At Bletchley Park with Sir Dermot Turing – The Issue of Cloud Security
We recently conducted an informal LinkedIn poll and this, together with a discussion over dinner at Bletchley Park with Sir Dermot Turing revealed Cloud Security to be the most burning and complex issue facing cybersecurity leads today.
The poll and dinner discussion highlighted the following viewpoints (we’d very much like your thoughts too):
- The security tools available from Cloud Service Providers (CSPs) are not good enough and are frequently CSP-specific. We need to use tools that work across any and all CSPs.
- “Mind the Gap”. Security professionals don’t understand enough about cloud security to be effective, and cloud DevOps folks don’t understand enough about general security to be effective. Cloud security can get lost in between the two.
- Cloud can make things quick and ephemeral, but that can lead to a lack of care about the quality of something that may not exist in an hour.
- It’s now practically impossible to understand all the services that a CSP provides, and this feels deliberate because it means you can never run a financially optimised environment in the cloud.
- The Shared Responsibility Model dictates that the Cloud Service Provider (CSP) is responsible for the security of the cloud, whilst the customer is responsible for the security of everything in the cloud.
- Often, customers don’t differentiate between the cloud service provider and the organisation delivering products and services using the cloud since they can’t transfer a reputational risk.
- Cloud is perfect for agile, mobile, instant and scalable, but if you want to do proper data analytics, nothing beats your own proprietary set-up for proper control, monitoring etc.
- Too many people misunderstand when to use cloud and when to go with their own hardware. Unless workloads are dynamic and lend themselves to being scaled up and down, they probably don’t belong in the cloud – especially if they consume a lot of resources.
- CFOs dislike surprises, and public cloud can often present surprising costs increases.
- One company shared that they reduced CSP spend by 10x by understanding the services better and making better choices.
- COVID-19 greatly accelerated cloud adoption. Whilst Cloud security has lagged way behind.
- The term CSPM has been around since 2014, the terms CIEM and CWPP since 2020, and the term CNAPP since 2021, and yet many, indeed most traditional security professionals are not familiar with them.
- DevSecOps may sound like a convenient answer, but it is a framework. People still need to understand the security piece for it to be effective.
- We now have coders designing and building infrastructure with no network or infrastructure design background.
- Businesses recognise the need for cloud and compliance and want to do the right thing but new services and tools are being created so fast that no one can keep up.
- In the cloud, one small mistake can be absolutely devastating.
- Security needs to be a part of Operations because Ops has a useful perspective.
- The need to deliver code fast for the business is not entirely aligned with the need to be secure and compliant.
- Many companies use multiple CSPs (multi-cloud), but the skills learnt on one CSP are not particularly transferable to another. This can mean separate teams supporting each CSP.
- AI is likely to lead to a brain drain as no one learns anything anymore because AI always has the answer.
- Machine learning can help but can also break things badly when it goes wrong. It is also possible to poison machine learning.
- The tools provided by the CSPs for security are not good enough and are frequently CSP-specifc. We need to use tools that work across all CSPs.
- CSPM (Cloud Security Posture Management) – we can’t secure what we don’t know about. CSPM maintains an inventory of cloud infrastructure and checks for misconfigurations across it.
- CIEM (Cloud Identity and Entitlement Management) – The concept of a perimeter has been lost with the advent of SaaS and Cloud. The phrase, “IAM is the new perimeter” speaks to the problem that, in cloud, every entity is a potential security risk due to the way permissions work. CIEM analyses and informs about over-permissioning or incorrect permissions.
- CWPP (Cloud Workload Protection Platform) – What about the apps running within the cloud? CWPP takes care of protecting the apps running in cloud, including within containers.
- CNAPP (Cloud Native Application Protection Platform) – This C-soup got a bit cumbersome, so the concept of CNAPP was created to incorporate CSPM, CIEM, CWPP and newer solutions for Kubernetes (KSPM), infrastructure as code (IaC), data security posture management (DSPM) etc.
We would very much like to get your perspective on cloud security and are planning more insight gathering and networking events – please get in touch here if you would like to register your interest.