Top Trends: Migrating Data Into the Cloud | DataOps Day
As cloud migration continues across regions and sectors, how are organizations migrating their data to the cloud? What are the right security tools, and how are those tools being operationalized? Which practices are producing the best security outcomes, and which are hampering efforts? Topics will include:
-Common use cases as companies migrate their data into the cloud
-The acceleration of shift-left security
-How to enable and train your teams to take advantage of the new capabilities in the cloud
-Why collaboration across teams is essential to better security outcomes
Transcript
Hello everybody. My name is Ben Nicholson, and I'll be talking about top trends, migrating data into the cloud. Thanks everybody for taking your time with me today.
My name is, uh, as I mentioned earlier, my name is Ben Nicholson. I'm a global practice leader with Palo Alto Networks in Prisma Cloud. I've been at Palo Alto Networks about seven and a half years.
I've been in a lot of variety of different roles as far as, you know, deploying things from the consulting side. I've also been on the architect side, and then previous to, to Palo Alto Networks. I've also been on the customer side.
So really experienced a lot of different things in the industry that I'm hoping I can share with you today. In particular, the things that I've been, uh, seeing lately in the cloud infrastructure or cloud environments in general. So, let's talk about enterprise architecture.
So previously to the cloud environments, we used had like a data center environment where we would say, okay, we're going to deploy our applications, we're gonna protect things at our edge, and now things have changed. Now we're moving things up into the cloud, and there's a lot of implications to that of what trends we're seeing when people are moving to the cloud. And I'm hoping to talk to everybody.
Yeah, talk to everybody about that today. Okay. So what are the market drivers and trends?
So acceleration of cloud adoption, as we all know, people moving into the cloud, right? And then there's a lot of architectural considerations. We're moving to the cloud, though.
There's a proliferation of, of different architectures and what that really means. You know, containers are the norm now, and there's a reason for that. It's the way that, you know, uh, applications are being deployed.
It makes it a lot easier and faster. And then when I'm talking about C S C D pipelines, there's a big part of that where we're, depending on how we're deploying things to the cloud, that plays a big piece. And what do I mean by that?
So right now, uh, based on the state of cloud native security report, 40% of companies are deploying code in a production weekly while 72% are deploying code in production daily. So if you think about that, okay, companies are moving faster now that they're in cloud, they're gonna deploy applications to the cloud at a, at a really high rate. What does that mean for security?
Okay? So we're gonna get all these things into, into production, but okay, what does that mean overall? Well, these key trends are impacting cybersecurity, 188% year, year increase in cloud incidents.
53% of organizations are turning to AI for better threat protection. 96% of organizations are attached in the last year. So the shift to the cloud has gone mainstream.
The nature of the work has changed fundamentally. And 61% of organizations say they're struggling to secure the hybrid workforce. So why is that so modern SOCs are being overwhelmed, and they're not stopping cyber attacks.
Less than 30% of SOC teams are meeting their goals for key metrics. 28% are alerts are being ignored, 287 average days to identify and contain a breach. And there's a reason for, and we're not using this as a, as a scare tactic.
Uh, I'm, I'm saying this to display that the way that work is, is being conducted in the cloud is fundamentally different in the cloud than it was in the data center. And there's, and the reason for that is because of the things that I was talking earlier about is that applications are being deployed faster. People are trying to wrap their arms around it.
And previously we had a different mindset for how we were trying to protect our data center. Previously we had this mindset of, okay, we have an S Q L injection attack. What are we gonna do for this to protect against, against the vulnerability?
Well, um, you know, we can't patch, make sure all of our servers a hundred percent patched all the time. So we're gonna put a firewall in front of it and we're gonna block this vulnerability. Well, what's happening in the cloud right now is all these alerts are being generated and they're all being sent to the SOC and they can't handle it, and they're being overworked.
And so the way that we've looked at security in the cloud is fundamentally different than the way that we looked at it previously, because we have to take into account now the overall software development lifecycle, which we weren't a hundred percent doing previously. I mean, we were sort of, but not to the extent that we really have to now in the cloud. So why are organizations struggling with cloud security?
