<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/cloud-security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Cloud-security ]]></title>
                <link>https://www.itpro.com/uk/cloud/cloud-security</link>
        <description><![CDATA[ All the latest cloud-security content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Thu, 23 Apr 2026 09:24:25 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ 'The goal for this year will be to automate all security processes': Google Cloud is betting on Wiz to usher in a new era of AI security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-goal-for-this-year-will-be-to-automate-all-security-processes-google-cloud-is-betting-on-wiz-to-usher-in-a-new-era-of-ai-security</link>
                                                                            <description>
                            <![CDATA[ Wiz wants to deploy its agents for continuous penetration testing, and in Google it’s found a parent company that can achieve this vision at scale ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ctMeUtSErHFYBMQui96CMY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N3B3FC3PLDnt7g9MWxz368-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Apr 2026 09:24:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Vep5JogbPhduK7R6CUWAm6.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N3B3FC3PLDnt7g9MWxz368-1280-80.jpg">
                                                            <media:credit><![CDATA[ITPro/Rory Bathgate]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Francis deSouza, COO and president of security products at Google Cloud, pictured speaking on stage at Google Cloud Next 2026 in Las Vegas. ]]></media:description>                                                            <media:text><![CDATA[Francis deSouza, COO and president of security products at Google Cloud, pictured speaking on stage at Google Cloud Next 2026 in Las Vegas. ]]></media:text>
                                <media:title type="plain"><![CDATA[Francis deSouza, COO and president of security products at Google Cloud, pictured speaking on stage at Google Cloud Next 2026 in Las Vegas. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N3B3FC3PLDnt7g9MWxz368-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google Cloud has announced a slew of new AI-powered security features, including new AI agents for continuous security developed by its new subsidiary Wiz.</p><p>Following <a href="https://www.itpro.com/business/business-strategy/google-confirms-wiz-acquisition-in-record-breaking-usd32-billion-deal">Google Cloud’s record $32 billion acquisition</a> of the Israeli-American cybersecurity startup, the hyperscaler is looking to deploy Wiz agents at a scale that was previously impossible.</p><p>To date, Wiz has made the detection of what it calls ‘toxic combinations’ in cloud environments – including misconfigurations, excessive permissions, and overlooked vulnerabilities – its bread and butter. </p><p>Google Cloud wants to apply this specialism to its entire platform, as well as those of partners.</p><p>While AI can be used to bolster defenses, improperly configured LLMs and AI agents can also complicate <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>strategies and introduce new risks of their own, such as <a href="https://www.itpro.com/security/ncsc-issues-urgent-warning-over-growing-ai-prompt-injection-risks-heres-what-you-need-to-know"><u>prompt injection attacks</u></a>.</p><p>Google Cloud and Wiz aim to identify these risks in real-time by embedding security into AI as it’s deployed rather than bolting it on after the fact. At Google Cloud Next 2026, both firms have led with a joint message of a deep-set need for AI preparedness.</p><p>“One of the things we do is provide the right protections associated with rolling out your AI infrastructure that you can then make available,” said Francis deSouza, COO and president, Security Products at Google Cloud.</p><p>“Because [it is] not possible to retrofit security into an IT environment, you need to design it in from the ground up.”</p><p>For example, Wiz has launched AI agents that act as automated security researchers and engineers: Red Agent, Blue Agent, and Green Agent.</p><p>“Red team is typically contesting from the outside, and the Red Agent actually leverages the deep visibility that we get into cloud environments and identifies all of the potential exposures, all of the APIs that are internet exposed,”<em> </em>explained Yinon Costica, VP Product and co-founder of Wiz.</p><p>“The Green Agent actually takes the risk that the, let's say the red agent found, and then it automates the triage process.”</p><p>Costica explained that this speeds up a process that normally takes days or even weeks of manual security work. Finally, the Blue Agent takes indications of compromise and automates the investigation process into these threats.</p><p>He added that the three agents can collaborate and work with one another to improve defenses. For example, Red Agent can invoke Green Agent after identifying a vulnerability, or Blue Agent can attempt to flag intrusions by Red Agent to test the effectiveness of an organization’s detection capabilities.</p><p>All of the agents are managed via Wiz AI Application Protection Platform (AI-APP), an umbrella offering that secures every enterprise AI layer including agents, models, infrastructure, data, and access permissions. </p><p>Reflecting on the increasing pace of AI-powered attacks, Costica argued that firms must begin to apply agents to “start using AI against ourselves as much as possible” to identify weaknesses and fix them before attackers find them.</p><p>“The goal for this year will be to automate all security processes we know, because that's the only way to go. </p><p>“So there are human automations that we've been using in industry, but I think what agents allow us to do is get to the next level of acceleration and automation of security work.”</p><p>This sentiment was echoed by deSouza in the <a href="https://www.itpro.com/cloud/live/google-cloud-next-2026-all-the-live-updates-as-they-happen"><u>event’s opening keynote</u></a>, in which he warned that hackers have reduced the time between initial access and handoff to secondary threat groups from eight hours to 22 seconds.</p><h2 id="secure-interoperability">Secure interoperability</h2><p>A core part of the updated security offering at Google Cloud is its interoperability. The hyperscaler has partnered with firms such as Darktrace, Gigamon, and SAP to extend its out of the box security features to their platforms, and also supports end-to-end AI application protection on platforms like AWS, Microsoft Azure, and Oracle Cloud.</p><p>Customers can even extend security functions to SaaS tools such as OpenAI and custom-hosted cloud environments.</p><p>“It is a <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud">multi-cloud</a> world, and we talk to our customers about that all the time saying every company is a multi-cloud company, and will need to continue to be a multi-cloud company,” said deSouza,</p><p>In addition to its GCP-native functionality, Wiz supports Databricks and agent platforms including AWS <a href="https://www.itpro.com/technology/artificial-intelligence/amazons-go-build-it-ai-strategy-is-a-perfect-fit-for-openais-big-enterprise-push"><u>Agentcore</u></a>, Gemini Enterprise Agent Platform, Microsoft Azure Copilot Studio, and Salesforce <a href="https://www.itpro.com/business/business-strategy/salesforce-announces-huge-partner-program-revamp-with-agentforce-360-launch"><u>Agentforce</u></a>. </p><p>Customers can also extend its security features to external security ecosystems such as Cloudflare AI Security for Apps, Google Cloud Apigee, and <a href="https://www.itpro.com/security/data-breaches/everything-we-know-about-the-vercel-data-breach-so-far"><u>Vercel</u></a>.</p><h2 id="expanding-security-agents">Expanding security agents</h2><p>Alongside the Wiz-developed tools, Google Cloud also highlighted its AI agents for SecOps. These include <a href="https://www.itpro.com/security/google-just-launched-a-new-gemini-powered-dark-web-monitoring-service"><u>Dark Web Intelligence</u></a>, an agent announced at RSAC Conference 2026 that produces organization-specific threat profiles based on Google Threat Intelligence Group’s <a href="https://www.itpro.com/security/32117/what-is-the-dark-web"><u>dark web</u></a> monitoring. </p><p>DeSouza noted that Dark Web Intelligence can identify threats with 98% accuracy, a step above what was previously capable within the security industry.</p><p>“Coming up with new rules is a complex process, it can be done by humans but you have new intelligence coming out all the time,” said deSouza, adding that many organizations have thousands of security rules already in place and that adding new ones onto this list can be an overwhelming task.</p><p>Additionally, cybersecurity teams can use the Threat Hunting Agent and Detection Engineering Agent to search for active threats and novel attacks, identify gaps in their organization’s cybersecurity, and create automated detection rules based on current threats.</p><p>In total, Google Cloud’s Triage and Investigation agent processed more than five million alerts in 2025. The firm said the tool helps teams to complete cybersecurity analysis that previously took 30 minutes in just 60 seconds, using Gemini for reasoning and text generation.</p><p>Another new platform, Google Cloud Fraud Defense, is intended to build upon reCAPTCHA services to assess the legitimacy of humans, bots, and agents within business processes and commerce.</p><p>The announcements made at Google Cloud Next 2026 represent not only the sum of Google Cloud’s teams but also the innovations of Google DeepMind and the proprietary technologies Wiz relied on prior to its acquisition.</p><p><em>ITPro </em>understands that Wiz uses a mix of backend models, which it chooses depending on customer use cases. But deSouza said that going forward both Google Cloud and Wiz teams would benefit from sharing notes with internal frontier model developers.</p><p>“We have an advantage here,” said deSouza. </p><p>“Our defense technologies like Wiz work with our frontier model teams, and we know in advance what the model is going to have. And so on day one, we're taking advantage of the cutting edge of defense to protect our customers.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wiz: 80% of cloud breaches are caused by basic mistakes ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/wiz-80-percent-of-cloud-breaches-are-caused-by-basic-mistakes</link>
                                                                            <description>
