{"id":45636,"date":"2020-02-14T12:27:11","date_gmt":"2020-02-14T12:27:11","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2020\/02\/14\/what-will-the-future-hold-for-security-when-everything-is-constantly-changing\/"},"modified":"2020-02-14T12:27:15","modified_gmt":"2020-02-14T12:27:15","slug":"what-will-the-future-hold-for-security-when-everything-is-constantly-changing","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/02\/14\/what-will-the-future-hold-for-security-when-everything-is-constantly-changing\/","title":{"rendered":"What will the future hold for security when everything is constantly changing?"},"content":{"rendered":"\n<p><em>In order to keep up with the rate at which technology is evolving, CISOs and their security teams must be mindful of the areas of change. Marco Rottigni, Chief Technical Security Officer EMEA, Qualys, offers seven predictions where he thinks security will develop most this year. <\/em><\/p>\n\n\n\n<p>Hacks still happen, software vulnerabilities get discovered and\npatches have to be applied, but the pace of change around security has gone up\nso much that the old processes are no longer enough. At the same time, cloud\nand container deployments can change at any time based on demand for those\napplications and services. So how will security have to change in 2020 to keep\nup?<\/p>\n\n\n\n<p><strong>Prediction #1 \u2013 Security will have to change in order to keep up<\/strong><\/p>\n\n\n\n<p>This year, there will be more emphasis on real-time updates around any assets that are getting created. The alternative is that images are getting created, used and then deleted without the security team even being aware that these assets exist. That is a potentially frightening thought and one that should lead to more changes throughout the year.<\/p>\n\n\n\n<p><strong>Prediction\n#2 \u2013 Digital biodiversity will force teams to deal with different work paces<\/strong><\/p>\n\n\n\n<p>There are so many different platforms in place within enterprises and\neach of them has to be kept secure. However, they all live at their own pace.\nFrom the traditional and legacy IT assets that move as fast as sloths through\nto the hummingbird pace of cloud, each platform will change in its own way over\ntime.<\/p>\n\n\n\n<p>Getting insight into these changes will be necessary so planning ahead around patch windows and major events should happen early. This will help teams prioritise and plan ahead, regardless of whether a change comes in suddenly or not.<\/p>\n\n\n\n<p><strong>Prediction\n#3 \u2013 Shared responsibility for cloud still needs to be understood<\/strong><\/p>\n\n\n\n<p>Cloud deployments are getting more and more popular. Providers like\nGoogle Cloud Platform, Microsoft Azure and Amazon Web Services all offer a\nrange of options for hosting, managing and implementing applications. Companies\nare also looking at multi-cloud and running across different cloud services\nwhere locations are available.<\/p>\n\n\n\n<p>These issues will continue as developers rush to get their applications finished or miss out working with IT security teams on moving services into production. To avoid this, companies will have to take more responsibility for their deployments. Educating developers is part of this, but building better DevOps processes that incorporate security tools into the release workflow will be just as important. This will make security &#8216;business as usual&#8217; rather than an additional headache.<\/p>\n\n\n\n<p><strong>Prediction\n#4 \u2013 Operational technology assets getting onto the Internet of Things will\nneed more security<\/strong><\/p>\n\n\n\n<p>The growth of the Internet of Things (IoT) continues. While there have been lots of consumer devices launched that simply add an Internet connection to an existing product, the market opportunity for the future is growing around the enterprise. From initial pilot projects, IoT implementations are growing in supply chain, logistics and services companies.<\/p>\n\n\n\n<p>In practice, this means that more assets are getting connected,\nincluding some that pre-date the Internet as it is today. Manufacturing\nexecution systems and operational technology assets that have to run around the\nclock can benefit from connectivity, but they also tend to be older and very\ndifficult to update. In some cases, application providers may have gone out of\nbusiness years ago.<\/p>\n\n\n\n<p>In the rush to make use of the IoT, it\u2019s important that companies\ndon\u2019t create security risks where they did not exist previously. The role for\nairgapping will continue to be important, while understanding IT assets in\ncontext will also spread to the operational technology sector too.<\/p>\n\n\n\n<p><strong>Prediction\n#5 \u2013 More security purchases will be by DevOps, not IT security <\/strong><\/p>\n\n\n\n<p>Traditional IT security sales were made by specialists to other\nspecialists. This meant that the CISO was the arbiter of who a company would\nwork with and how these solutions would be managed. <\/p>\n\n\n\n<p>This will change this year. Rather than security being solely the preserve of the IT security team, the DevOps team will be responsible for purchases or hugely influential on what gets implemented. When companies work around a CI\/CD pipeline, the DevOps team is the new buyer that has to be impressed.<\/p>\n\n\n\n<p><strong>Prediction\n#6 \u2013 Vulnerability detection will move to real-time, not scheduled <\/strong><\/p>\n\n\n\n<p>Traditionally, vulnerability management programmes ran to schedules.\nYou knew that Microsoft would release patches once a month, as would Adobe.\nOracle would release patches once per quarter. Managing these would sort out\nthe majority of problems. Looking for vulnerable software could be scheduled\naround these updates.<\/p>\n\n\n\n<p>However, today\u2019s issues are getting exploited faster than traditional patching schedules can cope with. The sheer variety of platforms in place means that changes can affect multiple systems running in different places. New technologies like cloud and containers can run intermittently, getting missed by scheduled scans. More companies will have to move over to real-time vulnerability scanning, looking for issues as they occur.<\/p>\n\n\n\n<p><strong>Prediction\n#7 &#8211; Integration and orchestration will become critical for security teams<\/strong><\/p>\n\n\n\n<p>This year, security teams will look to learn from DevOps teams around how they achieved their results and what changes were needed. At the same time, they will be looking to recruit more people with skills and understanding in building integrations and automated processes too. Security Operations Centres in particular will want to automate processes around data where they can, making existing staff more productive and helping those team members focus on more high-value tasks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In order to keep up with the rate at which technology is evolving, CISOs and their security teams must be mindful of the areas of change. Marco Rottigni, Chief Technical Security Officer EMEA, Qualys, offers seven predictions where he thinks security will develop most this year. Hacks still happen, software vulnerabilities get discovered and patches [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":45637,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,13],"tags":[832,2988],"class_list":["post-45636","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-top-stories","tag-devops","tag-qualys"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/45636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=45636"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/45636\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/45637"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=45636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=45636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=45636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}