At Bletchley Park with Sir Dermot Turing – The Issue of Cloud Security

At Bletchley Park with Sir Dermot Turing – The Issue of Cloud Security

We recently conducted an informal LinkedIn poll and this, together with a discussion over dinner at Bletchley Park with Sir Dermot Turing revealed Cloud Security to be the most burning and complex issue facing cybersecurity leads today.

The poll and dinner discussion highlighted the following viewpoints (we’d very much like your thoughts too):

  • The security tools available from Cloud Service Providers (CSPs) are not good enough and are frequently CSP-specific. We need to use tools that work across any and all CSPs.
  • “Mind the Gap”. Security professionals don’t understand enough about cloud security to be effective, and cloud DevOps folks don’t understand enough about general security to be effective. Cloud security can get lost in between the two.
  • Cloud can make things quick and ephemeral, but that can lead to a lack of care about the quality of something that may not exist in an hour.
  • It’s now practically impossible to understand all the services that a CSP provides, and this feels deliberate because it means you can never run a financially optimised environment in the cloud.
  • The Shared Responsibility Model dictates that the Cloud Service Provider (CSP) is responsible for the security of the cloud, whilst the customer is responsible for the security of everything in the cloud.
  • Often, customers don’t differentiate between the cloud service provider and the organisation delivering products and services using the cloud since they can’t transfer a reputational risk.
  • Cloud is perfect for agile, mobile, instant and scalable, but if you want to do proper data analytics, nothing beats your own proprietary set-up for proper control, monitoring etc.
  • Too many people misunderstand when to use cloud and when to go with their own hardware. Unless workloads are dynamic and lend themselves to being scaled up and down, they probably don’t belong in the cloud – especially if they consume a lot of resources.
  • CFOs dislike surprises, and public cloud can often present surprising costs increases.
  • One company shared that they reduced CSP spend by 10x by understanding the services better and making better choices.
  • COVID-19 greatly accelerated cloud adoption. Whilst Cloud security has lagged way behind.
  • The term CSPM has been around since 2014, the terms CIEM and CWPP since 2020, and the term CNAPP since 2021, and yet many, indeed most traditional security professionals are not familiar with them.
  • DevSecOps may sound like a convenient answer, but it is a framework. People still need to understand the security piece for it to be effective.
  • We now have coders designing and building infrastructure with no network or infrastructure design background.
  • Businesses recognise the need for cloud and compliance and want to do the right thing but new services and tools are being created so fast that no one can keep up.
  • In the cloud, one small mistake can be absolutely devastating.
  • Security needs to be a part of Operations because Ops has a useful perspective.
  • The need to deliver code fast for the business is not entirely aligned with the need to be secure and compliant.
  • Many companies use multiple CSPs (multi-cloud), but the skills learnt on one CSP are not particularly transferable to another. This can mean separate teams supporting each CSP.
  • AI is likely to lead to a brain drain as no one learns anything anymore because AI always has the answer.
  • Machine learning can help but can also break things badly when it goes wrong. It is also possible to poison machine learning.
  • The tools provided by the CSPs for security are not good enough and are frequently CSP-specifc. We need to use tools that work across all CSPs.
  • CSPM (Cloud Security Posture Management) – we can’t secure what we don’t know about. CSPM maintains an inventory of cloud infrastructure and checks for misconfigurations across it.
  • CIEM (Cloud Identity and Entitlement Management) – The concept of a perimeter has been lost with the advent of SaaS and Cloud. The phrase, “IAM is the new perimeter” speaks to the problem that, in cloud, every entity is a potential security risk due to the way permissions work. CIEM analyses and informs about over-permissioning or incorrect permissions.
  • CWPP (Cloud Workload Protection Platform) – What about the apps running within the cloud? CWPP takes care of protecting the apps running in cloud, including within containers.
  • CNAPP (Cloud Native Application Protection Platform) – This C-soup got a bit cumbersome, so the concept of CNAPP was created to incorporate CSPM, CIEM, CWPP and newer solutions for Kubernetes (KSPM), infrastructure as code (IaC), data security posture management (DSPM) etc.

We would very much like to get your perspective on cloud security and are planning more insight gathering and networking events – please get in touch here if you would like to register your interest.