                            <![CDATA[ Wiz Threat Research's analysis of 2025 cloud incidents shows that familiar risks are expanding with scale, shared trust, and AI-driven environments ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WWRRsFHuix7rkRiDpqA8CG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d4Q6FKh9ofCeeEtELW6vFm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Apr 2026 14:45:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d4Q6FKh9ofCeeEtELW6vFm-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud computing concept image showing multi-colored digitized cloud symbol.]]></media:description>                                                            <media:text><![CDATA[Cloud computing concept image showing multi-colored digitized cloud symbol.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud computing concept image showing multi-colored digitized cloud symbol.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d4Q6FKh9ofCeeEtELW6vFm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI isn’t creating new classes of vulnerabilities, according to research from <a href="https://www.itpro.com/business/business-strategy/google-confirms-wiz-acquisition-in-record-breaking-usd32-billion-deal">Wiz </a>– but it is expanding the range of where well-known risks can appear. </p><p><a href="https://www.wiz.io/reports/cloud-threat-retrospective-2026" target="_blank"><u>Analysis </u></a>from the cloud security firm found eight-in-ten cloud breaches last year were caused by basic mistakes. Common vulnerabilities, misconfigurations, and exposed secrets all ranked among the leading causes of breaches, Wiz found. </p><p>While the company called for enterprises to shore up basic best practices, the situation is being exacerbated by rapid AI adoption, which is creating larger, more complex attack surfaces. </p><p>"What changed was not the existence of these risks, but the environments in which they appeared and the speed at which they could be exploited," the company said.</p><h2 id="tried-and-tested-methods">Tried and tested methods</h2><p>Wiz noted that the most common entry points in 2025 weren’t novel cloud-specific exploits or advanced <a href="https://www.itpro.com/security/phishing/device-code-phishing-storm-2372-microsoft">identity bypass techniques</a>, but familiar weaknesses in exposure management, credential handling, configuration, and end-user security. </p><p>Wiz said this highlights that threat actors are still recording success by capitalizing on the basic fundamental mistakes made by enterprises. </p><p>Elsewhere, the majority (53%) of pre-access malicious actions were reconnaissance and discovery-related techniques, for example. </p><p>This showcases the increased investment among threat actors on mapping environments and testing trust boundaries, according to Wiz. </p><h2 id="ai-is-expanding-attack-surfaces">AI is expanding attack surfaces</h2><p>More than 85% of organisations are now using some form of AI, according to Wiz, which is creating new attack surfaces for security teams to monitor and shore up. </p><p>Notably, researchers warned this is increasing the number of places where familiar issues – such as misconfigurations or exposed credentials - could appear. </p><p>Given these services are often tightly connected to sensitive data, privileged identities, and high-value compute resources, the implications for poor practices on this front are dire. </p><h2 id="attackers-are-using-ai-at-scale">Attackers are using AI at scale</h2><p>While AI is creating new threats for organisations, Wiz warned the technology is also being used by threat actors to accelerate attacks. </p><p>This has become a common recurring talking point in recent months, with a slew of studies warning about the increased use of the technology for nefarious purposes. </p><p>Hackers have been observed using AI to <a href="https://www.itpro.com/security/hackers-are-using-ai-to-dissect-threat-intelligence-reports-and-vibe-code-malware">dissect threat intelligence reports</a> and <a href="https://www.itpro.com/security/malware/microsoft-quietly-launched-an-ai-agent-that-can-reverse-engineer-and-detect-malware">reverse engineer malware</a>, for example, or to create more convincing <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>lures. </p><p>Wiz noted, however, that attackers haven’t replaced tried-and-tested techniques with AI. Instead, they’re using the technology to accelerate reconnaissance, automate actions, and scale workflows. </p><p>Researchers said threat actors are now incorporating AI tooling into operations in a variety of ways, including AI-assisted malware execution, abuse of AI-based CLI tools such as Claude, or Gemini, and for environment reconnaissance after gaining initial access. </p><h2 id="what-can-defenders-do">What can defenders do?</h2><p>Given the key initial access vectors highlighted by Wiz, researchers said enterprises should sharpen their focus on identifying which assets are externally reachable and which risks are exploitable from the outside. </p><p>Continuous visibility into exposure and potential attack paths can also help teams focus on risks that are realistically exploitable. </p><p>Wiz also urged enterprises to treat pre-compromise reconnaissance as a detection opportunity, providing they can react swiftly. </p><p>The early part of the operations require malicious actors to not only gain some level of privileged access to a network, but conduct internal reconnaissance to understand where they are and how to accomplish their goal,” the report notes. </p><p>“This creates an opportunity for defenders to identify malicious activity before they are able to accomplish their goals.”</p><p>The number and severity of incidents involving compromised packages, CI systems, SaaS integrations, and automation workflows showed how inherited trust can extend impact beyond a single environment. </p><p>Wiz added that defenders should maintain visibility into trusted relationships across development pipelines, third-party services, and identity federations, and correlate these relationships with exposure and identity risk to reduce downstream impact.</p><p>"Security teams that maintain visibility into exposure, identities, and how risk propagates across cloud, development, and AI systems are better positioned to detect and disrupt attacker activity before it escalates."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Forescout and Netskope partner to bolster zero trust security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/forescout-and-netskope-partner-to-bolster-zero-trust-security</link>
                                                                            <description>
                            <![CDATA[ The new integration combines Forescout’s device intelligence with Netskope’s private access controls to extend zero trust across enterprise environments ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UpKgHYjxRL2mSn9PQQ7GrE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ux3V79nc6iXyfwiHXRzQi3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 27 Feb 2026 11:56:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ux3V79nc6iXyfwiHXRzQi3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI zero trust concept image showing shield symbol with digitized human brain in a circle, with distributed red data points with skull symbols.]]></media:description>                                                            <media:text><![CDATA[AI zero trust concept image showing shield symbol with digitized human brain in a circle, with distributed red data points with skull symbols.]]></media:text>
                                <media:title type="plain"><![CDATA[AI zero trust concept image showing shield symbol with digitized human brain in a circle, with distributed red data points with skull symbols.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ux3V79nc6iXyfwiHXRzQi3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>vendor Forescout Technologies has partnered with cloud security provider Netskope to expand zero trust security coverage across enterprise networks.</p><p>The new integration combines Forescout’s real-time device intelligence with Netskope’s AI, <a href="https://www.itpro.com/cloud/cloud-security/10-cloud-security-tips-every-it-leader-should-know">cloud security</a>, and private access controls to deliver zero trust for managed and unmanaged IT, OT, <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot">IoT, </a>and IoMT devices.</p><p>The pair said the joint solution continuously adapts access decisions based on device posture and risk to ensure <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero trust</a> is enforced, regardless of where devices connect.</p><p>Unlike traditional <a href="https://www.itpro.com/security/what-is-zero-trust-network-access-ztna">zero trust network access (ZTNA)</a> deployments that focus exclusively on north-south cloud traffic, the Forescout-Netskope integration secures east-west communications at the local network level. </p><p>In an announcement, Forescout CEO Barry Mainz said the collaboration will help organizations shrink their attack surface as digital environments continue to grow in complexity.</p><p>“The volume and variety of device types are exploding, along with the number of applications, users and access points,” he explained. </p><p>“By joining forces with Netskope, we are bringing together two best-of-breed solutions, granting customers complete visibility and control over their environments, with policies that automatically adjust as conditions change, and enabling north-south and east-west security policy enforcement.</p><p>“This is a gold standard of how ‘Universal’ Zero Trust Network Access is employed in practice, not just as a model.”</p><h2 id="addressing-enterprise-blind-spots">Addressing enterprise blind spots</h2><p>The duo said the move addresses a crucial enterprise challenge in which disparate and disconnected security tools are often managed by siloed teams, creating blind spots and restricting control and policy enforcement.</p><p>To overcome this hurdle, the new integration applies granular zero trust policies universally, identifies unmanaged or hidden endpoints, and adapts access decisions in real time based on behavior, device health, and application sensitivity.</p><p>Other benefits include improved containment of cyber threats through its east-west local traffic controls, streamlined compliance with frameworks such as HIPAA, NIST, and CIS, as well as automated enforcement to reduce reliance on manual security updates </p><p>Sanjay Beri, CEO of Netskope, said a zero trust approach has become essential to secure data and ensure business resilience in the cloud and <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>era.</p><p>“Our integrated solution with Forescout was designed for the scale, speed, and diversity of today’s modern enterprises, and provides the cohesive, centralized secure access organisations need,” he commented.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud security teams are in turmoil as attack surfaces expand at an alarming rate ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/cloud-security-teams-are-in-turmoil-as-attack-surfaces-expand-at-an-alarming-rate</link>