Disparate point products is compromising security. The majority of modern cloud security breaches are occurring across multiple points in security pipeline that don't talk to one another. This is a big part of the problem, and it was a problem before in our data centers, and it's a problem now in the cloud.
What is the problem? The problem is we have, you know, and I work at Palo Alto Networks, we're, we're a great security vendor. We have a lot of different security vendors out there that are coming in and saying, Hey, we've got this one thing that we do well, and we've got this other security vendor that says, we come in and we do this other great one thing that we do really well.
Well, the thing is, is that previously, I know when I was on the customer side, we would look at all these different point products and we'd be like, oh yeah, we really like this. We really like that, but we're gonna gain all this, uh, security technology, all this depth from, we're not putting all of our eggs in one basket because we're gonna gain all this information from all these different vendors. We're gonna get best of breed from everybody, but we're gonna have this great security, uh, in our data center.
The reality is, that's not what happened, and that's not what works. Because what happens is that you say, okay, I've got this vendor for this, this vendor for this, this vendor for this. They don't talk to one another.
And so you're not seeing the whole, the whole application lifecycle. You're not seeing everything from the endpoint to the cloud to, to everything from that perspective either. So what's happening is that you're, and then also you have the people that are managing that.
You have somebody who's like, oh, I'm great at this, or I'm great at that particular product. They leave. This particular product wants it being half configured or, or whatever.
I could tell you, when I came to Palo Alto Networks, I realized, oh, 'cause I, we were using Palo previously. I was like, oh man, we could have been doing so much more stuff. We could have, we could have really, you know, dug in and, and all these different things, but we didn't have time.
We really didn't have time in order to really, uh, utilize all these different products to the best capability. So what we really needed to do was do a platform approach, which is really where organizations are going right now in terms of cloud. So if you look at, and this becomes really, really important when we talk about security burden drains everyone's energy, the developers, the DevOps, and the IT teams dislike security.
They view it as a roadblock because of strict rules and regulations. You know, one of the things that I did previously in, in, in my previous line of work when I was on the customer side is I said, I'm going to set up a monthly security meeting and we're gonna have all these different people from different, uh, walks of life, different, uh, you know, people from the dev team, people from this other team, we're all gonna work together. We're gonna meet, we're gonna talk about security challenges, and we're going to see how it fits across the application life cycle.
And, you know, we're all gonna work together and it's gonna be great, right? It did not work. And I'll tell you the reason why it didn't work.
The reason why it didn't work is 'cause I came in with the idea that everybody else in that room, their, their goal was going to be to get the best security for the overall organization. But each one of those teams has their own budget and their own reasons for being there. And those reasons are very unlikely to be security related.
So I can't be coming in with what my idea of what is the best thing for the organization. I've gotta talk about, okay, from the DevOps team, what are their goals and what are they trying to accomplish? So in other words, they're trying to deploy applications quickly.
So from a security aspect, I need to be looking at automating security reviews, because if they have a security review that's required as a part of their, what they're doing, then I need to make sure I'm making things move faster for them, not introducing security and making things move slower. So again, in terms of the way that I approached it, it was just the wrong way to approach it in terms of, oh, we're all gonna work together in this kumbaya kind of mindset. And then we're gonna look at security from a whole.
It was really more should have been coming in for each individual team. What does that team need in order for them to be successful? And that's really the best way in order to work across these different teams in order to make sure that our cloud security plat our cloud security program is successful and that we're deploying our, our data into the cloud successfully.
So what does this all mean? Vendor consolidation is coming, we're all seeing right now, okay, 41% of organizations who work with 10 more cybersecurity vendors, we're making the same mistake we made over on the data center side, right? We're saying, okay, we're gonna go with best of breed platform for all these different things.
It doesn't work. Where we're really kind of to understand is we need a platform approach. Somebody that's gonna come in and, and show all this security across the entire application lifecycle.
