2019 saw massive growth in the cloud market. The worldwide public cloud services market is projected to grow 17.5 percent in 2019 — totaling $214.3 billion, up from $182.4 billion in 2018, according to Gartner.

Why has there been such a surge in cloud growth? Because as organizations move toward cloud computing, they are benefiting from capital expenditure cost savings and leveraging the flexibility of software-as-a-service (SaaS) solutions. However, as cloud adoption continues, organizations need to ensure they maintain a robust cloud security posture.

To dig deeper into this, as well as inquire about where cloud security will be heading in 2020, I spoke with subject matter expert and IBM Security Program Director for QRadar Cloud, SaaS and MSSP, Chris Collard. Chris is an information security professional with over 15 years of experience managing information systems and services, a Certified Information Systems Security Professional (CISSP) and holds a Certificate of Cloud Security Knowledge (CCSK) from the Cloud Security Alliance.

What Happened in Cloud Security in 2019?

Question: As we near the end of the year, what are your key takeaways from the 2019 cloud security market?

Collard: We continue to see a growing number of clients solidify and execute on their cloud-first strategies as well as make inroads into migrating applications, data and workloads to the cloud. Increasingly, cloud is the platform of choice for building new applications as well as acquiring new software services.

For those organizations that have already made the transition, often the focus turns squarely to the challenges of effectively monitoring these environments and building orchestration and augmented intelligence into operations and response capabilities.

Nevertheless, even with the significant momentum that has developed throughout 2019, we are still a fair way off from realizing all the benefits of pure cloud deployments. Our IBM Cloud team estimates that approximately 80 percent of production workloads are still not yet migrated to the cloud. This means that a significant set of the opportunities and discussions about cloud security are still in front of many of us.

As organizations prepare for and design their path to the cloud, they absolutely have the opportunity to reimagine business processes and an imperative to protect and secure their data at each stage in the journey — including the destination. When we look at the security product and solutions market, we continue to see a fragmented one leaving many organizations to attempt to manage a patchwork of point solutions on-premises and in the cloud.

What organizations ultimately need is a cohesive and well-structured set of solutions able to continuously monitor the compliance of multi-cloud and hybrid environments. When teams can better connect their environments and data, they are better positioned to gain security insights and to take action and respond quickly when required. With a unified approach to security, organizations can gain immediate benefits and be better prepared for security in a hybrid, multi-cloud world.

The Evolving Role of SaaS in Cloud Security

What is the state of the SIEM-as-a-service market as we near the end of 2019?

Collard: Cloud is increasingly the future of security information and event management (SIEM). The cloud as the platform for SIEM allows organizations to scale better and more flexibly to align with, and meet, the present demands of their business.

Consuming capabilities as a service typically comes with the added benefit of helping free organizations from the responsibility of staffing the range of specialists required to deploy and maintain complex technology stacks. Managing threats is hard enough without having to also manage and maintain on-premises software deployments. When organizations are freed up from nonessential activities, such as managing hardware and software related life cycles, they can re-invest this found time and further focus on more important activities, such as protecting and defending critical corporate data and other important assets.

As this market continues to expand, we expect to see further adoption of open standards for data and applications. The increased adoption of STIX, TAXII and other open standards points to a future built on interoperability and the ability to protect data everywhere it exists. By not adopting open standards, you run the risk of losing visibility into the breadth of your data over time or in limiting your abilities to analyze your data into the future.

Looking Ahead to Cloud Security in 2020

What would you say should be the No. 1 priority for organizations moving to cloud security in 2020?

Collard: The short answer is protect your data — wherever it resides. The longer answer ultimately depends upon where clients are in their journey, whether they are just embarking on their journey to the cloud or they have already fully adopted the cloud as their deployment platform of choice. Protecting data from loss or leakage is the ultimate goal. To get there, organizations should embrace the opportunity to refresh their overall deployment strategy, from the ground up if necessary, and ensure that this strategy has cloud considerations integrated throughout.

After protecting your data no matter where it lives, what other aspects of cloud security should organizations focus on in 2020?

Collard: While outlining a modernized strategy, you should also take the opportunity to rebuild your security policies. Applying best practices, including a zero-trust security model, can help protect not only your data but also your networks, users, workloads and devices. This strategy should include the definition of microperimeters based on the end-to-end flow of data as well as the employment of microsegmentation, wherein identities and access can be strictly controlled to a granular degree and not just at the level of an entire server or subnet.

Where possible, organizations should look to leverage available cloud-native security controls. These controls can unlock additional visibility into your environments and can be used to further feed SIEM detection capabilities.

Achieving the goal of protecting your data across multi-cloud and hybrid environments also requires a strong DevOps — or DevSecOps — organization that can help automate, apply and manage your security at the critical intersections within your business. DevOps can play an important policy enablement role within your organization. Through DevOps, you should expect to see your policies and rules enacted with greater speed, velocity and precision.

If you have instrumented your environment correctly, have built the right monitors and have the right processes in place, you should then be effectively positioned to continuously monitor your environments for compliance. Having defined what needs to be filtered out versus kept and what needs to be analyzed versus maintained for posterity, organizations are best positioned to deliver orchestrated incident response.

No matter the size, organizations understand the benefits of migrating data and applications to cloud environments as they see the necessity to leverage cloud infrastructure to elastically scale up, store data in a cost-effective manner and reach a global customer base.

Listen to the Defense in Depth podcast on securing hybrid cloud

More from Intelligence & Analytics

Despite Tech Layoffs, Cybersecurity Positions are Hiring

4 min read - It’s easy to read today’s headlines and think that now isn’t the best time to look for a job in the tech industry. However, that’s not necessarily true. When you read deeper into the stories and numbers, cybersecurity positions are still very much in demand. Cybersecurity professionals are landing jobs every day, and IT professionals from other roles may be able to transfer their skills into cybersecurity relatively easily. As cybersecurity continues to remain a top business priority, organizations will…

4 min read

79% of Cyber Pros Make Decisions Without Threat Intelligence

4 min read - In a recent report, 79% of security pros say they make decisions without adversary insights “at least the majority of the time.” Why aren’t companies effectively leveraging threat intelligence? And does the C-Suite know this is going on? It’s not unusual for attackers to stay concealed within an organization’s computer systems for extended periods of time. And if their methods and behavioral patterns are unfamiliar, they can cause significant harm before the security team even realizes a breach has occurred.…

4 min read

Why People Skills Matter as Much as Industry Experience

4 min read - As the project manager at a large tech company, I always went to Jim when I needed help. While others on my team had more technical expertise, Jim was easy to work with. He explained technical concepts in a way anyone could understand and patiently answered my seemingly endless questions. We spent many hours collaborating and brainstorming ideas about product features as well as new processes for the team. But Jim was especially valuable when I needed help with other…

4 min read

Ex-Conti and FIN7 Actors Collaborate with New Backdoor

15 min read -   April 27, 2023 Update This article is being republished with modifications from the original that was published on April 14, 2023, to change the name of the family of malware from Domino to Minodo. This is being done to avoid any possible confusion with the HCL Domino brand. The family of malware that is described in this article is unrelated to, does not impact, nor uses HCL Domino or any of its components in any way. The malware is…

15 min read