                                                                            <description>
                            <![CDATA[ Cloud security teams are scrambling to keep pace with expanding attack surfaces, new research from Palo Alto Networks shows, largely due to the rapid adoption of enterprise AI solutions. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xmJiif6isjjMgPzHVjNpxf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aFQH4uPtxoHfmM2w5QiHV5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Dec 2025 08:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aFQH4uPtxoHfmM2w5QiHV5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Private cloud concept image showing a cloud symbol on a server box, with digital interface and bright colors below. ]]></media:description>                                                            <media:text><![CDATA[Private cloud concept image showing a cloud symbol on a server box, with digital interface and bright colors below. ]]></media:text>
                                <media:title type="plain"><![CDATA[Private cloud concept image showing a cloud symbol on a server box, with digital interface and bright colors below. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aFQH4uPtxoHfmM2w5QiHV5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/cloud/cloud-security/10-cloud-security-tips-every-it-leader-should-know">Cloud security</a> teams are scrambling to keep pace with expanding attack surfaces, new research shows, largely due to the rapid adoption of enterprise AI solutions. </p><p>In a <a href="https://www.paloaltonetworks.com/state-of-cloud-native-security" target="_blank"><u>survey</u></a> of more than 2,800 security executives and practitioners by Palo Alto Networks, 99% said they had experienced an attack against AI applications and services in the past year.</p><p>Meanwhile, the firm warned generative AI-assisted <a href="https://www.itpro.com/technology/artificial-intelligence/vibe-coding-security-risks-how-to-mitigate">vibe coding</a> is in use by 99% of respondents - but is <a href="https://www.itpro.com/security/74-percent-of-companies-admit-insecure-code-caused-a-security-breach">generating insecure code</a> faster than security teams can review it. </p><p>Of the 52% of teams that ship code weekly, only 18% say they can keep up with fixing the vulnerabilities the technology creates.</p><p>“As organizations aggressively scale cloud investments to power AI initiatives, they are inadvertently opening the door to sophisticated new attack vectors," said Elad Koren, vice president of product management at the firm's Cortex security platform.</p><p>Notably, Palo Alto warned <a href="https://www.itpro.com/security/cyber-attacks/threat-actors-exploiting-quickly-what-business-leaders-should-do">attacks are getting faster</a>, with breaches that took an average of 44 days in 2021 now taking as little as 25 minutes.</p><p>"The speed, scale, and sophistication we’ve observed over the past couple of years is incredible," said Haider Pasha, vice president and chief security officer, EMEA, at Palo Alto Networks. </p><p>Attackers are increasingly exploiting the foundational layers of the cloud, targeting API infrastructure, identity, and lateral network movement. API attacks, for example, are up by 41%, making them a primary entry point for sophisticated threats.</p><h2 id="the-top-challenges-for-cloud-security-teams">The top challenges for cloud security teams</h2><p>Meanwhile, 53% of respondents cited lenient <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">identity and access management (IAM) </a>practices as a top challenge, saying that insufficient access controls are now a leading vector for credential theft and data exfiltration.</p><p>These findings align closely with a recent study from Okta, which also highlighted growing concerns about identity security. </p><p><a href="https://www.itpro.com/security/identity-security-is-more-important-than-ever-heres-why"><u>An August survey</u></a> from the firm found 85% of security leaders now view IAM as a critical security focus, marking an increase on the year prior. </p><p>Elsewhere, long-running issues with <a href="https://www.itpro.com/security/cybersecurity-teams-are-wasting-time-money-and-effort-dealing-with-tool-sprawl-and-multi-vendor-ecosystems">tool sprawl</a> are adding insult to injury for cloud and security practitioners. Disparate tools are creating dangerous blind spots, the company noted, with respondents now managing an average of 17 cloud tools from an array of vendors. </p><p>The resulting fragmented data and context gaps are prompting 97% of respondents to prioritize consolidating their cloud security footprint.</p><h2 id="soc-teams-are-struggling">SOC teams are struggling</h2><p><a href="https://www.itpro.com/security/370276/soc-modernisation-and-and-the-role-of-xdr">Security operations center (SOC) staff</a> are also struggling amidst a surge in cloud-related attacks, Palo Alto found. A key factor here lies in disjointed workflows and isolated data sources between cloud and SOC teams, the study noted. </p><p>This lack of alignment is stalling remediation efforts, with nearly one-third (30%) of respondents revealing they take more than a full day to resolve an incident. </p><p>To cope, researchers said cloud and SOC teams must merge, with 89% of organizations believing cloud and application security must be fully integrated with the SOC to be effective.</p><p>"Our research confirms that traditional approaches to cloud security are inadequate, leaving security teams to fight machine-speed threats with fragmented tools and slow, manual fix cycles," said Koren. </p><p>"Teams need more than just dashboards highlighting risks they can never burn down; they must transform with an agentic-first platform that spans code to cloud to SOC to finally operate faster than the adversary.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud security: How to detect breaches and stop them quickly ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/cloud-security-how-to-detect-breaches-and-stop-them-quickly</link>
                                                                            <description>
                            <![CDATA[ Cloud breaches are going undetected, posing a major risk to businesses. What is causing this growing problem, and what can firms do about it? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KjtmasEamUfNA4wU49pN5Q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/87BSyCjjR5QVShx4NmwLPF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Oct 2025 10:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 20 Oct 2025 13:15:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/87BSyCjjR5QVShx4NmwLPF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[SaaS security concept imaging showing centralized cloud symbol with orange coloring connecting to different data points. ]]></media:description>                                                            <media:text><![CDATA[SaaS security concept imaging showing centralized cloud symbol with orange coloring connecting to different data points. ]]></media:text>
                                <media:title type="plain"><![CDATA[SaaS security concept imaging showing centralized cloud symbol with orange coloring connecting to different data points. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/87BSyCjjR5QVShx4NmwLPF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security"><u>Cloud security</u></a> is a priority for most firms, but breaches aren’t always identified before they have caused substantial damage. In some cases, cloud breaches are going undetected for hours or days,<a href="https://www.itpro.com/cloud/cloud-security/cloud-breaches-check-point-security-report"> according to research</a> published earlier this year. </p><p>While nearly two-thirds of organizations suffered a cloud security incident in the past year, only 9% of breaches were detected within the first hour, according to Check Point’s 2025 Cloud Security Report. Researchers found just 6% of incidents were remediated within the first hour, with 62% of enterprises taking more than 24 hours to fully recover.</p><p>The speed at which firms are detecting and responding to cloud breaches is a concern because it could lead to data theft and further attacks, resulting in reputational damage and regulatory fines. </p><p>So what is causing companies to miss incidents involving cloud, and how can businesses recover more quickly?</p><h2 id="why-cloud-breaches-are-going-undetected">Why cloud breaches are going undetected</h2><p>Security teams are missing cloud breaches due to <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cybersecurity</u></a> alert fatigue, fragmented tools, and clunky legacy <a href="https://www.itpro.com/security/application-security-risk-how-leaders-can-protect-their-businesses"><u>applications</u></a>, according to experts. </p><p>Gaps in security can happen because of misconfigured storage or overly permissive access controls, which end up exposing data without triggering alerts, says Andy Green, a partner at Avella Security.</p><p>Businesses often fail to enable or properly use logging services such as AWS CloudTrail or Azure Monitor, so suspicious activity goes unnoticed, which just adds to the problem. </p><p>“And when monitoring is in use, security teams face alert fatigue, while critical warnings are buried among low-priority notifications and don’t get actioned,” Green adds. </p><p>This is made more complex by fragmented, hybrid environments with legacy perimeter defences not designed for cloud scale, which can lead to visibility gaps, says Dray Agha, senior manager of security operations at Huntress. </p><p>Simon Driscoll, network and security specialist at  ITGL, agrees. “For many organizations, the dispersal of information across multi-cloud means they don’t truly know where all of their data resides anymore,” he says. </p><p>“Inevitably, the chance of missing things, or the creation of gaps to exploit, magnifies significantly the more providers used, and the less control companies have.”