{"id":46538,"date":"2020-03-25T10:33:09","date_gmt":"2020-03-25T10:33:09","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2020\/03\/25\/how-to-manage-network-risk-using-fluid-security\/"},"modified":"2020-04-02T08:07:54","modified_gmt":"2020-04-02T07:07:54","slug":"how-to-manage-network-risk-using-fluid-security","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/03\/25\/how-to-manage-network-risk-using-fluid-security\/","title":{"rendered":"How to manage network risk using fluid security"},"content":{"rendered":"\n<p><em>With organisations utilising new technologies in the age of Digital Transformation, it is vital that the security surrounding innovation is up to standard. Amrit Williams, Vice President of Products at Skybox Security, tells us why fluid security\u2019 practices are so important in developing a successful security programme and thus relieving pressure for CISOs.   <\/em><\/p>\n\n\n\n<p>As organisations forge ahead with their Digital\nTransformation initiatives, there is a growing burden being placed on their\nsecurity teams. Their workload is only mounting as more businesses move towards\ncloud-first, or even cloud-only, infrastructure. As well as being expected to\nsecure new services, these teams must simultaneously manage the security of the\nprevailing on-premise infrastructure and assets. <\/p>\n\n\n\n<p>The promise of cloud-only environments is\nappealing: when properly executed, it promises to eliminate network\nfragmentation. But there are a number of challenges associated with the\nimplementation of each new service and device that are becoming increasingly\ndifficult for the CISO and their team to navigate. <\/p>\n\n\n\n<p>The complexity inherent to managing cybersecurity\nis continually ramping up. This is certainly true for managing the security\naround both public and private clouds. Although these are services that are\nusually supported by a variety of cloud service providers (CSPs), they are also\nregularly misconfigured. While the cloud promises great benefits for the\nbusiness, there is a long road to actually seeing them come into fruition. If\nthe security surrounding innovation is not up to par, it could end up doing\nmore harm than good. <\/p>\n\n\n\n<p><strong>Using fluid security to secure innovation within complex hybrid networks <\/strong><\/p>\n\n\n\n<p>For a majority of organisations, hybrid\nnetworks have become standard. This means security teams are required to manage\na growing attack surface made up of on-premise IT, OT, cloud and third-party\nenvironments. This has created a stressful environment for CISOs who are tasked\nwith preventing any mishaps. Never before has there been a greater need for a\nrobust, focused and lasting risk management strategy. One such strategy focuses\non developing \u2018fluid security\u2019 practices \u2013 this is a strategy that is popular\nwith some of the world\u2019s largest and most complex businesses. <\/p>\n\n\n\n<p>Fluid security places a heavy focus on developing a unified, agnostic and continuous security programme. This involves establishing processes that control the security of the network environment until it is no longer required while guaranteeing that the varied security environment doesn\u2019t include any redundancy \u2013 whether that be in technology, employees or processes. When properly applied, security teams are able to support changing enterprise needs at the drop of a hat with negligible impact on the rest of the business. <\/p>\n\n\n\n<p><strong>Prioritise data equality <\/strong><\/p>\n\n\n\n<p>In terms of security, being data agnostic\nmeans that, regardless of the source, data must be stored in a central hub, and\nlike-data must be normalised and amalgamated, irrespective of environment type,\nvendors, etc. Data should be integrated into clean datasets, eradicating\nduplicates, to facilitate more effective analysis. These data handling processes\nneed to be the first steps taken to guarantee the successful simplification and\ncentralisation of a complex, fragmented environment.<\/p>\n\n\n\n<p>Once the data is centralised, the next step in\nreducing the complexity of that data is to find a way to model it. By creating an\nalways up-to-date model of hybrid network infrastructure, security controls,\nassets, vulnerabilities and threats, new possibilities of insight into the\ninterrelationships of a network can be revealed. Modelling can help an array of\nsecurity management processes, unifying teams with a comprehensive overview of a\nbusiness\u2019 attack surface.