Cloud Security Challenges – Anant Adya, Infosys
Anant Adya, executive vice president for cloud, infrastructure and security (CIS) services at Infosys, explains what makes cloud security so challenging in the multi-cloud computing era.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with a knot idea who's Executive Vice President and emphasis for cloud infrastructure. And for the purposes of this conversation security not welcome the show. Thank you.
Thank you, Michael. Every time anybody talks about Cloud. The first thing that comes up is security everybody seems to be worried about Cloud security and yet arguably the cloud security is better than it is an on-premises environment.
So walk us through what from your perspective, you know, the challenge is that customers are really seeing when it comes to Cloud security. Sure. So first of all, thank you Michael for for inviting me for this interview and Essentially cloud is is as such a very complex subject and when it comes to security, it becomes more complex.
So one of the big things that we have been seeing customers face as a challenge is most of the customers think about the security as an afterthought right when it comes to Cloud, by the way. So nine order the ten customers where we have done transformation programs have actually put cloud as the first objective and security as something that you know that follows Cloud. So essentially I'll give you a couple of examples, right so there are a lot of customers of ours and most of the customer far do not use just one Cloud but they use multiple clouds and one of the big sort of you know, myth around Cloud security is once I move my workloads to Cloud.
I'm secure right because Cloud itself. The hyperscalers themselves are very secure. What customers don't realize is the limitations in terms of what the cloud providers provide you from a security standpoint versus what you actually need.
There is a big gap there. Right? So one of the myths that we have been trying to break with our clients is just by putting your workloads on cloud or just by working in the cloud doesn't mean that you are secure right?
So here are all the gaps that you need to understand and hear all the gaps that you need to fail. So that's number one. Number two, we have a concept in Infosys called secure by Design, right?
So we want to make sure that Security is embedded in the design when we are executing any project for that matter right? Not just Cloud project. But any project so when it comes to Cloud we want to make sure that when we design the Cloud solution which includes either just lifting and Shifting the workload or creating a cloud native application or looking at Cloud for some pass or SAS components.
We make sure that we highlight all the security things that customers need to embed in the design. So let you know as they move to Cloud they are secure by Design and not secure as an afterthought, right? I mean this and they don't start scrambling after they are moved to Cloud.
So these are two things that we are doing one is making sure that you know, we identify and highlight the gaps that clients will have once they move to cloud with respect to security and second is to make sure that you know, we and security at very proactive randomly. It's not an afterthought, but it is in the design. So these are two things that we do and that has actually helped customers to solve, you know, mitigate the risk associated with not having any Security in the cloud.
Do you think that this whole notion of shared responsibility kind of results in customers thinking that the cloud platform folks are doing more to secure the platforms than they are because it seems like they'll secure their infrastructure. But anything that is defined as access or the application itself is your responsibility, but it's not clear to me that everybody understands that Well, absolutely. In fact, in fact what we have done right by hyperscalers, we have actually highlighted to our customers.
You actually have created something called a service catalog which says by default when you actually go to Cloud here is what is included in your proposal in your pricing right in the sense. For example, if you migrate a workload from pointy to point B, here are the five things that the hyperskiller will provide you and here are all the things that they expect you to basically either sort of, you know, buy from them or bring on your own. Right?
So one of the things that is usually not clear to a lot of customers is for example, when when we look at security in general that there are three broad parameters one is who has access to your workloads, which is the first important thing that everybody has to understand number two. How is your workload protected with respect to a different different? Effects of security that we can bring in the workload itself or in the instance itself and number three, which is the most important thing.
How is it data within the workload protected which is the encryption tools or the encryption software that we can bring and this gets little more complicated as we start using Cloud for regulated Industries. For example, if you are working with the healthcare customers, we have a Healthcare Customer which actually deals with Medicare and Medicaid customers and they are extremely extremely worried about patient data right in the sense. How do we protect patient data in the cloud?
And essentially we have brought in tools like warmetric and we have brought some native encryption tools on Azure, which have implemented to make sure that the patient data is protected similarly when you go to a customer in the Life Sciences space, their requirements are very different and also of course financial services and insurance. So what we have done is we have made sure that you know, there is the basic access level security that is put in place, which is who accesses the workloads. What are the firework controls?