</p><h2 id="the-consequences">The consequences </h2><p>It’s clear there are issues preventing cloud incidents from being detected and responded to in time. However, the consequences of this can be devastating, allowing criminals to retain access to internal systems, data, and accounts. </p><p>The longer an adversary can hide, the greater the impact, says Harlin Lipman, head of information security, Chronosphere. For example: “They can perform account takeovers, privilege escalation, and tactics such as command and control,” he warns. </p><p>Operationally, breaches may disrupt critical services, delay projects, or cause downtime –  particularly if attackers exploit cloud resources for malicious purposes such as <a href="https://www.itpro.com/security/ransomware/building-ransomware-resilience-to-avoid-paying-out"><u>ransomware</u></a>, according to Green. </p><p>Undetected breaches can also lead to regulatory consequences. A cloud security breach that involves customer data is likely to qualify as a personal data breach under the legislation, such as the <a href="https://www.itpro.com/security/gdpr/four-years-on-hows-uk-gdpr-holding-up"><u>UK General Data Protection Regulation</u></a> (GDPR), says Olivia Mulvany, a senior associate at law firm Broadfield.</p><p>A personal data breach impacts a firm’s reputation and can result in substantial fines. “Time is of the essence: You need to act quickly,” Mulvany warns.</p><h2 id="how-to-detect-and-mitigate-cloud-breaches-quickly">How to detect and mitigate cloud breaches quickly </h2><p>The risk is real, but detecting cloud breaches and mitigating them before the damage is done is possible. </p><p>It’s important to understand the tools and applications you use on a daily basis and build a defence around the best native integrations, says Driscoll.</p><p>“Siloed tooling and poor visibility and control as a result of poor integration and overly complex analysis processes are the biggest blockers to improving detection and response,” he adds. </p><p>With this in mind, monitoring across all cloud services can help gain visibility, according to experts. </p><p>Depending on which cloud provider you are using, Green recommends tools such as AWS GuardDuty, Azure Defender, and Google Cloud Security Command Center, which “can detect threats early using behavioral analytics and threat intelligence”.</p><p>Regular cloud configuration audits using tools or penetration testers can identify and remediate misconfigurations before they’re exploited by attackers, Green adds.</p><p>Meanwhile, it’s a good idea to focus on a “<a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust</u></a> principle” mindset, says Driscoll.</p><p>“Verify and validate everything, all the time – no exceptions. Adopt least privilege access rules for all users across data stores. Ensure you have segmentation across your private cloud networks and that conditional access is in place for your public cloud environments.”</p><p>In addition, investing in cloud security training ensures teams understand evolving threats and response tactics, according to Green.</p><p>He says:  “Speed and efficiency come from combining the right tools, well-defined processes, and skilled personnel to act decisively — reducing breach dwell time and minimising potential damage.”</p><h2 id="incident-response">Incident response </h2><p>As attackers continue to target the cloud, prevention of attacks is key. However, when detecting breaches, it’s important to ensure you can respond quickly, via a solid <a href="https://www.itpro.com/security/building-an-incident-response-strategy#:~:text=Having%20stellar%20incident%20response%20plans,the%20costs%20of%20a%20breach."><u>incident response strategy</u></a>. </p><p>At the heart of this, Lipman advises firms to have “a well-documented incident response plan”. </p><p>Everyone in the business should be involved, so it’s a good idea to educate all employees who participate in incident response, according to Lipman.  </p><p>“Everyone needs to have a clear understanding of their roles and responsibilities, including their position in the call tree to facilitate quick contact in case of an incident,” he says. </p><p>At the same time, incident response plans must be tailored to cloud environments. </p><p>“This includes identifying which cloud assets are in scope, who is responsible under the shared responsibility model, and how to isolate affected resources quickly,” adds Green. </p><p>“For example, removing identity and access management (IAM) roles, revoking API keys, and detaching instances from networks.”</p><p>Once the plan is in place and everyone knows their roles, it needs to be tested regularly. For cloud specifically, regular tabletop exercises focused on scenarios involving the technology are “essential”, Lipman says.</p><p>It requires investment, so senior management needs to know the importance of securing the cloud and the consequences of not being able to respond in time. Security teams must advocate for the software, hardware, and headcount resources they require to enable this preparation,  Lipman advises. </p><p>“An organization cannot handle incidents if it is not well-equipped from both a software and personnel perspective, so having the necessary resources is imperative for success,” he concludes. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The unseen risks of cloud storage for businesses ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/the-unseen-risks-of-cloud-storage-for-businesses</link>
                                                                            <description>
                            <![CDATA[ Sensitive data is being held in publicly-accessible cloud storage, despite the obvious risks – what can firms do about it? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C5CFYkb3KTotPmzn2Vwok6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wETAzkC4PQQ6VjXVqxUHUN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Sep 2025 10:43:36 +0000</pubDate>                                                                                                                                <updated>Tue, 21 Oct 2025 11:49:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wETAzkC4PQQ6VjXVqxUHUN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud native security concept image showing cloud symbol pictured on top of a digitized cube representing a circuit board and GPU.]]></media:description>                                                            <media:text><![CDATA[Cloud native security concept image showing cloud symbol pictured on top of a digitized cube representing a circuit board and GPU.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud native security concept image showing cloud symbol pictured on top of a digitized cube representing a circuit board and GPU.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wETAzkC4PQQ6VjXVqxUHUN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloud storage is used by most businesses, with 78% of respondents to a <a href="https://www.pwc.co.uk/services/value-creation/insights/unlocking-value-of-cloud-investments.html" target="_blank"><u>2024 PwC survey</u></a> indicating they’ve adopted cloud across most of their organizations. But many firms are unknowingly opening themselves up to security and data protection risks: sensitive data is being held in 9% of publicly-accessible cloud storage, and 97% of this information is classified as restricted or confidential, according to Tenable's <a href="https://www.tenable.com/cyber-exposure/tenable-cloud-security-risk-report-2025" target="_blank"><u>2025 Cloud Security Risk Report</u></a>. </p><p>Over half of organizations using Amazon Web Services (AWS) ECS task definitions have at least one “secret” residing there. This creates “a dangerous exposure path” in cloud infrastructure entitlements, Tenable said.</p><p>Exposed data includes API keys, access and <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption"><u>encryption keys</u></a> and tokens, as well as usernames and passwords, according to the report.</p><p>As firms move away from on premises infrastructure towards cheaper and more efficient cloud services, they aren’t always considering the risk. Most companies have already migrated this data over, meaning they have to work backwards to secure it. </p><p>“Too often, the convenience of cloud overrides the need for careful consideration, and critical files migrate over by default, or due to expediency,” says Ali Sheikh, digital and cybersecurity expert at PA Consulting. “This transition isn’t always accompanied by robust oversight or shared understanding of risk.”</p><p>So why has such sensitive data ended up in insecure cloud storage and what can firms do to gain control over it?</p><h2 id="migration-issues">Migration issues</h2><p>Cloud storage has become the default for businesses moving away from on premises infrastructure due to its flexibility and ease of use. However, in the <a href="https://www.itpro.com/cloud/cloud-management/embracing-cloud-migration-at-scale"><u>rush to migrate</u></a>, many organizations “skip over essential security configurations”, says James Round, cyber security consultant at Pentest People. “We've seen this repeatedly in assessments when clients move to the cloud without applying strict access controls or properly safeguarding sensitive data including personally identifiable information.”</p><p>As firms strive for ease of access and the ability to quickly share information across teams, credentials, API keys and other sensitive details can end up being stored in plaintext, says Round. </p><p>Bernard Montel, EMEA technical director and security strategist at Tenable describes “numerous instances” of inadvertent exposure, misconfigured access settings and “overly permissive policies” in cloud environments. </p><p>For example, developers frequently utilize privilege elevation for short-term access during application or project development, with these privileges revoked once the project concludes. “But this is often forgotten and the access becomes permanent,” Montel warns.</p><p>Simple missteps in cloud-based development can “swing the door wide open for attackers”, says Crystal Morin, cybersecurity strategist at Sysdig. For instance, publicly exposed data is “shockingly easy” to find using common free open source tools, she says. “Combine public exposure with misconfigurations, <a href="https://www.itpro.com/security/patch-management-why-firms-ignore-vulnerabilities-at-their-own-risk">unpatched vulnerabilities</a>, or weak credential management and attackers can breach cloud systems in minutes.”