The Cloud and Fundamental Changes to Security | Predict 2024
What are the differences between security in the cloud and security in the data center? This presentation will talk about the main differences, why they matter and the impact those differences are having on the security industry.
Transcript
Hello everybody, my name is Benjamin Nicholson. Today I'm here to talk to you about the cloud and fundamental changes to security. So my name is Benjamin Nicholson.
I've been a global practice leader over at Palo Alto Networks for about eight years. I've been specializing in cloud about five years. And today I really want to talk to you about what I've seen and why security in the cloud is fundamentally different than what it is in the data center.
So when you look at the data center, you can look at it and say, okay, what are, where's our main focus? We're going to focus on security at the edge. We're gonna make sure that traffic coming in and out of the edge is secure, and we're, we're looking at that traffic accordingly.
But now that we have the cloud, there's uh, some big differences in why security is different there. And I think the biggest reason why security is different in the cloud is why we're moving to cloud in the first place. That is a fundamental question of why are you moving to the cloud?
A lot of times when I talk to customers, we talk about cost, and that's usually not the reason why or, okay, we're going to, we're gonna do ease of use, so it's easier for me to deploy this server here, but that's not really the reason why people are fundamentally moving to the cloud. The reason why is because it's designed for at rapid iteration and continuous application rollouts is because of the flexibility, the ability to highly automated builds, to reduce time to market, improve app team and developer productivity. It's about the applications.
The cloud applications are being created differently. That's the reason why we're moving to the cloud. So if the cloud applications are created differently, what does that mean?
What we're finding in the market right now is that 77% of enterprises are deploying code into production on a weekly basis, while 42% are deploying code into production on a daily basis. Now, what does that mean? If you are updating your applications on a weekly and a daily basis, it means your vulnerabilities in the same fashion are skyrocketing.
And that's the reason why security has to change in the cloud, is because the way that you're deploying the applications in the cloud have fundamentally changed. You can't approach security in the data center as the same way as you're approaching in the cloud when the applications that you are meant to protect are completely different. And what are we seeing right now in the market as we're seeing developers are moving fast, but the security teams can be left behind, or we're seeing in terms of the dev ops to ssec ratio 110 to one, and then 75% of application code is open source software.
So what we're seeing challenges overall in the cloud, a lot of times when I'm talking to customers, 75% are reported blind spots to the high number of tools. We'll talk about vendor consolidation in a little bit. 35% can't provide comprehensive coverage due to silo teams.
That's a really big one. And this plays a part in, in so many different organizations that I wind up talking to when we talk about real security and what it really means for security in the cloud. So we talked about that, and security of the cloud is fundamentally different because the applications are different.
What does that mean? It means security has to happen across multiple teams. So what does that mean?
That means, okay, how do we secure not just what's happening in runtime, but what's happening earlier in our application lifecycle? What's happening on the dev side of things and how do we involve both teams as a part of that conversation? A big part that I found is that my job is security is to secure the organization, but if I go into my dev teams and I say, and I come in with my point of view, which is we need to make sure you're securing across the apple lifecycle.
We need to secure the dev side of things. And that team is like, well, that's not my goal. My goal is to work in sprints.
My goal is to update these applications quickly. My goal is to update applications on a weekly and a daily basis. And that's where you have conflict because my, because they're concerned that my goal is gonna slow down what they're doing, which is making them not reach what they want to accomplish.
So what I found for security to really work across the app lifecycle to provide coverage across silo teams is to understand how we can speed things up over on the dev side, how we can make things advantageous for different teams to be involved in this. So in other words, if, and this goes back to vulnerability management, if the vulnerabilities that we get introduced later in the app life cycle over on the run time when the, when the application had been introduced and we say, oh, this needs to be sent back to the dev team to go fix X, Y, and Z. The team might be overloaded with these types of alerts or these tickets, and they, we'd say, Hey, I don't have time to deal with all this.
My job is to, to update these applications faster, recognize revenue. You know, if I, if I update this application, uh, that's really, really important this update, maybe we'll more recognize more revenue for the company. That's my job.
