{"id":27908,"date":"2019-08-05T09:11:16","date_gmt":"2019-08-05T08:11:16","guid":{"rendered":"https:\/\/www.intelligentcio.com\/africa\/?p=27908"},"modified":"2019-08-15T10:18:31","modified_gmt":"2019-08-15T09:18:31","slug":"sophos-expert-on-seven-best-practices-for-securing-the-public-cloud","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2019\/08\/05\/sophos-expert-on-seven-best-practices-for-securing-the-public-cloud\/","title":{"rendered":"Sophos expert on seven best practices for securing the public cloud"},"content":{"rendered":"\n<p><em>Harish Chib, Vice President \u2013 Middle East and Africa, Sophos, outlines seven important steps that every organisation can take to secure the public cloud.  <\/em><\/p>\n\n\n\n<p>The simplicity and cost-effectiveness of the public cloud\nhave led more and more organisations to take advantage of Amazon Web Services\n(AWS), Microsoft Azure and Google Cloud Platform (GCP). <\/p>\n\n\n\n<p>You can spin up a new instance in minutes, scale resources up and down whenever you need while only paying for what you use, and avoid high upfront hardware costs. <\/p>\n\n\n\n<p>While the public cloud solves many traditional IT\nresourcing challenges, it does introduce new headaches. <\/p>\n\n\n\n<p>The rapid growth of cloud usage has resulted in a fractured distribution of data, with workloads spread across disparate instances and, for some organisations, platforms. <\/p>\n\n\n\n<p>As a result, keeping track of the data, workloads and architecture changes in those environments to keep everything secure is often a highly challenging task.<\/p>\n\n\n\n<p>Public cloud providers are responsible for the security of the cloud (the physical data centres and the separation of customer environments and data). <\/p>\n\n\n\n<p>However, the responsibility for securing the workloads and data placed in the cloud lies firmly with the customer. Just as organisations need to secure the data stored in their on-premises networks, so they need to secure their cloud environment. <\/p>\n\n\n\n<p>Misunderstandings around this distribution of ownership is widespread and the resulting security gaps have made cloud-based workloads the new pot of gold for today\u2019s savvy hackers. <\/p>\n\n\n\n<p><strong>Seven steps to securing the public cloud<\/strong><\/p>\n\n\n\n<p>The secret to effective cybersecurity in the cloud is improving your overall security posture, ensuring your architecture is secure and configured correctly, that you have the necessary visibility into your architecture and importantly into who is accessing it.<\/p>\n\n\n\n<p><strong>Step 1: Learn your responsibilities<\/strong><\/p>\n\n\n\n<p>This may sound obvious, but security is handled a little differently in the cloud. Public cloud providers such as Amazon Web Services, Microsoft Azure and Google Cloud Platform run a shared responsibility model \u2013 meaning they ensure the security of the cloud, while you are responsible for anything you place in the cloud.<\/p>\n\n\n\n<p><strong>Step 2: Plan for multi-cloud<\/strong><\/p>\n\n\n\n<p>Multi-cloud is no longer a nice-to-have strategy.&nbsp; Rather, it\u2019s become a must have strategy. There are many reasons why you may want to use multiple clouds, such as availability, improved agility or functionality. When planning your security strategy start with the assumption that you\u2019ll run multi-cloud \u2013 if not now, at some point in the future. In this way you can future-proof your approach.<\/p>\n\n\n\n<p><strong>Step 3: See everything<\/strong><\/p>\n\n\n\n<p>If you can\u2019t see it, you can\u2019t secure it. That\u2019s why one of the biggest requirements to getting your security posture right is getting accurate visibility of all your cloud-based infrastructure, con\ufb01guration settings, API calls and user access.<\/p>\n\n\n\n<p><strong>Step 4: Integrate compliance into daily processes<\/strong><\/p>\n\n\n\n<p>The dynamic nature of the public cloud means that\ncontinuous monitoring is the only way to ensure compliance with many\nregulations. The best way to achieve this is to integrate compliance into daily\nactivities, with real-time snapshots of your network topology and real-time\nalerts to any changes.<\/p>\n\n\n\n<p><strong>Step 5: Automate your security controls<\/strong><\/p>\n\n\n\n<p>Cybercriminals increasingly take advantage of automation in their attacks. Stay ahead of the hackers by automating your defences, including remediation of vulnerabilities and anomaly reporting.<\/p>\n\n\n\n<p><strong>Step 6: Secure ALL your environments (including dev and QA)<\/strong><\/p>\n\n\n\n<p>You need a solution that can secure all your environments (production, development and QA) both reactively and proactively<\/p>\n\n\n\n<p><strong>Step 7: Apply your on-premises security learnings<\/strong><\/p>\n\n\n\n<p>On-premises security is the result of decades of experience and research. Use \ufb01rewalls and server protection to secure your cloud assets against infection and data loss, and keep your endpoint and email security up to date on your devices to prevent unauthorised access to cloud accounts.<\/p>\n\n\n\n<p>Moving from traditional to cloud-based workloads offers huge opportunities for organisations of all sizes. Yet securing the public cloud is imperative if you are to protect your infrastructure and organisation from cyberattacks. <\/p>\n\n\n\n<p>By following these seven steps you can maximise the security of your public clouds, while also simplifying management and compliance reporting.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Harish Chib, Vice President \u2013 Middle East and Africa, Sophos, outlines seven important steps that every organisation can take to secure the public cloud. The simplicity and cost-effectiveness of the public cloud have led more and more organisations to take advantage of Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP). You can [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":28230,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[399],"tags":[10532,1173,2974,279,10533],"class_list":["post-27908","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-more-news","tag-amazon-web-services-aws","tag-cloud-security","tag-harish-chib","tag-sophos","tag-vice-president-middle-east-and-africa-of-sophos"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/27908","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=27908"}],"version-history":[{"count":4,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/27908\/revisions"}],"predecessor-version":[{"id":28151,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/27908\/revisions\/28151"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/28230"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=27908"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=27908"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=27908"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}