</p><p>In fact, about ten minutes is all that stands between a cloud misconfiguration and data leaks or intellectual property theft, says Morin. </p><p>Without strong <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business"><u>access controls</u></a> and clear <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures"><u>data handling policies</u></a>, the confidentiality and integrity of critical systems can be “seriously undermined often” without the business realizing until after an incident has occurred, Round warns.</p><p>Adding to the issue is the still widespread misunderstanding that cloud providers manage all security, when in fact configuration responsibilities lie with the customer, he says.</p><p>If this led to a cloud breach or data leak the consequences could be huge, with customers potentially exposed to hackers and companies falling foul of laws such as the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>General Data Protection Regulation (GDPR)</u></a>.</p><p>Storing confidential or restricted data in exposed locations is “a direct path to compliance violations”, says Kim Larsen, CISO at Keepit.</p><p>In addition to fines, firms are exposing themselves to brand damage and operational disruption, says Larsen. “If you lose access to your identity and access management systems such as Entra ID or Okta, you’re not just exposed – you’re locked out of your own company.”</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/67261cbd-ac84-417f-837f-130fd30d3ed9/"></iframe><h2 id="how-to-gain-visibility-and-secure-cloud-data">How to gain visibility and secure cloud data</h2><p>The amount of sensitive data stored in the cloud is a concern, but firms can get a handle on the issue using the right policies and technology. </p><p>In the first instance, IT leaders must establish clear cloud storage policies, processes and security controls, and communicate them across the organization, says Sam Peters, chief product officer at ISMS.online. </p><p>Businesses should also “thoroughly vet the security posture of their cloud suppliers”, says Peters. </p><p>Visibility is key to securing data in the cloud. You need to know what data you have, where it lives, and who can access it, says Larsen. “Classify that data. Encrypt it. Monitor access with defined time limits and remove standing privileges. Don’t assume that just because something’s behind a login it’s safe — credentials are one of the top targets for attackers. “</p><p>Regular monitoring is key, Round says. Tools include AWS Security Hub and Microsoft Defender for Cloud, which offer “a centralized view of risks, alerts, and compliance gaps”, he adds.</p><p>Combine this with a <a href="https://www.itpro.com/security/361919/how-to-build-a-zero-trust-model"><u>least-privilege access model</u></a>, automated alerting, and default denial of public access to build strong cloud hygiene, Round advises. “A proactive approach, supported by continuous review and enforcement of internal policies, is essential for preventing breaches and maintaining control over critical assets.”</p><p>When securing cloud data, it also helps to look at things from a different perspective. Richard Cassidy, EMEA CISO at Rubrik urges security teams to “act like attackers, by targeting high-value data first and looking at all the possible ways to access it”. Teams can also look to put stronger controls in place, improve their recovery strategies, and utilize continuous backups much as they would with data held on premises, he adds.</p><p>As increasing amounts of data is created and stored in cloud services, gaining control over your own estate is important. Once you have visibility of information residing in the cloud, regular audits, strong authentication and clear policies are essential, according to Sheikh.</p><p>It’s important to get all employees on board, so they understand that <a href="https://www.itpro.com/security/gen-z-has-a-cyber-hygiene-problem">security is everyone’s responsibility</a>, he says. “Cultivating a culture where everyone, from executive to end user, sees themselves as a guardian of data, shifts security from a technical afterthought to a shared value,” he says.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Global cybersecurity spending is going to hit $213 billion in 2025 — here's what’s driving investment ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/global-cybersecurity-spending-is-going-to-hit-usd213-billion-in-2025-heres-whats-driving-investment</link>
                                                                            <description>
                            <![CDATA[ Spending across major fronts comes in the wake of rising cloud security threats and growing skills gaps ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VgkyPmhJrBNv4sGWF6t3dC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2mpxSzoRj8PaKnmA43F4pX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Jul 2025 08:46:24 +0000</pubDate>                                                                                                                                <updated>Wed, 10 Sep 2025 09:23:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2mpxSzoRj8PaKnmA43F4pX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image showing a digitized shield sign surrounded by data blocks.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image showing a digitized shield sign surrounded by data blocks.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image showing a digitized shield sign surrounded by data blocks.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2mpxSzoRj8PaKnmA43F4pX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Gobal <a href="https://www.itpro.com/security/cybersecurity-spending-is-going-to-surge-in-2025-and-ai-threats-are-a-key-factor" target="_blank">cybersecurity spending</a> is expected to reach $213 billion by year's end, according to Gartner – a 10.4% increase on 2024 budgets.</p><p>New stats from the consultancy show spending will surge well beyond the 2024 figure of $193 billion - and the trend shows no sign of slowing down. </p><p>In 2026, Gartner estimates spending to increase by 12%, totaling $240 billion, while end-user spending in the UK specifically is expected to skyrocket 30% to $13.3 billion.</p><div class="product"><a data-dimension112="8975a534-8023-4dbb-ad5f-661621e13905" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="8975a534-8023-4dbb-ad5f-661621e13905" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="8975a534-8023-4dbb-ad5f-661621e13905" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Speaking to <em>ITPro</em>, Ruggero Contu, senior director analyst at Gartner, said this spending surge is being driven by a confluence of issues, including rising cyber criminal threats, compliance-related considerations, and the emergence of <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>. </p><p>Spending on security software, for example, is an area where there is a huge enterprise appetite, with spending between 2024 and 2026 increasing from around $95 billion to $121 billion. </p><p>A key factor behind this increase, Contu noted, is a concerted enterprise effort to shore up <a href="https://www.itpro.com/business/what-are-the-benefits-of-unified-cloud-security">cloud security</a> capabilities, particularly in relation to AI workloads. </p><p>This isn’t a one-size-fits-all situation, however, and he explained that spending habits will differ based on both the maturity of the organization and where it lies along its own <a href="https://www.itpro.com/cloud/cloud-management/how-to-embark-on-your-cloud-repatriation-journey">cloud journey</a>. </p><p>“If you look at the different segments that compose this broad category, there is a need to apply security to different stages of cloud adoption,” he told <em>ITPro</em>. </p><p>“From the development of applications within cloud environments, the security of workloads stored, handled in cloud environments, and testing of third party applications.”</p><p>“Now with AI, they need to secure AI-specific configurations and runtime requirements. So we do expect this segment to continue to grow in the next couple of years as a result of this.”</p><h2 id="skills-gaps-drive-security-services-spending">Skills gaps drive security services spending</h2><p>Security services spending has increased consistently in recent years – from $77 billion in 2024 to an estimated $92.7 billion by 2026. Contu told <em>ITPro</em> this encompasses a broad range including managed services and third-party vendor support. </p><p>A major driver of enterprise spending on this front lies in the combination of rising cybersecurity risks and continued skills gaps, with organizations turning to managed services to compensate for a lack of in-house talent. </p><p>Indeed, a recent study from CyberSmart shows organizations are <a href="https://www.itpro.com/security/pressure-mounts-on-msps-as-enterprises-flock-to-managed-cybersecurity-services">relying more than ever on MSPs</a></p><p>“One of the major drivers for security services is the skills gap,” he said. “This is obviously not a new problem. It’s an issue that enterprises across the group have been facing – having the skills and resources within cybersecurity that matches increasing requirements. </p><p>“So obviously relying on a managed security provider, or even more so a managed detection and response provider, can help fill that gap.”</p><p>Engagement with managed providers spans a range of organizations, Contu added, and isn’t necessarily limited to those that don’t have mature cybersecurity practices. </p><p>Those with a higher level of capability often require specific skills that are hard to come by. </p><p>As an example, Contu said that one area the consultancy expects to see increasing growth is the area of "cyber-physical systems security” – mainly <a href="https://www.itpro.com/security/cyber-security/359213/it-and-ot-how-cisos-can-best-handle-the-dangers-of-integration">operational technology (OT)</a>. </p><p>“That’s a challenging area,” he said. “Particularly because it needs knowledge of both security and industrial infrastructure and the requirement to apply security to that world.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/how-the-cybersecurity-industry-can-seize-the-uks-new-gbp1-billion-cyberem-command-opportunity-and-play-a-role-in-the-future-of-national-defence">How the cybersecurity industry can seize the UK's new £1 billion CyberEM Command</a></li><li><a href="https://www.itpro.com/security/uk-cybersecurity-sector-economic-value">The UK cybersecurity sector is worth over £13 billion, but experts say there’s huge untapped potential if it can overcome these hurdles</a></li><li><a href="https://www.itpro.com/security/uk-smbs-are-ramping-up-cybersecurity-spending-and-its-about-time">UK SMBs are ramping up cybersecurity spending – and it’s about time</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud confusion: Why can't we say what we mean? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/cloud-confusion-why-cant-we-say-what-we-mean</link>
