{"id":52949,"date":"2022-12-05T07:18:00","date_gmt":"2022-12-04T23:18:00","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=52949"},"modified":"2022-12-03T12:22:31","modified_gmt":"2022-12-03T04:22:31","slug":"the-future-of-cloud-delivered-cybersecurity-solutions","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/12\/05\/the-future-of-cloud-delivered-cybersecurity-solutions\/","title":{"rendered":"<strong>The future of cloud-delivered cybersecurity solutions<\/strong>"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>By Guy Matthews<br>Editor, NetReporter<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Like it or not, the enterprise world is entering a phase of \u2018digital dependence\u2019. This somewhat sobering conclusion is drawn by Fernando Montenegro, Senior Principal Analyst, Cybersecurity Infrastructure Security Intelligence Service with analyst firm Omdia.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The recent pandemic, he says, has driven digital transformation up the corporate agenda and led to technology being more essential to business success than ever. So what has brought about this heightened level of reliance on tech? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe first driver has been the rise of more distributed workforces, especially for knowledge workers,\u201d he says. \u201cThe second thing is what I call fast-paced digital value chains. We\u2019ve moved towards adopting different providers of different services across our value chains. Thirdly, transformation has led to much more distributed compute, particularly where technology is supporting physical processes in the world. We are further ahead in the deployment of 5G technology, supporting IoT use cases and industrial IoT use cases. Lastly, we have now adopted cloud-based environments almost as a default for organizations.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Underpinning all four of these areas is the perennial headache of cybersecurity. So what, in the context of a multitude of transformational initiatives, are the top security priorities that Omdia has uncovered in its research? Securing the cloud is perennially cited by IT bosses as their most difficult task, says Montenegro.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Figure 1: Complex threats demand intelligent solutions<\/em><\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"486\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1.jpg\" alt=\"\" class=\"wp-image-52951\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1.jpg 864w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1-300x169.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1-768x432.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1-600x337.jpg 600w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As part of its research, Omdia also sought to find out when enterprises expect to have the majority of their workloads in what they clearly see as the somewhat vulnerable environment of the cloud. It turned out that 25% have already passed that tipping point, while 20% said they would be there within the year.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Figure 2: Workloads in the cloud<\/em><\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"486\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2.jpg\" alt=\"\" class=\"wp-image-52952\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2.jpg 864w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2-300x169.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2-768x432.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2-600x337.jpg 600w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, for CIOs considering cloud adoption, along with all its attendant threats, perceived or real, what seem to be the most compelling use cases for the application of appropriate security? And what of cloud-delivered security \u2013 that is security designed to live in the cloud or be consumed as a cloud-based service? To help answer this knotty problem, Montenegro pulled in a panel of leading names in the cyber and cloud fields.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Chad Skipper, Global Security Technologist, Network &amp; Advanced Security Business Group with vendor VMware sees lots of opportunities, not for any old security but for cloud-delivered security. He identifies two use cases, firstly traditional applications with the sort of virtualized capabilities that were commonplace before digital transformation intervened: \u201cNow enterprises want to take those workloads and deliver them off premise in the cloud, as cloud-delivered security,\u201d he observes. Secondly, post digital transformation, Skipper identifies \u2018modern\u2019 applications as a second use case. Think containers, think Kubernetes, think cloud applications delivered as a service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThat\u2019s a different delivery model because those are running itty bitty micro services within that cloud infrastructure,\u201d he says. \u201cThe security is somewhat the same in both cases, but the insertion mechanism is different. Traditionally, you need visibility right into every packet and every process. But for a modern application, we\u2019re talking APIs and the ability to discern what threat actors are doing once they get inside a perimeter. Once everything outside of your perimeter was considered bad and everything inside was considered good. But that\u2019s no longer the case. And so we need to have that visibility, whether it\u2019s in the modern applications or the traditional applications to really understand what those threat actors are doing.