Friday, 20 Mar 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Cloud Computing > A CISO game plan for cloud security
Cloud Computing

A CISO game plan for cloud security

Last updated: June 13, 2024 10:46 am
Published June 13, 2024
Share
A CISO game plan for cloud security
SHARE

As companies more and more migrate to the cloud, chief data safety officers (CISOs) face quite a few crucial challenges in guaranteeing strong cloud safety. Don’t consider me? Consultants highlighted this on the latest Gartner Safety & Danger Administration Summit. Gartner initiatives a big 24% enhance in spending on cloud safety, positioning it because the fastest-growing phase throughout the world safety and danger administration market.

Adapt, alter, execute

The underside line is that shifting to cloud computing necessitates basically rethinking safety. Organizations attempt to combine the cloud into normal enterprise operations, nonetheless, this transition has extra pitfalls than most CISOs perceive. I’ve seen this in my analysis and my expertise as a marketing consultant for 20 years, cloud and prior.

Points which have been current in conventional IT environments persist within the cloud, equivalent to governance, misconfiguration, insecure provide chains and pipelines, knowledge loss or exfiltration, and failures in secrets and techniques and key administration. The cloud introduces distinctive dangers, together with restricted visibility, dynamic assault surfaces, identification proliferation, and misunderstandings round shared duty, compliance, regulation, and sovereignty. And that is simply the tip of the iceberg.

Most CISOs inform me they’ve but to know precisely what ought to change. Many really feel misled by the cloud supplier concerning the work required to safe their cloud deployments. I’ve written loads of recommendation on the contrary, however it’s by no means a good suggestion to say “I informed you so” to somebody struggling, so we have to work out easy methods to do higher.

The shared duty mannequin

Many CISOs and safety groups want clarification in regards to the shared duty mannequin utilized by main public cloud suppliers equivalent to Amazon Net Providers (AWS) and Microsoft Azure. This mannequin delineates the safety duties of the cloud supplier and the shopper and is generally on the primary slide of any cloud safety presentation since 2008.

See also  CVS Health builds consumer health platform on Google Cloud

Challenges typically come up from assumptions associated to expertise and the extent of the cloud suppliers’ safety obligations. Compliance, visibility of delicate knowledge, enterprise continuity, and complicated service-level agreements (SLAs) develop into issues CISOs didn’t see coming. As one CISO good friend of mine stated after 12 years of coping with cloud safety: “It was by no means about ‘shared duty,’ it was all the time all my duty, interval.”

CISOs typically encounter a number of key pitfalls in managing cloud safety:

  • Enterprise strains have inadequately addressed safety wants.
  • The cloud is extra complicated than initially understood.
  • Cloud technique, structure, or transformation initiatives typically proceed with out enter from the CISO, who’s then anticipated to make all of it safe.
  • Failure to collaborate with CIOs to combine safety into platform engineering and devops bottlenecks growth pipelines with outdated safety processes.
  • Previous safety patterns are utilized to new applied sciences.

No substitute for laborious (boring) work

I like to recommend a number of methods for navigating these challenges. Using automated instruments to handle cloud atmosphere safety is essential. Automation is your good friend. Furthermore, establishing strong cloud safety governance might help prioritize alerts and safe service edges. Working round in circles for each anomaly doesn’t scale, and the danger of being “the boy who cried wolf” will possible trigger a breach.

Consolidating safety efforts and dealing in direction of immutability are additionally important finest practices. Moreover, reskilling and upskilling the safety workforce is crucial to adapting to the evolving panorama of cloud safety. Most breaches are attributable to a scarcity of coaching and never a scarcity of expertise. CISOs perceive they will have one of the best cloud safety expertise obtainable, however they will’t repair silly. Misconfigurations are the first reason behind cloud breaches.

See also  Cloud security, IAM, data encryption, endpoint protection, IDS/IPS, compliance, staff training

After all, particular points need to be addressed in your distinctive wants. CISOs typically undertake good concepts from analysts and consulting corporations which are the incorrect match for them. Cloud safety isn’t a “one measurement suits all” answer, and it must be systemic to all techniques, not put in over the last step of deployment. Enterprises typically get into hassle as a result of safety is loosely coupled and thus ineffective.

I want I had a magic components to present CISOs on the lookout for higher cloud safety, however it’s about doing issues neatly and purposefully to win the sport. Folks hate to listen to that—it means extra boring planning and analysis. However there is no such thing as a substitute.

Copyright © 2024 IDG Communications, .

Contents
Adapt, alter, executeThe shared duty mannequinNo substitute for laborious (boring) work

Source link

TAGGED: CISO, cloud, game, Plan, security
Share This Article
Twitter Email Copy Link Print
Previous Article Connected data ecosystems are unlocking business growth Legrand acquires two new companies for DC expansion
Next Article Incorporating 'touch' into social media interactions can increase feelings of support and approval, study suggests Incorporating ‘touch’ into social media interactions can increase feelings of support and approval, study suggests
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

OpenAI’s ChatGPT Mac app was storing conversations in plain text

Till Friday, OpenAI’s not too long ago launched ChatGPT macOS app had a probably worrying…

July 4, 2024

Invalda INVL Group Holds First Close of Second PE Fund, at € 305M

Vilnius, Lithuania-based Invalda INVL Group accomplished a primary closing of its second technology personal fairness…

February 17, 2025

GrayMatter acquires Servy

Vikas Gupta, Founder and CEO, GrayMatter Software program Providers (PRNewsfoto/GrayMatter Software program Providers) GrayMatter, a…

November 17, 2024

Two Raises €13M in Funding

Two, an Oslo, Norway-based B2B funds platform supplier, raised €13M in Funding. The spherical was…

July 11, 2025

Profound Raises $20M in Series A Funding

Profound, a NYC-based supplier of a platform relied on by entrepreneurs to grasp and management…

June 19, 2025

You Might Also Like

NTT commits to billions in investment into DCs
Cloud Computing

NTT commits to billions in investment into DCs

By saad
Cloud demand shifts toward AI as enterprise usage deepens
Cloud Computing

Cloud demand shifts toward AI as enterprise usage deepens

By saad
shutterstock 676845610 21.12.20 emerging network edge trends to watch out for in 2021 100869154 pos
Global Market

Cato Networks unveils GPU-powered SASE with native AI security controls

By saad
CVS Health builds consumer health platform on Google Cloud
Cloud Computing

CVS Health builds consumer health platform on Google Cloud

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.