                                                                            <description>
                            <![CDATA[ Cloud jargon creates confusion, risking security gaps and business vulnerabilities in organizations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KgCH6Vw7vLCTcXz9BLjw4K</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mS6ujj6Mag4ht33ZseZnza-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Jul 2025 22:07:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Baker ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/rRbnbZfK9PALj5TqLo78UX.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mS6ujj6Mag4ht33ZseZnza-1280-80.jpg">
                                                            <media:credit><![CDATA[Adobe Stock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital cloud with connecting lines and glowing particles on a blue and red gradient background]]></media:description>                                                            <media:text><![CDATA[Digital cloud with connecting lines and glowing particles on a blue and red gradient background]]></media:text>
                                <media:title type="plain"><![CDATA[Digital cloud with connecting lines and glowing particles on a blue and red gradient background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mS6ujj6Mag4ht33ZseZnza-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloud computing is fascinating. Whether you’re an IT professional who uses the term ‘cloud’ 150 times a day, or you’re only vaguely aware that ‘the cloud’ stores your photos and files, cloud has become ubiquitous – and it isn’t going anywhere.</p><p>However, at the same time, the term &apos;cloud&apos; has become a vague catch-all. It’s taken for granted, leading to ambiguity about what the cloud is. Managed Service Providers (MSPs) and IT firms offer expertise in cloud, cloud security, cloud posture management, and more. But all too often, the way they discuss it leads to confusion, because speaking ‘cloud’ can be like speaking a foreign language. And like learning another language, unless you’re immersed in it, it’s hard to become fluent.</p><h2 id="cloud-is-a-double-edged-sword">Cloud is a double-edged sword</h2><p>MSPs are cloud experts; they’re fluent in the language, but when they’re speaking to those who aren’t immersed in cloud architecture, there’s still a language barrier that’s difficult to overcome and to understand. This results in security gaps and vulnerabilities in cloud infrastructure.</p><p>It’s this confusion over cloud that cybercriminals are looking to exploit. They’re searching for the easy way in; they’re looking for the misconfigured bucket which is facing the open internet, they’re looking for human accounts which are vulnerable because they’re only protected with default credentials; identities with long-standing access to cloud resources; or regular accounts which have mistakenly been equipped with administrator privileges – without anybody noticing.</p><p>One of the major advantages of the cloud is that it can help organizations boost business efficiency. That said, while the cloud can simplify applications and services for employees or customers, the reality is that configuring the cloud correctly is a complex task. And if this isn’t managed correctly, the cloud quickly becomes a double-edged sword, providing cyber attackers with access to misconfigurations and vulnerabilities that they can exploit as an efficiency tool.</p><p>Threat actors know this. That’s why they’re mercilessly targeting the cloud, be it finding ways to gather passwords to access cloud-based user accounts, <a href="https://www.lbc.co.uk/news/uk/co-op-marks-spencer-cyberattackers-tricked-it-workers/"><u>which it’s believed is how the recent spate of incidents targeting UK retailers began</u></a>, or be it via searching for unsecured storage buckets facing the internet. No matter the method, cybercriminals are increasingly relentless in their attacks against the cloud, and just like legitimate businesses, the bad guys are moving forward with their cloud-based business models. This creates a business risk that can not be ignored.</p><p>Businesses have become reliant on cloud applications and services. It’s a mature concept, but many organizations still don’t fully understand what they’re dealing with or the implications it has on cybersecurity, especially if their MSPs are speaking about the cloud in complex language, which is difficult to translate into actions.</p><p>Have they thought about the ins and outs of securing the cloud? Or what would happen if the cloud went down or access was revoked because of a security incident? Would the business still even be able to operate?</p><h2 id="multi-cloud-environments">Multi-cloud environments</h2><p>This only becomes more complex in a multi-cloud environment. Not so long ago, when a business rolled out cloud computing, it was likely restricted to using products from a single vendor. That’s now changed, with businesses potentially using Microsoft 365, Amazon Web Services, and Google Cloud, all in the same environment.</p><p>Managing one cloud service was already difficult enough, and the addition of extra services, each with their nuances, only further complicates this, especially if the business doesn’t truly grasp the complexities around securing the cloud.</p><p>Much of this misunderstanding comes from misconceptions around cloud posture management and who is responsible for managing it. Sometimes, businesses are under the impression that because they’ve outsourced their cloud management to an MSP, securing it isn’t their responsibility.</p><p>But this is incorrect; the organization needs to ensure that not only are they aware of any potential security issues, but that they have plans to manage them, and in the worst-case scenario, that means strategies for how to deal with an incident and reduce their business risk.</p><h2 id="msps-are-vital">MSPs are vital</h2><p>However, MSPs are still key to this. If they’re using complex, difficult-to-understand language about cloud services and security, businesses may not fully understand their role in securing the cloud. It’s therefore vital for MSPs and IT providers to talk about cloud in a clear, meaningful way that&apos;s understandable to outsiders.</p><p>Businesses employ MSPs because they bring expertise in areas like cloud deployment and security. But it’s still vital for the organisation to do due diligence on who they’re partnering with and what expertise they bring. That partner should be the provider who best understands your business, best understands the challenges the business is likely to face, and is equipped to help find the right solutions for your cloud environment, plus the right security tools and processes to help keep it safe from cyber threats.</p><p>The cloud is confusing, and it’s only going to become more complex and more ingrained in environments as cloud-native becomes the norm. Ensuring that it’s protected from cyber threats can only happen if communication around it is clear – if it&apos;s ambiguous, organisations are going to find themselves vulnerable to threats and challenges. Strong cyber practices are about exposing and closing cyber risk.</p><p>The time to demystify cloud confusion is now.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trend Micro and Google Cloud double down on AI security with expanded partnership ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/trend-micro-and-google-cloud-double-down-on-ai-security-with-expanded-partnership</link>
                                                                            <description>
                            <![CDATA[ The agreement targets improved proactive security across cloud environments, alongside enhanced scam defense capabilities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m4Bkbd8uwaPYDgJ4F8UN7o</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5Mnanf8KdNTKawhTtWsdHi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Jul 2025 09:25:34 +0000</pubDate>                                                                                                                                <updated>Tue, 29 Jul 2025 09:25:54 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5Mnanf8KdNTKawhTtWsdHi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Trend Micro logo and branding pictured on a smartphone screen with cityscape pictured in background.]]></media:description>                                                            <media:text><![CDATA[Trend Micro logo and branding pictured on a smartphone screen with cityscape pictured in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Trend Micro logo and branding pictured on a smartphone screen with cityscape pictured in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5Mnanf8KdNTKawhTtWsdHi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Trend Micro has announced an expansion of its partnership with Google Cloud that will focus on enhancing AI-powered cybersecurity for complex cloud environments.</p><p>The pair’s latest collaboration aims to deliver a multi-cloud, AI-first environment that supports sovereignty requirements, bolsters proactive security, and increases protection against online scams.</p><p>At the core of the agreement, Trend Micro’s Vision One Sovereign and Private Cloud (SPC) solution has been integrated with Google Cloud Assured Workloads to help organizations better secure data across public, hybrid, and air-gapped on-prem environments.</p><p>Trend Micro said the move will equip organizations with greater flexibility and control over their most sensitive data, while also helping those in highly regulated markets to optimize security and compliance.</p><p>“Among hyperscalers, we’ve seen Google Cloud accelerate as the most in tune with real-world demands, standing out not only for its cloud infrastructure but also for its leadership across AI, data analytics and multiple other domains,” explained Bharat Mistry, Field CTO at Trend Micro.</p><p>“Google Cloud’s hybrid- and multi-cloud approach—seamlessly supporting both public and private cloud models—reflects the growing enterprise demand for flexibility.”</p><h2 id="trend-micro-eyes-deeper-integration-with-google-ecosystem">Trend Micro eyes deeper integration with Google ecosystem</h2><p>The freshly expanded partnership also broadens Trend Micro’s reach across the cloud giant’s software ecosystems. Organizations can now also access the Trend Vision One platform and Trend Vision One Sovereign and Private Cloud offering via Google Cloud Marketplace to help streamline deployment.