Companies are increasing their cloud adoption. Simultaneously, cloud environments face both the security challenges of on-premises environments and new ones that arise from their core benefits. Hence, companies should become smarter about their defenses. Here, Mark Kedgley, CTO, Netwrix, shares the best practices regarding cybersecurity defenses.
I find that the second week of a diet is easier than the first I have always given up by then! While we all know that the only way to achieve lasting fitness is to eat smarter and be active, it is difficult to stop looking for a magic pill. We want to believe that just a kale smoothie will deliver the results we want.
Similarly, there are no shortcuts to attaining strong cybersecurity, and many organizations are falling short of their goals. Netwrix recently surveyed over 700 IT security professionals, and there were a couple of findings that should grab everyones attention:
Source: Netwrix 2022 Cloud Security Report
Even as the threat to cloud IT systems grows, organizations are increasing their cloud adoption. About 54% of workloads are planned to be in the cloud by the end of 2023, compared to 41% today. Accordingly, it is vital to get a lot smarter about cybersecurity defenses.
As with fitness, strong cybersecurity requires disciplined, consistent practice. It is not quite no pain no gain, but it is much more than just buying a SIEM system and configuring some firewall rules. Indeed, cloud environments face both the security challenges of on-premises environments and new ones that arise from their core benefits, such as:
See More: Cloud Security Posture Management: Four Ways To Clear Your Clouded Vision
Let us assume that a strategic business case has already been made to migrate to the cloud. Today that often happens when the realization dawns that a new data center will be needed or a hardware refresh is coming around. The eye-watering costs and the anticipated logistical challenges almost inevitably lead to the conclusion that cloud computing would make life much better.
A key question that decision-makers should consider: are we re-hosting, re-platforming, or re-architecting? The answer is largely driven by whether or not the assets in question are in-house developed applications and the current state and future direction of IT services. For most organizations, it is a combination of all three paths because every application has different requirements for now and moving forward. If you are stuck with any legacy applications running on old platforms, then it is likely that a hybrid cloud is coming your way. Then you will have the opportunity to reap the benefits of DevOps with a CI/CD pipeline and instantly refreshed, elastic, container-based microservices applications down the line!
From a security standpoint, the cloud is highly attractive if it removes your data center security and business continuity responsibilities. However, even though you will no longer have a physical data center to secure, you will need to implement new access security controls and get a clear understanding of the activities and rights of your in-house resources and those of the service provider.
Start with the basics. One fundamental security best practice is the principle of least privilege. But that principle is as likely to be flouted in the cloud as on-premises. It is simply easier to over-provision accounts than to tailor rights as tightly as possible, much as it is easier to overindulge in treats or skip todays workout than to stick to your fitness plan. For help, look to cloud infrastructure entitlement management (CIEM) tools that facilitate processes like regular entitlement reviews to accurately enforce the least privilege, as well as monitor user activity and maintain clear and complete audit trails. Also, consider adopting a zero standing privilege (ZSP) approach in which privileged access is granted only temporarily, on demand, when required.
Multifactor authentication (MFA) offers another layer of identity security, helping to prevent the hijacking of credentials. In many cloud environments, MFA is offered as a configurable option but is not a default setting. Organizations need to weigh the benefits of increased security against the risk of user frustration and productivity losses.
Pre-built images provide a good starting point for hardening an environment. It is vital to remember that hardening is not a one-time operation; you also need automated, continuous monitoring for drift backed by effective reporting and alerting. It is rather like an exercise log that helps you keep your fitness program on track.
However, effective change control can be a steep challenge. You need a consistent picture across all cloud systems in use, including hybrid and private clouds, as well as the traditional data center and legacy IT platforms and applications. And on top of gaining complete visibility into all changes, you need to understand whether each change was planned or unplanned, good or bad, expected or potentially malicious. Again, there are tools and technologies that can help you achieve and maintain a hardened cloud or hybrid infrastructure.
Cloud technologies and platforms are comparatively new, so none of us have as much experience with the challenges as we do with systems like Linux and Windows. So set the alarm clock and get to the gym early as soon as you finish your workout, there is another busy day of cloud security to get on with!
What are the best practices you are following to keep your cloud environment secure? Share with us on Facebook, Twitter, and LinkedIn.
