyzers play a vital role in ensuring compliance with industry standards and regulations. These tools continuously monitor firewall configurations and traffic, checking them against compliance benchmarks such as PCI DSS, HIPAA, or GDPR. By generating detailed reports and alerts, firewall analyzers help organizations identify and rectify non-compliance issues promptly. This proactive approach not only avoids potential fines and legal consequences but also instills trust among customers and partners by demonstrating a commitment to meeting stringent security and privacy requirements. Optimization: Firewall analyzers can help optimize firewall performance by identifying and eliminating unnecessary rules and policies. By streamlining firewall configurations, organizations can improve network performance and reduce the risk of security incidents. Overall, they are essential tools for maintaining the security and performance of network firewalls. They provide valuable insights into firewall activity, which can help organizations identify and respond to potential threats, comply with regulatory requirements, and optimize network performance. Firewall logs: Analyzers can monitor and analyze firewall logs to provide insight into network activity. This includes information such as source and destination IP addresses, port numbers, protocols, and the type of traffic (e.g., web, email, file transfer). How Network visibility can be achieved with firewall analyzer Traffic analysis: They can perform deep packet inspection (DPI) to analyze the content of network traffic. This can help identify the applications and services that are being used on the network, as well as detect and block suspicious activity. Network mapping: Analyzers can map out the network topology and provide insight into the devices that are connected to the network. This includes information such as IP addresses, device types, and operating systems. User behavior: They can monitor user behavior and identify patterns of activity that may indicate security threats. For example, they can detect multiple failed login attempts or unusual access to sensitive data. By leveraging these capabilities, firewall analyzers can provide comprehensive visibility into network activity. This information can be used to identify potential security threats, troubleshoot network issues, optimize network performance, and comply with regulatory requirements. Firewall Analyzer vs Firewall Automation Solutions Firewall analyzers and firewall automation solutions are two different types of tools that serve different purposes in network security management. Analyzers are designed to provide visibility into firewall activity and help organizations understand what is happening on the network. On the other hand, firewall automation solutions focus on automation manual activities that is going on for firewall management. While they both serve the purpose of managing firewalls, they have different functionalities and benefits. Here are some differences between firewall analyzers and firewall automation solutions: Functionality: They are primarily used for monitoring and analyzing firewall activity, while firewall automation solutions are used for automating firewall management tasks such as rule creation and configuration updates. Time and resource savings: Firewall automation solutions can save time and resources by automating repetitive firewall management tasks. This can free up network administrators to focus on other important tasks. Analyzers, on the other hand, provide valuable insights into network activity but require manual analysis and interpretation. Complexity: Firewall automation solutions tend to be more complex than analyzers because they involve automating complex tasks such as rule creation and configuration updates. Analyzers are generally easier to set up and use. Compliance: Both analyzers and firewall automation solutions can help organizations comply with regulatory requirements and industry standards. Firewall analyzers provide detailed reports and audits of firewall activity, while firewall automation solutions can ensure that firewalls are configured according to best practices and compliance standards. Overall, firewall analyzers in modern networks and firewall automation solutions are complementary tools that can be used together to manage network firewalls. Analyzers provide valuable visibility into network activity, while firewall automation solutions can save time and resources by automating repetitive tasks. Depending on the needs of the organization, one or both of these tools may be used in conjunction with each other.
Security Automation – The Absolute Need

With the increasing number of cyber attacks and security breaches, it has become essential to have security automation, automated security solutions that can detect, prevent, and respond to threats in real-time. Security automation helps organizations improve their security posture by reducing the time and effort required to detect and respond to security incidents. It also allows security teams to focus on more strategic tasks, such as threat hunting and analysis, rather than routine and repetitive tasks. Furthermore, automation can provide consistency and accuracy in security operations, as machines are less prone to human errors and can perform tasks faster and more efficiently. This can help organizations meet compliance requirements and reduce the risk of data breaches and other security incidents. There are several types of security automation solutions that organizations can use to improve their security posture. Here are some common examples: Security Information and Event Management (SIEM): SIEM solutions automate the collection, analysis, and correlation of security events across an organization’s IT infrastructure to detect and respond to security incidents in real-time. Vulnerability Scanners: Vulnerability scanners automate the discovery of vulnerabilities in an organization’s IT infrastructure, including network devices, servers, and applications. They can identify security weaknesses and provide recommendations for remediation. Security Orchestration, Automation, and Response (SOAR): SOAR solutions automate incident response processes by integrating various security tools and workflows. They can help security teams to respond to security incidents faster and more efficiently. Identity and Access Management (IAM): IAM solutions automate the management of user identities and access privileges across an organization’s IT infrastructure. They can help to ensure that only authorized users have access to sensitive data and resources. Endpoint Detection and Response (EDR): EDR solutions automate the detection and response to security threats on endpoints, including desktops, laptops, and mobile devices. They can help organizations to detect and respond to cyber threats before they can cause significant damage. Cloud Security Automation: Cloud security automation solutions automate the monitoring and management of security controls across an organization’s cloud infrastructure. They can help organizations to secure their data and applications in the cloud. Data Loss Prevention (DLP): DLP solutions automate the monitoring and prevention of data loss across an organization’s IT infrastructure. They can help to ensure that sensitive data does not leave the organization through unauthorized channels. Firewall Management: Firewall management solutions automate the management of firewall policies across an organization’s network devices. They can help to ensure that firewalls are properly configured and up-to-date, reducing the risk of unauthorized access and data breaches. Network Access Control (NAC): NAC solutions automate the management of network access policies and authentication across an organization’s IT infrastructure. They can help to ensure that only authorized devices and users can access the network. Incident Response Management: Incident response management solutions automate the management of security incidents from detection through resolution. They can help organizations to respond to incidents faster and more efficiently, reducing the impact of cyber attacks. Threat Intelligence: Threat intelligence solutions automate the collection and analysis of threat data from various sources, including threat feeds, social media, and the dark web. They can help organizations to identify and respond to emerging threats before they can cause significant damage. In summary, there are many different types of security automation solutions available, each designed to address specific security challenges. By implementing these solutions, organizations can improve their security posture, reduce the risk of data breaches and other security incidents, and free up security teams to focus on more strategic tasks.
What Are The Things To Be Done On Firewalls