So what we need to say is, if we introduce security earlier in the application lifecycle, what will wind up happening is you don't have to deal with all these tickets that are gonna slow you down. So us introducing security earlier is actually gonna speed you up or to understand what your security review process currently looks like. So if you're talking about, okay, what does your security process look like?
If it requires a manual review, maybe we can automate the review to speed things up. Or what we can do is put in comments earlier in that lifecycle to say, 'cause some people are like, well, I don't know about changing this on the fly, doing an automated way, but in signing off on comments that, okay, we've deployed this application, everybody's accepted this level of risk, we understand this earlier on in the application lifecycle. Really what the intent is, it's to speed things up across the lifecycle while introducing security.
And you can't, you can't come in it from a security point of view and not see their point of view, which is to speed this up. Now, training all staff, this is something that I see across the board and it's really because we're asking a lot from our security teams right now. I know when I was early in my career, you know, I was learning network routing and I was trying to figure that out and understand OSPF and BGP and, and rip, you know, back in the day and stuff like that.
And then, you know, then it was like, okay, I'm introducing security now. We're like, oh, we want you to understand AWS and not just the routing stuff, but we wanted you to introduce everything in GCP and Azure and also understand the edge and all these additional things that really take somebody who's been in the industry a really long time to want to really fully understand all these things. So are we seeing is that they don't have large teams?
So we need to be very efficient, which means we need to automate everything across the application lifecycle. We can't have siloed tools, one doing one thing, one doing another thing, and then expect to achieve the results that we want. What we really need to do is we need to automate things across the app lifecycle so that we don't have the staff in order to handle all these things.
What I found earlier in my career is that we would have one person that would be the firewall guy or one person that would know this tool and that tool and that tool, and then that person would wind up leaving and then we'd be like, oh, uh, what did that person handle? Oh, Bob handled this X, Y, and Z and X, Y and Z. And they'd be like, oh, okay, well then we're, you know, I'm already doing this thing, so now we're gonna be okay at this tool, sort of bad at this tool.
I don't even know what that tool does over there. Well, winds up happening over time. So you have some tools that wind up being really well configured, some not, and then seeing things across an app lifecycle, you don't really have that visibility.
And then you're, you're asking other teams to be involved that you don't have a single tool to see it have a single pane of glass. It winds up being kind of a hodgepodge mess of like, we're trying to achieve our security goals, but we're not really doing what we wanna do. And that comes back to lack of visibility.
You know, contain 96, 90 6% of container apps contain known vulnerabilities and then finding the right tools, that's a really big one. 78% of people struggle to identify tools, need to achieve security goals and really be able to showcase like, yeah, we're securing our environment, we're burning down a risk. That's really what it comes down to is, you know, when we're looking at, I know per, for my, for for me, earlier in my career when I was looking at our data center, we bought into the idea of defense in depth or don't put all of your eggs in one basket or all these different things to say we're going to gain all this intelligence from all these different tools.
But the reality, that reality was not what actually wound up happening. What wound up happening is, what I kind of mentioned before is that some tools were better configured than others and really being able to, now we're moving to the cloud, we have different challenges and so we need to look at security from a different perspective. We need to look at it across nap lifecycle.
And really we just don't wanna repeat the same mistakes that we made in the data center. I don't know how many times where, uh, particularly from a network routing perspective or from a security perspective, we would be like, oh man, if I could just start from the beginning. We can't just redesign our entire security infrastructure.
You know, we did it all bad in the beginning, but you know, if I could just start, well, in the cloud for a lot of organizations, we are starting from the beginning. We have the chance to do it right. So when you're starting off, look at security across the application lifecycle.
Look at all the different types of security vectors. Make sure you're implementing security correctly from the start. Why are we saying this?
It's 'cause what we're saying in the market right now is the good guys are losing. We're saying a lot of different ransomware attacks, we're seeing a lot of people having issues. Uh, it's, you know, security incidents are not going down.
They're going up. And so how do we protect ourselves? Again, one of the other issues we're seeing is modern socks are being overwhelmed with alerts that're not stopping enough cyber attacks.
This goes back to, okay, we're going to go into the cloud. We're going to, we are going to deploy code on a weekly and daily basis. We're gonna get all these vulnerabilities, we're going to send them all to the soc, and then they're not gonna be able to do anything with them.
