{"id":29526,"date":"2017-05-24T13:31:40","date_gmt":"2017-05-24T13:31:40","guid":{"rendered":"https:\/\/www.cloudcomputing-news.net\/news\/2017\/may\/24\/wannacry-and-public-cloud-ciso-perspective\/"},"modified":"2017-05-24T13:31:40","modified_gmt":"2017-05-24T13:31:40","slug":"wannacry-and-the-public-cloud-the-ciso-perspective","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/wannacry-and-the-public-cloud-the-ciso-perspective\/","title":{"rendered":"WannaCry and the public cloud: The CISO perspective"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/www.cloudcomputing-news.net\/media\/iStock-466683417.jpg\"><\/p>\n<p><strong><span>By Matthew Sharp, CISO, Logicworks<\/span><\/strong><\/p>\n<p><span>I recently attended a CISO Executive Summit here in NYC. &nbsp;The room was packed with 175 CISOs and top-level security leaders from various industries. &nbsp;There was broad agreement that WannaCry was a scramble for many of their teams, and created a long weekend for some. &nbsp;We concurred that we were lucky the &ldquo;kill switch&rdquo; was triggered, and we soberly recognised that the exploit is being redeployed with newly weaponised malware.<\/span><\/p>\n<p><span>The consensus among CISOs is that some key processes were tested, and those with critical structures in place fared much better than those with less mature programs. &nbsp;At the same time, the incident highlighted the benefits of public cloud computing &ndash; and the need to apply automation in order to respond quickly and proactively to threats.<\/span><\/p>\n<p><span>Implementing a strategy to protect and respond to attacks like these goes beyond patching and extends to automating provisioning that supports continuous integration \/ continuous delivery (CI\/CD) pipelines, and adopting the tenants of immutable infrastructure. When your infrastructure is designed to operate like a piece of software, you can reduce or eliminate the time it takes to respond to events such as WannaCry.&nbsp; We have found AWS indispensable in that regard.<\/span><\/p>\n<p><span>In the best case, clients have a defence in depth strategy with strong endpoint technologies employing artificial intelligence, machine learning, statistical analysis or other buzz-wordy endpoint mitigation technologies.<\/span><\/p>\n<p><span>This is then combined with the abstraction layer afforded by public cloud providers that empowers a clear use of automation, often driven via Infrastructure as Code (IaC) and purposeful orchestration.&nbsp; The powerful result is that clients can perfectly define the intended state of every environment.&nbsp; They can then provide assurance that the congruence between dev, stage, test, prod is precise.&nbsp; By doing so, they accelerate their ability to deploy micro changes in addition to patches and configuration updates while understanding and mitigating many of the risks associated with change.<\/span><\/p>\n<p><span>This year&rsquo;s DevOps report again confirms that DevOps practices lead to better IT and organizational performance. High-performing IT departments achieve superior speed and reliability relative to lower-performing peers.<span>&nbsp;<\/span><a href=\"https:\/\/puppet.com\/resources\/whitepaper\/how-build-high-performing-it-team\"><span>The 2015 survey<\/span><\/a><span>&nbsp;<\/span>showed that high-performing teams deploy code 30 times more often and with 200 times shorter lead times than their peers. And they achieve this velocity and frequency without compromising reliability &mdash; in fact, they improve it. High-performing teams experience 60 times fewer failures.<\/span><\/p>\n<p><span>In the case of WannaCry, the malware exploited a critical&nbsp;SMB remote code execution vulnerability&nbsp;for which Microsoft has already released a patch (MS17-010) in mid-March.<\/span>&nbsp;<\/p>\n<p><span>For clients already taking advantage of agile operations and leveraging public cloud technologies,&nbsp;their environments were unaffected because patches were applied months ago. If it had been a zero-day exploit, the ability to implement configuration changes efficiently means that teams must still scramble to patch, but you avoid the long weekends.<\/span><\/p>\n<p><em>The post <a href=\"http:\/\/www.logicworks.com\/blog\/2017\/05\/wannacry-public-cloud\/\" rel=\"nofollow\">WannaCry and Public Cloud<\/a> appeared first on <a href=\"http:\/\/www.logicworks.com\/\" rel=\"nofollow\">Logicworks<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Matthew Sharp, CISO, Logicworks<br \/>\nI recently attended a CISO Executive Summit here in NYC. &nbsp;The room was packed with 175 CISOs and top-level security leaders from various industries. &nbsp;There was broad agreement that WannaCry was a scramble fo&#8230;<\/p>\n","protected":false},"author":60,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-29526","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/29526","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/60"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=29526"}],"version-history":[{"count":1,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/29526\/revisions"}],"predecessor-version":[{"id":29527,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/29526\/revisions\/29527"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=29526"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=29526"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=29526"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}