Firewalls are devices used for segmentation of networks and it is a basic cyber security product that every entity has in their infrastructure. For this post we have asked ChatGPT what additional tasks that must be done on a firewall apart from rule creation. See how it has responded to this question. Here are some common tasks that are typically performed on a firewall: So, it is clear that there are several important tasks to be done on firewalls analysis. If you have a chance to automate policy change activity or any similar activity that is repeatitive that certainly makes sense. Otherwise, you need to have a larger team that would handle that much activity. Frequently Asked Questions 1. What are the essential tasks involved in firewall management? Effective firewall management includes rule creation, policy configuration, monitoring, logging, software updates, rule optimization, performance tuning, compliance checks, and regular security reviews to keep networks secure and efficient. 2. Why is regular firewall maintenance important? Regular firewall maintenance helps identify outdated or risky rules, improve network performance, reduce security vulnerabilities, ensure regulatory compliance, and protect against evolving cyber threats. 3. How can firewall management be automated? Firewall management can be automated by using a Network Security Policy Management (NSPM) solution to streamline policy changes, automate rule analysis, optimize firewall rules, generate compliance reports, and reduce manual administrative tasks. 4. What security features should a modern firewall include? A modern firewall should support access control, VPN connectivity, intrusion detection and prevention, application control, URL and content filtering, network segmentation, traffic monitoring, encryption, logging, and high availability. 5. How does Opinnate simplify firewall management? Opinnate automates firewall policy management by providing centralized visibility, rule analysis, policy optimization, change automation, compliance reporting, and continuous monitoring, enabling IT teams to manage complex firewall environments more efficiently.
Corporate Security Policy Need

Today every organization has a corporate security policy that is developed in years. The corporate security policy is a must have any organization follow and keep up to date. The implementation of corporate security policy on firewall devices is one of the major needs that must be fulfilled since firewalls are devices that opens and closes door to any service or application to anywhere. However, the following of the policy or keeping security policies on firewalls in parallel with it is not so easy. In this post we will be dealing with the reasons of this issue. To start with, firewalls must be managed in a segregation of duties principle. The application of firewall policies and the decision of which policies are allowed or not must be handled by different teams or employees reporting to a different manager. With the help of this segregation, operation teams be mentored or have a control over what they are doing on firewalls. This segregation of duties principle can not be applied on all the corporations and generally the people managing firewalls are the same with the people having the responsibility of checking corporate security policy. This is a condition that may lead to some kind of blindness and operation teams may apply policies on behalf of their needs or choice. This uncontrolled condition may lead to firewall rules that is not accordance with the decided corporate policies. As to companies having the segregation of duties already in place there are other difficulties exist. First of all, checking or approving security policies if they have accordance is some kind of operational activity since it is repetitive. One will do the same controls on the firewall access tickets for every ticket. Since this is an operational activity although there is a need of higher experience level, generally the people assigned to this activity are junior level engineers. This low level security experience may lead to decisions that are not appropriate or wrong. Apart from that, since approval duty is somehow an operational activity the people doing this activity have a potential of making mistakes of what they are doing anytime. Also, the turnover rate in security teams is quite high. So, for every newcomers to the teams there is a need of learning what kind of infrastructure exist, what business they are doing and surely what corporate security policies there are. It is a tedious process for the existing employees also. And surely there is a potential of making mistakes for every newcomer dealing with tickets. Effective implementation of corporate security policies on firewalls is pivotal in safeguarding an organization’s digital assets. These policies encapsulate the organization’s cybersecurity objectives, defining the rules and regulations that govern network access, data sharing, and overall information protection. Successfully translating these policies into firewall configurations demands meticulous attention to detail. The alignment of security policies with firewall rules ensures that only authorized users and traffic can traverse the network, minimizing the attack surface and potential vulnerabilities. Regular audits and updates are essential to ensure that security policies remain current and aligned with emerging threats and changing business needs. The interplay between well-crafted security policies and accurately enforced firewall rules forms a robust defense against cyber threats, enabling organizations to maintain a proactive security posture and mitigate risks effectively. To sum up, corporate security policy implementation on the firewalls and keeping it in accordance with it is a need. In placed segregation of duties is a must, however it is not a guarantee since it is thought to be an operational activity and is treated accordingly. There must be a mechanism in place to make corporate security policies applied and kept on firewalls.
Security Operations to be Handled in a Different Way

