Vodafone and IBM help National Express get on the digital transformation bus


Rene Millman

29 Aug, 2019

National Express has signed an eight-year IT modernisation deal with IBM and Vodafone Business to help the coach company with its hybrid cloud plans.

Under the agreement, the Vodafone Business and IBM venture will modernise National Express’ IT estate by moving to IBM Cloud and implementing a hybrid cloud strategy, building on the existing connectivity services provided by Vodafone Business.

IBM and Vodafone said that this would allow National Express to manage multiple clouds in different locations and from different vendors, as well as letting it scale up and down to support spikes in usage.

There will also be extra security and risk management to protect National Express’s infrastructure.

The agreement covers the provision of cloud and digital services that will underpin National Express’ ‘digital first’ approach; to use the latest technologies to raise customer and safety standards, drive efficiencies and grow its business. 

The deal will also mean that National Express can start to develop customer-focused innovations, such as personalised passenger experiences, flexible payment options and always-connected vehicles.

The coach firm will also have access to other cloud services and new technologies such as 5G, IoT, edge computing and analytics.

Debbie O’Shea, group chief information officer for National Express said that the partnership enables the company to “move to a cloud environment giving us a future-proofed platform with increased flexibility that will better support our business”.

“It also will provide access to emerging and innovative new technologies,” she added.

Anne Sheehan, business director at Vodafone UK, said that cloud services and connectivity are now “inseparable”.

“We will provide National Express with the holistic solution it requires to drive digital innovation across its business – faster, simpler and at scale,” she said.

Carbon Black execs reveal post-acquisition plans


Adam Shepherd

29 Aug, 2019

Last week, VMware threw the tech industry a curveball when CEO Pat Gelsinger announced that not only would it be acquiring Pivotal, as had been announced the previous week, it was also snapping up security firm Carbon Black. While the deal isn’t expected to close until the end of January next year, the company has devoted a substantial chunk of this year’s VMworld conference to discussing the acquisition, and what it means for the future of both companies.

For Carbon Black CEO Patrick Morley, the acquisition presents a huge opportunity for the company to expand its capabilities, and he sees a number of areas where being part of VMware can help it protect its customers in new ways.

“Pending close, I think there’s a number of opportunities,” he tells Cloud Pro. “The biggest one’s end user computing. Management and security go hand in hand, so end user computing is a huge opportunity for us.”

A substantial part of this is integration with Workspace ONE, VMware’s desktop virtualisation product. It’s one of four key integrations with its existing portfolio that VMware has already identified as priorities once the deal goes through. Not only does it make sense from a customer use-case perspective, VMware COO Sanjay Poonen pointed out that many Workspace ONE customers are also Carbon Black customers, a fact which supposedly influenced the decision to acquire the company.

While both VMware and Carbon Black executives have indicated that the company intends to keep the Carbon Black brand alive once the deal closes, and there are no immediate plans to shutter any of its services, Gelsinger told Cloud Pro that the goal is eventually to weave Carbon Black’s technology into VMware’s platform rather than offering it via standalone applications.

“The plans are to bring these integrated solutions together,” he says. “You could imagine you’re going to buy your Workspace ONE with Carbon Black. And these just end up being features. The thing is, we don’t want customers to be ‘buying point products for point use cases’ – buy a platform that gives you lots of those benefits.”

“Customers today will have a Tanium agent, Right? And they’ll have a McAfee agent, and they’ll have a Qualys agent. They’ll also have a Workspace ONE agent for management. So I’ve got four agents on the client. I have customers literally, who have 17 agents on every PC. 17 agents. What are you talking about? One was our goal, as we collapse all of those use cases into one underlying agent.”

Don’t wait, integrate

Being owned by VMware will make Carbon Black a de facto part of the Dell Technologies family, which also opens up other avenues for expanding its endpoint protection.

“Obviously, the Dell family is another capability, because Dell increasingly is providing security to its customers, as part of the laptops and other hardware that they’re providing. And so if we can build security right into that, it’s hugely advantageous too,” Morley says. “You will certainly see us work with Dell – again, pending close – to actually give customers the option to be able to put security right onto the machine, if they so choose.”

