As business exigencies drive datacenters toward ever increasing scales, agility and levels of automation, the underlying technologies expose the need to manage and control deeper stacks, more dynamic configurations and more rapidly evolving system behaviors. The days of relying on telemetry from a few choke points, over a static network topology, with stale behavioral baselines are rapidly receding toward the horizon. Traditional asset and workload identifiers and physical network topology are becoming increasingly inadequate as a foundation for supporting security correlation, analytics and the development of actionable mitigation context. At the same time, new attacks are stimulating the need for new kinds of visibility and control. As a result, the complexity of leveraging a security portfolio is increasingly a barrier to effective protection This session will dive into the implications for both defenders and attackers, of increasing containerization, virtualization and softwarization of security controls. We’ll look at the emerging trends in attack technology including firmware exploits, open source poisoning, side channels and the increasing emphasis on layer 7 intrusion. Finally, we’ll consider opportunities to transform the security portfolio, making security telemetry more effective while concurrently reducing the complexity of detection, analysis and response.