With the arrival of internet, we started working with security technologies and since that time everything has changed. Cloud adoption is increasing each day, firewall is not the only protection mechanism against threats, each year we meet with new threats and technologies, there are IT service companies managing security products for their customers, there are several compliances to comply with. How about security operations? When we talk about security operations it generally means administration of security devices. Firewalls, proxy, IPS, WAF are some of the devices that is managed by security operation teams. These teams do maintenance activities for these devices, also they need to resolve tickets coming from the ticketing system related with these devices. Security administration was something like that 20 years before except the addition of new devices to the system. Daily routines and effort needed activities must somehow need to be changed. Security administrators need to focus on advance capabilities of the systems they are managing and advance more on their knowledge. To be able to do that they must follow new publications and new technologies, test new technologies in their lab environment. They need to focus on Improving the infrastructure and harden it and also make extensive testing before making any changes to the system. With the daily ongoing operations although it is necessary it is not possible to arrange time for these activities. So, daily routines, operational tasks and all other things that can be automated must be automated. We are not in an era that configuration backups of the devices are managed manually for example. We are using systems that can do it daily for us. Similarly, policy changes are also among the activities that can easily be handled by specialized products. Periodical analysis and hardening activities can also be managed in a way that operation teams not spend time on with the aid of same kind of systems. If an activity that is done manually can easily be written down step by step, then it can be said that it can also be done automatically by the aid of any system, so the approach to this kind of any task must be to automate it. The realm of security operations places a significant burden on IT teams, particularly when it comes to complex tasks like firewall management. In addition to their core responsibilities of maintaining IT infrastructure, IT teams are tasked with configuring, monitoring, and updating firewalls to thwart potential cyber threats. This burden is amplified by the constant evolution of attack techniques and the need for stringent policy enforcement. Manual firewall management consumes valuable time and resources, diverting IT personnel from other critical duties. Furthermore, misconfigurations or delays in updating firewall rules can inadvertently open vulnerabilities in the network. As organizations grow and networks become more intricate, this burden becomes even more challenging to bear. To address this, IT teams are turning to automation and advanced management solutions that not only streamline firewall operations but also free up IT personnel to focus on strategic initiatives and proactively addressing security concerns. Cyber defense or cyber monitoring activities are also security operations that not include administration of security devices, instead including analysis of events generated on the system. These events are managed in tiered levels of experts, however in the first layer it is needed to use orchestration solutions to triage the events going on. It is a triage activity automation, otherwise to be done by people. Security operations in nowadays is composed of administration of many devices. Manual routine activities on these devices need to be automated to make use of qualified employees in an optimum way. In a way that enable them advance more on their security knowledge.
New Security Trends and Technologies

According to Gartner the digital footprint of companies expanded so much during pandemic, so this introduced us with new network security challenges, security trends and new kind of attacks. These events lead companies to reframe their security practice, rethink on technology and find ways to respond to new threats. To start with, the increased scale and complexity of digital organizations change the approach of the obsolete centralized security management. It is a tendency to decentralize security decisions to different part of the organization. That means different security leaders to lead different part of the organization to make this management more effective. Social engineering based successful security attacks and decisions made by business technology leaders has changed the security awareness programs effectiveness. Security leaders must invest in security behavior and culture programs. When thinking about technology shift, it is the technology itself, the complexity of security infrastructure is increasing when new technologies arrive each year. However, coping with the increased complexity is not preferred with the restricted human resources. During the last 10 years we have witnessed that IPS and proxy kind of technologies lost market share in total security market due to new generation firewall and UTM solutions. It is a widespread tendency nowadays to use IPS on firewall devices even in highly regulated and attacked industries like finance companies. Consolidated security technology usage is still a need and will be in place in the following years with the increasing cloud adoption and increasing attack surface. Companies start working in hybrid environments; different public clouds, on-prem and DRC sites usage, branches and home office adoption necessitate usage of security implementation on each site. SASE and XDR are the solutions that most companies are planning to use in the following years for the sake of this security consolidation need. With the expanded digital footprint of companies the visibility of companies decreased and there are now blind spots in the environment that is targeted by attackers. During the last year two changes in the attack landscape became more obvious. The first one is exploitation of identity. Credential misuse leading to increase in security incidents. Indeed, more complicated attacks target identity system itself. This may cause the identification of the attack itself. The second important attack domain is the digital supply chain. Vulnerabilities embedded in digital supply chains are often difficult to detect and thousands of applications or devices simultaneously be impacted. In summary, new security trends with the increased cloud adoption and digital footprint of companies and with limited resources it is now necessary to change the effectiveness of security leadership by segmentation of the organization, to consolidate the security technologies and cope with new kind of attacks targeting identity and supply chains.