If Dell’s business laptops come preloaded with a free subscription to Carbon Black’s endpoint detection and response (EDR) service, this could be hugely beneficial for organisations. The more exciting prospect, however, is the potential impact Carbon Black’s technology can have on application security for VMware customers.

“The second piece is the work that’s already been done around app defence, which is actually building security hooks right into vSphere,” Morley explains.

This integration would enable agentless protection of applications running in vSphere, improving both application performance and detection rates. This would be groundbreaking and, if successfully integrated, has the potential to radically improve the security of organisations running vSphere.

Elsewhere, VMware is planning to integrate Carbon Black’s technology into its NSX platform to provide more in-depth network security analytics, as well as partnering it with another recent acquisition – Secure State – to address security configuration challenges. However, while the acquisition will allow Carbon Black to expand into new kinds of protection, the company executives are also extremely excited about its potential to supercharge its existing services.

One of the linchpins of Carbon Black’s technology is the collection and analysis of security data from all of the endpoints that are running its agent. At the moment, that consists of 15 million endpoints, but if Carbon Black’s agent is incorporated into vSphere or Workspace ONE, that total significantly increases overnight.

Room for growth

“We’re super excited to be able to leverage the reach that Dell EMC and VMware bring to the equation here. I mean, there’s 70,000 partners that we’re going to be able to tap into,” says Carbon Black’s senior vice president of corporate and business development Tom Barsi. “That’s really where you’re talking about adding a zero to the number of customers we’re touching.”

In addition to improving its protection capabilities, this increase in footprint and telemetry will give more fuel than ever to Carbon Black’s Threat Analysis Unit (TAU), which conducts research into security trends as well as analysing new and emerging threat actors and attack methodologies. This research, Morley promises, will most certainly continue and will in fact likely expand once the company joins VMware.

Carbon Black’s executives seem to be exceedingly positive about the prospect of joining the VMware family, which should come as no surprise. Carbon Black has been a technically-focused company since its inception – Morley notes that the company was founded by a team of actual hackers – and this emphasis on technology and engineering is at the core of its new owner’s values.

“I’m really excited,” Carbon Black CTO Scott Lundgren told Cloud Pro. “As CTO, it’s pretty amazing to have an opportunity to work with a highly technical leadership team. It starts with Pat. As ex-CTO of Intel, he’s got a great reputation, and he deserves it. He’s fantastically technical, so he understands the problem. He knows what it takes to actually address it, he can act with confidence, because he knows what’s going on under the hood. But it isn’t just Pat, the whole team is deeply technical [and has] a lot of expertise in a wide variety of technical fields across the board. It’s really great to see.”

“We’re going to have some work to do, obviously, to scale up but it’s very tractable, as long as you’ve got the right mindset at the top – and Pat has that.”

Alibaba, Google Cloud and Microsoft among inaugural members of cloud security consortium

The Linux Foundation has announced the launch of a new community of tech all-stars focused on advancing trust and security for cloud and edge computing.

The open source community, dubbed the Confidential Computing Consortium (CCC), has 10 initial members: Alibaba, Arm, Baidu, Google Cloud, IBM, Intel, Microsoft, Red Hat, Swisscom and Tencent.

“Current approaches in cloud computing address data at rest and in transit but encrypting data in use is considered the third and possibly most challenging step to providing a fully encrypted lifecycle for sensitive data,” the foundation noted in its press materials. “Confidential computing will enable encrypted data to be processed in-memory without exposing it to the rest of the system and reduce exposure for sensitive data and provide greater control and transparency for users.”

Members are encouraged to bring their own projects to the consortium, with Microsoft offering Open Enclave SDK, a framework which allows developers to build trusted execution environment (TEE) applications using a single enclaving abstraction. Intel’s Software Guard Extensions (SGX) SDK aims to help app developers protect select code and data from disclosure or modification at the hardware layer, while Red Hat’s Enarx provides hardware independence for securing applications using TEEs.

This is by no means the only cross-industry collaboration taking place in the cloud space right now. In March Intel led a launch of cohorts in a campaign to improve data centre performance through Compute Express Link (CXL), an emerging high-speed technology standard.

