{"id":40522,"date":"2024-10-23T12:54:31","date_gmt":"2024-10-23T11:54:31","guid":{"rendered":"https:\/\/www.intelligentcio.com\/apac\/?p=40522"},"modified":"2026-07-06T15:30:36","modified_gmt":"2026-07-06T14:30:36","slug":"editors-question-is-apacs-complex-cloud-climate-ripe-for-a-storm","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/apac\/2024\/10\/23\/editors-question-is-apacs-complex-cloud-climate-ripe-for-a-storm\/","title":{"rendered":"Editor\u2019s Question: Is APAC\u2019s complex cloud climate ripe for a storm?"},"content":{"rendered":"\n<p><strong><em>Peter Lees, Head of Solution Architecture for Asia Pacific, SUSE, says there\u2019s a fine line between controlling clouds and allowing them to cause a \u2018hurricane of hurt\u2019.<\/em><\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"780\" src=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2024\/10\/Peter-Lees-003-www.jpg\" alt=\"\" class=\"wp-image-40524\" style=\"width:238px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2024\/10\/Peter-Lees-003-www.jpg 500w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2024\/10\/Peter-Lees-003-www-192x300.jpg 192w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption class=\"wp-element-caption\"><strong>Peter Lees, Head of Solution Architecture for Asia Pacific<\/strong><\/figcaption><\/figure><\/div>\n\n\n<p>Australian companies are accustomed to quite a cloudy technology climate.<\/p>\n\n\n\n<p>It\u2019s birthed a cloud continuum comprising a broad spectrum of computing deployment models. Yesteryear\u2019s on-premises infrastructures have made way for a blend of public and private clouds of many different flavours, headlined by AWS and Azure.<\/p>\n\n\n\n<p>Research shows 93% of Australian enterprises use at least two cloud infrastructure providers; 30% of those lean on four or more. This is further supplemented with edge computing as technology increasingly supports the business need to decentralise.<\/p>\n\n\n\n<p>That\u2019s not a bad thing per se. Organisations have hedged their bets across various cloud modalities for enormous benefits. For most, it\u2019s to improve the predictability of cloud costs and performance, maintain better control over what applications and data live where, provide high availability and redundancy (particularly to minimise the impact of an outage to one provider) and drive cost efficiency.<\/p>\n\n\n\n<p>Outside the operational realm, it has also allowed them to invest in cloud providers that best serve their vast and specific business objectives across various departments.<\/p>\n\n\n\n<p>However, there\u2019s a fine line between controlling these clouds and allowing them to cause a hurricane of hurt. Preventing the latter from unfolding in a heterogeneous ecosystem demands consistency to reel in complexity, driving productivity among the developers responsible for maintaining those clouds and adopting a zero-trust mentality towards security.<\/p>\n\n\n\n<p><strong>Consistency is key<br><\/strong><br>One size never fits all in the technology infrastructure game. However, the convenience of picking and choosing the cloud that fits best comes with the challenge of handling a highly distributed environment.<\/p>\n\n\n\n<p>Heterogeneity is complex. How you manage, operate, automate, and update operating systems, Kubernetes clusters &amp; runtimes, management platforms, security, and the software supply chain, to name a few, varies significantly across different clouds. With every provider wanting you to do it their way, consistency in methodology is key.<\/p>\n\n\n\n<p><br>From the perspective of operating systems, Kubernetes distributions and cloud-native deployment, it\u2019s a matter of finding consistent tools that can encompass multiple platforms in a scalable way \u2013 taking advantage of the native capabilities of those platforms while providing a consistent administrative interface and a single point to integrate ancillary components, such as security and identity management, usage monitoring, application catalogue and so on.<\/p>\n\n\n\n<p>With the right set of \u2018master\u2019 tools, ICT teamscan easily adapt to different underlying cloud platforms as and&nbsp; when the need arises without an extensive review of management processes. This in turn provides a consistency of experience for developers and other consumers of the infrastructure, which helps to streamline productivity.<\/p>\n\n\n\n<p>The added advantage of this approach is that it alleviates the pressure of needing to onboard an excessive number of platform engineers to manage very specific sets of technologies, applications, and clouds \u2013 no less during ongoing skills shortages. Instead, it allows companies to invest in high-level skills across their whole team.<\/p>\n\n\n\n<p><strong>Let developers develop<\/strong><\/p>\n\n\n\n<p>As with many jobs, developers are often pulled away from their forward-looking priorities to keep the lights on. Many of these tasks are cumbersome and border on menial \u2013 whether setting up CI\/CD pipelines, integrating toolchains, or setting up coding environments in a fragmented cloud environment.<\/p>\n\n\n\n<p>CTOs and CIOs can free their developers from these operational tasks through platforms that address cross-cutting concerns while providing support for shared tools and services. This should be complemented by frictionless experiences that enable developers to focus on coding, both on local desktop machines and in remote environments on the cloud.