Todos los fabricantes

Vendor lineage

Trend Micro - the vendor that buys the flaws it defends against

Founded on a dongle, run by a co-founder since 2005, owner of the Zero Day Initiative - and the source of a 2005 update that did more damage in ninety minutes than the worm it targeted.

Trend Micro is a Japanese-American security company founded in Los Angeles in 1988 and headquartered in Tokyo, known for endpoint and cloud security, the Zero Day Initiative and the Pwn2Own contests.

Trend Micro began in Los Angeles in October 1988 with the proceeds of a copy-protection dongle, founded by Steve Chang, his wife Jenny Chang and her sister Eva Chen. It moved to Taipei almost at once and, after taking over a Japanese software firm in 1992, to Tokyo, where it has been listed since 1998. The early growth came through other people's channels: Intel sold its LAN antivirus under the Intel name, with royalties flowing one way in America and Europe and the other way in Asia, and from 1993 Novell bundled it with NetWare - the same Novell that appears elsewhere in this catalogue selling hardware at cost to grow an installed base.

Eva Chen became chief executive in January 2005 and still is, which makes her one of the longest-serving leaders in security and one of the few founders of either sex to run a company of this size for two decades. The company's current platform is sold as Vision One, with the AI branding that every security vendor now carries; the record worth keeping is older than the branding and comes in three parts.

The first is the Zero Day Initiative, acquired with TippingPoint from HP in 2015 for 300 million dollars. Started in 2005, it buys vulnerabilities from independent researchers and hands them to the affected vendors to fix before disclosure, and it runs the Pwn2Own contests where the year's browsers, phones and, lately, cars are broken on stage for prize money. A security vendor that buys the flaws it defends against is competing with the grey market on price, and the effect of a lawful buyer is to raise the floor of what a vulnerability is worth. That market is where a great deal of the industry's knowledge of its own weaknesses now comes from.

The second is the morning of 23 April 2005, when a routine pattern update pegged processors to a hundred per cent on Windows XP and Server 2003. The file was pulled after ninety minutes; by then it had been downloaded some three hundred thousand times, support took roughly 370,000 calls, and East Japan Railway and three national newspapers lost their networks for part of a morning. The cause was insufficient testing in the rush to detect a new worm. The lesson is the one the Xerox repairman and the Siemens controllers teach: the channel that keeps a product current is the channel through which it can do the most damage, and a defensive product with automatic updates has a blast radius the threat it targets could only envy.

The third is from 2019 and the company said it plainly: not an external hack. An employee with a premeditated plan reached a consumer support database, took the contact details of about 68,000 customers and sold them to criminals, who then telephoned those customers impersonating Trend Micro support. The Ubiquiti entry records what an insider can do with data; this is the same thing at a company whose product is the defence against it, and the company's own plain disclosure is the source. A security vendor is a company like the others, with employees like the others, and its own controls are the ones it is asked to be judged by.

Sources