{"id":3234,"date":"2024-04-23T15:47:27","date_gmt":"2024-04-23T20:47:27","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/5-hard-truths-about-the-state-of-cloud-security-2024"},"modified":"2024-04-23T15:47:27","modified_gmt":"2024-04-23T20:47:27","slug":"5-hard-truths-about-the-state-of-cloud-security-2024","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/04\/23\/5-hard-truths-about-the-state-of-cloud-security-2024\/","title":{"rendered":"5 Hard Truths About the State of Cloud Security 2024"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blta42700bbb6bb2cac\/66270d51810cc88d48a28e52\/truth-Diego_Schtutman-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While cloud security has certainly come a long way since the wild west days of early cloud adoption, the truth is that there&#8217;s a long way to go before most organizations today have truly matured their cloud security practices. And this is costing organizations tremendously in terms of security incidents.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.illumio.com\/resource-center\/cloud-security-index-2023\" rel=\"noopener\">A Vanson Bourne study<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> earlier this year showed that almost half of breaches suffered by organizations in the past year originated in the cloud. That same study found that the average organization lost almost $4.1 million to cloud breaches in the last year.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dark Reading recently caught up with the godfather of zero trust security, John Kindervag, to discuss the state of cloud security today. When he was an analyst at Forrester Research, Kindervag helped conceptualize and popularize the zero trust security model. Now he&#8217;s chief evangelist at Illumio, where amid his outreach he&#8217;s still very much a proponent for zero trust, explaining that it is a key way to redesign security in the cloud era. According to Kindervag, organizations must deal with the following hard truths in order to achieve success with this.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"1. You Don't Become More Secure Just by Going to the Cloud\">1. You Don&#8217;t Become More Secure Just by Going to the Cloud<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One of the biggest myths today about the cloud is that it is innately more secure than most on-premises environments, Kindervag says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;There&#8217;s a fundamental misunderstanding of the cloud that somehow there&#8217;s more security natively built into it, that you&#8217;re more secure by going to the cloud just by the act of going to the cloud,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The problem is that while hyperscale cloud providers may be very good at protecting infrastructure, the control and responsibility over their customer&#8217;s security posture they have is very limited.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;A lot of people think they&#8217;re outsourcing security to the cloud provider. They think they&#8217;re transferring the risk,&#8221; he says. &#8220;In cybersecurity, you can never transfer the risk. If you are the custodian of that data, you are always the custodian of the data, no matter who&#8217;s holding it for you.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is why Kindervag is not a big fan of the oft-repeated phrase &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/shouldering-the-increasingly-heavy-cloud-shared-responsibility-model\" rel=\"noopener\">shared responsibility<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; which he says makes it sound like there&#8217;s a 50-50 division of labor and effort. He prefers the phrase &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/rackspace-strengthens-its-managed-security-story\" rel=\"noopener\">uneven handshake<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; which was coined by his former colleague at Forrester, James Staten.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;That is the fundamental problem, is that people think that there&#8217;s a shared responsibility model, and there&#8217;s an uneven handshake instead,&#8221; he says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"2. Native Security Controls Are Hard to Manage in a Hybrid World\">2. Native Security Controls Are Hard to Manage in a Hybrid World<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, let&#8217;s talk about those improved native cloud security controls that providers have built up over the past decade. While many providers have done a good job offering customers more control over their workloads, identities, and visibility, that quality is inconsistent. As Kindervag says, &#8220;Some of them are good, some of them aren&#8217;t.&#8221; The real problem across all of them is that they&#8217;re hard to manage out in the real world, beyond the isolation of a single provider&#8217;s environment.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It takes a lot of people to do it, and they&#8217;re different in every single cloud. I think every company that I&#8217;ve talked to in the past five years has a multicloud and a hybrid model, both happening at the same time,&#8221; he says. &#8220;Hybrid being, &#8216;I&#8217;m using my on-premises stuff and clouds, and I&#8217;m using multiple clouds, and I may be using multiple clouds to deliver access to different microservices for a single application.&#8217; The only way that you can solve this problem is to have a security control that can be managed across all the multiple clouds.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is one of the big factors driving discussions about moving zero trust to the cloud, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Zero trust works no matter where you put data or assets. It could be in the cloud. It could be on-premises. It could be on an endpoint,&#8221; he says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"3. Identity Won't Save Your Cloud\">3. Identity Won&#8217;t Save Your Cloud<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With so much emphasis placed on cloud identity management these days, and disproportionate attention on the identity component in zero trust, it&#8217;s important for organizations to understand that identity is only part of a well-balanced breakfast for zero trust in the cloud.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;So much of the zero trust narrative is about identity, identity, identity,&#8221; Kindervag says. &#8220;Identity is important, but we consume identity in policy in zero trust. It&#8217;s not the end-all, be-all. It doesn&#8217;t solve all the problems.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">What Kindervag means is that with a zero trust model, credentials don&#8217;t automatically give users access to anything under the sun within a given cloud or network. The policy limits exactly what and when access is given to specific assets. Kindervag has been a longtime proponent for segmentation \u2014 of networks, workloads, assets, data \u2014 long before he began mapping out the zero trust model. As he explains, the heart of defining zero trust access by policy is divvying up things into &#8220;protect surfaces,&#8221; since the risk level of different kinds of users accessing each protect surface will define the polices that will be attached to any given credential.