For all the flexibility and cost management upsides to hybrid, multicloud IT infrastructure, there is a major trade-off: The complexity of the environment breeds security issues. Challenges include a lack of visibility, an expansive attack surface, and governance and data protection hurdles, among other things.
What’s the answer? The dynamic nature of hybrid and multicloud calls for a robust security game plan and a centralized cloud management platform that works across chosen clouds. Foundry reached out to the CIO Experts Network, a community of IT professionals and technology industry influencers, to get their perspective on hybrid, multicloud security. This includes insights and recommendations for tightening up controls and delivering resiliency to an ever-expanding and increasingly diverse IT landscape.
“For all the good hybrid and multicloud presents to a business, the risks only increase when it comes to securing these platforms due to their complexity and distributed nature,” notes Alex Farr (@AlexFarr_IT), chief technology officer at Christie Group. “The attack surface becomes vast and monitoring, governing, and protecting data becomes much more challenging.”
IT leaders must first get a handle on the totality of potential exposure, including both internal and external points where vulnerabilities could exist or where an attacker is likely to target. APIs, public-facing websites, and authentication pages that are part of core business processes and transactions should be evaluated for potential vulnerabilities. Secure file transfer processes, unsecured cloud storage, and the management and rotation of encryption keys are under-policed areas where companies often increase the risk of exposure without knowing, notes Sawan Joshi, founder of TriStep.io.
The lack of expertise in the targeted cloud environments, coupled with poor cross-platform visibility and limited knowledge about cloud ecosystem compatibility, are additional complicating factors, says Elitsa Krumova (@Eli_Krumova), a global thought leader and tech influencer. IT leaders need to marshal the full complement of security controls to help manage risks while implementing best practices, including regular security audits and continuing assessment of risks and vulnerabilities.
A holistic security plan
As part of a holistic security strategy for hybrid and multicloud environments, it’s essential to encrypt data at rest and in transit. This includes implementing robust logging and monitoring solutions that provide real-time visibility into end-to-end infrastructure, along with Data Loss Prevention (DLP) solutions to effectively monitor and control the movement of sensitive information. A centralized Identity and Access Management (IAM) solution is another critical part of the stack to manage user IDs and permissions consistently across all cloud environments. Other key measures include single sign-on (SSO) capabilities and a Security Information and Event Management (SIEM) solution for real-time analysis of security alerts across platforms.
Cultivating an incident response plan and dedicating a cloud team to conduct security testing and patching are best practices that need to become part of the mix. “Incident response and forensics remain challenging even after teams become comfortable operating in their new environment,” notes Will Kelly (@willkelly), a writer focused on DevOps and the cloud. “Your IT and security teams must develop and regularly test an incident response plan that spans all your cloud environments.”
Adopting least privileged access in each environment and introducing an AI for IT Operations (AIOps) capability will help IT teams manage cloud environments effectively and securely around the clock, says Kieran Gilmurray (@KieranGilmurray), CEO at Digital Automation and Robotics Limited.
Paradigm shifts in the workplace – a propensity for working from home as well as bringing your own device (BYOD) – have erased the traditional “perimeter” long used to safeguard corporate networks. Now, a zero trust architecture (ZTA) model is essential for securing hybrid and multicloud environments, says Dipti Parmar (@dipTparmar), chief strategist at Dipti Parmar Consulting and co-founder at 99stairs. “The more granular security you have, the more doors you close to attackers,” Parmar says. “A GUI or console that presents a single pane of glass to manage all resources, assets, and services in the entire cloud environment is another must-have for administrators to successfully manage data storage, operations, and security.”
Adoption of FinOps capabilities for cost management helps bring cohesion and consistency across diverse clouds while helping to establish visibility and accountability for cloud expenses. “Organizations planning or already in hybrid or multicloud environments should invest in FinOps capabilities and establish cloud governance to instill discipline and data-driven decision-making around cloud architectures,” advises Isaac Sacolick (@nyike), president of StarCIO and author of Digital Trailblazer.
As the plan comes together, consistency is key. “Extending control from on-premises systems to the cloud ensures uniform protection,” explains Gene De Libero (@GeneDeLibero), principal at Digital Mindshare LLC. “A solid data security strategy, including encryption and access controls and managing data throughout its lifecycle, is vital.”
For many companies, the biggest cloud security challenge is knowing exactly who is responsible for what level of security. “When it comes to cloud it’s a shared responsibility, but many people believe the cloud provider does it all,” says Ben Rothke, (@benrothke), senior information security manager at Tapad. Rothke advises companies to check the providers’ responsibility matrix, an accessible document that clarifies who exactly is responsible for specific security tasks.
Finally, employee training and cybersecurity awareness are a must, yet they are often overlooked or underplayed. “Phishing attacks continue to evolve and pose a significant security risk to every organization,” says Scott Schober (@ScottBVS), president and CEO at Berkeley Varitronics Systems Inc. “You need to keep in mind there are human factors and errors that can lead to misconfigurations.”
Click here for more information on Cisco’s security solutions.
Simplify complexity and make better decisions to secure your enterprise. Speak to a specialist to get the details on Cisco Cloud Protection.
