Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

1/18/2017
10:30 AM
Bill Kleyman
Bill Kleyman
Commentary
Connect Directly
Facebook
Twitter
LinkedIn
Google+
RSS
E-Mail vvv
50%
50%

Cloud Security & IoT: A Look At What Lies Ahead

In the brave new world of cloud, security teams must be as agile as possible. This means leveraging proactive monitoring tools, locking down access points, and forecasting requirements

In the cloud – just as in the physical world – the evolving threat dynamic is moving beyond services, users, and applications to new attack targets in the Internet of Things ranging from CCTV installations, refrigerators – and possibly even drones. This new paradigm will present many challenges for organizations; consider this, Gartner recently predicted that by 2018, 25% of corporate data traffic will flow directly from mobile devices to the cloud, bypassing enterprise security controls.

So, what does this mean for the modern organization? Where should companies be focusing their efforts when working to secure their cloud and IT environments? The new digital challenge is that our configurations and workloads will be at risk, requiring out-of-the-box thinking and new security strategies. Here are four examples of what I mean:

Greater Focus on Endpoints and Users
We all remember the good old days of traditional AV. We’re pretty far beyond that now with the next-generation of new endpoint protection (EPP) and endpoint detection and response (EDR) systems. This will require advanced capabilities around sandboxing, cloud integration, and intelligent threat analytics that offer new ways to secure users, your mobile environment, and how data interacts with endpoints.

Companies like Trend Micro, CrowdStrike, CarbonBlack, and others fall into the EPP/EDR market. They’ve introduced a new generation of endpoint security that integrates with overall managed security solutions and utilize machine-learning capabilities and security artificial intelligence to look into malformed files, deep metadata analytics, and even powerful offline capabilities. This helps mobile users leveraging a variety of devices to be secure and still consume digital content from their organizations.

Security Automation and Orchestration
Automated IT systems you can incorporate into your security architectures will be a big business in 2017 and beyond. With security workflow automation, you can intelligently control massive settings and environment changes encompassing multiple data centers and global locations. In other words, instead of manual process and configurations, you can use automation tools to ensure you have the right security policies in place. The great impact here is that you can have heterogeneous security systems all automatically managed by a single system.

The other big automation security control factor revolves around users. Today, there are powerful user-control automation systems which can integrate with human resource and business processes. I often see organizations working with hundreds, sometimes thousands, of contacts. Managing user identities isn’t always easy – and many times it’s a very manual process. This needs to stop. Rogue accounts, lost users, misconfigured permissions, and forgotten access controls are ALL security holes. Today’s automation software tools allow organizations to onboard and offboard entire subsets of users. Plus, they will integrate with HR systems and even alert administrators as well as HR when new users are created or removed.

Internal Security Lifecycle Management
This falls into the manual category of security control. New tools around security event and information management (SIEM) give administrators a lot more control around their security ecosystem. Remember, it’s not just a firewall any longer. We have app firewalls, security analytics, network forensics and intelligence, and a lot of other tools helping keep our infrastructure secure. Aggregating logs and events is going to be critical to catch problems before they become major issues. Furthermore, you’ll be able to control updates, patches, and see which systems need to be updated. Even in large organizations, you can still find old Cisco or Juniper devices which haven’t patched in ages. How much do you know about what’s going in your cloud ecosystem?

Testing, cloud-to-cloud security, and file watermarking
Cloud and virtualization have made it much easier to test out new types of security systems. If you’re planning on new cloud deployments or are working with an expanding data footprint, it’s critical for you to look at new technologies aimed at new wave IT initiatives that help with cloud vulnerability management, compliance, visibility, app security, and even penetration testing. There are other technologies that will interrogate the requesting source, and help further lock down data being sent down via authentication, watermarking, and advanced access rights management. The point is that emerging security technologies are specifically taking aim at new types of cloud and physical threats. Don’t be afraid to test out these systems or work with a partner to help guide the way.

At the end of the day, my biggest piece of advice is for organizations to remain agile with your cloud security. This means leveraging proactive monitoring tools, locking down access points and forecasting requirements. No environment will ever be 100% safe. Your goal should be to create as much visibility into your environment you can, and have contingency plans for as many security events as possible.

Related Content:

 

  Bill Kleyman brings more than 15 years of experience to his role as Executive Vice President of Digital Solutions at Switch. Using the latest innovations, such as AI, machine learning, data center design, DevOps, cloud and advanced technologies, he delivers solutions ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5118
PUBLISHED: 2019-11-18
A Security Bypass Vulnerability exists in TBOOT before 1.8.2 in the boot loader module when measuring commandline parameters.
CVE-2019-12422
PUBLISHED: 2019-11-18
Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.
CVE-2012-4441
PUBLISHED: 2019-11-18
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.
CVE-2019-10764
PUBLISHED: 2019-11-18
In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which m...
CVE-2019-19117
PUBLISHED: 2019-11-18
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter.