{"id":36923,"date":"2019-11-01T04:15:58","date_gmt":"2019-10-31T20:15:58","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=36923"},"modified":"2019-11-01T04:15:57","modified_gmt":"2019-10-31T20:15:57","slug":"70-of-apac-enterprises-falsely-believe-that-cloud-providers-security-is-sufficient","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/11\/01\/70-of-apac-enterprises-falsely-believe-that-cloud-providers-security-is-sufficient\/","title":{"rendered":"70% of APAC enterprises falsely believe that cloud providers\u2019 security is sufficient"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Palo Alto Networks released a report that uncovers the truth about the state of cloud security among large enterprises across Asia-Pacific, including many cases where perception doesn\u2019t match the reality of professionals who know best. <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conducted by Ovum Research, the report\nshows that large enterprises, defined as those with more than 200 employees,\nare not prepared for cloud-related cybersecurity threats, and more importantly,\nmake the assumption that public clouds are by default secure. In fact, 70\npercent of security decision-makers in large enterprises believe that security\nprovided by cloud providers is sufficient to protect them from cloud-based\nthreats. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOrganisations need to recognise that cloud security\nis a shared responsibility,\u201d said Elaine Liew, regional vice president for\ncloud security, Asia-Pacific at Palo Alto Networks. \u201cWhile cloud providers are\nresponsible for the security of their infrastructure, the onus is on companies\nthemselves to secure their data and applications stored in that\ninfrastructure.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Large Organisations Have Many\nSecurity Tools, but Lack a Unified View of Security<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Among the companies surveyed, three out of five (59%)\noperate with more than 10 security tools within their infrastructure to secure their\ncloud. However, having numerous security tools creates a fragmented security\nposture, adding further complexity to managing security in the cloud,\nespecially if the companies are operating in a multi-cloud environment. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The multi-cloud approach creates a dangerous lack of\nvisibility that is prevalent in 64 percent of large organisations surveyed,\naccording to Andrew Milroy, head of advisory services, Asia-Pacific, Ovum. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe ubiquity of multi-cloud deployments in large\norganisations calls for a unified view of all cloud-native services. It is\nideal for organisations to have a central console that uses technologies such\nas artificial intelligence to help prevent known and unknown malware threats,\nand quickly remediate accidental data exposure when it arises,\u201d said Milroy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Large Organisations Lack\nCloud Security Audits and Training <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The need for automation is further underscored by the\nstudy, which revealed that large enterprises do not have enough time and\nresources to dedicate to cloud security audits and training. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">76 percent of organisations have either never\nconducted a security audit or do not do it on a yearly basis. Furthermore, a\nquarter of audits do not even include cloud assets and 65 percent of\norganisations conduct internal audits only. Besides audits, there is also\ninadequate cloud security training for both IT and non-IT staff. About 57\npercent of organisations do not provide cybersecurity training to IT security\nemployees on a yearly basis. It is, therefore, not surprising that staff outside\nof IT departments receive even less training \u2013 74 percent of non-IT\nprofessionals do not receive cybersecurity training on a yearly basis. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Despite organisations\u2019 inability to provide more\nfrequent audits and security training for IT teams and employees, it is\nencouraging to see that almost half (49%) of the organisations surveyed use\nthreat intelligence and analytics to identify new threats and take necessary\naction. Some 19 percent of the organisations have also equipped themselves with\nreal-time threat monitoring capabilities. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In order to be truly secure in cloud environments, it is pertinent for organisations in Asia-Pacific to be cognisant of cloud security best practices, which include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Building security into the cloud environment from the get-go;\nsecurity should be an enabler to accelerate cloud adoption.<\/li><li>Developing consistent security policies across all types of cloud\ndeployments, which can be implemented properly through the help of tools that\nprovide a unified view of all cloud assets and the threats they face. <\/li><li>Allowing for frictionless deployment and easy scalability in\nmulti-cloud environments, bridging the gap between highly controlled security\nteams and highly agile development teams.<\/li><li>Increasing audits and training for employees, both IT and non-IT.<\/li><li>Automating threat intelligence\nwith natively integrated, data-driven, analytics-based approaches\n(leveraging machine learning\/artificial\nintelligence) to avoid human error.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u201cOrganisations need to recognise that cloud security is a shared responsibility,\u201d said Elaine Liew, regional vice president for cloud security, Asia-Pacific at Palo Alto Networks.<\/p>\n","protected":false},"author":6,"featured_media":30627,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[1923,6951,54],"class_list":["post-36923","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cloud-security","tag-palo-alto","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=36923"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36923\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/30627"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=36923"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=36923"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=36923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}