How Cloud Native Delivers Security, Governance and Trust in Finance | Cloud Native Now 2023
Trust is crucial for financial institutions, especially for attracting and retaining customers and providing a competitive edge; security and governance are the foundations of banking operations.
New cloud-native tools and practices, like DevSecOps, are automating and enhancing security and compliance. The integration of application developers in security as part of DevSecOps initiatives can further boost security and compliance. GitOps and policy-as-code paired with advanced application delivery methods shift security left and accelerate innovation.
Join AWS solutions expert Andrew Park and security transformation lead Joe Dahlquist at Weaveworks to hear how they jointly solved security, governance and compliance challenges for two of the top 10 global financial institutions.
Transcript
Welcome everybody. Uh, I'm lucky to have Andrew from a w s with me. He's a senior solutions architect at, uh, aws.
I'm Joe Quist, VP of Marketing at WeWorks. Today we're talking about Cloud native and how you can deliver security governance and trust to highly regulated companies like those in finance and big banks. Just get right on into it.
So highly regulated industries like banking and others are, uh, always the target of cyber crime. Um, you know, end to end, insider threats, external threats, advanced threats, nation state threats. I mean, it is nonstop work for, uh, security operations teams and DevSecOps teams at organizations like this.
Um, you know, the highest stakes are, are, are, uh, in place for things like human error and misconfiguration. Um, it's not just that an app might not work right, or that a pixel won't be perfect. It really comes down to, um, people's lives, their livelihoods, the money that they have in their bank, their life savings, their mortgages, uh, their loans, their credit cards, the the stakes are have, are never higher than when it comes to financial institutions dealing with these kinds of risks.
Um, and they're all on a journey to try and reduce this risk and shift security left, um, make it integral to the things that they do and, and the products that they build. Um, but it's a, it's a really challenging situation. Uh, Andrew, I'm sure that you've run into a lot of customers that struggle with these kinds of situations, uh, that are AWS customers.
Yeah, absolutely. And what I'd say there is, you know, when we talk about building a secure strategy for highly regular industries, there's so many different components that build a sound and secure strategy that sometimes easy to forget, you know, a thing or two when you're actually building that out for your organization. So yeah, absolutely would absolutely agree there.
So all of these companies are trying to undergo some form of digital transformation. Um, and we've been lucky enough to work with a w s, uh, and two of the top 10 largest financial firms in the world. And these financial firms wanted to reduce the risk that they undertook while going through this digital transformation phase.
Some things that were, uh, absolutely required and not optional, uh, were security and compliance, um, but also maintaining speed and, and, and business, um, uh, efficiency, while also being secure and compliant and also being highly reliable and being able to kind of plan for a secure future. Um, they found with, uh, Amazon, and we've worked a solution that allowed them to kind of standardize on a w s and use e k s, uh, cuddle, which is based on flux cd some, uh, work that we've worked has, has been, uh, putting forth for, for years now. And together we've been able to make it easy for them to deploy Kubernetes, um, to manage and, and stand up clusters that are, uh, trusted, secure, compliant, auditable, and being able to do that all with relative ease compared to, you know, the difficulty that some organizations have managing, uh, containers.
So we picked three things that we wanted to talk about, Andrew and I, in terms of kind of the secret sauce that these large, uh, financial institutions and other regulated industries have at their fingertips and can leverage to be able to accomplish this right, uh, scale and growth while being secure and compliant. The first, um, is what we call runtime security. And although, you know, it's a stack and there's a lot of responsibility that gets shared between the customer, between the infrastructure, between the code that they're building, um, you know, all bets are off when things go live in production, and that's when things really get critical.
Um, Andrew, how does AWS help secure the runtime environment for companies like, you know, the world's largest banks? Yeah, absolutely. And so I think to provide some context, when we talk about runtime security, there's really two core components when we talk about runtime security specifically, right?
So you have runtime monitoring, so basically getting alerted when there is a runtime threat that gets deployed into your containers environments. And then there's runtime remediation, right? So once a threat or alert goes off, um, what steps can my organization take to actually address that particular vulnerability or that alert that may have went off in my environment, right?
So I think those two things, um, are two different things that ultimate build up a secure runtime strategy. And so there's a, a handful of options in AWS that we recommend. So I think the first option for runtime monitoring specifically would be to use something like, uh, guard duty.
And so with guard duty, what happens is you deploy an agent into your e K s cluster that basically monitors your e k s clusters and your workloads for particular vulnerabilities or, um, alerts that may go off in your cluster. So for example, like if a, if an attacker got access to your cluster, they may deploy like a Bitcoin miner, for example, or they may start, uh, deploying other resources, spinning up various nodes. Um, you know, there's a, there's a whole list on our documentation page as to the various things that guard duty actually looks for.
So that's like the monitoring aspect of it, right? So with guard duty, it's not gonna do like auto remediation, but it will notify you when these things happen. And so typically what we recommend there is to pair it with something like AWS Security hub so that you have a single pane of glass for all of your alerts metrics, um, or really anything that might go off with respect to security, um, in your particular e K s clusters.
And then when we talk about automated remediation or just remediation in general of these runtime vulnerabilities and threats, um, it's really gonna depend on the organization, right? Like, you know, I've talked to organizations where because they have such large, um, workloads and so many people working on these particular workloads, that sometimes automated remediation isn't gonna be the most effective solution for that particular organization. Where I've talked to other organizations where they, they do prefer that approach where if something does go off, they would rather have something like, you know, uh, Lambda and config take care of that particular alert or that threat for them.
So it really comes down to your organization's policies, um, your regulations and requirements that you need to abide by. Um, but those are really two of the main things that, um, I typically think of when I think about runtime security in general. Thanks, Andrew.