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Haiyan Song, Executive Vice President and the Head of Security with security vendor F5 sees a key benefit of cloud-delivered security as the chance to deliver security where users are actually located: \u201cWhen you think about federated identity, I think that\u2019s one of the good use cases,\u201d she claims. \u201cYou no longer have to go back to your own central identity and access management. It can be delivered in a much better and faster way, more flexibly. The other nature of cloud delivered security has something to do with the ability to correlate, aggregate and get insights from a cloud-connected world. You\u2019re able to see what\u2019s coming and what\u2019s happening in the network, and apply that to the rest of the company. I think that\u2019s one of the crown jewels of cloud-delivered security \u2013 having insights that one once analyzed, many can benefit from.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With security going from on-prem to cloud comes the evolution of firewall services and also web application and API protection services, believes Sashi Jeyeratnam, Senior Director of Product Management for Security Solutions with security vendor Spirent. The nature of cloud, she says, is very elastic: \u201cYou have highly ephemeral workloads, and things change very quickly. You need to make sure tools have cloud awareness, and awareness of workloads. If your security solutions are not aware, then they are not going to scale very well and be effective for you.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The main reason why people move to the cloud is because of agility, she adds: \u201cYou need to be able to embrace new workloads that are popping up and new security policies that need to scale effectively. CISOs now have a goal of making sure of business continuity. They don\u2019t want to be seen as roadblocks.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Also up for debate was the panel\u2019s recommended practices for an organization that is going down the cloud-delivered security path. Regardless of where you are in your transformation journey, argues Jeyeratnam of Spirent, whether you have just one workload in the cloud or half of them, you need an end goal in mind on the journey to ensure that you make the right choices: \u201cHaving to set visibility and security controls, having tool sets that help you navigate the heterogeneous environment that your hybrid networks represent, I think that\u2019s going to be a critical factor,\u201d she says. \u201cAnd the other thing is that with cloud, it\u2019s all about scale.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Song of F5 warns of the need to be mindful of vendor management at the outset: \u201cWhen you deal with incident response, that\u2019s when you depend on a third party,\u201d she explains. \u201cYou need to have agreements in place and your drills down ahead of time, especially for business-critical applications. Consider the example of Log4J, one of the biggest cybersecurity events of last year. In order to work through that one you needed to have an agreement and protocol in place with your vendors. The other thing I would certainly advocate is always to have multi-layer defence. Nothing is perfect, but you need best practices for your venture into cloud-based security.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thoughts turn lastly to likely future developments in IT that will have a bearing on adoption of cloud-based security. Song of F5 summed up her considerations in three words, all starting with a D: \u201cEveryone is becoming more and more decentralized,\u201d she notes. \u201cPeople work from anywhere, and applications need to be delivered to wherever. The second word is disaggregated. Every app uses multiple components and services and that adds more and more complexity. Thirdly, everything is going digital.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Skipper of VMware argues that visibility is and always will be key: \u201cHow do you get all packets and processes right, especially in a multi cloud world?\u201d he muses. \u201cIn a virtualised world, the future is going to be about data processing units, or DPUs. We\u2019ve heard of GPUs, we\u2019ve heard of CPUs, but look out for DPUs, also called Smart NICs. The challenge that we\u2019ve had in the cloud operating model is when we add security we are consuming the CPU and memory of the application. Moving those security capabilities off the CPU onto a smart NIC is the future for a multi cloud operating model.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In conclusion, Jeyeratnam of Spirent sees the future in terms of the data that is coming from the mass of cloud infrastructure in use: \u201cHow to manage that data? Some kind of AI or ML applied to it is going to be very important, so as to be able to manage the vast amount of logs and alerts that are coming down. A major trend going forward is being able to correlate that data. We need information to be able to correlate and use data to predict what a security posture might look like, or what might to go wrong. The industry is going to have to move towards being able to help organizations achieve that.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The recent pandemic has driven digital transformation up the corporate agenda and led to technology being more essential to business success than ever. So what has brought about this heightened level of reliance on tech? <\/p>\n","protected":false},"author":7,"featured_media":52950,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[96,2727,1656],"class_list":["post-52949","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-technology","tag-technology-adaption","tag-technology-investment"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/52949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=52949"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/52949\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/52950"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=52949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=52949"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=52949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}