28% of alerts are being ignored. Less than 30% of SOC teams meet their goals for key metrics. And the average day is to identify and contain a data breach is 287.
Right? It's not working. That's the problem.
All this stuff is not working. And so if you really wanna do security well in the cloud, you need to shift left, you need to look at things earlier in the application lifecycle. You start reducing the amount of alerts that come out into your runtime so that your socks aren't overwhelmed so that your, uh, developers aren't overwhelmed with tickets.
All these different things about really good security. Now, I know some of you might be seeing this, you might say, yeah, that sounds great, but you know, my teams aren't gonna buy into this. Or maybe that's phase two.
Maybe that's phase three. And I think that's okay. I think there's a way to look at this to say, okay, we need to burn down our risk in phase one.
We need to get visibility into what we're doing. Maybe we don't have visibility phase one, right? We need to look at this, get visibility to what we're doing and start burning down our risk, start becoming more compliant in our cloud environment, right?
Then we need to look at our overall application life cycle. Okay, let's, let's, let's get all these different teams involved. Let's remediate early in our application life cycle.
Let's start reducing the amount, alerts, all these different things and start looking at things, you know, whether we're doing an agent or agentless based approach to get our vulnerabilities. Where are we correlating our vulnerabilities at all those sorts of things. And again, this kind of drives home the point, again, when it comes to effort to fix a bug founder production, it's 20 times more expensive than to fix it, uh, you know, earlier in the lifestyle field than than later in the last cycle.
Well, it's, it's much more expensive to fix it later in the application life cycle. If we see one vulnerability turns to a hundred deployments turns into a thousand security events, what we really need to do is that we need to fix that vulnerability earlier on. Vendors and tools, consolidations coming, and this is something I mentioned earlier in the call, but really what we're seeing right now is organizations saying, we have too many tools.
39 total average security tools. Well, vendors 13, security 2 31. That's crazy.
You're not gonna get anything done with 32 security tools. You need to kind of, uh, particularly what we just said, we're like the amount of, uh, security people that you have on your team compared to the amount of dev team, dev team members. You're not gonna be able to really manage all those different security tools and do it in an effective way.
You can't look at your overall cloud infrastructure and be like, well, we, we wanna look at identity, we wanna look at, um, you know, we wanna look at API security. We wanna look at our, you know, vulnerability management, we wanna look at our, our cloud, we wanna look at this and then do a different vendor for every single one of those tools. It's not gonna work.
You know, you're gonna wind up coming back and saying, oh, well, did we update that? Did that happen? Did that happen?
All the te all the organizations that I am who are becoming more mature, or all the organizations that I talk to are, that are becoming more mature, are doing better consolidation, trying to figure out how can we reduce the amount of vendors? How can we make this more efficient? And vulnerability management, this is really where the rubber meets the road, um, in the cloud in particular.
Whereas, okay, we've just, we've put in our tool, we're getting all this great information. Are we burning down our risk? Are we becoming more secure?
Are we becoming more compliant? And a lot of this comes down to processes, processes on the backend to make sure that you're prioritizing those processes that you're saying, Hey, we're gonna spend time every week to look at our processes and make sure that the right people are getting the alerts and they're actually are remediating them. Who are the teams that are receiving the alerts?
What's the fixed process? What data's needed? How are you gonna prioritize each item for fix?
How do we provide the best service to our extended team members? How does this scale as you more move towards infinite and additional tools? What tools do we have on hand to implement the needs?
Again, building out automation extract, building out ticketing to proper groups for alerts, iterating on improvement to the ticketing system, you know, improving and adding on additional dashboards, filtering assignment capabilities. All of these things are really, really important. If you really wanna have, uh, a great security platform, you know, it doesn't matter what tool you use here, but if you're not looking at your overall vulnerability management and your processes on the backend to make sure that the right people are getting it, you're remediating in the, in the correct way, you're not gonna be successful and, and, and becoming more secure.
So thank you everybody for your time. Uh, I appreciate, uh, you know, all everybody's time today and, and thank you.





