2019 saw massive growth in the cloud market. The worldwide public cloud services market is projected to grow 17.5 percent in 2019 — totaling $214.3 billion, up from $182.4 billion in 2018, according to Gartner.

Why has there been such a surge in cloud growth? Because as organizations move toward cloud computing, they are benefiting from capital expenditure cost savings and leveraging the flexibility of software-as-a-service (SaaS) solutions. However, as cloud adoption continues, organizations need to ensure they maintain a robust cloud security posture.

To dig deeper into this, as well as inquire about where cloud security will be heading in 2020, I spoke with subject matter expert and IBM Security Program Director for QRadar Cloud, SaaS and MSSP, Chris Collard. Chris is an information security professional with over 15 years of experience managing information systems and services, a Certified Information Systems Security Professional (CISSP) and holds a Certificate of Cloud Security Knowledge (CCSK) from the Cloud Security Alliance.

What Happened in Cloud Security in 2019?

Question: As we near the end of the year, what are your key takeaways from the 2019 cloud security market?

Collard: We continue to see a growing number of clients solidify and execute on their cloud-first strategies as well as make inroads into migrating applications, data and workloads to the cloud. Increasingly, cloud is the platform of choice for building new applications as well as acquiring new software services.

For those organizations that have already made the transition, often the focus turns squarely to the challenges of effectively monitoring these environments and building orchestration and augmented intelligence into operations and response capabilities.

Nevertheless, even with the significant momentum that has developed throughout 2019, we are still a fair way off from realizing all the benefits of pure cloud deployments. Our IBM Cloud team estimates that approximately 80 percent of production workloads are still not yet migrated to the cloud. This means that a significant set of the opportunities and discussions about cloud security are still in front of many of us.

As organizations prepare for and design their path to the cloud, they absolutely have the opportunity to reimagine business processes and an imperative to protect and secure their data at each stage in the journey — including the destination. When we look at the security product and solutions market, we continue to see a fragmented one leaving many organizations to attempt to manage a patchwork of point solutions on-premises and in the cloud.

What organizations ultimately need is a cohesive and well-structured set of solutions able to continuously monitor the compliance of multi-cloud and hybrid environments. When teams can better connect their environments and data, they are better positioned to gain security insights and to take action and respond quickly when required. With a unified approach to security, organizations can gain immediate benefits and be better prepared for security in a hybrid, multi-cloud world.

The Evolving Role of SaaS in Cloud Security

What is the state of the SIEM-as-a-service market as we near the end of 2019?

Collard: Cloud is increasingly the future of security information and event management (SIEM). The cloud as the platform for SIEM allows organizations to scale better and more flexibly to align with, and meet, the present demands of their business.

Consuming capabilities as a service typically comes with the added benefit of helping free organizations from the responsibility of staffing the range of specialists required to deploy and maintain complex technology stacks. Managing threats is hard enough without having to also manage and maintain on-premises software deployments. When organizations are freed up from nonessential activities, such as managing hardware and software related life cycles, they can re-invest this found time and further focus on more important activities, such as protecting and defending critical corporate data and other important assets.

As this market continues to expand, we expect to see further adoption of open standards for data and applications. The increased adoption of STIX, TAXII and other open standards points to a future built on interoperability and the ability to protect data everywhere it exists. By not adopting open standards, you run the risk of losing visibility into the breadth of your data over time or in limiting your abilities to analyze your data into the future.

Looking Ahead to Cloud Security in 2020

What would you say should be the No. 1 priority for organizations moving to cloud security in 2020?

Collard: The short answer is protect your data — wherever it resides. The longer answer ultimately depends upon where clients are in their journey, whether they are just embarking on their journey to the cloud or they have already fully adopted the cloud as their deployment platform of choice. Protecting data from loss or leakage is the ultimate goal. To get there, organizations should embrace the opportunity to refresh their overall deployment strategy, from the ground up if necessary, and ensure that this strategy has cloud considerations integrated throughout.

After protecting your data no matter where it lives, what other aspects of cloud security should organizations focus on in 2020?

Collard: While outlining a modernized strategy, you should also take the opportunity to rebuild your security policies. Applying best practices, including a zero-trust security model, can help protect not only your data but also your networks, users, workloads and devices. This strategy should include the definition of microperimeters based on the end-to-end flow of data as well as the employment of microsegmentation, wherein identities and access can be strictly controlled to a granular degree and not just at the level of an entire server or subnet.

Where possible, organizations should look to leverage available cloud-native security controls. These controls can unlock additional visibility into your environments and can be used to further feed SIEM detection capabilities.

Achieving the goal of protecting your data across multi-cloud and hybrid environments also requires a strong DevOps — or DevSecOps — organization that can help automate, apply and manage your security at the critical intersections within your business. DevOps can play an important policy enablement role within your organization. Through DevOps, you should expect to see your policies and rules enacted with greater speed, velocity and precision.

If you have instrumented your environment correctly, have built the right monitors and have the right processes in place, you should then be effectively positioned to continuously monitor your environments for compliance. Having defined what needs to be filtered out versus kept and what needs to be analyzed versus maintained for posterity, organizations are best positioned to deliver orchestrated incident response.

No matter the size, organizations understand the benefits of migrating data and applications to cloud environments as they see the necessity to leverage cloud infrastructure to elastically scale up, store data in a cost-effective manner and reach a global customer base.

Listen to the Defense in Depth podcast on securing hybrid cloud

More from Intelligence & Analytics

X-Force Threat Intelligence Index 2024 reveals stolen credentials as top risk, with AI attacks on the horizon

4 min read - Every year, IBM X-Force analysts assess the data collected across all our security disciplines to create the IBM X-Force Threat Intelligence Index, our annual report that plots changes in the cyber threat landscape to reveal trends and help clients proactively put security measures in place. Among the many noteworthy findings in the 2024 edition of the X-Force report, three major trends stand out that we’re advising security professionals and CISOs to observe: A sharp increase in abuse of valid accounts…

Web injections are back on the rise: 40+ banks affected by new malware campaign

8 min read - Web injections, a favored technique employed by various banking trojans, have been a persistent threat in the realm of cyberattacks. These malicious injections enable cyber criminals to manipulate data exchanges between users and web browsers, potentially compromising sensitive information. In March 2023, security researchers at IBM Security Trusteer uncovered a new malware campaign using JavaScript web injections. This new campaign is widespread and particularly evasive, with historical indicators of compromise (IOCs) suggesting a possible connection to DanaBot — although we…

Accelerating security outcomes with a cloud-native SIEM

5 min read - As organizations modernize their IT infrastructure and increase adoption of cloud services, security teams face new challenges in terms of staffing, budgets and technologies. To keep pace, security programs must evolve to secure modern IT environments against fast-evolving threats with constrained resources. This will require rethinking traditional security strategies and focusing investments on capabilities like cloud security, AI-powered defense and skills development. The path forward calls on security teams to be agile, innovative and strategic amidst the changes in technology…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today