<\/p>\n\n\n\n<p>The rise of AI-powered coding assistants \u2013 including GitHub\u2019s Co-pilot and Amazon\u2019s CodeWhisperer \u2013 is primed to tackle mundane coding tasks, leaving developers to focus on the innovative aspects of their jobs, such as creating intuitive features and user experiences. However, they can\u2019t operate alone, and it\u2019s crucial that their use is never the main driver for developer decision-making but is instead limited to use cases that generate the highest value.<\/p>\n\n\n\n<p><strong>Zero Trust across all clouds<br><\/strong><br>About a decade ago, keeping technology safe was a fairly simple prospect: blending physical security, traditional networking and firewalls, and reasonable identity and access management tools was sufficient to keep monolithic applications and systems secure.<\/p>\n\n\n\n<p>As distributed, cloud-native, microservices-based applications have become more and more the industry standard for new development, this connected nature of the enterprise has vastly increased the potential attack surface of key systems. Application development is now more frequently a matter of \u2018gluing together\u2019 different pieces of existing code, and these varied components often have complex dependencies themselves \u2013 the software supply chain \u2013 and so can be very difficult to holistically assess.&nbsp;<\/p>\n\n\n\n<p>Between this increased use of code components, and an increase in the level of vulnerability research, it\u2019s perhaps no surprise that we\u2019ve seen a hike in software common vulnerabilities and exposures (CVEs), surging from 5,000 in 2013 to roughly 30,000 in 2023. Fortunately, known vulnerabilities can be protected against \u2013 but that still means the correct monitoring, controls, and secure software supply chain must be in place.&nbsp;<\/p>\n\n\n\n<p>The hike in hacks, exploits, and breaches has been met with a healthy rise in cyber security spending.<\/p>\n\n\n\n<p>Market intelligence firm IDC noted that, in 2024, with the frequency of cyberattacks increasing, Australia contributed over 25% of security spending in the region, alongside India, across all of Asia Pacific, excluding Japan.<\/p>\n\n\n\n<p>Even where software code vulnerabilities aren\u2019t the direct vector for attacks, the increasing complexity of distributed cloud-native applications and systems means configuration errors or omissions can introduce paths that can be exploited.<\/p>\n\n\n\n<p>Just in recent memory we\u2019ve seen some high profile breaches of Australian brands, apparently as a result of this kind of issue, including Optus, Medibank and Ticketmaster, which clearly showed how impactful security incidents can be.<\/p>\n\n\n\n<p>While continued security investment is essential, the vulnerability scanners that form part of that security spend only work against known threats. That exposes organisations to zero-day attacks \u2013 think Log4Shell \u2013 which targets a security vulnerability that has not previously been identified and for which a patch hasn\u2019t been issued.<\/p>\n\n\n\n<p>Another potential source of zero-day attacks is a bad actor within an organisation: proper implementation of zero trust means that even code from \u2018the inside\u2019 must be treated with caution.<\/p>\n\n\n\n<p>Although the consensus is that no one is immune to vulnerabilities or breaches, an uptick in cloud-native security solutions that protect applications from zero-day attacks at runtime will ensure threat actors are blocked even if malicious code is present, unauthorised access to sensitive resources is detected, code is executed remotely, or attempts at data exfiltration are made.<\/p>\n\n\n\n<p>As digital landscapes expand, so will the reliance on multi-cloud environments, each with its own nuances as dictated by cloud providers. A combined focus on consistency, developer productivity and zero-trust security stands to strip away the complexity of managing heterogeneity, ultimately making the core objectives of technology investments achievable while mitigating the risk of a storm.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Peter Lees, Head of Solution Architecture for Asia Pacific, SUSE, says there\u2019s a fine line between controlling clouds and allowing them to cause a \u2018hurricane of hurt\u2019. Australian companies are accustomed to quite a cloudy technology climate. It\u2019s birthed a cloud continuum comprising a broad spectrum of computing deployment models. Yesteryear\u2019s on-premises infrastructures have made [&hellip;]<\/p>\n","protected":false},"author":58,"featured_media":40523,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[7027,1463,12,35,55,53,1281,44,54],"tags":[549,655,5023,1070,7345,7346],"class_list":["post-40522","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-intelligent-technologies-ai","category-apac","category-cloud","category-more-news","category-oceania","category-regional-news-newsletter","category-tech","category-top-stories","category-used","tag-aws","tag-azure","tag-cloud-infrastructure","tag-kubernetes","tag-peter-lees","tag-suse"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/40522","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/users\/58"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/comments?post=40522"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/40522\/revisions"}],"predecessor-version":[{"id":40769,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/40522\/revisions\/40769"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media\/40523"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media?parent=40522"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/categories?post=40522"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/tags?post=40522"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}