The Hard Truth About Network Security

The rapidly expanding multitude of cloud services creates a never-ending and extraordinarily rapid cycle of change for enterprise IT and security teams. Many teams are scrambling to protect data in the public cloud, and most organizations are using outdated security strategies that fail when applied to cloud environments like AWS, Azure and Google Cloud.

Jay Gazlay, a technical strategist at the Cybersecurity and Infrastructure Security Agency (CISA), recently told the National Institute of Standards and Technology’s (NIST) Information Security and Privacy Advisory Board: “Identity is everything now. We can talk about our network defenses, we can talk about the importance of firewalls and network segmentation, but really, identity has become the boundary and we need to start readdressing our infrastructures in that manner.”

Understanding the Importance of Identities

Gazlay’s assessment brings to light that identities are the new perimeter. Security teams are used to thinking about creating boundaries using networks, placing security stacks where those boundaries meet and configuring them based on known and locked-down data paths. This simply doesn’t work as a holistic security solution in the cloud. Instead, cloud security teams must think about what identities they control, what those identities can be used for and what resources they have access to.

The modern attack cycle starts with identity. Attackers seek to gain access via an identity, then pivot between resources, discovering credentials and other people and non-people identities that give them greater access to critical data and lead to data breaches. It’s important to understand that identity extends security beyond the traditional walls of the enterprise, which is why we are seeing data breaches a failure in applying old network security strategies to the cloud. 

Security teams should ask themselves the following when assessing their cloud security positions:

It’s Time to Improve Your Enterprise Strategy

The cloud involves multiple accounts, trust relationships and permission inheritances, making it extremely challenging for data owners to keep close tabs on it. Here are some areas you can use to improve your strategy:

As part of a zero trust strategy, organizations should take steps to move to least privilege, identify activities that will have the most immediate security impact and include a schedule to implement them. This means investing in a solution that meets your zero trust strategy by continuously monitoring every permission, access and identity to determine its effective permissions, what it can do and what data it can access. 

Prevent data risk before it causes damage. Treat remediation and prevention bots like a person. A spotted issue should be escalated to the right team or bot (the team tracks and audits). This results in a high-performance compliance structure for your environment. Put prevention rules in place and make sure the rules are continuously met.

An enterprise that doesn’t fully understand its role in securing its identities and data in the public cloud takes unnecessary risks with outdated strategies that can lead to disastrous consequences.

Source: Eric Kedrosky CISO, Sonrai Security

Exit mobile version