Alibaba, Google, and Microsoft are, alongside Intel, members of both initiatives. The three pretenders to the cloud infrastructure throne made all the right noises upon launch, with the three gifts of the Magi being looked upon with awe.

“We hope the [Open Enclave SDK] can put the tools in even more developers’ hands and accelerate the development and adoption of applications that will improve trust and security across cloud and edge computing,” said Mark Russinovich, Microsoft CTO.

“As the open source community introduces new projects like Asylo and Open Enclave SDK, and hardware vendors introduce new CPU features that change how we think about protecting programs, operating systems, and virtual machines, groups like the CCC will help companies and users understand its benefits and apply these new security capabilities to their needs,” said Royal Hansen, Google vice president for security.

The FAQ section also provides some interesting titbits. Under the question of ‘why does this require a cross-industry effort?’, the CCC responds with the following. “Of the three data states, ‘in use’ has been less addressed because it is arguably the most complicated and difficult. Currently confidential computing solutions are manifesting in different ways in hardware, with different CPU features and capabilities, even from the same vendor.

“A common, cross-industry way of describing the security benefits, risks, and features of confidential computing will help users make better choices for how to protect their workloads in the cloud,” it adds.

One notable absentee from the CCC party is Amazon Web Services (AWS). The launch, at Open Source Summit, may be something of a clue. While AWS promotes its open source initiatives through its @AWSOpen Twitter handle among others, several in the community feel differently about AWS’ relationship with open source players. The launch of DocumentDB, a database offering compatible with MongoDB in January caused TechCrunch to lead with the brazen headline that AWS had ‘[given] open source the middle finger’. Yet as reported by Business Insider in June, the company is increasingly ‘listening’ to the community.

You can find out more about CCC here.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Equinix ties up with VMware to speed up hybrid cloud deployments


Rene Millman

28 Aug, 2019

Equinix has expanded its partnership with VMware to jointly develop solutions to speed up enterprise hybrid cloud transformations. The partnership will see VMware Cloud on Dell EMC (VCDE) hardware running within Equinix data centres worldwide.

According to an announcement by both companies, enterprises will be able to use hybrid, multicloud infrastructures and network connectivity to address the increasing volume and complexity of their application workload needs.

VMware will support Equinix as a global colocation provider for VMware Cloud on Dell EMC, combining systems and storage in hybrid cloud infrastructures.

With the Equinix Cloud Exchange Fabric (ECX Fabric) interconnection service on Platform Equinix, the colocation firm said enterprises can take advantage of private multicloud connectivity and deploy hybrid cloud infrastructures.

ECX Fabric is an on-demand, SDN-enabled interconnection service that helps meet the digital transformation needs of enterprises today by allowing any business to connect between its own distributed infrastructure and any other company’s distributed infrastructure, including the world’s largest cloud providers, on Platform Equinix.

Users will also gain access to potentially thousands of new global partners they can interconnect with via ECX Fabric.

Pat Gelsinger, CEO of VMware, said that the expanded partnership “will enable our mutual customers to gain the benefit of the Equinix enterprise capabilities and the world-class VMware Cloud on Dell EMC solution”.

Rick Villars, research vice president of Datacenter & Cloud at IDC, said digital businesses require IT transformation and a complete end-to-end workload modernisation plan that enables full automation and continuous optimisation of applications.

“Shifting to an interconnected, hybrid cloud model that enables optimal placement and easy movement of workloads across multiple shared and dedicated cloud environments based on latency, resiliency and data security requirements is the critical first step in this transformation. Solutions like VMware Cloud on Dell EMC, integrated with the Equinix interconnection platform, provide businesses with a well-connected, hybrid cloud-ready foundation to quickly address the increasing complexity and volume of applications in a digital world,” he added.

Why it continues to make sense for IT ops to move to the cloud: A guide

There’s been a lot of movement in the IT operations management (ITOM) business lately, from the acquisition of SignalFx by Splunk to the PagerDuty IPO, and all signs point to a Datadog IPO in the future. What’s with all this consolidation? I believe we’re seeing the rise of a future-state of ITOM; that is to say, it’s the rise of SaaS-based ITOM. And it’s easy to see why.