Beaten by credentials: Why identity-based attacks are booming

Beaten by credentials: Why identity-based attacks are booming

Identity-based attacks have become one of the most rapidly evolving and dangerous threat vectors in recent years. Organisations are struggling to protect against identity-based attacks, which are growing in speed and sophistication. In this blog, Ian Tinney, CEO of 4Data Solutions, looks at why cybercriminals thrive on credentials and identities, explains why existing solutions can miss identity-based attacks and highlights why speed of real-time detection is a critical factor in mitigating the damage of identity-based attacks.

Identity-based threats have emerged as a primary vector for cyberattacks, posing significant risks to modern organisations. By exploiting vulnerabilities in identity and access management systems, threat actors can gain unauthorised access to sensitive data and systems. To mitigate these risks, organisations must implement comprehensive identity security solutions that incorporate strong authentication, authorisation and continuous monitoring.

Let’s look at some of the key factors behind the rise in identity-based attacks.

1. Increased reliance on digital identities
As organisations increasingly adopt cloud-based services and remote work models, the reliance on digital identities has grown significantly. This creates more opportunities for attackers to target and compromise these identities.

2. Increasingly sophisticated attack techniques
Attackers have become more sophisticated in their ability to steal, compromise and exploit identities. Techniques such as phishing, credential stuffing and social engineering are used to trick users into revealing their credentials or bypassing security controls.

3. Rise of remote work and BYOD
The rise of remote work and bring-your-own-device (BYOD) environments has introduced new challenges for identity management. It can be difficult to ensure that all devices and users are adequately protected and compliant with security policies.

4. Humans are easy to trick
As with so many other aspects of adversary tradecraft, phishing and smishing campaigns are growing more subtle and sophisticated, an unsettling trend fuelled by the rise of artificial intelligence (AI). AI has also made it significantly easier and cheaper for adversaries to create technologies such as stealer malware – specialised malware used to steal account passwords, cookies, credit card details, etc – giving criminals yet another method to harvest credentials and either use them against you or sell them on the criminal underground.

5. Identities are easy to monetise
There’s a thriving underground economy for stolen credentials, making them easier for criminals to monetise. Just a decade ago, usernames and passwords were essentially worthless. Today, threat actors can use, trade or sell stolen credentials more easily than ever, giving them more incentive to target this information.

6. Valid credentials are like cheat codes
Valid credentials allow attackers to bypass initial access and quickly move laterally within an environment, significantly reducing the time needed to achieve their objectives. This is partly why the average breakout time – the time it takes for an attacker to move from initial compromise to another host within the victim’s environment – is down to 79 minutes, with the fastest eCrime breakout time at just seven minutes!

7. Identities span the enterprise
Stolen credentials provide attackers with access to various systems and data, including cloud infrastructure and sensitive information. Without strong security controls like MFA, attackers can move quickly and freely within an organisation’s environment, potentially causing significant damage.

Why identity-driven attacks are extremely hard to detect
When a valid user’s credentials have been compromised and an adversary is masquerading as that user, it’s often challenging to differentiate between the user’s typical behaviour and that of an attacker using applications and tools existing in the target environment.

Lack of visibility and protection across attack paths means that it’s difficult to identify and address potential vulnerabilities throughout the complex web of interconnected components in a cloud infrastructure.

Existing solutions can miss identity-based attacks due to several factors:

  • Relying on outdated methods: Traditional security measures often focus on perimeter protection and network-based threats, overlooking the vulnerability of identities themselves. This includes relying on passwords as the primary authentication method, which can be easily compromised through phishing or brute-force attacks.
  • Lack of comprehensive identity visibility: Many organisations have fragmented identity systems, making it difficult to have a complete view of all user identities and their access privileges. This lack of visibility can make it challenging to detect and respond to unauthorised access or identity compromise.
  • Limited analytics and threat detection: Traditional security solutions may not have the advanced analytics capabilities to detect and respond to sophisticated identity-based attacks. This includes the ability to identify unusual patterns of behaviour, such as multiple failed login attempts from different locations, or the use of compromised credentials.
  • Slow response times: In the event of an identity-based attack, traditional security solutions may be slow to detect and respond. This can allow attackers to gain unauthorised access and cause significant damage before the breach is identified and remediated.
  • Inadequate risk assessment: Organisations may not have a comprehensive risk assessment process to identify and prioritise identity-related threats. This can lead to a focus on low-risk threats while neglecting more critical vulnerabilities that could lead to a data breach or other serious consequences.

