It seems like just yesterday that widespread enterprise cloud adoption was seen as futuristic. Today, many of the largest companies in the world are hosting their data, applications and services in public cloud — and this trend shows no signs of slowing. This year, IDC forecast that worldwide public cloud services spending will more than double to nearly $500 billion by 2023.

When it comes to the ease-of-deployment, scalability, flexible resource consumption and cost savings, the benefits that enterprises gain from moving to the cloud are largely known. In fact, according to the IBM Institute for Business Value (IBV), 98 percent of organizations expect to operate within a multicloud environment by 2021.

However, while businesses are increasingly seeking the business growth and innovation opportunities that cloud adoption can provide, many are discovering it comes with a host of new data security challenges that stall, prevent or even reverse strategic technology innovations and digital transformation initiatives, including cloud migrations.

Visibility Into Multicloud Environments

As infrastructure-as-a-service (IaaS), software-as-a-service (SaaS) and database-as-a-service (DBaaS) consumption becomes commonplace for enterprises, their data is becoming more dispersed than ever, making it extremely difficult for organizations to discover, visualize and protect their sensitive data across multiple environments. The same IBV study found that only 38 percent of organizations have the procedures and tools in place to operate a multicloud environment.

Moreover, as data and workflows continue to move to the cloud, security teams are becoming inundated with security and compliance point tools, each designed to be used within specific environments and/or use cases. This is leading to what many refer to as “tool sprawl.”

Tool sprawl can add significant operational complexity, not just in terms of security teams having to leverage disjointed dashboards and piecemeal reports, but it can lead to ineffective workflows and processes as well. Likewise, it can perpetuate a siloed approach to hybrid multicloud data security and compliance, resulting in security teams having:

  • Limited data security and compliance risk visibility
  • Fragmented data access and entitlement controls
  • Soiled security and audit reporting
  • Disconnected risk prioritization and remediation

Who Is Responsible for Cloud Security?

Scaling data security solutions and best practices across a hybrid mix of on-premises, private and cloud deployment models introduces additional layers of data security and compliance complexity, specifically around visibility and control. This is largely due to the fact that cloud service providers work on a shared responsibility model between the cloud provider and the consumer.

For instance, with an IaaS model, the customer can implement data protection measures similar to those that they would deploy on-premises. The user can then exercise tight controls through actionable policies. On the other hand, with a SaaS model, consumers often have limited visibility and control over the management of data running through that service — or none at all. They must rely on the limited, one-size-fits-all data security options offered by each of their cloud providers. This model not only perpetuates tool sprawl, it can also greatly limit an organization’s ability to exercise the specific controls needed to protect and secure sensitive data.

It is ultimately the customer’s responsibility to ensure proper data protection measures are in place, regardless of the chosen architecture.

Download the infographic: “Unifying Data Security with IBM Security Guardium Insights”

Control the Sprawl of Data Security Tools

Consolidating down to a manageable number of security tools and centralizing data security and compliance management can help organizations spot potential risks faster and execute remediation actions across disparate data environments. Having centralized visibility and control over the organization’s data security and compliance posture helps security teams take a comprehensive approach to hybrid multicloud data protection by:

  • Discovering and evaluating risk across the entire data landscape
  • Setting and monitoring access policies across environments
  • Centralizing the discovery and remediation of issues

Additionally, to protect these environments at scale, it behooves security teams to apply predictive analytics that can span across their on-premises and cloud-hosted data repositories to evaluate and prioritize threats.

Empower Your Business With Comprehensive Data Protection

As more and more businesses turn to hybrid multicloud, containers and internet of things (IoT) technologies to drive their competitive advantage, data security and compliance concerns alone must not become a roadblock. Instead, security organizations should consider a comprehensive approach to data protection. With the ability to visualize, understand and respond to risk holistically across disparate data environments, your security organization can address new risks and support emerging regulations at scale as the business drives forward with modern technologies.

Learn more about data security for hybrid multicloud

More from Cloud Security

How I got started: Cloud security engineer

3 min read - In today’s increasingly cloud-focused business environment, cloud security engineers are pivotal in protecting an organization’s critical data and infrastructure. As experts in cloud security, they leverage their expertise to ensure that the ever-expanding amount of cloud data is safe from emerging threats and vulnerabilities. Cloud security professionals combine their passion for technology with a deep understanding of security principles to design and implement robust cloud security strategies. What experience do these security experts have, and what led them to the…

“Authorized” to break in: Adversaries use valid credentials to compromise cloud environments

4 min read - Overprivileged plaintext credentials left on display in 33% of X-Force adversary simulations Adversaries are constantly seeking to improve their productivity margins, but new data from IBM X-Force suggests they aren’t exclusively leaning on sophistication to do so. Simple yet reliable tactics that offer ease of use and often direct access to privileged environments are still heavily relied upon. Today X-Force released the 2023 Cloud Threat Landscape Report, detailing common trends and top threats observed against cloud environments over the past…

Lessons learned from the Microsoft Cloud breach

3 min read - In early July, the news broke that threat actors in China used a Microsoft security flaw to execute highly targeted and sophisticated espionage against dozens of entities. Victims included the U.S. Commerce Secretary, several U.S. State Department officials and other organizations not yet publicly named. Officials and researchers alike are concerned that Microsoft products were again used to pull off an intelligence coup, such as during the SolarWinds incident. In the wake of the breach, the Department of Homeland Security…

What you need to know about protecting your data across the hybrid cloud

6 min read - The adoption of hybrid cloud environments driving business operations has become an ever-increasing trend for organizations. The hybrid cloud combines the best of both worlds, offering the flexibility of public cloud services and the security of private on-premises infrastructure. We also see an explosion of SaaS platforms and applications, such as Salesforce or Slack, where users input data, send and download files and access data stored with cloud providers. However, with this fusion of cloud resources, the risk of data…