Top Cloud Security Challenges in 2022 and How to Avoid Them in 2023!

Credit for the motivation behind this article goes to Mick Brady, who originally wrote this article on the top cloud security challenges for 2022 identified by the recent surveys from Proofpoint and the Cloud Security Alliance (CSA). You can find the full 18-page eBook here for more details.

It has been quite a turbulent year for a few well-known Australian businesses on the Cyber front. Earlier this week, I came across the above article in the November edition of the ISC2 Cloud Security Insights newsletter.

Although the article covers some good cloud security insights (as the name would suggest), I thought I’d take it up a notch or two and add some practical advice on how you can take action right now and get the most out of this timely cloud security advice.

Let’s get into it!


Insight #1: Protect your data

  • What does it look like?

    • Organisational control over business-critical information assets.

    • Regular access review processes.

    • Visibility across on-premises and public cloud shared technology stack.

    • An up-to-date information asset register (IAR).

    • Defence in depth. Well-architected security controls (based on zero trust principles).

    • Up-to-date documentation, including logical diagrams to show where & how sensitive data is stored in the organisation.

  • Why?

    • Avoid significant financial loss/penalties.

    • Protect brand/reputation.

    • Protect sensitive, non-public information.

    • Strengthen business operations.

    • Effectively manage risk appetite.

  • How to do it

    • A defined and well-managed data security strategy.

    • A documented, reviewed and tested business continuity and disaster recovery (BC/DR) plan.

    • Dynamic access controls based on least privilege and conditional access policies.

    • Proactive due diligence and compliance with applicable regulatory controls.

    • External penetration testing against internet-facing web applications and infrastructure.

    • Leverage SAST/DAST/RAST tools for in-house and custom-developed applications.

  • Who’s involved?

    • Chief Information Officer (CIO) or CISO

    • Data Owners

    • Business Analysts

    • Information Security Managers

    • Security Architects

    • Security Operations Team

    • Penetration Testers

Insight #2: Manage risks associated with third-party relationships

  • What does it look like?

    • Proactive due diligence and vetting of all third-party vendors before signing with them.

    • An up-to-date list or database containing all the organisation's past/current third-party vendors and the types of information shared/stored with them.

  • Why?

    • Minimise the risk of an incident or data breach due to a negligent third party.

    • Protect the organisation from a vendor lock-out situation (vendor ceasing its operations).

    • Build trust and confidence that third-party vendors will protect your organisation’s information assets.

  • How to do it

    • A documented and maintained External Supplier Assessment (ESA) process.

    • Create a third-party self-assessment questionnaire to assess third parties and vendors on their internal information security processes and practices.

    • Pre-defined contractual clauses that protect the organisation in case of any incident or data exposure.

    • Contract templates and defined service level agreements (SLAs).

  • Who’s involved?

    • Chief Risk Officer (CRO) or Chief Operations Officer (COO)

    • Vendor Management Team

    • Legal Team

    • Information Security Managers

    • Security Governance Team

Insight #3: Embrace the digital transformation

  • What does it look like?

    • Fully integrated business, security and technology teams working together.

    • Automated business and security processes.

    • Investment in upskilling staff in Cyber Security and other related fields.

    • Continuous improvement program.

  • Why?

    • Increase opportunities for innovation

    • Reduce capital expenditure (CapEx)

    • Take advantage of market trends

    • Decreased reliance on legacy technology

    • Attract top talent

    • Develop a competitive advantage

  • How to do it

    • Automate threat prevention and detection as much as possible.

    • Leverage cloud technology to provide robust security controls.

    • Develop an infrastructure-as-code (IaC) library for deploying immutable infrastructure.

    • Use well-known open-source tools to test and scan your internal systems and applications for threats.

    • Run security awareness campaigns across the organisation.

  • Who’s involved?

    • Executive Leadership Team / C-Suite

    • Information Security Managers

    • Security Operations Team

    • Security Engineers

    • Development Teams

Taking all of the above into account, if there is just one key takeaway that I can hammer home, it is this; start getting security more involved in the business. Give security teams a seat at the table so that when the big decisions are made, security can be right there from the start to help the business stay secure and minimise the risks while chasing new opportunities.

Previous
Previous

Getting Started in (Cyber) Security

Next
Next

CCSP and Me: A Practical Guide To Getting CCSP Certified