In my previous consulting career as lead enterprise systems architect, our team had an impeccable record in designing and implementing well-architected hybrid infrastructure solutions. We maintained an immaculate record and near-flawless customer satisfaction record. By project sign-off, our job was always done. And yet, returning to the same solutions six months later told a different story entirely.

Well-architected solutions are similar to human bodies: They are perfect when they’re born but need constant care and feeding. These same solutions that satisfied SLAs, exceeded expectations and transformed organizational efficiency can easily degenerate, and just like our bodies have their nervous systems to monitor, brains to send alerts, and tissue to self-heal, well-architected systems need operational maintenance to keep them humming.

The traditional approach for solving this eternal need was and still is to design and implement well-architected IT Operation Management (ITOM) solutions, around a well-architected infrastructure. And yet, this is a self-fulfilling paradox because the ITOM solution itself needs the same care and feeding.

There’s a problem on-premise

ITOM is a broad term encompassing application and operating system (OS) performance, alerts, log management, notification, asset configuration, incident management and more. It typically involves the purchase of a suite of on-premise point tools addressing each need, and then to develop an internal framework to help those tools interoperate in a meaningful way. While that is possible conceptually, the facts on the ground reflect a very different reality:

  • Multi-vendor tools are often not designed to work together
  • Creating an internal logical framework that orchestrates various teams and technologies can be very complex in large enterprises
  • It’s near-impossible to create technical integrations flexible enough to adhere to inevitable organizational and technological changes that will affect this logical framework
  • Predicting cost-of-ownership is nearly impossible since each tool is controlled by a different vendor, and the internal integration effort is often unknown
  • Predicting the cost of the manpower required is also very difficult, as each tool requires its own set of specialists, in addition to integration specialists to make it all work together
  • Upkeep is often overwhelming, as vendors offload software patches, upgrades, and on-premises hardware costs to the customer

In the face of all these challenges, the end result is often unrealized value, overwhelmed operational teams, loss of service, inability to accommodate new technologies resulting business service disruptions.

Why cloud? Why now?

It’s historically been near-impossible to build a traditional ITOM platform on-premise. Vendors typically sell a collection of white-labeled tools cobbled together by acquisitions, and this is far from a platform. The complexity and the rate of technological change make it difficult to provide consistent quality and value across the various product lines. This puts the IT ops team squarely in the middle of a pickle: How can they ride the wave of a changing environment without relying on static tool suites?

The future is flexible

Enterprise IT operations has been stretched now more than ever. There is a serious skills gap, shortage in IT workforce, and ever-increasing technical complexity. Time and resources are precious and enterprise IT operations need simplicity and predictability along with flexibility and control.

Enter SaaS ITOM. By moving the ITOM function to a SaaS orientation, the responsibilities, workloads, and daily tasks can transform according to the needs of the organisation:

  • Keeping up with the business: SaaS ITOM can keep up with technological change, and keep pace with cloud, DevOps, artificial intelligence and more. In the world of SaaS, change is an accepted constant and not an inconvenience. What’s more, SaaS ITOM is infinitely more consumable than the tool suites of legacy past, and that reduces the learning curves associated with running IT operations
     
  • Keeping up with industry needs: A SaaS ITOM platform will be able to deliver a framework that’s both flexible and governed, and can accommodate technical and organizational complexities. This agility is a feature of modern SaaS. SaaS ITOM can also integrate features running on a single code base supported completely by the SaaS vendor, who will absorb maintenance and upgrade cycles, freeing considerable and valuable time back to the operator. All of this results in a more predictable total cost of ownership, improved service quality and more value to the business user

It’s not news that the world of IT is moving to the cloud. It is news, however, that cloud can offer such transformational benefits in ways we’ve never seen before.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Google to shut down Hire service from 2020


Keumars Afifi-Sabet

28 Aug, 2019

Google is shutting down its dedicated recruitment tracking service Hire from next year in order to focus resources on other areas of its cloud portfolio.