Why speed is of the essence when detecting identity-based attacks
Speed is absolutely of the essence when detecting identity-based attacks. Modern cyberattacks, especially those targeting identities, are often highly automated and can happen within minutes or even seconds. The sooner an attack is detected, the less time an attacker has to exploit the compromised identity and cause damage. Quick detection can prevent the exposure of sensitive data, mitigate reputational damage, and prevent future breaches.

Breaches with stolen credentials take 292 days to detect. Adversaries move laterally undetected with valid credentials.

Several factors influence the time it takes to detect identity-based attacks:

  • Complexity of the attack: Sophisticated and novel attacks, such as credential stuffing, phishing, and account takeovers, can be difficult to detect in real-time due to their mimicry of legitimate user behaviour and their evolving nature.
  • Security infrastructure: The sophistication of security tools and the quality of data significantly impact the speed of detecting identity-based attacks. Advanced tools like IDS, SIEM, and behavioural analytics platforms, combined with accurate and timely data, are crucial for identifying suspicious activities.
  • Response time: The speed and efficiency of incident response teams and automated response mechanisms can significantly impact the containment of identity-based attacks.
  • Data volume and velocity: Analysing vast amounts of data in real-time, a computationally intensive task, is crucial for detecting and responding to fast-moving attacks. Efficient infrastructure and algorithms, along with real-time data streaming capabilities, are essential for timely detection.
  • Human factors: Skilled security analysts can identify subtle indicators of compromise that automated systems may miss. However, heavy workloads can hinder their ability to respond promptly to alerts and investigate incidents.

Conclusion

In today’s digital age, identity-based attacks pose a significant threat to organisations of all sizes. The rapid evolution of attack techniques, coupled with the increasing reliance on digital identities, has created a complex security landscape. To effectively combat these threats, organisations must prioritise speed and accuracy in detecting and responding to incidents. By implementing robust identity and access management solutions, leveraging advanced security technologies, and fostering a culture of security awareness, organisations can significantly reduce their risk exposure and protect their valuable assets.

You can register here to arrange a FREE Identity Security Risk Review from one of our identity experts. Alternatively, you can find out more about CrowdStrike Falcon® – the industry’s only adversary-focused platform that unifies endpoint and identity telemetry – by phoning us on +44 330 128 9180 or emailing info@4datasolutions.com.

CrowdStrike Falcon® provides real-time correlation of threats along with threat intelligence and adversary tradecraft. This is the only effective method to get full visibility into attack paths covering all aspects of the adversary toolkit – from exploitation and malware delivery to fileless attacks and stolen credentials – to stop the full attack lifecycle.

4Data partners with CrowdStrike and Ignition to bring AI-powered cybersecurity to our UK customers

4Data partners with CrowdStrike and Ignition to bring AI-powered cybersecurity to our UK customers

With the speed and ferocity of cyberattacks continuing to accelerate, the rise of generative AI has the potential to lower the barrier of entry for low-skilled adversaries, making it easier to launch more sophisticated attacks. As organisations increasingly move business to the cloud, threat actors are advancing their capabilities to exploit this and abuse cloud-unique features. Identity-based attacks continue to take centre stage as threat actors use social engineering to bypass multi-factor authentication.

We are entering an era of a cyber arms race where AI will amplify the impact for both the security professional and the adversary. Organisations cannot afford to fall behind, and legacy technologies are no match for the speed and sophistication of today’s threat actors.

As part of Ignition’s market-leading partner network, 4Data is a highly skilled and experienced strategic partner and is well positioned to offer CrowdStrike’s AI-native Falcon® platform to UK businesses.

Ian Tinney, CEO of 4Data Solutions, comments: “Our mission is to help our customers get value from data while keeping it secure and compliant. As such, the CrowdStrike Falcon® platform is a powerful addition to our portfolio. It covers the complete defence-in-depth spectrum, from endpoint security to identity management, SIEM and cloud security – all of which align with our skill set and value proposition. There is no better brand to add to the mix that will enable us to address our customers’ biggest challenges around consolidating costs and simplifying security solutions without compromising on protection.

“More than that, all aspects of the platform are properly integrated, providing a truly unified platform using just one agent. This is critical because, in any large organisation, systems typically have between 7 and 15 agents installed, which is a major challenge when it comes to ensuring all agents are patched and running the latest versions.

