Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

6/16/2017
03:40 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Forrester: Rapid Cloud Adoption Drives Demand for Security Tools

Cloud services revenue is poised to skyrocket from $114 billion in 2016 to $236 billion by 2020, driving the market for products to secure data in the cloud.

The global cloud services market is poised to skyrocket from $114 billion in 2016 to $236 billion by 2020. Its rapid growth is driving the market for cloud security tools, which will increase from $1 billion in 2016 to $3.5 billion in 2021.

Researchers at Forrester recently published the Cloud Security Solutions Forecast, which includes predictions of how the market for products like cloud access security brokers (CASBs), centralized cloud security management (CCSM), hypervisor security, and infrastructure-as-a-service and platform-as-a-service will grow over the next five years.

Businesses are moving more analytics and core businesses applications to the public cloud, driven by the flexibility it provides. While public cloud providers run data centers more efficiently and securely than tech managers would, cloud security is still a major concern.

Traditional security tools aren't enough to monitor data moving to and from the cloud, and between cloud platforms. Forrester found the cloud security market will grow 28% each year from 2016 to 2021 as the cloud grows in complexity and more security is needed.

Andras Cser, vice president and principal analyst for security and risk management at Forrester, says there are two key elements increasing cloud complexity. The cloud is a changing and moving target to secure, for one, and on-premise technologies aren't as effective in the cloud.

Public, private, and hybrid cloud all coexist and serve different needs and applications, the report states. More people are using sanctioned and unsanctioned cloud applications, sending data inside and outside the organization.

"Shadow IT causes a lot of concern," says Cser. Businesses are worried about the complications of monitoring data in the cloud. "If you don't understand what applications you're using, and the data in those applications, you can't understand the risks."

Data security is one of the top drivers of cloud security spend, especially the complications of monitoring data across cloud applications. Other factors include conversion from on-premise to hybrid cloud, data loss prevention, identity and access management, and compliance.

"There's a lot more concern around data security," he explains. "Companies are showing markedly more interest. Breaches are increasing, and we've seen a lot of internal security guidelines becoming more stringent."

Businesses are also recognizing a lack of good key management among cloud providers, he says. As a result, they're willing to spend more money, resources, and time on management. Many are realizing the need to automate security as they move workloads to the cloud.

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

Forrester found the growth of software-as-a-service (SaaS) as slowed, but infrastructure-as-a-service (IaaS) and platform-as-a-service (PaaS) are both seeing aggressive growth. More than 50% of security leaders are worried about the risk of SaaS, PaaS, IaaS, and virtualization in the data center.

More businesses are using multiple IaaS cloud providers as individual providers don't offer cross-platform security support, the report explains. For example, for AWS users, it's not easy to enable centralized security management for workloads in clouds outside AWS.

About half of security leaders prefer to use third-party security vendors to protect their SaaS and IaaS operations. Forrester found that many believe if the cloud provider gets hacked, their data is useless to hackers who have no access to the encryption keys.

"In the last two years, native IaaS and PaaS security have become an increasingly important part of the cloud security ecosystem," says Jennifer Adams, Forrester senior forecast analyst focusing on business technology and ecommerce. This is the first time IaaS and PaaS have been included in this forecast, she says, and they make up the report's fastest-growing segment.

It's worth noting that cloud tools aren't enough to fully defend against security problems.

"Solutions and technical capabilities won't solve all the problems by themselves," says Cser, noting that people and processes are also important. Technology aside, security teams must think about governance, training, communication, recertification, and vendor selection.

"I think it's improving, and people are recognizing many areas may be falling short of requirements," he continues. Cser advises businesses to take steps toward cloud security with privileged identity management, risk assessments, and data classification and discovery.

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "He's too shy to invite me out face to face!"
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17789
PUBLISHED: 2019-09-20
Prospecta Master Data Online (MDO) allows CSRF.
CVE-2019-11280
PUBLISHED: 2019-09-20
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote authenticated user can gain ...
CVE-2019-11326
PUBLISHED: 2019-09-20
An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product is protected by a login. A guest is allowed to login. Once logged in as a guest, an attacker can browse a URL to read the password of the administrative user. The same pro...
CVE-2019-11327
PUBLISHED: 2019-09-20
An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product has a local file inclusion vulnerability. An attacker with administrative privileges can craft a special URL to read arbitrary files from the device's files system.
CVE-2019-14814
PUBLISHED: 2019-09-20
There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.