{"id":39820,"date":"2019-07-31T10:54:20","date_gmt":"2019-07-31T09:54:20","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=39820"},"modified":"2019-08-06T12:01:17","modified_gmt":"2019-08-06T11:01:17","slug":"industry-experts-on-how-best-to-secure-the-data-centre","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/07\/31\/industry-experts-on-how-best-to-secure-the-data-centre\/","title":{"rendered":"Industry experts discuss how best to ensure the data centre is secure"},"content":{"rendered":"\n<p>Ensuring\nthe data centre is secure should be a top priority for CISOs as the consequences\nof a breach are catastrophic. Industry experts from Vectra and Red Seal outline\nsome of the biggest cyber-risks to data centres and offer their advice on how\nto ensure this critical infrastructure is protected. <\/p>\n\n\n\n<p><strong>What are some of the key cyber-risks to data\ncentres?<\/strong><\/p>\n\n\n\n<p><strong><em>Ammar\nEnaya, Regional Director \u2013 Middle East, Turkey and North Africa (METNA) at\nVectra <\/em><\/strong><\/p>\n\n\n\n<p>Attackers are\nincreasingly recognising that the keys to the kingdom can be found deeper in\nthe physical devices used to build the data centre infrastructure. As a consequence, security practitioners need to\nsecure their low-level data centre management protocols, such as Intelligent\nPlatform Management Interfaces (IPMI). <\/p>\n\n\n\n<p>These protocols are increasingly targeted by attackers because they\ncreate a backdoor into the virtualised data centre environment, access to the\nsub-OS environment and control over hardware resources. <\/p>\n\n\n\n<p>In spite of these risks, these protocols are rarely effectively\nmonitored by the security solutions in place. <\/p>\n\n\n\n<p>In fact, 32% of IPMI servers have been found to run decades-old insecure\nversions, 5% were \u2018secured\u2019 by the default password, 30% had easily guessable\npasswords and only 72% had authenticate access. Today there are over 100,000\nhosts responding to IPMI queries made across the public Internet, making it an\nattractive target for cybercriminals.<\/p>\n\n\n\n<p>We\u2019ll continue to\nsee lower level architectural layers inside the data centre becoming\nincreasingly targeted by cyberattacks.<\/p>\n\n\n\n<p>This exposure represents an untapped opportunity for the channel to\ncreate long term, strategic engagements and create value inside their clients\u2019\norganisations.<\/p>\n\n\n\n<p><strong>What best practice approach should data centre\nowners take to ensure the infrastructure is well protected against\ncyberattacks?<\/strong><\/p>\n\n\n\n<p>With cloud and VM mobility, it\u2019s hard for\nsecurity teams to even keep a track of what workloads are where, never mind\nsecuring them. Having security detection and response tools that integrate\ndirectly with the hypervisor and\/or cloud service can bridge that gap. The question\nthen becomes how quickly and effectively can you detect and respond to\ndeveloping attacks in your infrastructure?<\/p>\n\n\n\n<p>Automation in cybersecurity can take\nsome of the heavy load off the shoulders of human\nanalysts and can make a considerable contribution to securing infrastructure. <\/p>\n\n\n\n<p>AI has an increasingly important role in this respect, not to replace,\nbut to augment humans and to make it easier for them to operate by providing\nthem with security analysis and insights at a speed and scale impossible for\nhumans to achieve. <\/p>\n\n\n\n<p>This provides the opportunity to spot and respond to attacks that gain a\nfoothold inside an organisation, before they can move, escalate privileges, and\nmeet their nefarious end game goals. <\/p>\n\n\n\n<p>All defences are imperfect and you increasingly achieve diminishing\nreturns for additional layers of defence. <\/p>\n\n\n\n<p>Security leaders must adopt a healthy paranoia of \u2018I\u2019m already\ncompromised, where and how?\u2019 and it is imperative to take an early detection\nand response approach to active attacks.<\/p>\n\n\n\n<p><strong>Ensuring resilience <\/strong><\/p>\n\n\n\n<p><strong><em>Mike\nLloyd, CTO, RedSeal, outlines why, when it comes to resilience, it\u2019s crucial to\nhave the basics covered. <\/em><\/strong><\/p>\n\n\n\n<p>When\nthinking about risks to data centres, I\u2019m reminded of an old bank robber story\n\u2013 when asked why he robbed banks, he replied \u2018because that\u2019s where the money is\u2019.&nbsp;It\u2019s\nalways good to think like an attacker.<\/p>\n\n\n\n<p>The people who build applications inside data centres may appreciate the\nbenefits of security, but they tend to think about it narrowly.