What are the controls on the instance? Then we go up the value chain and make sure you know all the way up to the industry requirements the compliance requirements the regulatory requirements, they are protected. So that's what we look at.
Defense in depth as we call it by implementing all these tools and that's how we have been protecting our customers. One of the issues the we think we hear a lot about is that it's just too easy to put a workload on the cloud because the developer does it directly themselves and they use infrastructure as code tools and before you know it there's a misconfiguration. And it seems like back in the old days.
You know, there was a security team that checked on stuff before was deployed on premise in a production environment. So we kind of gotten a little too loose in our processes for deploying workloads and that's part of our issues. who absolutely infectious that is and and honestly speaking Michael there have been several scenarios like this where there is no Central governance when it comes to how cloud is being leveraged.
Right? And essentially there is a very easy thing for some of these developers to just go and create an instance in the cloud. And they start using some of the data they play with the data in the cloud and then suddenly somebody from GitHub will access that instance and you know, there is proprietary and confidential data that they have access to so what we have been trying to do essentially to sort of you know mitigate this risk is when we actually have these provisioning tools that are made available to our developers.
We have multiple checks that we have put in place before actually the instance gets deployed in the cloud and what we've essentially done is we have created three broad reference architectures where we have a reference architecture for Azure for Google and for AWS, which actually clearly defines what is something that we need to put in place before the workload actually gets deployed in the cloud. So one of them there is one big thing that the developer has to Enough before he or she starts uploading data and you know populating data in this particular instance is to give a very clear confirmation that here are all the security checks and process that has been put in place and here is what is the data that is going to get uploaded and here is the required level of permissions and required level of approvals that we have got to upload this data because a lot of times what what we have seen happening Michael is there's always this finger pointing right that you know, okay. We we had created instance.
We uploaded data as per the process developers not need to take any approval and all of that right? So I think there is a lot of these finger pointing happen. So there is a lot of process gaps also that we need to fix right?
So we have put these process things in place which actually makes sure that you know, the developers are while they're free and they have good amount of sort of you know, I I would say authority to create this instances and Leverage The Power of cloud. But when it comes to data when it comes to confidentiality when it comes to Regulatory Compliance, we we have put process in place which actually makes sure that you know, they actually take the approvals at every step of the way. So I think that's essentially how we have done it.
We hear a lot about shifting responsibility for security further left and just how practical is that. I mean ultimately most the developers. I know security was an elective for training.
They never took it so, you know, can we teach them security or do we need to figure out some way to put more automated Garden rails in place? No, I think see the basic second. Awareness is very Good, right, I think essentially if you look at the cloud security framework itself, right the architecture it goes from the bottom most layer, which is network security all the way up to the governance.
Then of course identity access monitoring locking all those aspects but the most important thing in all these steps or the entire security stack as we call is the piece which is related to data security, right? I think the all the aspects related to network. How do we basically make sure, you know, we actually handle endpoint security.
How do we handle identity access? These are things that the developers do not have to worry about because that is something that is embedded as we create the instances as we deploy the instances in the cloud so they don't have to worry about that because it is completely automated but when it comes to data security and when it comes to court security, right, I think how do they make short? You know, the code is secure these are two places where the develop Towards the application teams play a big role.
So what you know, they know that you know, when they are dealing with some of these aspects as the develop an application or they as they manage the application or as they test the application they will test these things as well at the same time one more important thing that we have done Michael is that there are templates and there are checklists that some of them are automated in nature some of them for example code review, right? I mean there are multiple tools today that are available from for example, we work very close with Palo Alto and Palo Alto Prisma cloud has a solution for how do we basically secure the code that is in the cloud. So we bring some of these aspects as well where we actually do three things.
That one is we secure the workload that is running on the cloud. The second is as the application developers and application. Testing teams are actually testing the Code how do we basically make sure to the code is secure and you know, we do a review of the code itself, which sometimes is automated sometimes it is manual and the last but not the list is how do we encrypt and how do we protect the data that is in the cloud?