</p><p>The <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>firm also revealed that its Cloud App Security solution has now surpassed four million downloads on the Google Workspace Marketplace for enterprise deployments.</p><p>Additionally, the companies are also collaborating to help tackle online scams. </p><p>Trend Micro’s ScamCheck app now utilizes Google Cloud’s Gemini models through Vertex AI for a host of capabilities, including the ability to verify images and SMS content used by scammers.</p><p>“By seamlessly extending Google Cloud's native security with Trend Micro's specialized defenses, we empower organizations to accelerate their cloud transformation journeys,” commented Karan Bajwa, president of Google Cloud Asia Pacific. </p><p>“This enables them to innovate securely and scale confidently in a dynamic <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>era.”</p><h3 class="article-body__section" id="section-more-from-channelpro"><span>MORE FROM CHANNELPRO</span></h3><ul><li><a href="https://www.itpro.com/security/msps-emerge-as-key-security-partners-for-mid-market-enterprises">MSPs emerge as key security partners for mid-market enterprises</a></li><li><a href="https://www.itpro.com/security/ransomware/nearly-half-of-msps-admit-to-having-a-ransomware-kitty">Nearly half of MSPs admit to having a ransomware kitty</a></li><li><a href="https://www.itpro.com/business/business-strategy/red-hat-targets-greater-partner-autonomy-with-latest-channel-updates">Red Hat targets greater partner autonomy with latest channel updates</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Majority of engineers bypass security controls to do their job – as zero trust ambitions aren't being met ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/majority-of-engineers-bypass-security-controls-to-do-their-job</link>
                                                                            <description>
                            <![CDATA[ Legacy VPNs and an overreliance on manual processes are leaving internal systems open to access by former employees ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LAPL5FKGZGugB6ETnBYc8Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Lq6brmg8jRUNyRnyv5SBxe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Jul 2025 12:03:01 +0000</pubDate>                                                                                                                                <updated>Wed, 23 Jul 2025 12:35:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Lq6brmg8jRUNyRnyv5SBxe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A glowing shield formed from glowing points and lines in an abstract landscape to represent security controls.]]></media:description>                                                            <media:text><![CDATA[A glowing shield formed from glowing points and lines in an abstract landscape to represent security controls.]]></media:text>
                                <media:title type="plain"><![CDATA[A glowing shield formed from glowing points and lines in an abstract landscape to represent security controls.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Lq6brmg8jRUNyRnyv5SBxe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The vast majority of engineers are bypassing security controls just to get their job done – and most even retain access after leaving.</p><p>This is according to a new <a href="https://tailscale.com/resources/report/zero-trust-report-2025" target="_blank"><u>survey</u></a> commissioned by Tailscale, which found 83% of IT and engineering professionals admitted to actively bypassing security controls in order to get their work done.</p><p>Drawn from the responses of 1,000 IT, security, and engineering professionals across North America, the survey also found that 99% of companies want to redesign their company’s access and networking setup from the ground up.</p><div class="product"><a data-dimension112="162e4f7b-8ac9-447f-8717-39f22559e77f" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="162e4f7b-8ac9-447f-8717-39f22559e77f" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="162e4f7b-8ac9-447f-8717-39f22559e77f" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Two-thirds said their organization's IT and security policies actively block or misunderstand their workflows and almost half (49%) said their access infrastructure cannot be scaled.</p><p>For example, 68% of organizations are still reliant on manual processes to manage network access, using tools such as static firewalls and permissions based on user IP rather than <a href="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan"><u>software-defined access</u></a>.</p><p>The findings made clear that this is not where leaders want to be. Though <a href="https://www.itpro.com/security/what-is-zero-trust-network-access-ztna">zero trust network access (ZTNA) </a>was pointed to as an aspirational process for respondents to adopt, just 29% said they use identity-based access as their primary model.</p><p>The report underscored the shortcomings of relying on manual systems by revealing as many as 68% of respondents retained access to internal systems after leaving their previous employer. </p><p>While just under a third (32%) reported having access revoked immediately, 27% said they still had access for several weeks and 13% for a few months. In a small but not insignificant number of cases (6%), former employees could still access internal systems for a year or more.</p><p>The report also highlighted <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/367994/vpn-or-virtual-private-networks-what-businesses">virtual private networks (VPNs)</a> as a particular problem, with companies heavily reliant on them nearly twice as likely to report broken access or security workarounds compared to those using modern tools. Only 10% of respondents said their current VPN setup works well, with no major issues, while 90% reported limitations such as security risks, latency, or operational overhead. </p><p>“Security and productivity shouldn’t be at odds,” said Avery Pennarun, CEO at Tailscale. </p><p>“When developers, engineers, and IT all say the current system is broken — and worse, start working around it — that’s a sign the tools need to change, not the people. <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero trust</a> can solve this, but only if it’s actually implemented as a strategy, not just used as a buzzword.”</p><p>Tailscale said it expects security-minded organizations to retire or phase out their legacy VPNs by the end of 2026, making way for more flexible, composable solutions.</p><p>Over the next two years, it said, there will be a big move towards unified, <a href="https://www.itpro.com/cloud/cloud-computing/what-is-cloud-native-and-how-can-it-generate-business-value">cloud-native</a> secure access platforms, sometimes referred to as universal ZTNA.</p><p>"Nearly every organization says they’re on a Zero Trust journey, which is a polite way of saying they aren’t done, and maybe never will be," the researchers said. </p><p>Meanwhile, many companies are juggling too many point solutions, with 92% using multiple tools for network security, and nearly a third using four or more. </p><p>Nearly half, though, are actively trying to consolidate their toolsets, and early adopters are moving to identity-first architectures and just-in-time access models that offer better security and a smoother user experience. </p><p>And at the same time, AI and automation are on the rise, not just for detecting threats, but also adjusting access dynamically in response to context.</p><p>But, the report found, 55% of respondents were sceptical or said they didn’t know where to look for better solutions. </p><p>"That knowledge gap is one of the biggest barriers to progress," the researchers said. "Education around adaptive access, AI-enhanced threat detection, and modern zero trust architectures will be critical over the next two years."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/development/think-ai-coding-tools-are-speeding-up-work-think-again-theyre-actually-slowing-developers-down">Think AI coding tools are speeding up work? Think again – they’re actually slowing developers down</a></li><li><a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/367994/vpn-or-virtual-private-networks-what-businesses">Everything businesses need to know about VPNs</a></li><li><a href="https://www.itpro.com/security/it-leaders-are-facing-major-work-device-blind-spots-and-its-putting-security-at-risk">IT leaders are facing major work device blind spots – and it's putting security at risk</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud breaches are surging, but enterprises aren’t quick enough to react ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/cloud-breaches-check-point-security-report</link>
                                                                            <description>
