The Evolving Landscape of Cloud Security with Nayeem Islam | Qualys QSC23
Nayeem Islam, VP of product management for cloud security at Qualys, discusses the evolving landscape of cloud security. He addresses the challenges organizations face as they migrate to the cloud, emphasizing the need for a comprehensive solution beyond initial concerns like misconfigurations and vulnerabilities.
Transcript
This is Textron tv. Welcome back to the Qualys Security Conference Americas. We're here with Naim Islam, who's vice president of product management for cloud security at Qualys.
And we're talking about, well, the state of cloud security 'cause it's a bit challenging at the moment. Naim, welcome to the show. Thank you.
I'm glad to, uh, be here with, uh, with you guys. How, um, did we get to the current state that we're in? Because everybody I talked to is challenged by cloud security and a lot of it more so than anything that they ever had dealt with on premise.
And I think a lot of it just has to do with the way that the cloud is initially provisioned and then who's responsible for managing that. But are things getting better? Where are we?
Yeah, I think, uh, initially the cloud was sort of a new environment for most enterprises as they were migrating to the cloud, they really didn't know quite what to do. Uh, the cloud is really an API managed, uh, um, environment. So I have to learn the APIs.
So one of the first things people do is try to make sure that they're not misconfigured in the cloud. And there are certain things, um, that have transferred from the on-prem environments, the data center environments like vulnerability management, which Qualys is pretty well known for. So those are sort of the initial things that people look at.
And what has happened now is that as they've started adopting the cloud at scale, other things start appearing. So you start to have to worry about things like threats. So just because you've done some basic hygiene like misconfiguration management and vulnerabilities, that does not prevent you from having actual attackers try to get in.
There's always gonna try to get in. They're gonna try to find some backdoor, they're gonna try to find a misconfiguration, something you might have missed. So we are now seeing this real need for a complete solution, if you will.
So it is getting, um, more comprehensive. Who's driving that conversation in these organizations? 'cause a lot of the initial cloud work was a development team somewhere as it matures.
Are we starting to see more of a cybersecurity team and IT team specialists? Yeah, I think this is a great question. I think you are right.
When you first started this, um, there was no such thing as cloud security developers would go ahead and start, uh, spinning up with virtual machines and start using the services in the cloud. And what would happen then is that if, uh, there was a breach, then you would start thinking, hey, maybe we need to take this a little bit more seriously. Maybe some of the controls that we have on-prem need to be sort of translated into the cloud.
So that transition we're now beginning to see. But it typically happens when an organization gets a little bit more mature. So initially when you have a small part of your infrastructure in the cloud, yeah, developers are trying doing everything, but as you get larger, as it gets more complex, your attack surface increases, that's when you see cloud security, uh, folks being brought into the solve the issue.
But at the end of the day, the CISO will be responsible for the security, the entire organization. And that's what we're seeing including the cloud. I feel like a lot of people are patting themselves in the back as they finally figured out virtual machines in the cloud and yet we now have all this cloud native stuff, Kubernetes stuff, serverless computing frameworks.
Is it getting more complex? And it seems like there's just a lot more nuance and a lot more layers. I think we are seeing a lot of options for developing applications in the cloud and certainly you're seeing a lot of managed services and so that is kind of a big shift that you might have seen with cloud native providers giving you more tools.
But tools typically initially when they're new do lead to misconfigurations. I think that's part of the issue, but I think that's just a question of time where the newness starts to subside and then you have to look at real security issues, which are going to be, look, I've gotten the basics correct, but I'm still gonna have attackers come in. And I think that's kind of where we are now going where, you know, people are know how to use serverless, they're getting better at it, they're beginning to use Kubernetes and containers getting better at it in the cloud.
But even when you have these, they have to do things like runtime monitoring just as they were doing network inspection in the on-prem environments, they have to have some kind of inspection in the cloud. So you will see the totality of all of the different techniques that we have on-prem end up in the cloud to secure complex environments. There's just no way around it.
We hear the phrase shared responsibility all the time. I think that does as much to confuse as to enlighten a lot of folks. So, um, what am I responsible for in the cloud?