Image Source: Shutterstock
Visit link:
- Nigeria's Okra joins cloud hosting race to challenge AWS and Azure - Developing Telecoms - October 10th, 2024
- US Signal Introduces IaaS Solution OpenCloud for Open-Source Cloud Hosting - The Fast Mode - October 1st, 2024
- Waite Park hosting Coffee with a Cop on Wednesday - St. Cloud Live - October 1st, 2024
- Internet Vikings Approved to Offer VMware Private Cloud Hosting in Arizona - Cision News - August 23rd, 2024
- We wanted to become the Rolls-Royce of cloud hosting: Inside Hyve Managed Hostings global expansion plans - ITPro - July 20th, 2024
- Hostinger Review: VPS, Cloud, and Shared Hosting - Tom's Hardware - July 12th, 2024
- Optimizing Web Performance with Cloud Hosting - Spiceworks News and Insights - June 26th, 2024
- Oracle to open third Spanish cloud region with Telefonica as hosting partner - Telecompaper EN - June 26th, 2024
- Interior awards $2 billion cloud hosting contract to 7 vendors - FedScoop - June 5th, 2024
- From Clean Energy to Cloud Hosting: Bitcoin Miners Have Diverse Operations - Finance Magnates - June 5th, 2024
- Top 10 Cloud Hosting Providers in 2024: Plans, Prices, and Key Factors - mitechnews.com - May 27th, 2024
- Bare Metal Cloud Market Grows with Demand for High-Performance Hosting Solutions As Revealed In New Report - WhaTech - May 19th, 2024
- Ahrefs Joins Others in Suggesting That On-Premises Hosting Can Be More Cost Effective than Cloud - InfoQ.com - May 19th, 2024
- St. Cloud's Rainbow Wellness Collective Hosting Series of Events - WJON News - March 20th, 2024
- Safe in the Cloud: A Deep Dive Into Hosting Security Measures - AppleMagazine - February 11th, 2024
- Why Peachtree Cloud Hosting Is The Future Of Streamlined Accounting - WhaTech Technology and Markets News - January 13th, 2024
- Unravelling The Secrets Of Sage 50 Cloud Hosting: Everything You Need To Know - WhaTech Technology and Markets News - January 13th, 2024
- Gift a Blogger, Student, or Professional a Lifetime of Cloud Web Hosting With iBrave, Now Only $40 - PCMag - December 26th, 2023
- These are the factors you need to take into account for Cloud hosting - TechiExpert.com - December 26th, 2023
- Andrew Lobel: Tech Luminary's Perspective On Cloud Hosting And AWS Lightsail's Prowess - Business Manchester - December 18th, 2023
- Hostereo revolutionizes cloud hosting with user-centric solutions, Powered by Interhost B.V. - NL Times - December 10th, 2023
- What Are The Advantages and Drawbacks of Cloud Hosting and ... - Analytics Insight - November 24th, 2023
- Cloud Computing Hosting Service Market 2031 Insights with Key Innovations Analysis | Leading Companies Acce... - SeeDance News - October 17th, 2023
- Multi Cloud Hosting and its Impact on Businesses - Digital Journal - April 26th, 2023
- What is cloud hosting and how do you use it? - TechRadar - April 26th, 2023
- How QuickBooks Hosting on the Cloud Server Helps Businesses in ... - Universe News Network - April 26th, 2023
- Mayor of St. Cloud Hosting State of the City Address - KVSC-FM News - April 18th, 2023
- Moro Hub join hands with Indias Cloud4C to offer cloud hosting ... - Arabian Business - March 25th, 2023
- Build unlimited sites with this $86 cloud-based web hosting - Cult of Mac - March 25th, 2023
- The role of cloud hosting in digital transformation and cloud computing - HostReview.com - March 9th, 2023
- [Webinar] Cloud Utility Pricing: Reduce Hosting Costs and Go Green ... - JD Supra - March 1st, 2023
- Features of Cloud Hosting Services Offered By Hosting Companies - HostReview.com - March 1st, 2023
- Cloud Hosting Contracts | Freedom of Information - Ordnance Survey - February 21st, 2023
- Cost Comparison of Cloud Hosting vs Traditional Hosting: What You ... - HostReview.com - February 13th, 2023
- Google hosting in-person Cloud Next 23 this August - 9to5Google - February 5th, 2023
- Agreement inked to provide cloud, hosting services at Musandam ... - Times of Oman - January 28th, 2023
- St. Cloud State Huskies have ended their losing streak after 0-2 vs ... - The Rink Live - January 28th, 2023
- Rise in Cyber Attacks Expected in 2023: Passwords and Cloud ... - TECH dot AFRICA - January 28th, 2023
- How to Find the Best Web Host for Your Business - The Yucatan Times - January 28th, 2023
