Changing technical requirementsEntrenched systems
In 2012 security teams protecting employee computers and servers relied on antivirus, most often from McAfee or Symantec, which compared each file with the signatures of malware already catalogued CY1 CS2. New malware and fast-changing variants outran the catalog, so attacks the signatures had not seen got through, and teams spent their effort investigating compromises afterward CY1. The products could also misfire: in 2010 a faulty McAfee update flagged a core Windows file as malicious and locked up Windows XP machines CS8. Replacing the incumbent was still a hard sell; Dmitri Alperovitch, who had come out of McAfee, compares it to IBM, which no one was fired for buying CS2. Teams wanted protection that stopped new threats before they ran, without blocking legitimate software or burying them in alerts CY1.