So, uh, it, it a little bit of a tailored glove, um, not necessarily a one solution fits everybody in every, uh, application, but, um, some great tools that are available depending on the needs of the customer. Awesome. So the next thing that we wanted to talk about that's in the quiver of, of tools for, uh, for regulated companies looking to operate securely in, in, in a compliant manner is being able to enforce policy as code.
And this still feels like new technology, I think, to a lot of us, but policy of code has been around for a long time and, um, it's really easy to shift security left and use automation as control points for security, um, both through the CI and the CD life cycles of, of applications, and in many cases even beyond that as well. So, um, you know, policy as code is, is an important component of being compliant. Um, it gives you the ability to run audits and verification.
Um, it allows for automated enforcement where otherwise humans can introduce errors, mistakes, misconfigurations. Um, and I know that, um, there's data out there, uh, from Gartner, from Verizon and from others that state that, you know, as much as 95% of the security incidents that happen, um, and breaches that occur boil down to human error and misconfiguration. So policy as code is a fantastic tool to be able to, um, reduce some of that risk and automate large portions of, of, of the security that's built into cloud native applications.
Uh, policy as code is pretty big with AWS customers, especially banks. Is that right? Yeah, absolutely.
And you know, when I think about policy as code, I think about this from a variety of perspectives, right? So with respect to Kubernetes or e k s, um, you know, you have things like hio, you have things like, uh, gate Gatekeeper, um, and so with that, there is ways to apply policies within the cluster directly, but to actually build a sound security strategy, you have to look at policy as code from the different layers that actually build, um, the security that you actually need to secure your environment. So with that said, I think one of the cool things about weaveworks is they have, um, pre-built policies that will help you adhere to particular requirements, particular, um, regulations.
And from your ci cd pipeline or from an automation perspective, it just helps you to secure your environments just that much more, right? So when you pair something like WeWorks on top of some of the open source tools and solutions that we have today for Kubernetes, um, it really just helps you to really, uh, tune your security standards based on your organization requirements or responsibilities, right? And you're right, weaveworks has a library of more than 150 policies that are ready to go out of the box and fit most of the common security, um, and compliance requirements.
Um, and of course, it's something that we've recently open sourced. So we're excited to see what the community does with our Weave policy agent in terms of the additional policies and libraries that they're gonna be able to build and the great things they're gonna be able to do with it. That's fantastic.
Um, so the third and last thing that we wanted to talk about in terms of how you can become secure and compliant in a cloud native world is using a pattern called GI Ops, or I guess it's maybe a little bit more than a pattern. It's a, it's a mantra, right? It's a, it's a state of being and GI Ops has a lot of security advantages, um, whether it's, um, you know, creating guardrails and safe workspaces for developers to be able to build great code in safely and securely from the get-go, um, to things like automated drift detection and self-healing reconciliation, where whether it's an internal source or an external source that changes, you know, the declarative state of your application in the infrastructure, uh, GI ops is a tool that can put it right back where it needs to be and, uh, enforce compliance and enforce security, um, uh, with the agents that are looking for changes in, in Git.
Um, are you finding that GI Ops is something that's attractive to, uh, highly regulated companies and something that they're starting to really ask about and get on board with? Yeah, and I think a big reason for that is when we think about just the idea of infrastructure as code. You know, all organizations at this point in time are using something like Terraform, the D, d, K, whatever it might be, right?
And so I think the natural progression if you're using something like Kubernetes is, okay, so I have everything defined in code, so why wouldn't I take advantage of my kid ops? Right? And so when we talk about compliance too, I think one of the cool examples that I've personally seen is if an organization is using something like AWS config to, um, monitor their clusters for compliance.
Um, so let's say for example, you have a bunch of clusters deployed in different regions, and you have, your organization has a mandate that says, all of my clusters cannot have public endpoints, right? What config will do is it will scan your various agents accounts and your clusters to ensure that, you know, those, none of those clusters have public endpoints. And so what you can do is you can pair that with something like GI Ops for WeWorks to say, if, uh, the config scan does find the cluster with a public endpoint, let's go ahead and apply a policy that will turn off that endpoint and make it purely private.
Right? And so, you know, there's only advantages at this point to using GI Ops. And so, um, again, so using AWS services in conjunction with something like, um, WeWorks GI Ops is, it just helps you to build that security strategy better, right?
Absolutely. And we, we think of GI Ops as something that is an enabler of DevSecOps or this shift left, um, kind of strategy. It, it's something that enables the posture of an organization to become more proactive and less reactive.
And, you know, an, uh, an ounce of prevention is worth a pound of cure in cybersecurity and in, in, in the world of compliance and, and meeting regulatory pressures as well. So policies, uh, you know, workspaces, uh, an end-to-end ability to instill trust in the software that you're building, the environments that you're running it in, is absolutely required fair for large institutions like the biggest banks of the world. Um, and, uh, and aerospace, defense, you name it.
These, these organizations that are under a lot of scrutiny and pressure and are, are big targets, um, with a w s and WeWork. Uh, we provide, I think, a happy home and, and a wide range of solutions that help these, uh, companies focus on doing business and, you know, not have to, uh, feel the pain and challenges of constantly being under these pressures. Uh, thanks very much Andrew, for being with me today.
And, uh, absolutely we hope that, hope that this was, you know, valuable to everybody out there. Um, you can check out some white papers that we've written. Um, you can request a demo of, uh, the, the products that we build, and you can take advantage of things like the e k s blueprints and get off's, best practices that are well documented and available for everybody out there.
Thanks so much. Hope you all have a great day.