Now, if you look at software development lifecycle, what I was saying before, why is this so important? Why is this becoming such a problem? Because if you look at it, one vulnerability turns into a hundred deployments, uh, which turns into a thousand security alerts.
So what does this mean? Uh, this means that, okay, if I am on the DevOps side of things and I build an application and I'm deploying across all these Kubernetes clusters and I'm not securing it earlier in code, it's creating these thousands of different security alerts and then we're playing whack-a-mole trying to figure out how to, how to remediate them. What we need to do from the security side, from uh, when we are moving things into the cloud is secure.
Things really on the application lifecycle, kind of I was talking about earlier, automating those security reviews put around, uh, guardrails around, around what we're building so that, you know, one of the, uh, one of the great examples is I was talking to a company and they were saying, we were talking about what is the time that is taking in order to, okay, we've created instant around a vulnerability. And then what is the time in order to taken to remediate each one of these? I think it was something like, it was, it was like five or six hours for each one of these, or something along those, along those lines.
And when you really start putting time around each one of these things about the amount of money and time that you're spending, like I said, 20 times effort to fix a bug found in production, you really start seeing, oh, this is costing my company money. We're really, we're, we really need to look at this from an overall application lifecycle. 'cause if we don't, we're just, we're really shooting ourselves in the foot.
Now this is where just the overall mindset of deploying applications in the cloud just has to change. So we're not overwhelming our sock. So we're looking at saying, what is the best way to run training our employees in order to implement security or implement applications to the cloud?
What is the best way in order to, for us to look at from a platform approach and saying, let's get, let's get the right products in here. They're looking at things overall so that we can see things across an application lifecycle. And what's the best way to make things simpler and easier for, for everybody?
So when we look at prevention first, and of course, you know, from Palo Alto Networks, we have a prevention per first approach. But where we're looking at cloud security just in general, we wanna prevent misconfiguration cloud infrastructure with Shift left. What I was saying earlier, you know, we're looking at a W s Azure, Google Cloud, all these things.
We wanna prevent vulnerable containers in production with C I C D integration. We wanna prevent malware and crypto miners from executing on containers, and we wanna prevent application layer attacks. It's a whole process that we need to do and we need to do that when we're going to migrate things to the cloud.
I know I've had conversations with people who are going about to migrate and they, they say, well, you know, we're, we're starting off in our cloud journey. Do we need security from the start? You know, and I would say a hundred percent yes.
I know previously in my, in my other world, we would have these mergers and acquisitions and then we would, we would acquire a new company and we would fight tooth and nail to make sure that when a, a company got acquired, that from the start we were talking about security as opposed to bolting it on at the end. Because if you bolt it on at the end, you're getting all the data flowing. Now you just, you're, you're, again, you're playing whack-a-mole, you're making things more difficult for yourself later on.
It's much better, particularly if you're early on in your cloud journey, start thinking about security, start thinking about the overall application lifecycle. And I understand the, the, the issue with securing things across an application lifecycle is not all a technology based problem. What I was talking earlier about the meeting, it's a lot of times a people problem to make sure that the teams are working together.
Everybody sees the value of what you're trying to accomplish, though you're all working together in a key cohesive manner. And, and some people will say, well, I don't have control over these teams, or, you know, this is not a, a realistic goal. I would say there, there is, I would say that for the teams that I've worked with, there are, you can still have that conversation and start moving in that direction.
You know, it just, it doesn't have to be okay. Every single application that we, that we create has to be secure from day one. But we can start integrating into our full application lifecycle, talking to our DevOps team, working together, get everybody thinking in that mindset, and then move towards that direction.
And you know, it, you know, if you're earlier on and you, maybe you, you have that type of, uh, organization where you can do that early on, Hey, the more that you can integrate into the application lifecycle, the better. But if we, if we don't do these things, as I mentioned earlier, you're gonna lose a lot of time and money and you're not gonna be, you're gonna overwhelm your soc. So these are some of the top trends that are going on in cloud security and cloud, uh, data security in general right now.
So overall we've got 99 problems, but vulnerability and vulnerable. So thank you everybody for your time.