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;That&#8217;s my mission, is to get people to focus on what they need to protect, put that important stuff into various protect surfaces, like your PCI credit card database should be in its own protect surface. Your HR database should be in its own protect surface. Your HMI for your IoT system or OT system should be in its own protect surface,&#8221; he says. &#8220;When we break up the problem into these small bite-sized chunks, we solve them one chunk at a time, and we do them one after another. It makes it much more scalable and doable.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"4. Too Many Firms Don't Know What They're Trying to Protect\">4. Too Many Firms Don&#8217;t Know What They&#8217;re Trying to Protect<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As organizations decide how to segment their protect surfaces in the cloud, they first need to clearly define what it is that they&#8217;re trying to protect. This is crucial because each asset or system or process will carry its own unique risk, and that will determine the policies for access and the hardening around it. The joke is that you wouldn&#8217;t build a $1 million vault to house a few hundred pennies. The cloud equivalent to that would be putting tons of protection around a cloud asset that&#8217;s isolated from sensitive systems and doesn&#8217;t house sensitive information.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kindervag says it is incredibly common for organizations to not have a clear idea of what they&#8217;re protecting in the cloud or beyond. In fact, most organizations today don&#8217;t even necessarily have a clear idea of what it is that is even in the cloud or what connects to the cloud, let alone what needs protecting. For example, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/cloudsecurityalliance.org\/artifacts\/the-state-of-security-remediation-survey-report\" rel=\"noopener\">a Cloud Security Alliance study<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> shows that only 23% of organizations have full visibility into cloud environments. And the Illumio study from earlier this year shows that 46% of organizations don&#8217;t have full visibility into the connectivity of their organization&#8217;s cloud services.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;People don&#8217;t think about what they&#8217;re actually trying to accomplish, what they&#8217;re trying to protect,&#8221; he says. This is a fundamental issue that causes companies to waste a lot of security money without appropriately setting up protection in the process, Kindervag explains. &#8220;They&#8217;ll come to me and say &#8216;Zero trust isn&#8217;t working,&#8217; and I&#8217;ll ask, &#8216;Well, what are you trying to protect?&#8217; and they&#8217;ll say, &#8216;I haven&#8217;t thought about that yet,&#8217; and my answer is &#8216;Well, then you&#8217;re not even close to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/zero-trust-takes-over-63-percent-of-orgs-implementing-globally\" rel=\"noopener\">beginning the process of zero trust<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.'&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"5. Cloud Native Development Incentives Are Out of Whack\">5. Cloud Native Development Incentives Are Out of Whack<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">DevOps practices and cloud native development have been greatly enhanced through the speed, scalability, and flexibility afforded them by cloud platforms and tooling. When security is appropriately layered into that mix, good things can happen. But Kindervag says that most development organizations are not properly incentivized to make that happen \u2014 which means that cloud infrastructure and all of the applications that rest upon it are put at risk in the process.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I like to say that the DevOps app people are the Ricky Bobbys of IT. They just want to go fast. I remember talking to the head of development at a company who eventually got breached, and I was asking him what he was doing about security. And he said, &#8216;Nothing, I don&#8217;t care about security,'&#8221; Kindervag says. &#8220;I asked, &#8216;How can you not care about security?&#8217; and he says &#8216;Because I don&#8217;t have a KPI for it. My KPI says I have to do five pushes a day in my team, and if I don&#8217;t do that, I don&#8217;t get a bonus.'&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kindervag says this is an illustration of one of the big problems, not just in AppSec, but in moving to zero trust for the cloud and beyond. Too many organizations simply do not have the right incentive structures to make it happen \u2014 and in fact many have perverse incentives that end up encouraging insecure practice.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is why he&#8217;s an advocate for building up zero trust centers of excellence within enterprises that include not just technologists but also business leadership in the planning, design, and ongoing decision-making processes. When these cross-functional teams meet, he says, he&#8217;s seen &#8220;incentive structures change in real time&#8221; when a powerful business executive steps forward to say the organization is going to move in that direction.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The most successful zero trust initiatives were the ones where business leaders got involved,&#8221; Kindervag says. &#8220;I had one in a manufacturing company where the executive vice president \u2014 one of the top leaders of the company \u2014 became a champion for zero trust transformation for the manufacturing environment. That went very smoothly because there were no inhibitors.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/5-hard-truths-about-the-state-of-cloud-security-2024\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>While cloud security has certainly come a long way since<\/p>\n","protected":false},"author":12,"featured_media":3235,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3234","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?fit=1800%2C1012&ssl=1",1800,1012,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?fit=1800%2C1012&ssl=1",1800,1012,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/5-hard-truths-about-the-state-of-cloud-security-2024.jpg?fit=1800%2C1012&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3234","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3234"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3234\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3235"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}