Top Threats to Cloud Computing with Sean Heide
Traditional cloud security issues often associated with cloud service providers (CSPs) are continuing to decrease in importance, according to the Top Threats to Cloud Computing 2024 report — the latest installment in the Top Threats to Cloud Computing series from the Cloud Security Alliance. These findings highlight a growing trust in the cloud as traditional cloud security concerns lessen in importance.
Transcript
This is Textron tv. Hi everyone. Welcome back to Textron tv.
We've got another great guest to bring to you in right now. His name is Sean Heide. I hope I pronounced that right.
If not Sean, correct me Heidi, but Sean. Heidi. Okay.
Like, like, like the girl. Yes. Uh, Sean Heide, technical research director of the over at the Cloud Security Alliance, the CSA.
Hey Sean, how are you? Welcome to Tech Strum tv. Doing good, Alan, I, I appreciate you having me.
I'm really looking forward to this discussion. Absolutely. Sean, before we jump into our topic of discussion today, you know, it's your first time on Tech Show tv.
You're the technical research director at CSA. Look, I personally, I was at the very first formation meeting, um, of CSA at RSA, I guess it was what, 2006, 2005. Around then, um, Chris Hoff was there.
I remember distinctly. Um, it was, you know, it was happening and it, and it kind of instantly rocketed. But why don't you give us maybe a little bit of your background and how you came to be, you know, the, uh, research director over here?
Yeah. Uh, well, I will say it was a long road that I probably didn't expect. I spent right outta high school, went right into the US Navy, uh, spent about eight years doing, uh, naval intelligence, uh, that was operational ground warfare intelligence.
Uh, a few deployments mixed in between. And I was always interested in computers. It was never something that I truly dove into, though at a younger age, I really wish I had.
Uh, seeing us where I'm at now, it probably would've helped me a little bit more. Um, but, you know, after getting out, I had found kind of a, a love and passion for security. I was seeing things breaking everywhere.
I was seeing all these breaches, reading the news, and a little bit of what I had done in the Navy had kind of been along the same lines on technical expertise, but wasn't exactly hands-on. Uh, so after I got out, I was like, Hey, we got the GI bill. Why, why don't we, uh, use something here for schooling?
Uh, so went into the bachelor's, master's degree, kind of just dove headfirst into, uh, the cybersecurity area and really haven't looked back since. And then, uh, actually CSA was my first gig outside of the military. They, they gave me an opportunity and, and I took the chance to kind of run with it.
And here we are today. You know, I, I think, uh, we're six years into this expedition and, uh, I love it. Wouldn't look back at all.
Excellent. I love that. It's a great story, man.
Congratulations to you. Thank you. Thanks for your service.
Sean, technical research director. Is there a technical research team, I assume that you're working with, but you know, one of the unique things about CSA is its industry alliances. So I would imagine you also have a lot of dotted line type of relationships to industry here as well.
Why don't you describe sort of the whole technical research operation, if you will, over at CSA? Yeah, absolutely. Uh, it's CSA, of course, we're nonprofit, it's vendor neutral.
So everything we do, like you said, aligns to all industry verticals, um, both up sideways, left right, it, we wanna make sure what we're doing is able to be adopted by everyone, not just one specific industry. And so we really, we really bleed the area of being flexible when it comes to technical, uh, technical expertise, cloud security configurations, the research we do, um, is it able to be adopted by other, uh, areas of business and not just one focal point. And so what we do on the research team, and as a technical research director, uh, we do lead a team of research analysts who specialize in multiple areas of cloud.
And now these can go into health information services, our cloud controls matrix, the top threats report, which we will be getting into, um, fully homomorphic encryption. Uh, we, we do all areas of cloud. So even if you don't even think a certain area of cloud in technical aspects is a part of something, we typically will go and touch on it.
And so one of those new initiatives is artificial intelligence. It's been a big key word for, you know, I would say the last year or two it really blew up. And so one of our goals was to actually dive headfirst into this.
And so we have a lot of initiatives at CSA now, uh, for technical research. We're really trying to dive in more into the technical realm for hands-on stuff. Uh, but we're really trying to address how is AI impacting the industry?
You know, how can security engineers, how can cloud engineers, how can executive teams, um, really hit this head first and ensure that they're capturing the right things in this space? And so that is another one of our, our big research portfolio items right now as the artificial intelligence space. And really for us, what we are aiming to do is to build with other industry members, with other companies, how do we align to that?
And so that's building frameworks, assisting with standards with other organizations, other governing bodies. Um, what are things that they're doing that maybe we can align with and what can we just build that the industry can use for free? 'cause like I said before, all of the research is free, uh, for anyone to use.
Uh, you don't have to be a member, you don't have to, you know, have a, a certain background. Anyone can come and use it. And I think that's one of the beautiful things about the Cloud Security alliance is kind of our adaptability to the industry in that perspective.
Agreed. Very cool. org, isn't it?
Or am I wrong? org. Yep.
Yeah, it's cloud so it's not the initials it, you gotta spell it out. org. Yep.
Very cool. Alright, so Sean, part, you know, part of this look is the, the CS a has been coming out with reports, you know, on top threats and, and you know, timely information about cloud security almost since the beginning. You guys have a new top threats to cloud computing 2024 report that's out there before we even even dive in for people who maybe want to go and, uh, download that so they can see it for themselves.
org/artifacts/help me out here short. Yeah. What's the last piece?
Yeah, it is top thrust to cloud computing 2024, But there are some hyphens in there. It's actually top dash threats. Dash two dash, so there's a dash between every word.