“We are delighted to have been approached by Ignition Technology and CrowdStrike specifically for our relevant experience and expertise in cybersecurity. CrowdStrike’s Falcon® platform is the industry’s best security platform, delivering the outcome of stopping breaches. That, together with Ignition’s specialist SaaS cybersecurity focus, go-to-market strategy, channel development capabilities and sales expertise, is going to help us enormously. Not to mention the fact that they are also a great bunch of people to work with.

“In line with CrowdStrike’s mission, we are committed to stopping breaches and working with cutting-edge technology to do so. Adding Falcon®, CrowdStrike’s leading security platform, is essential in meeting customer demand and overcoming their complex challenges.”

About 4Data Solutions

At 4Data Solutions, we help our customers leverage data to innovate, differentiate and create new efficiencies while ensuring data is secure and aligned with regulatory compliance.

We believe that data analytics and data security are two sides of the same coin, so we operate at the intersection of both bringing market leading analytics and cybersecurity solutions from CrowdStrike, Centripetal, Corelight, Splunk, Axiom and Cribl, to our clients.

We invest heavily in ongoing training and certification so our professional services consultants are always at the very top of their game in terms of solution knowledge, skills and capabilities. We pride ourselves on our in-depth understanding of the unique requirements of every sector we work in – including highly regulated industries such as defence, government, finance, retail, healthcare, insurance, energy and telecoms. Our technology experts are passionate about integrating solutions that are tightly aligned to clients’ business requirements, ensuring we maximise value from their data by making it available, observable, secure and compliant at all times.


About CrowdStrike

CrowdStrike (Nasdaq: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk – endpoints and cloud workloads, identity and data. In June 2024, CrowdStrike was added to the S&P 500 Index, making CrowdStrike the fastest cybersecurity company to attain this achievement.

Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritised observability of vulnerabilities.

Purpose-built in the cloud with a single lightweight agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity, and immediate time-to-value.

Learn more: https://www.crowdstrike.com/
Follow us: Blog | Twitter | LinkedIn | Facebook | Instagram
Start a free trial today: https://www.crowdstrike.com/free-trial-guide/

© 2024 CrowdStrike, Inc. All rights reserved. CrowdStrike, the falcon logo, CrowdStrike Falcon and CrowdStrike Threat Graph are marks owned by CrowdStrike, Inc. and registered with the United States Patent and Trademark Office, and in other countries. CrowdStrike owns other trademarks and service marks, and may use the brands of third parties to identify their products and services.

About Ignition Technology

Ignition Technology, an Exclusive Networks company, is a security distributor for the SaaS world. We believe in the power of the channel to enable and secure business transformation. We enable our partners to architect solutions that better protect their customers and help them navigate the future of cybersecurity through our people, our knowledge and our solutions and services.

By discovering innovative, emerging cybersecurity solutions, we help them de-risk their business, create value and maintain relevance with their customers whilst delivering peace of mind.

For more information visit ignition-technology.com.

 

An overview of Tenable’s CIEM solution

An overview of Tenable’s CIEM solution

Today, the public cloud has become the preferred way of doing business, which is causing challenges for security teams, as public cloud environments often create many access entitlements and associated vulnerabilities. In the latest blog in our cloud security series, I take a closer look at Tenable’s CIEM solution and highlight some of the benefits it offers customers.


Tenable’s CIEM solution provides customers with visibility, risk prioritisation and security control across multiple cloud environments and services. It delivers granular, role-based access controls (RBAC) for each user and is intended to give customers better control over access management in a cloud environment. Tenable CIEM provides organisations with real-time visibility into the entitlements granted to both human and machine identities.

With Tenable CIEM, organisations can enforce the security principle of least privilege for access control management. This means that access should be limited to only those users, applications and devices that need it to perform their tasks, and the least privileged access required to accomplish a specific action is the most secure approach. Tenable CIEM’s advanced security analytics also give customers insight into who has access to what resources, how often they’re using those resources, and when, allowing them to quickly detect anomalous or suspicious behaviour.

One of the key benefits of Tenable CIEM is that it gives organisations complete visibility and control over all their cloud resources, enabling them to maintain a more secure cloud environment. By reducing the risk of insider threats and external cyberattacks, companies can reduce costs, optimise their compliance and minimise the damage from breaches. Tenable CIEM provides insights into potential risks, like high-privileged accounts, stale and orphaned users and resources, as well as access misconfigurations that can leave the organisation open to vulnerabilities.