So I think we have to educate our application teams on this see the rest of things like network security firewall security access. These things can be taken care of India design itself. But these are important steps that application team.
So I think shifting left is is something that I mean, I know it works both ways that I think but having knowledge of this is very important. I think that's that's essentially what we have been doing is cloud security gonna get harder because every time I turn around people are moving from monolithic applications to Cloud native, you see things like kubernetes and serverless Computing Frameworks and containers and all these things appear to be a lot more Dynamic so it will things get maybe more difficult before they get better. Yeah, so I think you'll see we in fact, you know.
I would say compared to the cloud native development that used to happen. I mean when I say development that used to happen on-prem, I think cloud native development is far far more. I would say methodical in nature, right?
Because the the amount of sort of you know controls and the amount of automation the amount of standardization that we can bring when it comes to Cloud native development is far more compared to how it used to happen when we were doing the standard application development right using the the Legacy tools as we call. So but at the same time thanks to all these Cloud native security companies. There's a lot of focus when it comes to Native security or Cloud native security that they have brought in place whether it is whether it is companies like like, you know, Palo Alto or whether it is working with companies like zscale and all these companies.
They have a lot of these solution options that are available. Today to secure a cloud native sort of, you know workloads whether it is kubernetes or open shift or anthos or any of those things, right? Because what essentially happens is, for example, we've been with one of our financial services customer in 2019.
They decide that you know that all their Cloud work that they will do will be Cloud native. They are not going to do any lift and shift. They're not going to basically take a workload and move it from point to point B, but they're going to transform the workload in the cloud using AWS kubernetes and basically deployed and use it right.
So essentially for such customers defining Cloud security for the cloud native development is far more easy because there are templates there are different architectures. There are certain guidelines that you know, the kubernetes and AWS kubernetes actually brings from a security standpoint. So I would say essentially this is far more easier compared to the way it used to happen in the So I would say but not many customers are going the kubernetes and you know openshift and you know and thoughts way but as more and more customers going that way, I would say Security will be much more contained compared to how it is today on Prem.
Right. So once you're best advice to folks or what's that one thing you continue to see that makes you shake your head when it comes to Cloud security and what we wish that people would know or do better than they are doing today. So one is of course, I would I always recommend is to customers that you know, please do not think about security after you have decided what you want to do with Cloud majority of our customer site and fortunately it is changing now post-covid started thinking about security after they started using Cloud.
So they moved and workloads to Cloud they started doing Cloud native development. And then there was this big side report that we ran on the median rect team exercise and then we identified so many issues so many vulnerabilities and their customers started thinking. Oh my God, I thought cloud is secure but look at all these things that I'm now discovering so they started then implementing the mitigated Solutions or mitigation on the issues that there is right.
So one thing that we are doing is think about cloud proactively and not as an afterthought, right? So that's one thing which we are doing second is we are working very Was a little bit all the three hyperscalers to bring more and more sort of, you know capabilities to highlight. What are the gaps that the customers would have as they move into the cloud.
So they we have published reference architectures with AWS with as your with Google as to what is the basic security that you will get what are some of the additional security things that you need to buy or you need to build as you go into the cloud, right? So educating the customers on what are those gaps is a very important thing and last but not least don't don't just stop at what you're implemented. When you move to Cloud right continuously keep reviewing your Cloud security bring team exercise bring in you know, some of these third party providers who can do the assessment of your code assessment of your containers assessment of your workloads and keep identifying the vulnerabilities that you have in Cloud, right?
Because you you just cannot do an implementation of security one time and then forget about it. You have to keep evaluating. You have to keep auditing.
You have to keep reviewing the security in the cloud. So that's the third thing that we're doing. So basically think about security before you move to Cloud embed security the design identify the gaps that you have.
Once you move to the cloud and third is basically keep reviewing and keep auditing your workloads. That way you'll be actually much safer. So that's essentially what we are seeing and what we are recommending to our customers.
All right folks Cloud security first second and always. Hey you're not. Thanks for being on the show.
Thank you. Thank you. All right back to you guys in studio.