Yeah. So it's it's org slash artifacts slash top dash threats dash. Uh, you can honestly just do the artifacts slash top threats to cloud computing 2024 and it'll, it'll get there.
It'll pop you up there. Oh, you can even Google it. Google still works.
I think sometimes it, It does. Uh, um, so talk to us, what, what, what, what's this one about? What do, what do you think it shows?
What are the kind of the highlights? What, what should we know about it? Yeah, so maybe a bit of background too on the survey itself.
You know, this is, I believe we're on the eighth installment, and so if I got that wrong, I do apologize. There's, uh, we go through this, you know, every other year in between these surveys is a deep dive where we, uh, take a use case and build upon what this survey actually is. The whole purpose of this survey report was to capture what the general enterprise space is currently seeing.
So these actually are things that, you know, my research team or myself have been seeing this is taking the voice of the greater audience and putting out a survey that they can actually able, they're able to take and they can vote on what they are seeing from their day-to-day jobs, what they've seen in the news, what they know has evolved in the cloud space. And so I think that is what is different from this to a lot of others, is we are taking a lot of knowledge from industry experts and actually creating this list of top threats. Uh, in some instances, a lot of these are considered risks as well.
So however you wanna interchange the vocabulary there is absolutely fine. The whole purpose of this though, was to identify those things in cloud from year to year in order to appropriately, uh, change how you are looking at what you need to, uh, build out for your cloud in your industry. So whether that's your identity and access management, whether you have misconfiguration concerns, the whole purpose is to kind of put those in an order to see how does that align to, you know, your three year, your five year, your 10 year project outlines when it comes to cloud.
And if you're not even focusing on those as a business, this is a good way for those to take it to stakeholders internally to their executive teams and be like, Hey, I really think we should start focusing on these things because these are the top concerns that, you know, 700 plus industry experts have said are of importance in this year. And so it's, it's really used to kind of help facilitate those outlines, but to also maybe take a step back from the past few years of things you've been working on and see how that aligns to your strategic goals within a business. Excellent.
Um, so let, let's jump into some results though here. What do you like, you know, I always like to say what are the top three kick takeaways? Yeah.
Uh, and this is easy because we actually, our, our top three this year, it, it changed quite a bit. And so I, I can talk to, it's a good thing. It is a great thing because it means the industry is not stagnant, which right.
It, it's moving. It is moving, which, you know, we can expect. Um, I think if it stayed stagnant, we'd, we might have some bigger problems.
It means we're at least addressing some things. Um, so the big three takeaways for this year's survey report were misconfiguration and inadequate change control, uh, in your cloud environments identity and access management, which actually was 2022 survey report's number one issue, it dropped down a spot, which I'm sure we will get to later. And then the third being insecure interfaces and APIs.
And so those aren't any surprise to a lot of individuals, I would think, because if you take a look holistically at your entire cloud exploration, some of the main things you're probably still having issues with, or something that's a little bit out of your controller in your business is the ability to adopt to new controls. Uh, these vendors are constantly pushing out new updates that are changing how the backend is working in your cloud environment. Um, you know, identity and access management.
I feel like this is a discussion every single year and nothing really is changing around that discussion. But being able to properly manage your users, you know, we're moving into the AI realm, so non-human identity now is a big part of identity and access management. And then of course, uh, you know, I was just on a talk the other day and one of the things that somebody said was APIs.
So the, if you're in cloud, chances are you're gonna be using an API in some form or fashion. And so securing those is I guess of importance here as well. And so those are the big top three for this year.
This, I love it. I always, every report I've ever gotten involved in Sean, there's always something that kind of, wow, that I didn't see that coming, you know, a bit of a surprise outta left field. What w what was the left field out of this one, if you have one?
Yeah, And I think one of the ones that dropped was data exposure. Um, I think it was accidental data loss or there was a data exposure. It, it had completely dropped off the list this year.
I think it was data exfiltration. And if it didn't drop off the list, it was extremely low from the prior years. Um, and so what's that is really telling me is, you know, maybe businesses aren't necessarily seeing a whole lot of data exfil, maybe they're doing data practices a little bit better, um, under certain regulations they fall under.
I think the financial industry certainly has started taking a lot stronger stance on controls when it comes to data. I think healthcare has done the same. And these are some of the biggest cloud users.
They're some of the biggest cloud, uh, customers right now. And so I think what we've seen is less of a concern perhaps around that. Maybe there aren't as there's still breaches taking place.
And that's not to say they're not, but perhaps, you know, they have some control over that data X fill and they're trying to get back to the basics. And so it's kind of, it's kind of a life cycle with these surveys that we've seen. And it's that, you know, you would think data x fill would be pretty important.
Uh, it would be a huge topic of concern because maybe you don't have a data loss prevention system in place, but heard the survey and the results and the research we've done. It's showing that kind of ardent controls are becoming more important again, uh, in cloud native environments. We good?
Alright. Hey Sean, we're about outta time. I want to thank you for coming on though, man.
That was, uh, we, we condensed it into 15, which is what I promised you. org. And if you go there slash art artifacts, you can find this, this report.
But it's also, look, if you're, if you're in cloud security, you want to be in cloud security, the CSA is a great organization. Course, it is a not-for-profit and it is an industry alliance kind of thing, but it's also a great place for individuals. Right.
Um, Sean, keep up the great work. Come back and keep us posted here. Okay, Lynn.
Thank you Alan, I appreciate it. Alrighty. Sean, Heidi, uh, technical research director at the Cloud Security Alliance here on Tech Drunk tv.
We're gonna take a break. We'll be back in a minute.