Cloud Initiatives Growing Faster Than Ability to Secure and Manage Hybrid Environments
March 20, 2019

Tim Woods
FireMon

Cloud-based business initiatives are accelerating faster than security organizations' ability to secure them, according to the State of Hybrid Cloud Security Survey from FireMon.

The survey revealed 60% of respondents either agreed or strongly agreed that this was happening in their organizations. In many cases, security personnel are not even included in cloud business initiatives.


Additional key findings include:

■ Only 56% of respondents indicated that network security, security operations or security compliance teams are responsible for cloud security.

■ In the remaining 44% of cases, IT/cloud teams, application owners or other teams outside the security organization are responsible for cloud security.

Similarly, the relationship between security and DevOps is inconsistent across organizations, which can impact the consistency of cloud security controls, as more enterprises deploy "as-a-Service" models in the cloud. In some cases, DevOps and security are fully aligned and working well together. In other cases, the relationship is difficult or even dysfunctional:

■ 39% of respondents said they are using Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS) and Software-as-a-Service (SaaS) models concurrently.

■ 7% of respondents said they are part of the DevOps team, as part of the emerging DevSecOps trend.

■ However, 30% indicated their relationship with DevOps is either complicated, contentious, not worth mentioning or non-existent.

Existing Security Tools Can't Handle Scale and Complexity

The survey found that enterprises are inadvertently introducing complexity into their environments by deploying multiple solutions on-premise as well as across multiple private and public clouds. That complexity is compounded by a lack of integrated tools and training needed to holistically manage and secure hybrid cloud environments. Respondents also cited a lack of integration across tools, and lack of qualified personnel or insufficient training for using the tools, as key roadblocks to achieving cross-environment security management.

Key findings include:

■ 59% of respondents use two or more different firewalls in their environment, with 67% also using two or more public cloud platforms.

■ More than 80% of respondents are challenged with the limitations and complexity of security tools used for managing security across hybrid cloud environments.

■ Only 28% of respondents said they were using tools that can work across multiple environments to manage network security.

■ Almost 36% indicated using native tools for each environment or manual process, which means they are managing security in a stand-alone fashion within each component of a hybrid environment.

■ 5% of respondents said their top three challenges for securing public cloud environments are: lack of visibility, lack of training and lack of control.

Mandate: Do More with Less

The transition to hybrid cloud environments has dramatically expanded the enterprise attack surface and, subsequently, the range of assets that must be secured, but security resources are not expanding at that same scale. Budget and staffing are the key resource constraints cited:

■ 5% of respondents indicated that less than 25% of their security budget was dedicated to cloud security.

■ 52% indicated they had security teams of 10 people or fewer.

The results of our survey are compelling, but not surprising. In large, complex enterprise environments, budget constraints, lack of clarity around which team is responsible for cloud security, and the absence of standards for managing security across hybrid cloud environments are impairing organizations' ability to secure their cloud business initiatives. This problem will only be solved with a new generation of security technologies and processes that fully integrate with DevOps and provide end-to-end visibility and continuous security and compliance across hybrid environments.

There is clear indication that many companies are no longer aligned to a central security policy or security doctrine that provides the necessary security guardrails across their hybrid environments. In the absence of a concise security rule book, where departments are managing their own security controls, they will do so on a best-effort basis. You can be guaranteed that this opens the door for increased risk.

If decentralized security responsibility is the future for cloud-first strategies, and we believe it is, then we must look for a way to reestablish a global security management strategy that aligns business intent, with compliance intent, with security intent. Security implementations should closely reflect a central security doctrine. Security must be a component of application deployments where both are synchronized to each other.

Tim Woods is VP of Technology Alliances at FireMon
Share this

Industry News

November 30, 2023

Parasoft, a global leader in automated software testing solutions, today announced complete support for MISRA C++ 2023 with the upcoming release of Parasoft C/C++test 2023.2.

November 30, 2023

Solo.io achieved the Amazon Elastic Kubernetes Service (Amazon EKS) Ready designation from Amazon Web Services (AWS).

November 29, 2023

CircleCI implemented a gen2 GPU resource class, leveraging Amazon Elastic Compute Cloud (Amazon EC2) G5 instances, offering the latest generation of NVIDIA GPUs and new images tailored for artificial intelligence/machine learning (AI/ML) workflows.

November 29, 2023

XM Cyber announced new capabilities that provide complete and continuous visibility into risks and vulnerabilities in Kubernetes environments.

November 29, 2023

PerfectScale has achieved the Amazon Elastic Kubernetes Service (Amazon EKS) Ready designation from Amazon Web Services (AWS).

November 28, 2023

BMC announced two new product innovations, BMC AMI DevX Code Insights and BMC AMI zAdviser Enterprise.

November 28, 2023

Rafay Systems announced the availability of the Rafay Cloud Automation Platform — the evolution of its Kubernetes Operations Platform — to enable platform teams to deliver automation and self-service capabilities to developers, data scientists and other cloud users.

November 28, 2023

Bitrise is integrating with Amazon Web Services (AWS) to provide compliance-conscious companies with greater access to CI/CD capabilities for mobile app development.

November 28, 2023

Armory announced a new unified declarative deployment capability for AWS Lambda.

November 27, 2023

Amazon Web Services (AWS) and Salesforce announced a significant expansion of their long standing, global strategic partnership, deepening product integrations across data and artificial intelligence (AI), and for the first time offering select Salesforce products on the AWS Marketplace.

November 27, 2023

Veracode announced product innovations to enhance the developer experience. The new features integrate security into the software development lifecycle (SDLC) and drive adoption of application security techniques in the environments where developers work.

November 27, 2023

Couchbase announced a new Capella columnar service on Amazon Web Services (AWS), enabling organizations to harness real-time analytics to build adaptive applications.

November 21, 2023

Redgate announced the launch of Redgate Test Data Manager, which simplifies the challenges that come with Test Data Management (TDM) and modern software development across multiple databases.

November 21, 2023

mabl announced an integration with GitLab, the AI-powered DevSecOps platform.

November 21, 2023

FusionAuth announced the availability of new software development kits (SDKs) that support Angular, React and Vue JavaScript front-end frameworks.