Aimed primarily at SMBs, Hire serves as a job application tracking app that integrates functions like applicant search and scheduling interviews into the wider G Suite.

Google has decided to discontinue the service from 1 September 2020, however, despite describing the app as «successful» in an official notice.

This announcement has also been made just shy of six months since the HR automation platform fully launched in the UK.

Customers will continue to receive support throughout the duration of existing contracts, and no additional charges will be levied for usage once contracts expire up until the end-of-life date. Contracts can also be terminated without penalty.

Meanwhile, there will be no new features developed for the service and all experimental features that have not been officially launched will be switched off within the next month.

A host of the features included recruiters contacting potential hires via Gmail, scheduling interviews and induction days through Google Calendar, and tracking progress through Google Sheets.

The Candidate Discovery function, in which hiring managers can trawl through several information sources to learn about potential recruits, was also considered one of the biggest draws.

Hire was initially released in 2017 following the $380 million acquisition of Bebop, founded by the former Google Cloud CEO Diane Green. The app’s closure will also be made just a few months after Green’s departure from Google’s cloud computing arm.

Despite targeting SMBs in the main, Hire is also used by a number of larger companies such as Cloudera and Atom Group.

The app’s closure doesn’t mark Google’s withdrawal from the recruitment tech sector entirely, however, with the company still committed to its Google for Jobs search tool, which is intended to rival the likes of Indeed.

Cloud Pro approached Google for comment but the firm did not respond at the time of writing.

Microsoft and Oracle bring multicloud alliance to the UK


Rene Millman

28 Aug, 2019

Oracle and Microsoft have expanded their multicloud alliance to the UK, following the launch of the partnership in June.

Users of both companies’ clouds will be able to interconnect IT environments and applications that span both clouds. Vinay Shivagange Chandrashekar, vice president of product management at Oracle, said that linking cloud regions that are physically close to each other makes the interconnection more useful.

“Closer cloud resources means less latency, which enables better data transfer and application interaction between clouds, and supports a broader spectrum of workloads using resources on both sides. By enabling this interconnection in London, we’re opening the door for usage of this kind on a whole new continent,” he said, adding that London is “one of the most active Oracle Cloud regions”.

“By enabling a preconfigured, dedicated interconnection, common controls, integrated identity management, and support capabilities, we’re giving customers a roster of new services in Azure that they can use with the services that they use in our cloud,” he said.

He added that many customers that run in the UK can now deploy Oracle databases and applications as cloud services, and connect those services to applications on Azure that run the Microsoft stack. Joint customers can create a combination of services from each cloud, matching each part of their workload inventory to the optimal cloud for each, without added complexity or settling for an inferior environment for parts of what they run.

Chandrashekar said that before the cloud Oracle and Microsoft technologies could coexist effectively in customer data centres, with systems running each stack close enough for easy information exchange.

“The move to cloud broke this capability. Each vendor’s cloud was isolated from the others, making interchange between solutions on each difficult or impossible,” he said. “This alliance gives customers the ability to interconnect workloads from multiple vendors as they could in their own data centres.”

Chandrashekar added that more multivendor solutions will be enabled by decoupled application architectures, common management frameworks, and better interconnection of networks.

Google and Dell team up on enterprise Chromebooks


Bobby Hellard

27 Aug, 2019

Google and Dell are teaming up to take on Microsoft with two enterprise-ready Chromebooks, according to reports.

Dell is launching Chrome OS takes on a pair of its popular business-focused laptops in the form of the Latitude 5400 Chromebook Enterprise and the Latitude 5300 2-in-1 Chromebook Enterprise.

Both of these computers will be the first machines to fall under Google’s new Chromebook Enterprise line, which will see the search giant and partner hardware makers keenly target Chromebooks at business use. While Chromebooks aren’t unknown to the business world, they haven’t taken the market by storm, with Microsoft dominating in the enterprise arena and Chromebooks finding more use in the education sector. 

But Google hopes to challenge Microsoft in a more comprehensive manner with the Chromebook Enterprise line, with Dell helping lead the charge. 