Tenable CIEM delivers flexible policy controls to detect risky behaviours in real-time and generates detailed compliance and security reports to facilitate regulatory and audit requirements. It is also built with extensible APIs that provide integrations with your current security tools, enabling them to consolidate alerts and notifications. With its user-friendly dashboard, users can view information on all entitlements across their organisation and an automated alert feature allows them to track changes in the privileges, configurations, and accesses. Moreover, Tenable CIEM gives security teams the flexibility to generate specific entitlement reports on-demand or set them up to generate automatically.

Tenable CIEM is cloud-native, which means it’s optimised for modern cloud infrastructures and built to deliver agility and scalability in cloud-based applications and services. It offers ease of integration, so you can work seamlessly with all the existing tools and services that you use, without needing to set up new tools or training sessions for the IT teams.

CIEM from Tenable is essential for cloud security and the organisation’s overall risk management, which requires a comprehensive view of user and machine identities and how they access and use cloud resources. Its enhanced functionality gives security teams a real-time insight into the usage of identity privileges and mitigates risks in complex environments. By prioritising the right users, systems and devices for attention, CIEM provides advanced threat analysis and prioritisation capabilities to detect the latest threats and zero-day vulnerabilities. In conclusion, Tenable CIEM is an excellent tool that enhances organisations’ overall cybersecurity and regulatory compliance posture.

For more information about Tenable’s CIEM solution, call us on +44 330 128 9180 or email info@4datasolutions.com.

Solving cloud security challenges with CIEM

Solving cloud security challenges with CIEM

With the increasing adoption of cloud computing, organisations face numerous challenges in ensuring the security of their cloud environments. Cloud Infrastructure and Platform as a Service (IaaS and PaaS) providers offer built-in security measures, but organisations often struggle to manage and monitor these resources effectively. Cloud Infrastructure Entitlement Management (CIEM) has emerged as a solution to address these issues. In this blog, I discuss the problems that CIEM solves in cloud security and the benefits it provides to organisations.


Problem 1: Misconfiguration and Access Control

One of the primary issues in cloud security is the misconfiguration of resources and ineffective access control. Organisations often unintentionally expose sensitive data, applications or services due to misconfigured security settings, leaving them vulnerable to security breaches. Additionally, managing user access privileges and permissions across various cloud services can be complex and error-prone. CIEM offers centralised management and visibility into access controls, enabling organisations to identify and rectify misconfigurations in real-time. By automating the enforcement of security policies, CIEM helps prevent unauthorised access and provides granular control over user entitlements, reducing the risk of data breaches.

Problem 2: Insider Threats and Shadow IT

Insider threats and shadow IT are major concerns for organisations operating in the cloud. Employees with privileged access can misuse their privileges, intentionally or unintentionally, leading to data leaks or unauthorised access. Additionally, the use of unauthorised cloud services, known as shadow IT, can exacerbate security risks by bypassing corporate security policies. CIEM helps mitigate these risks by providing continuous monitoring of user activities, detecting anomalous behaviour and alerting administrators of any suspicious activities. It offers insights into both authorised and unauthorised cloud resources, allowing organisations to identify and address any shadow IT usage. By minimising the potential for insider threats and shadow IT, CIEM strengthens cloud security overall.

Problem 3: Compliance and Regulatory Challenges

Complying with industry regulations and data protection laws is critical for organisations, especially those that handle sensitive customer data. Ensuring continuous compliance in dynamic cloud environments can be a daunting task. CIEM facilitates compliance efforts by providing visibility into user entitlements, monitoring cloud configurations, and detecting policy violations. By generating detailed reports on user access, privilege usage and compliance metrics, CIEM helps organisations demonstrate adherence to regulatory requirements. The automation of compliance controls and real-time monitoring offered by CIEM significantly reduces the manual efforts required to maintain compliance, allowing organisations to focus more on their core business while ensuring data security.

Conclusion

Cloud Infrastructure Entitlement Management (CIEM) addresses critical cloud security challenges faced by organisations today. By solving problems such as misconfigurations, access control, insider threats, shadow IT and compliance, CIEM enhances the security posture of cloud environments. It provides comprehensive visibility and centralised management, enabling organisations to identify potential vulnerabilities, detect unauthorised activities and enforce security policies effectively. With CIEM, organisations can confidently embrace the benefits of the cloud while ensuring the protection of their sensitive data and maintaining regulatory compliance. By leveraging CIEM capabilities, organisations can strengthen their cloud security strategy and minimise the risk of breaches, ultimately preserving their reputation and customer trust.