Because the infrastructure, at least the hardware provided by the cloud service provider is taken care of, but maybe not so much everything else. Yeah, so I think the both basic infrastructure, the network for example, that, uh, you reside on that gets, uh, published externally, yes, the, the CSP or the cloud service provider handles that, but your applications you are responsible for. So for example, if your application happens to download a piece of malware, you are responsible for that and that could proliferate within your organization.
So your applications are still communicating with the outside people are, if you build an external service, people are gonna access it from the outside. It's your responsibility. That software that you run on the virtual machine is your responsibility.
So that shared response does confuse people and sometimes they think, Hey, my application's running and the application layer is also being protected by the cloud security department. That's not the case. It is your responsibility.
And, and, and that's actually part of the confusion also. You're right. And and the complexity lies in turn to define that bind boundary.
But we partner very carefully with, uh, all the major cloud service provider and we have a better together story with all of the major cloud providers where we know our customers will ask what does the native provider do? And what do you do? And in our total cloud story that we present to our customers, we have clear services that we provide that show the value at the application layer that you need to consider.
Are we moving towards centralizing the management of cloud security? Because um, today everybody has workloads on different platforms and they're kind of managed in isolation, but I feel like we're moving to the next wave of, um, whether you want to call it multi-cloud or hybrid cloud doesn't really matter to me, but, um, are we getting more sophisticated in our approach and what are the implications from a cost perspective? Yeah, so I do think that at least in the short term, I think there are two things, concepts you're gonna see hybrid, which means you're gonna have your own data centers and the cloud because a lot of our, these larger customers already have an on-prem data center.
They start migrating to one of the preferred clouds initially, and then they start moving to other clouds for a variety of different reasons. Um, disaster recovery could be one just spreading their betts could be another. Once you do that spread and you're on multiple cloud, it does become pretty, uh, complicated unless you have a tool like Total Cloud that sort of brings everything together and gives you a single pane of glass to manage the security across these different clouds.
And that is a very important thing to have. Alright, For those that don't know what Total Cloud is, describe what it does. How does it function?
Where does it fit in the landscape? Yeah, total Cloud is our cloud multi-cloud security solution. And what, uh, what it does is it provides basic functionality that you need plus more sophisticated functionality end to end.
So we are a vulnerability posture and threat management platform that runs on all the major clouds. What that means is that we do vulnerability checks for your workloads. We also look at the misconfigurations that you have across all of your, uh, different, um, uh, clouds and we check for threats actively.
And what's really different from what we do and what others do is we have big built AI native threat detection throughout our platform. All the way from when you, for example, create a container, we scan container registries for threats using ai. Once the container starts running in a virtual machine, we inspect the network traffic and the logs to detect threats as well because we know that attackers are getting increasingly sophisticated.
So the only way you can really prevent these attackers from getting in is using some kind of tool like AI that can predict the next attack. Mm-Hmm. So that's kind of what differentiates Total Cloud from a lot of the other, uh, vendors that are out there.
We also believe that being able to scan for vulnerabilities, not just the way you might do on-prem with agents, which we have across all of our, um, cloud, uh, infrastructure, but also agent less, which means being able to scan without agents for vulnerabilities. So that's kind of the totality of what Total Cloud is. Have we reached a point where we can't really secure and manage these environments without ai?
It's just a level of complexity. We don't have enough people, there aren't enough humans. So I know there was a lot of folks that were skeptical of AI initially, but it's improved.
And right now I don't see how you can cope. Yeah, I think what's happened is that AI has matured a lot to the point where you, we are seeing so many sophisticated attacks. The only way you can really prevent these attacks is by using some kind of measure that is able to predict the different ways an attacker might come into the enterprise.
In the old days, what you would use are rules, ways to, to define the different attacks. You can't predict that anymore. It's become very sophisticated.
So attackers are also using, uh, mechanisms that are automated to attack your infrastructure. So you have to have some kind of ai And Qualys is, is a, is a leader in applying a deep learning AI technologies, which is a mechanism or a a neural net technology, if you will, throughout all the different clouds to look at different ways that, uh, someone might attack your infrastructure. We hear a lot about generative ai and depending on who you talk to, it's a form of a neural net.
It's a type of machine learning algorithm, but people seem to delineate between predictive and generative. What impact will generative AI technologies have? Will it become easier to understand what we're looking at or?
