December 23, 2019 By Rob Young 3 min read

It seems like just yesterday that widespread enterprise cloud adoption was seen as futuristic. Today, many of the largest companies in the world are hosting their data, applications and services in public cloud — and this trend shows no signs of slowing. This year, IDC forecast that worldwide public cloud services spending will more than double to nearly $500 billion by 2023.

When it comes to the ease-of-deployment, scalability, flexible resource consumption and cost savings, the benefits that enterprises gain from moving to the cloud are largely known. In fact, according to the IBM Institute for Business Value (IBV), 98 percent of organizations expect to operate within a multicloud environment by 2021.

However, while businesses are increasingly seeking the business growth and innovation opportunities that cloud adoption can provide, many are discovering it comes with a host of new data security challenges that stall, prevent or even reverse strategic technology innovations and digital transformation initiatives, including cloud migrations.

Visibility Into Multicloud Environments

As infrastructure-as-a-service (IaaS), software-as-a-service (SaaS) and database-as-a-service (DBaaS) consumption becomes commonplace for enterprises, their data is becoming more dispersed than ever, making it extremely difficult for organizations to discover, visualize and protect their sensitive data across multiple environments. The same IBV study found that only 38 percent of organizations have the procedures and tools in place to operate a multicloud environment.

Moreover, as data and workflows continue to move to the cloud, security teams are becoming inundated with security and compliance point tools, each designed to be used within specific environments and/or use cases. This is leading to what many refer to as “tool sprawl.”

Tool sprawl can add significant operational complexity, not just in terms of security teams having to leverage disjointed dashboards and piecemeal reports, but it can lead to ineffective workflows and processes as well. Likewise, it can perpetuate a siloed approach to hybrid multicloud data security and compliance, resulting in security teams having:

  • Limited data security and compliance risk visibility
  • Fragmented data access and entitlement controls
  • Soiled security and audit reporting
  • Disconnected risk prioritization and remediation

Who Is Responsible for Cloud Security?

Scaling data security solutions and best practices across a hybrid mix of on-premises, private and cloud deployment models introduces additional layers of data security and compliance complexity, specifically around visibility and control. This is largely due to the fact that cloud service providers work on a shared responsibility model between the cloud provider and the consumer.

For instance, with an IaaS model, the customer can implement data protection measures similar to those that they would deploy on-premises. The user can then exercise tight controls through actionable policies. On the other hand, with a SaaS model, consumers often have limited visibility and control over the management of data running through that service — or none at all. They must rely on the limited, one-size-fits-all data security options offered by each of their cloud providers. This model not only perpetuates tool sprawl, it can also greatly limit an organization’s ability to exercise the specific controls needed to protect and secure sensitive data.

It is ultimately the customer’s responsibility to ensure proper data protection measures are in place, regardless of the chosen architecture.

Download the infographic: “Unifying Data Security with IBM Security Guardium Insights”

Control the Sprawl of Data Security Tools

Consolidating down to a manageable number of security tools and centralizing data security and compliance management can help organizations spot potential risks faster and execute remediation actions across disparate data environments. Having centralized visibility and control over the organization’s data security and compliance posture helps security teams take a comprehensive approach to hybrid multicloud data protection by:

  • Discovering and evaluating risk across the entire data landscape
  • Setting and monitoring access policies across environments
  • Centralizing the discovery and remediation of issues

Additionally, to protect these environments at scale, it behooves security teams to apply predictive analytics that can span across their on-premises and cloud-hosted data repositories to evaluate and prioritize threats.

Empower Your Business With Comprehensive Data Protection

As more and more businesses turn to hybrid multicloud, containers and internet of things (IoT) technologies to drive their competitive advantage, data security and compliance concerns alone must not become a roadblock. Instead, security organizations should consider a comprehensive approach to data protection. With the ability to visualize, understand and respond to risk holistically across disparate data environments, your security organization can address new risks and support emerging regulations at scale as the business drives forward with modern technologies.

Learn more about data security for hybrid multicloud

More from Cloud Security

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Cloud threat report: Possible trend in cloud credential “oversaturation”

3 min read - For years now, the dark web has built and maintained its own evolving economy, supported by the acquisition and sales of stolen data, user login credentials and business IP. But much like any market today, the dark web economy is subject to supply and demand.A recent X-Force Cloud Threat Landscape Report has shed light on this fact, revealing a new trend in the average prices for stolen cloud access credentials. Since 2022, there has been a steady decrease in market…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today