- Here Are 2 Technology Stocks of the Future You Can Buy Today - The Motley Fool - January 28th, 2023
- What is PSaaS and is it Worthwhile? - Security Boulevard - January 28th, 2023
- Business was always a way of serving people - New Hampshire Business Review - January 28th, 2023
- Squire Patton Boggs assists in the acquisition of Sered - Iberian Lawyer - January 28th, 2023
- Whats Ahead for the Future of Data Streaming? - DevOps.com - January 28th, 2023
- How to create a new project in the self-hosted version of Orangescrum - TechRepublic - January 28th, 2023
- The Global Access Control as a Service (ACaaS) Market size is expected to reach $2.3 billion by 2028, rising at a market growth of 15.0% CAGR during... - January 28th, 2023
- Amazon wanted to discuss opportunities for fine-tuning NZs policy ... - New Zealand Herald - January 28th, 2023
- 3 Reasons Why Wall Street Analysts Think Amazon Stock Could ... - The Motley Fool - January 28th, 2023
- OnePlus Cloud 11 launch event: Heres everything OnePlus is launching in India on February 7 - Times Now - January 28th, 2023
- Auckland's giant new data centres - and the power they'll chug - New Zealand Herald - January 28th, 2023
- Octo Consulting Group, Inc. | U.S. - Government Accountability Office - January 28th, 2023
- The Venture Leaders Mobile 2023 kick off their roadshow to the ... - Venturelab - January 28th, 2023
- Demand for Server Virtualization Software Rises as Cloud and OS Technologies Proliferate: Fact.MR Exclusive Analysis - Yahoo Finance - January 20th, 2023
- Sabre CIO on the impact of cloud in travel - PhocusWire - January 20th, 2023
- cPanel Partners With CloudFest to Bring CloudFest USA Back to ... - InvestorsObserver - January 20th, 2023
- Basecamp details 'obscene' $3.2 million bill that caused it to quit the cloud - The Register - January 20th, 2023
- Microsoft set to make 5% of workforce redundant - Information Age - January 20th, 2023
- Who Owns the Generative AI Platform? - Andreessen Horowitz - January 20th, 2023
- 3 Warren Buffett Stocks That Could Soar 33% to 80% in 2023 ... - The Motley Fool - January 20th, 2023
- Earth Bogle: Campaigns Target the Middle East with Geopolitical ... - Trend Micro - January 20th, 2023
- Many businesses are set to spend big to raise their security game - TechRadar - January 20th, 2023
- Nvidia and 2 Other Stocks That Could Be Helped or Hurt by ChatGPT - Barron's - January 20th, 2023
- ESGold Welcomes Mr. Pierre-Olivier Mathys to its Advisory Board - TheNewswire.ca - January 20th, 2023
- How Has the Ramsar Convention Shaped China's Wetland ... - Sixth Tone - January 20th, 2023
- Chengdu Science Fiction Museum by Zaha Hadid Architects to host ... - Archilovers.com - January 20th, 2023
- Why I Bought This Promising Cloud Computing Stock - The Motley Fool - January 4th, 2023
- Brighton cloud company bringing 100 new skilled jobs to city - The Argus - January 4th, 2023
- Apache Iceberg promises to change the economics of cloud-based data analytics - The Register - January 4th, 2023
- MSP vs Vms: What Are the Differences? - StartupGuys.net - January 4th, 2023
- 5 Unstoppable Metaverse Stocks to Buy in 2023 - The Motley Fool - January 4th, 2023
- Top 10 Middle East IT stories of 2022 - ComputerWeekly.com - January 4th, 2023
- Potential cloud protests and maybe, finally, more JADC2 jointness ... - Breaking Defense - January 4th, 2023
- Double Down On Innovation With Edge Computing | - Spiceworks News and Insights - December 27th, 2022
- Simplifying digital sovereignty in a multi-cloud world - The Register - December 27th, 2022
- The Global IT Services Market size is expected to reach $2,013.6 billion by 2028, rising at a market growth of 8.4% CAGR during the forecast period -... - December 27th, 2022
- St. Cloud hockey games scheduled in honor of player killed in crash - SC Times - December 27th, 2022
- 2 Metaverse Stocks That Could Make You Richer in 2023 - The Motley Fool - December 27th, 2022
- EDNS inks a partnership deal with Alibaba Cloud to explore the ... - PR Newswire - December 27th, 2022
- Looking for a Surefire Winner in the Next Bull Market? Buy Amazon ... - The Motley Fool - December 27th, 2022
- Bank of England mulls future regulatory oversight over Ethereum ... - Ledger Insights - December 27th, 2022