A Guide to Cloud Infrastructure and Entitlement Management (CIEM)

A Guide to Cloud Infrastructure and Entitlement Management (CIEM)

The cloud has revolutionised the way we work, providing businesses with on-demand access to scalable and cost-effective resources. But with great power comes great responsibility, especially when it comes to managing cloud infrastructure and entitlements.

There is growing recognition that traditional cybersecurity approaches – such as the castle-and-moat approach to protecting the perimeter – simply don’t work in the cloud because they focus solely on external threats, neglecting the growing concern of insider threats and vulnerabilities within the cloud infrastructure itself.

Instead, the primary attack surface is now identity.

Identity is everything in the cloud, and Identity and Access Management (IAM) has become the new perimeter and a critical component of security in this distributed environment. It encompasses the tools and policies used to ensure that the right users – and only the right users – have access to the right resources at the right times and for the right reasons. It involves managing identities (both human and non-human, such as services or IoT devices), their permissions and various authentication mechanisms (like passwords, multi-factor authentication, etc.).

Let’s first look at why the castle-and-moat approach to protecting the perimeter no longer suffices when it comes to the cloud. The castle and moat analogy in cybersecurity refers to a perimeter-based security model. It visualises an organisation’s network as a castle, with valuable data and systems residing within. The moat represents the security measures implemented to protect the internal network from external threats.

In the digital world, the ‘castle’ is your computer network with valuable data, and the ‘moat’ is a strong outer defence. Firewalls and security systems act like guards, keeping intruders out. However, once inside the network (like crossing the drawbridge), users have free reign. The castle and moat method to security works well against external threats, but it has weaknesses. It assumes everyone inside is trustworthy and doesn’t address insider threats or attacks that bypass the perimeter.

The current cyber-attack cycle often starts with attackers seeking access through poorly managed privileges and then pivoting between resources, discovering credentials and other identities to obtain something of value.

In the public cloud, where resources are spread out and accessible remotely, identity becomes paramount for security because it dictates who can access what, and how. Here are some of the reasons why identity is paramount:

  • Access Control: Centralised identity management allows you to define granular permissions for users and applications. Without proper identity controls, anyone could potentially access sensitive data or perform unauthorised actions.
  • Authentication: Strong identity verification ensures only authorised users and applications can access cloud resources. Multi-factor authentication (MFA) adds an extra layer of security beyond just usernames and passwords.
  • Accountability: Identity creates an audit trail. By tracking who accessed what resources and when, you can identify suspicious activity and hold individuals accountable for their actions in the cloud.
  • Shared Responsibility: Public cloud security is a shared model. While the provider secures the infrastructure, you control who has access to your resources. Identity management is crucial in fulfilling your part of the security responsibility.
  • Dynamic Environments: The public cloud is fluid, with resources constantly being created, modified, and deleted. Identity helps maintain control in this dynamic environment by ensuring access permissions are always up-to-date and aligned with current needs.

Effectively managing identities in the public cloud is like managing the keys to your digital kingdom. Strong identity practices and carefully managed privileges are the foundation for securing your data, applications and overall cloud environment. However, with hundreds of privileges available to assign to an entity, the chance of getting it right for every entity all of the time is very low indeed without a tool like CIEM (Cloud Infrastructure Entitlements Management).

Whereas the castle and moat analogy focuses on keeping attackers out, CIEM also focuses on detecting and responding to threats within the system. CIEM goes beyond just perimeter security and encompasses activities like user behaviour monitoring, log analysis and incident response. It keeps track of who has keys (access permissions) to each room and ensures no one has more access than they need. CIEM constantly monitors these permissions, identifying overly powerful keys and potential security risks. CIEM continuously monitor for new threats and vulnerabilities, therefore helping organisations follow the ‘least privilege’ principle and reducing the chances of data breaches in the cloud.

CIEM uses analytics to identify potential security incidents and threats, allowing security teams to gain visibility into security events across the organisation; detect and investigate suspicious activity and respond to security incidents more quickly and effectively.

To conclude, the phrase ‘IAM is the new perimeter’ reflects a paradigm shift from network-centric security models to identity-centric models, where managing identities and access effectively is key to securing digital assets in a distributed and cloud-based computing environment. A robust CIEM solution can significantly improve your cloud security posture, ensure compliance, optimise costs and give you peace of mind knowing that your cloud kingdom is well-protected.