Yeah. Yeah, I think that's a very good question. I think over the last, uh, you know, year or so, um, certainly with the advent of chat GPT last year, it's just been on fire.
The use of generative ai and the way I see that is, at least the interfaces that we use for interacting with, uh, systems is going to be become a lot more natural. So you're gonna see natural interfaces and Qualys is definitely gonna be a leader in that as well. So how do you interact with the machine that you have in front of you to get information?
That dialogue will become very natural. So that is I think, one of the top areas where generative AI is gonna have a fairly significant impact. I think it's important because you, we talked initially about the skills shortage that it, that's in cybersecurity, et cetera.
Generative AI will have a significant impact on that because once you start introducing a natural interface into your tool, you've really made your tool adoption and operationalization significantly easier. And that will happen and it'll happen I think, throughout the industry and, uh, we hope to be a leader in that too. But it will happen.
But beyond that, I think you're gonna see AI being help, help you automate also, um, gathering information, generating reports, and then disseminating those reports. At Qualys, we've enterprise the, we've introduced, um, the true risk, um, enterprise platform, enterprise true risk, which allows you to both measure your risk, which is using the various techniques that we have, um, by doing vulnerability management, posture management, and threat. Aggregating that data to give you a measure of your risk, then to communicate it through reporting, through alerting mechanisms and finally eliminate it.
We have an automated mechanism called Q Flow that allows you to do remediation in the cloud by writing scripts or with a, a view, easy to use visual interface. Now with generative ai, we think these interactions will become significantly easier as you can interact with the system to do a lot of these things, particularly communicate, for example, in a natural way. Are we on the cusp of kind of democratizing security in the sense that I'll be able to share that information with a developer or an IT operations person or the cloud e service provider even?
And we can act on this in a more cohesive way because I feel like a lot of the threats move between the seams. Yeah. And I think we're on the cusp of something here, but what do you say?
Yeah, I think so. I think, I think automation helps you. Um, I think it's, it's important to understand that with these new automated technologies, I think everyone's gonna be safer.
So we'll have more tools at our disposal to both protect ourselves and communicate where we are. The, the challenge might be that just as these tools are now available for us, on the defense side, on the offensive side, you're gonna have the same opportunities for disinformation, communicating the wrong information, giving out the wrong measures, and suggesting the wrong remediation strategies. So I think we're gonna have to balance that and at some point, um, you know, we'll have, we'll just have to keep ahead of the attackers with our knowledge of what we know and keep building better tools.
Mm-Hmm. Do you think the bad guys are following the workloads? It seems to me there's more workloads being dropped into the cloud and then that attracts the bad guys 'cause they're kind of just like bank robers, they go where the money is.
No, that's for sure. So I think when, when the initial migration started to the cloud, we had very few people, um, uh, you know, very few attacks. But as the adoption increases, it's natural, you're right, the attackers go where their money is and, um, you know, easy, you know, the easiest way to make money is to rob the bank, right?
So, um, so you're gonna see a lot more attacks on, on, on, on cloud infrastructure and in cloud applications, multi-cloud, it, it's only gonna accelerate. So it's very, very important for us to make sure that, uh, we can provide the right tools like total Cloud to our customers to keep ahead of the attackers. So what ultimately is your best advice to security people right now about how to approach this, how to have this conversation?
'cause there is such a disconnect in the, between the business people, the IT people, the developers, the security people who are in the middle of this. How do they get this conversation going? No, I think within an organization you have to have an honest discussion on how you're gonna deploy your infrastructure.
One of the interesting challenges in a cloud environment where there's rapid deployment and development and there's a security team, the developers and security team, typically when a security team finds something, it's the developer that has to do the work to clean up. Um, and, um, and in some cases you can automate that. So if we build mechanisms to allow the right people to be involved in the process of both measuring it, the, the, the risk, communicating it to the right people and then remediating it, it has to be part of the tool in my view, then you'll have a, a, a solution that brings everyone in to solve a critical problem, which is cybersecurity.
All right folks. Well, you heard it here. There's an old saying that says that if you're not part of the solution, you're part of the problem.
And I think with cloud security, we need to get everybody on board and it all starts with sharing some basic information. Hey Raheem, thanks for being a Thank You very much.