“Chromebook Enterprise is a game-changer for businesses looking for a modern OS that provides end-users with speed and productivity while offering IT the comprehensive security they need,” said John Solomon, vice president of Chrome OS at Google. “As a longtime global leader in the enterprise, Dell Technologies has a deep understanding of end-user and IT needs and is a natural fit to bring powerful devices with the benefits of Chrome Enterprise to businesses worldwide.”

“IT administrators want to give users choice when it comes to OS, device, and when and where work gets done, but they struggle with the growing number of unmanaged devices in their environments,” said Jay Parker, president of the Client Product Group at Dell. “By adding Chrome to Dell Technologies Unified Workspace, we’re giving IT the power to offer a consistent and secure experience for everyone, no matter the OS they choose. And best of all, users get the flexibility to choose the devices and use cases that fit their needs.”

For the two Latitudes models, Dell will bundle in its cloud-based support services, which allow admins to have greater control over how these Chromebooks are deployed within their business. This should help IT admins integrate the Chromebooks into existing Windows environments and manage them through tools like VMware Workspace One.

The Latitude 5400 will have a 14in screen and start at £449, while the 13inch the 5300 13inch 2-in-1 has a starting price of £699. Both can be configured with Intel’s 8th Gen Core i7 processors, up to 32GB of RAM.

Oracle to appeal «unlawful» decision on JEDI contract lawsuit


Dale Walker

27 Aug, 2019

Oracle said it plans to appeal a recent court decision that saw the dismissal of its challenge against the US’ JEDI cloud contract, the company confirmed on Monday.

Oracle has consistently argued that the procurement process of the Joint Enterprise Defence Infrastructure (JEDI) contract, awarded by the US Department of Defence, contravened federal laws and unfairly favoured AWS over other providers.

The company filed a lawsuit against the DoD in December last year, arguing that there were conflicts of interest between former Pentagon and AWS employees. Before a ruling was made on that lawsuit, Oracle was removed from the bidding process in April when it failed to meet the requirement of having three data centres with FedRAMP Moderate ‘Authorised’ support.

The Federal Claims Court ruled in July that because Oracle was unable to qualify for the bid criteria, it lacked the legal standing to challenge the procurement process and therefore dismissed its lawsuit.

Oracle believes the latest dismissal fails to address federal laws that prohibit the awarding of contracts to a single provider.

«Federal procurement laws specifically bar single award procurements such as JEDI absent satisfying specific, mandatory requirements, and the Court in its opinion clearly found DoD did not satisfy these requirements,» said Dorian Daley, general counsel for Oracle.

«The opinion also acknowledges that the procurement suffers from many significant conflicts of interest. These conflicts violate the law and undermine the public trust. As a threshold matter, we believe that the determination of no standing is wrong as a matter of law, and the very analysis in the opinion compels a determination that the procurement was unlawful on several grounds.»

JEDI, a contract said to be worth up to $10 billion, will see the winning bidder take charge of hosting and distributing DoD workloads, including those related to classified military operations. Currently, Microsoft and AWS are the only providers being considered for the contract – Google dropped out of the running early after an employee protest claimed the deal would contravene company ethics.

Earlier this month the DoD announced it would suspend the awarding of the contract while it investigates allegations of bias towards AWS.

How does privileged access security work on AWS and other public clouds?

Bottom line: Amazon’s Identity and Access Management (IAM) centralises identity roles, policies and Config Rules yet doesn’t go far enough to provide a Zero Trust-based approach to Privileged Access Management (PAM) that enterprises need today.

AWS provides a baseline level of support for Identity and Access Management at no charge as part of their AWS instances, as do other public cloud providers. Designed to provide customers with the essentials to support IAM, the free version often doesn’t go far enough to support PAM at the enterprise level. To AWS’s credit, they continue to invest in IAM features while fine-tuning how Config Rules in their IAM can create alerts using AWS Lambda. AWS’s native IAM can also integrate at the API level to HR systems and corporate directories, and suspend users who violate access privileges.

In short, native IAM capabilities offered by AWS, Microsoft Azure, Google Cloud, and more provides enough functionality to help an organisation get up and running to control access in their respective homogeneous cloud environments. Often they lack the scale to fully address the more challenging, complex areas of IAM and PAM in hybrid or multi-cloud environments.