<\/p>\n\n\n\n<p><strong>Eradicating disconnected processes<\/strong><\/p>\n\n\n\n<p>Having disconnected processes in a hybrid environment\nis a common pitfall, primarily because individual teams are made to take\nresponsibility for separate areas of the network. In a growing number of\nworkplaces, the problem of operational siloes goes beyond security and\noperations teams and is also an issue for DevOps\/DevSecOps teams. <\/p>\n\n\n\n<p>While each team has their own specific task,\nthe procedures that make up their everyday role must point towards a single aim.\nTaking DevSecOps as an example, they may have processes\nfor \u2018security in code\u2019, but any updates to new or prevailing systems could have\nconsequences for compliance status. Owing to this, they will need to be constantly\nobserved in case their risk status changes. <\/p>\n\n\n\n<p>In this instance, having full visibility of\ncloud networks is vital. It\u2019s only with a comprehensive understanding of the\nenvironment that security teams are able to identify and analyse\nvulnerabilities within services and containers. In addition, when considering\npolicy compliance, the testing of accessibility, security tags, cloud firewall\nrules and configurations by security teams is also a necessity. <\/p>\n\n\n\n<p>These scenarios all illustrate how beneficial a\nhybrid environment model can really be. Offline models can be regularly updated\nvia application programming interface (API)\nconnections, which means that security and operations teams do not need\nadministrative access to cloud platforms. When this is in place, security teams\ncan complete necessary tasks with minimal disruption to the deployment of the\ncloud. If a violation or risk were to be identified, the problem can be removed\nwhen security and operations teams report back to DevSecOps and perform necessary\namends together.<\/p>\n\n\n\n<p><strong>Replication of risk <\/strong><\/p>\n\n\n\n<p>To safeguard the longevity of any fluid security strategy, ongoing cyberhygiene processes designed to reduce risk and compliance violations are also important to take into account. Often, there\u2019s a tendency for teams to &#8216;set it and forget it&#8217; during deployments because cloud services often have short life cycles. This is a habit that needs to be wiped out: it simply doesn\u2019t work well with the way that DevOps teams are set up. <\/p>\n\n\n\n<p>Work conducted by DevOps professionals is\nfounded on replication. This relates to their activities \u2013 say, &nbsp;replicating the simple creation of\ncontainer-based services, the move from image to instance, and so on \u2013 but it\nalso means that risk can be easily replicated within cloud services on a faster\nand wider scale that it would do within on-premise infrastructure. That\u2019s why cloud\nservices should be treated with the same careful consideration that is given to\nother areas of the infrastructure, even if the processes and tools that need to\nbe used to achieve that vigilance are different.<\/p>\n\n\n\n<p>Making sure the data handling and unified management processes described above become the standard is the only way to guarantee the future security of hybrid networks. By taking a fluid approach to security, the right foundations will be in place to support an established programme ready to cope with today\u2019s challenges and to support innovation going forward. While cloud is now viewed as a &#8216;must-have&#8217; technology, innovation is being spun-up so quickly that dynamic computing could be a very different beast in a matter of years. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>With organisations utilising new technologies in the age of Digital Transformation, it is vital that the security surrounding innovation is up to standard. Amrit Williams, Vice President of Products at Skybox Security, tells us why fluid security\u2019 practices are so important in developing a successful security programme and thus relieving pressure for CISOs. As organisations [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":46542,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[331,5,6,4115,3629,13,79],"tags":[22,832,5651],"class_list":["post-46538","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud","category-enterprise-security","category-insights","category-intelligent-technology-newsletter","category-newsletter","category-top-stories","category-used","tag-cloud","tag-devops","tag-devsecops"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=46538"}],"version-history":[{"count":4,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46538\/revisions"}],"predecessor-version":[{"id":46630,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46538\/revisions\/46630"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/46542"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=46538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=46538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=46538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}