&nbsp;They focus on how to secure the aspect they are familiar with \u2013\nif they understand users, they think a lot about single sign on and federated\nidentity, which is great, but it\u2019s not the whole of security.&nbsp;<\/p>\n\n\n\n<p>Likewise,\nthe people most familiar with databases tend to think about the problem in\ndatabase terms \u2013 row-level and column-level access controls, etc. All this\nsiloed thinking, though, tends to make a data centre with a scatter of security\nideas sprinkled around it, but no coherent overall design.&nbsp;<\/p>\n\n\n\n<p>Imagine\na corporate building built in this haphazard way, where some people lock their\nfile cabinets, but others don\u2019t, some labs have security and some don\u2019t, and\nall the while, the building has no badge readers at the edge, because nobody\nwas thinking about the big picture.<\/p>\n\n\n\n<p>Security\nfailures are almost always about gaps.&nbsp;As the crypto nerds have found, the\nsecurity arms race really isn\u2019t about evil genius hackers breaking yesterday\u2019s\ncipher math, forcing us up to a new mathematical level.&nbsp;<\/p>\n\n\n\n<p>Instead,\nreal database breaches are because someone exposed their AWS bucket to the\nInternet, when it was only supposed to be reachable internally.&nbsp;Security, or the lack of it, is all about defensive gaps.&nbsp;This\nmeans the only viable defense is to think about the system as a whole, identify\ngaps and prioritise them.&nbsp;Narrow thinking about\none control or one security technology won\u2019t work \u2013 the attackers will just\nfind a path in that evades your elaborate control.&nbsp;Breadth is far\nmore important than depth. It\u2019s far more important to check that every basic\ncontrol has been implemented consistently, than to get into depths of the\ncountermeasure of the month.<\/p>\n\n\n\n<p>In\na sense, this is good news \u2013 if you need to increase the defensive posture of a\ndata centre, your best next step is almost certain to be a simple one, where\nsome of the Centre for Internet Security (CIS) Top 20 basic controls are not in\nplace or not being used properly.&nbsp;<\/p>\n\n\n\n<p>The\nhard part is consistency \u2013 humans are not that good at being thorough and if\nyou only lock 99% of the doors, the bad guys will find that other 1% through\nsimple persistence. <\/p>\n\n\n\n<p>Attackers\nuse automation to search out any corner of your data centre that is weak and so\nthe defenders need to use automation too, to find the defensive gaps before\nthey are exploited.&nbsp; <\/p>\n\n\n\n<p>This\nmeans looking at the whole environment, end to end and checking the basics \u2013 is\nthe inventory complete?&nbsp;Are the access controls enforced\nconsistently?&nbsp;Do you have a pre-set plan to shut down or isolate any asset\nthat proves to be compromised?&nbsp;&nbsp;<\/p>\n\n\n\n<p>Being resilient in the face of cyberattacks is about doing the basics\nwell.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ensuring the data centre is secure should be a top priority for CISOs as the consequences of a breach are catastrophic. Industry experts from Vectra and Red Seal outline some of the biggest cyber-risks to data centres and offer their advice on how to ensure this critical infrastructure is protected. What are some of the [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":39825,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[46,5,6,4115,3629,13,79],"tags":[9409,156,9882,9883,3563,8455,9884,9413],"class_list":["post-39820","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-centres","category-enterprise-security","category-insights","category-intelligent-technology-newsletter","category-newsletter","category-top-stories","category-used","tag-ammar-enaya","tag-cto","tag-mike-lloyd","tag-red-seal","tag-redseal","tag-regional-director-middle-east","tag-turkey-and-north-africa-metna-at-vectra","tag-vectra"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/39820","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=39820"}],"version-history":[{"count":5,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/39820\/revisions"}],"predecessor-version":[{"id":39881,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/39820\/revisions\/39881"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/39825"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=39820"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=39820"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=39820"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}