The truth about privileged access security on cloud providers like AWS

The essence of the Shared Responsibility Model is assigning responsibility for the security of the cloud itself including the infrastructure, hardware, software, and facilities to AWS and assign the securing of operating systems, platforms, and data to customers. The AWS version of the Shared Responsibility Model, shown below, illustrates how Amazon has defined securing the data itself, management of the platform, applications and how they’re accessed, and various configurations as the customers’ responsibility:

AWS provides basic IAM support that protects its customers against privileged credential abuse in a homogenous AWS-only environment. Forrester estimates that 80% of data breaches involve compromised privileged credentials, and a recent survey by Centrify found that 74% of all breaches involved privileged access abuse.

The following are the four truths about privileged access security on AWS (and, generally, other public cloud providers):

Customers of AWS and other public cloud providers should not fall for the myth that cloud service providers can completely protect their customised and highly individualised cloud instances

As the Shared Responsibility Model above illustrates, AWS secures the core areas of their cloud platform, including infrastructure and hosting services. AWS customers are responsible for securing operating systems, platforms, and data and most importantly, privileged access credentials.

Organisations need to consider the Shared Responsibility Model the starting point on creating an enterprise-wide security strategy with a Zero Trust Security framework being the long-term goal. AWS’s IAM is an interim solution to the long-term challenge of achieving Zero Trust Privilege across an enterprise ecosystem that is going to become more hybrid or multi-cloud as time goes on.

Despite what many AWS integrators say, adopting a new cloud platform doesn’t require a new Privileged Access Security model

Many organisations who have adopted AWS and other cloud platforms are using the same Privileged Access Security Model they have in place for their existing on-premises systems. The truth is the same Privileged Access Security Model can be used for on-premises and IaaS implementations.

Even AWS itself has stated that conventional security and compliance concepts still apply in the cloud. For an overview of the most valuable best practices for securing AWS instances, please see my previous post, 6 Best Practices For Increasing Security In AWS In A Zero Trust World.

Hybrid cloud architectures that include AWS instances don’t need an entirely new identity infrastructure and can rely on advanced technologies, including Multi-Directory Brokering

Creating duplicate identities increases cost, risk, and overhead and the burden of requiring additional licenses. Existing directories (such as Active Directory) can be extended through various deployment options, each with their strengths and weaknesses. Centrify, for example, offers Multi-Directory Brokering to use whatever preferred directory already exists in an organisation to authenticate users in hybrid and multi-cloud environments.

And while AWS provides key pairs for access to Amazon Elastic Compute Cloud (Amazon EC2) instances, their security best practices recommend a holistic approach should be used across on-premises and multi-cloud environments, including Active Directory or LDAP in the security architecture.

It’s possible to scale existing Privileged Access Management systems in use for on-premises systems today to hybrid cloud platforms that include AWS, Google Cloud, Microsoft Azure, and other platforms

There’s a tendency on the part of system integrators specialising in cloud security to oversell cloud service providers’ native IAM and PAM capabilities, saying that a hybrid cloud strategy requires separate systems. Look for system integrators and experienced security solutions providers who can use a common security model already in place to move workloads to new AWS instances.

Conclusion

The truth is that Identity and Access Management solutions built into public cloud offerings such as AWS, Microsoft Azure, and Google Cloud are stop-gap solutions to a long-term security challenge many organisations are facing today. Instead of relying only on a public cloud provider’s IAM and security solutions, every organisation’s cloud security goals need to include a holistic approach to identity and access management and not create silos for each cloud environment they are using.

While AWS continues to invest in their IAM solution, organisations need to prioritise protecting their privileged access credentials – the “keys to the kingdom” – that if ever compromised would allow hackers to walk in the front door of the most valuable systems an organisation has. The four truths defined in this article are essential for building a Zero Trust roadmap for any organisation that will scale with them as they grow.

By taking a “never trust, always verify, enforce least privilege” strategy when it comes to their hybrid- and multi-cloud strategies, organisations can alleviate costly breaches that harm the long-term operations of any business.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.