Top Cloud Security Challenges in 2022 and How to Avoid Them in 2023!
Credit for the motivation behind this article goes to Mick Brady, who originally wrote this article on the top cloud security challenges for 2022 identified by the recent surveys from Proofpoint and the Cloud Security Alliance (CSA). You can find the full 18-page eBook here for more details.
It has been quite a turbulent year for a few well-known Australian businesses on the Cyber front. Earlier this week, I came across the above article in the November edition of the ISC2 Cloud Security Insights newsletter.
Although the article covers some good cloud security insights (as the name would suggest), I thought I’d take it up a notch or two and add some practical advice on how you can take action right now and get the most out of this timely cloud security advice.
Let’s get into it!
Insight #1: Protect your data
What does it look like?
Organisational control over business-critical information assets.
Regular access review processes.
Visibility across on-premises and public cloud shared technology stack.
An up-to-date information asset register (IAR).
Defence in depth. Well-architected security controls (based on zero trust principles).
Up-to-date documentation, including logical diagrams to show where & how sensitive data is stored in the organisation.
Why?
Avoid significant financial loss/penalties.
Protect brand/reputation.
Protect sensitive, non-public information.
Strengthen business operations.
Effectively manage risk appetite.
How to do it
A defined and well-managed data security strategy.
A documented, reviewed and tested business continuity and disaster recovery (BC/DR) plan.
Dynamic access controls based on least privilege and conditional access policies.
Proactive due diligence and compliance with applicable regulatory controls.
External penetration testing against internet-facing web applications and infrastructure.
Leverage SAST/DAST/RAST tools for in-house and custom-developed applications.
Who’s involved?
Chief Information Officer (CIO) or CISO
Data Owners
Business Analysts
Information Security Managers
Security Architects
Security Operations Team
Penetration Testers
Insight #2: Manage risks associated with third-party relationships
What does it look like?
Proactive due diligence and vetting of all third-party vendors before signing with them.
An up-to-date list or database containing all the organisation's past/current third-party vendors and the types of information shared/stored with them.
Why?
Minimise the risk of an incident or data breach due to a negligent third party.
Protect the organisation from a vendor lock-out situation (vendor ceasing its operations).
Build trust and confidence that third-party vendors will protect your organisation’s information assets.
How to do it
A documented and maintained External Supplier Assessment (ESA) process.
Create a third-party self-assessment questionnaire to assess third parties and vendors on their internal information security processes and practices.
Pre-defined contractual clauses that protect the organisation in case of any incident or data exposure.
Contract templates and defined service level agreements (SLAs).
Who’s involved?
Chief Risk Officer (CRO) or Chief Operations Officer (COO)
Vendor Management Team
Legal Team
Information Security Managers
Security Governance Team
Insight #3: Embrace the digital transformation
What does it look like?
Fully integrated business, security and technology teams working together.
Automated business and security processes.
Investment in upskilling staff in Cyber Security and other related fields.
Continuous improvement program.
Why?
Increase opportunities for innovation
Reduce capital expenditure (CapEx)
Take advantage of market trends
Decreased reliance on legacy technology
Attract top talent
Develop a competitive advantage
How to do it
Automate threat prevention and detection as much as possible.
Leverage cloud technology to provide robust security controls.
Develop an infrastructure-as-code (IaC) library for deploying immutable infrastructure.
Use well-known open-source tools to test and scan your internal systems and applications for threats.
Run security awareness campaigns across the organisation.
Who’s involved?
Executive Leadership Team / C-Suite
Information Security Managers
Security Operations Team
Security Engineers
Development Teams
Taking all of the above into account, if there is just one key takeaway that I can hammer home, it is this; start getting security more involved in the business. Give security teams a seat at the table so that when the big decisions are made, security can be right there from the start to help the business stay secure and minimise the risks while chasing new opportunities.