The cornerstone of digital transformation is the migration of apps and data to the cloud. There are obvious benefits to doing this. Businesses become more nimble and agile, and the cost of maintenance and development is off-loaded to a third-party. The benefits are so profound that, as of 2019, 84% of businesses used cloud-based SAAS (software as a service) apps.
However, there exists a common misperception that organizations can trust their security to the cloud provider. This however is almost always not the case, especially when it comes to large cloud providers like AWS, Oracle, and Microsoft, who rely on the shared responsibility security model. Such is the confusion around this model though that 82% of CISOs report a security incident related to misunderstanding or misinterpreting the shared responsibility model. Indeed, when polled, only 10% of CISOs stated that they really understood it.
This disconnect between cloud utilization and understanding how to secure the data in the cloud presents an obvious risk to organizations, but one that might be easier to manage than you think.
What is the shared responsibility model?
The shared responsibility model basically says that the cloud provider will secure the cloud architecture itself, while the customer is responsible for securing data and apps in the cloud. Sounds simple? In theory, yes. But in practice it can be much more difficult to do. Securing data housed in an offsite cloud may require intimate familiarization with the specifics of the cloud environment, and a lot of attention to detail when it comes to not only major security measures like firewalls, but even seemingly small things like configuring webapp headers. Regular patching and update cadences must be maintained, and regular management audits must be done to ensure data is secure.
This was already difficult for many teams when assets were primarily on-premise, but with the move to an off-site cloud there is the danger of an “out of sight, out of mind” mentality creeping in, and not everyone who has access to a cloud environment will be aware of the unique security risks and requirements.
Complicating matters further is that even if a CISO or security manager understands the shared responsibility model and is ensuring new cloud services are brought online properly, there is little guarantee that existing cloud infrastructure that was spun up years ago or under a predecessor was properly configured. Furthermore, infrastructure that was brought on board as part of an M&A deal may not be set up correctly, and geographical regions may have their own specific requirements. Shadow IT can make the job even more difficult, since by definition security teams are probably not even aware of apps or cloud services bought without their approval.
With security teams already overwhelmed, how can the task be made more manageable?
The solution starts with visibility
To ensure your cloud is secure, you need to know which clouds your organization is operating in and what data and apps are stored on them.