June 18, 2018 By Scott McAvoy 3 min read

I joined a number of security professionals at the IBM Security Summit in London last month during the “Innovating With Cloud Security” breakout session, which was hosted by Martin Borrett, chief technology officer (CTO) of IBM Security Europe. The audience took part in discussions about typical cloud transformation journeys, security for and from the cloud, development operations (DevOps) disruption of enterprise security and regulatory expectations.

Audience polls discovered that all of the attendees use cloud services in their business — and the majority use the public multi-cloud. (This is also true for our working environment at IBM.) The audience also reflected our past experiences with polar business attitudes toward security in the cloud. For example, the assumption that the cloud is too insecure for use in the enterprise, or (just the opposite) that security is automatically built into cloud platforms.

What’s more, less than 10 percent of the audience had a formal strategy supported by policies and procedures for security in the cloud.

Cloud Security: For vs. From

It’s essential to distinguish security for the cloud (which protects cloud workloads) and security from the cloud (which safeguards other cloud workloads or on-premises infrastructure and applications).

Examples of security for the cloud include native and off-the-shelf products for identity and access management (IAM), patching and data encryption. Security-as-a-service (SECaaS) offerings for security information and event management (SIEM), IAM and vulnerability and application scanning are examples of security from the cloud.

Regulatory Requirements and the Cloud

Though enterprise workloads are often modified to adapt to the cloud, the standards, regulations and legislation that govern these workloads won’t necessarily change. Where compliance has been achieved in on-premises environments, organizations must assess policies, procedures and controls to determine whether they are still required and (if so) whether they are implemented effectively.

Auditors, in particular, will expect security leaders to account for data sovereignty, IAM, auditability, availability, data classification, encryption, incident management and response and business continuity in the context of the cloud.

Map Your Cloud Transformation Journey

During the breakout session, we talked about the transformation contexts of migrating workloads to the cloud, cloud-native and hybrid cloud. Migration and hybrid were the most popular approaches in the room, in addition to a general desire to move toward cloud-native.

We recommend conducting a current state security assessment and mapping exercise to translate it to the cloud, as well as developing a cloud security strategy. Where security policies, procedures and controls are already documented, refresh these with the cloud environment in mind. Also, look for how the cloud environment can be used to improve, streamline or automate your security enforcing functions. This is particularly true of cloud-native, but it applies to migration and hybrid too.

Infusing Cloud Security Into DevOps

The cloud has enabled new ways of working, including tightly integrated development and operation teams and processes. DevOps has taken advantage of the cloud to enable continuous delivery.

In many cases, DevOps engineers have direct access to cloud environments and are in a position to make and implement business-changing decisions. We need to integrate security into DevOps to take advantage of cloud and deliver security. Developers write application code and operations staffers write infrastructure-as-code (IaC). We need to get in line with this and demonstrate how security-as-code can be part of this process and how a culture of security can help DevOps teams think and behave like security professionals. This will enable us to organically move security to the left within our organizations.

Different Techniques, Same Outcomes

Across everything we discussed, one thing hasn’t changed: the security outcomes we’re aiming to achieve. We’re all using different techniques, implementing more automation and achieving greater efficiency and faster improvements — but all in the name of the same outcomes.

If we change the way we think about security delivery, we can not only secure our cloud workloads, but also drive support for the enterprise as a whole as it transforms to a cloud business.

Read the interactive white paper: One for All — New Parity for Your Enterprise Security

More from Cloud Security

2024 Cloud Threat Landscape Report: How does cloud security fail?

4 min read - Organizations often set up security rules to help reduce cybersecurity vulnerabilities and risks. The 2024 Cost of a Data Breach Report discovered that 40% of all data breaches involved data distributed across multiple environments, meaning that these best-laid plans often fail in the cloud environment.Not surprisingly, many organizations find keeping a robust security posture in the cloud to be exceptionally challenging, especially with the need to enforce security policies consistently across dynamic and expansive cloud infrastructures. The recently released X-Force…

Cloud threat report: Why have SaaS platforms on dark web marketplaces decreased?

3 min read - IBM’s X-Force team recently released the latest edition of the Cloud Threat Landscape Report for 2024, providing a comprehensive outlook on the rise of cloud infrastructure adoption and its associated risks.One of the key takeaways of this year’s report was focused on the gradual decrease in Software-as-a-Service (SaaS) platforms being mentioned across dark web marketplaces. While this trend potentially points to more cloud platforms increasing their defensive posture and limiting the number of exploits or compromised credentials that are surfacing,…

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today