Organisations can be 100% more secure in the cloud, may resonate as some bold statement, but this is backed up by corporate feet on the digital street, as we see security as one of the main drivers for clients moving to the cloud. This is a well-worn path with a wealth of experience NCC Group is providing to support organisations through this Transformation. So why do so few reach out and lean on that experience before jumping in feet first. Part of it is technical complacency, capable and competent IT and InfoSec teams who have run a tight ship on premise underestimating the event horizon they are crossing when extending into Cloud. Another leading factor is not knowing the right questions to ask to get the support needed. As the old adage goes there is what we know, what we do not know, what we cannot know, but often the most poignant one is what we do not like to know – that Cloud rings changes across almost everything and we humans are not great at change.
The questions need to start in some very mundane areas that surprise organisations because these fundamentals expose an unexpected level of Governance Debt. Not through any negligence, simply a reality that conventional IT environments have evolved, so no clear strategies may have ever been defined around disciplines that are in fact the cornerstones of a resilience in the Cloud. The consequence is that there are key artefacts missing that are critical checks and balances when engaging Utility Computing. The four core pillars being:
- Identity is the new Network Edge – Have you an Identity strategy that has been updated to reflect a Cloud, if not Hybrid Cloud and mobile world? If not then how do you know you can trust the identities that exist in your organisation are fit for a Digital Economy, or the external third party ID’s you may federate with? The network-based zone defence mentality needs to be relegated.
- Data context is key to control – Do you have a Data Protection Strategy that enables you to differentiate between different classes of your data? Hmm …. you’re not alone in finding this may be a little abstract within your organisation. This comes in two dimensions, Data Lifecycle Management (DLM) or the governing principles that define and help to automate the stages of useful life, and Information Lifecycle Management (ILM). Don’t confuse these two, thing of DLM as the files and ILM as the accuracy of the information within those files and critically the MetaData.
- Visibility of your threats – The critical word being ‘YOUR’ threats. How much of your security investment is leaning on gut feel configuration, institutional norms and or vendor defaults? Save yourself the ignominy and don’t pass ‘Go’, instead go straight to a Threat Profiling exercise and understand what your unique Cyber Fingerprint looks like. For NO business is the same, there is no Vanilla. Default/industry standards are better than nothing but they rarely provide the control framework that plays to your organisations unique demands. They instead provide a false sense of security and control, risking putting operations into a strait jacket. You can guarantee the threat actors know exactly how to circumvent these ‘defaults’, and that leaves you wide open in areas you do not recognise. Not to mention the reality that users and operations teams find ways to work around ‘defaults’.
- Responsiveness, because it’s not IF but WHEN. So what is your ability to react to changing events, recognition of indicators of compromise (IOC’s), vulnerability management and configuration drift in an Evergreen Cloud world that is changing in real time. To get close to an acceptable maturity is to engage automation and orchestration, you can guarantee the threat actors are and the only way you are going to stay in the fight will be to adopt similar attributes into your countermeasure tactics.
These are foundational maturity check marks when moving to the Cloud. They are not compulsory, but they will save time, money and organisation credibility. Foundational because they are the basis not the end goal when building for success in a fast moving Digital Economy. It is a journey that relies on effective risk management to introduce agility and dynamic modes of operating and managing systems, like CARTA (continuous adaptive risk and trust assessment) and SASE (Secure Access Software Edge) that we will cover in a later article.
For now, the advice is to focus on what you do best and partner to do the rest. A mantra that has seen some of the greatest success stories in business down the generations. Yet too many organisations today think that Cyber Security is optional and IT a core competencies? Well truth be told whilst every company is being turned into a software company by the Digital Economy, the IT is turning into a utility and Cyber Security a mandatory. We use the term Cloud, but should really say ‘Utility Computing’. The compute, storage etc is now a commodity, the advantage is not in the tech, it’s what organisations can do with it and build the trust and confidence of users and customers alike. Cybersecurity is the new operating model, if your organisation is not embedding this at a cultural DNA level, you can regard yourselves as still being in Beta in a Digital Economy.
Posted on April 2, 2021
0