                            <![CDATA[ The rise in cloud breaches has been attributed to a series of factors ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fHPtsXZ2bnjb8cfpUHiaug</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vbf7xVoz6pxHRJtC7FYyy9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Jun 2025 10:58:48 +0000</pubDate>                                                                                                                                <updated>Fri, 06 Jun 2025 10:58:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vbf7xVoz6pxHRJtC7FYyy9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud breaches concept image showing locked padlock symbols with one unlocked in red color. ]]></media:description>                                                            <media:text><![CDATA[Cloud breaches concept image showing locked padlock symbols with one unlocked in red color. ]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud breaches concept image showing locked padlock symbols with one unlocked in red color. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vbf7xVoz6pxHRJtC7FYyy9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloud breaches are going undetected for hours or days, according to new research, with security workers pinning blunders on ‘alert fatigue’, fragmented tools, and clunky legacy applications. </p><p>While nearly two-thirds of organizations suffered a cloud security incident in the past year, only 9% were detected within the first hour, according to Check Point’s 2025 <em>Cloud Security Report</em>. </p><p>Notably, researchers found just 6% of incidents were remediated within the first hour, with 62% of enterprises taking more than 24 hours to fully recover. </p><p>Paul Barbosa, Check Point's VP of cloud security, said the statistics paint a concerning picture for enterprises dealing with cloud security incidents. Speed and efficiency, he noted, are key factors in preventing long lasting damage. </p><p>"This is an obvious area of concern as any delay opens a window of vulnerability during which attackers can move laterally, exfiltrate data, or cause operational disruption," Barbosa commented. </p><p>"The longer an incident takes to be detected and addressed, the greater the likelihood of escalation."</p><p>When incidents are detected, two-thirds of the time it's through end users, third parties or during audits, rather than through security tools.</p><h2 id="what-s-behind-the-rise-in-cloud-breaches">What’s behind the rise in cloud breaches?</h2><p>The biggest problems identified by Check Point include ‘alert fatigue’, which occurs when security practitioners are bombarded by an overwhelming volume of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>alerts. This <a href="https://www.itpro.com/security/cyber-security/370051/information-overload-a-key-barrier-to-effective-threat-intelligence-mandiant">information overload</a> impacts their ability to effectively respond to genuine threats. </p><p>It’s an issue that’s been highlighted repeatedly by industry experts in recent years, largely due to the <a href="https://www.itpro.com/security/enterprises-are-bogged-down-with-disparate-cyber-tools-heres-why-a-platform-security-approach-could-tackle-growing-complexity">growing number of security tools</a> and solutions used by organizations in daily activities. </p><p>Indeed, <a href="https://www.itpro.com/software/software-sprawl-is-getting-out-of-control-86-percent-of-it-leaders-say-disparate-tools-are-creating-financial-strain-and-security-risks-but-consolidation-is-now-a-high-priority">‘tool sprawl’ </a>was also highlighted by Check Point as a key factor in the sluggish response times outlined in its report. More than seven-in-ten organizations now operate with more than 10 separate <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a> tools, while almost half receive more than 500 alerts per day, many of which may be false positives.</p><p>Fundamentally, cloud growth is outpacing security readiness, Check Point noted. In the past year alone, 62% of organizations have expanded cloud edge technologies like <a href="https://www.itpro.com/cloud/cloud-security/what-is-secure-access-service-edge-sase">secure access service edge (SASE)</a>, 57% have increased their hybrid cloud footprint, and 51% adopted multi-cloud strategies.</p><p>"This acceleration, while strategic, is fragmenting environments and straining legacy perimeter-based defenses — many of which were never designed to operate at this scale or complexity," Barbosa said. </p><h2 id="confidence-in-ai-security-is-also-shaky">Confidence in AI security is also shaky </h2><p>Unsurprisingly, AI is an important issue for security leaders, with Check Point revealing that nearly seven-in-ten organizations consider AI a strategic priority.</p><p>Confidence in defending against AI-powered threats is alarmingly low, however, with only a quarter of respondents saying they feel prepared to handle machine-driven attacks like automated evasion or <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>generation.</p><p>Meanwhile, application-layer security is lagging behind, with six-in-ten organizations still relying on signature-based web application firewalls (WAFs) as their primary line of defense. </p><p>"As evasive app-layer threats and API attacks grow more sophisticated, legacy tools offer limited protection — and adoption of AI/ML-based detection remains inconsistent," said Barbosa.</p><p>"There exists a clear need across organizations to modernize the application layer to strengthen overall cloud security posture."</p><h2 id="what-can-organizations-do">What can organizations do?</h2><p>Check Point outlined a number of areas that enterprise security leaders should prioritize in the year ahead, including exploring the potential for automated, AI-based threat detection. </p><p>Similarly, they should invest in a unified, intelligent architecture that consolidates enforcement across layers and environments, without relying on many disconnected point products or siloed teams.</p><p>Naturally, reducing the volume of alerts security practitioners contend with on a daily basis is also a key priority, enabling cyber pros to focus on legitimate threats.</p><p>In doing so, the security firm noted this will optimize efficiency in security center operations and deliver long-term benefits. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/cloud/cloud-security/enterprises-are-facing-a-cloud-security-crisis">Enterprises are facing a ‘cloud security crisis’</a></li><li><a href="https://www.itpro.com/cloud/cloud-security/enterprise-ai-is-surging-but-is-security-keeping-up">Enterprise AI is surging, but is security keeping up?</a></li><li><a href="https://www.itpro.com/cloud/cloud-security/ai-is-putting-your-cloud-workloads-at-risk">AI is putting your cloud workloads at risk</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google is getting serious on cloud sovereignty ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-computing/google-is-getting-serious-on-cloud-sovereignty</link>
                                                                            <description>
                            <![CDATA[ Google has joined Microsoft in bolstering its sovereign cloud services as tensions grow over US influence on big tech providers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r5KtNkMa3baMWgcuiagPSR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/c8MyD2XE8r5Q7seTVwmqaj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 May 2025 10:03:03 +0000</pubDate>                                                                                                                                <updated>Thu, 22 May 2025 10:03:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Computing]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/c8MyD2XE8r5Q7seTVwmqaj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Cloud logo pictured on a wall at Mobile World Congress (MWC) 2023 in Barcelona, Spain.]]></media:description>                                                            <media:text><![CDATA[Google Cloud logo pictured on a wall at Mobile World Congress (MWC) 2023 in Barcelona, Spain.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Cloud logo pictured on a wall at Mobile World Congress (MWC) 2023 in Barcelona, Spain.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/c8MyD2XE8r5Q7seTVwmqaj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has joined Microsoft in bolstering its <a href="https://www.itpro.com/cloud/cloud-computing/what-is-a-sovereign-cloud">sovereign cloud</a> services as tensions grow over US influence on big tech providers. </p><p>The tech giant has rapidly expanded its sovereign cloud services in recent years, now boasting more than 42 cloud regions, 127 zones, and 202 network edge locations. </p><p>In a <a href="https://cloud.google.com/blog/products/identity-security/google-advances-sovereignty-choice-and-security-in-the-cloud" target="_blank">blog post</a> detailing the updates, Hayete Gallot, president of customer experience at Google Cloud said the move underlines the company’s commitment to “enabling customers to choose the cloud provider and solution that best fit their needs”. </p><p>“We offer customers a portfolio of solutions that align with their business needs, regulatory requirements, and risk profiles,” Gallot added. </p><p>So what can customers expect from the new updates?</p><h2 id="google-eyes-air-gapped-solutions">Google eyes air-gapped solutions</h2><p>The move by the tech giant includes three dedicated sovereign cloud services, including <em>Google Cloud Air-Gapped</em>, which offers enterprises a standalone air-gapped solution that “does not require connectivity to an external network”. </p><p>“This solution is tailored for customers in the intelligence, defense, and other sectors with strict data security and residency requirements,” Gallot said. “The air-gapped solution can be deployed and operated by Google, the customer, or a Google partner.”</p><p>The air-gapped solution has been developed using open source components, according to Google, and offers a range of AI, database, and infrastructure services. </p><p>Google Cloud Air-Gapped previously received authorization to host top secret materials belonging to the US government. </p><h2 id="setting-strict-boundaries">Setting strict boundaries</h2><p>Elsewhere, the company unveiled an expansion of the Google Cloud Data Boundary service. This service has been operational for a while now, and gives customers the ability to deploy sovereign data boundaries and thereby control where corporate materials are stored and processed. </p><p>“This boundary also allows customers to store and manage their encryption keys outside Google’s infrastructure, which can help customers meet their specific data access and control requirements no matter what market.”</p><p>Similar to the air-gapped service, this gives customers access to a raft of Google Cloud products, including AI solutions, as well as confidential computing and external key management capabilities to “control access to their data and deny access for any reason”. </p><p>Notably, through this service Google Workspace customers can implement boundary controls to limit the processing of data to the United States or EU and choose a specific country to store data locally. </p><p>As part of the update, Gallot revealed the launch of User Data Shield, which leverages Mandiant services aimed at validating applications built on top of the boundary service. </p><p>“User Data Shield provides recurring security testing of customer applications to validate sovereignty postures,” Gallot explained. </p><h2 id="google-eyes-local-partner-support">Google eyes local partner support</h2><p>The third and final update focuses on Google Cloud Dedicated, a solution designed to help enterprises meet local sovereignty requirements, particularly those in the EU. </p><p>Support for the service is underpinned by “independent local and regional partners”, Google said. This was developed alongside Thales as part of a long-standing partnership between the two firms. </p><p>Google Cloud originally partnered with Thales in 2021 to build the <a href="https://www.s3ns.io/en/offres/trusted-cloud-by-S3NS"><u>Trusted Cloud by S3NS</u></a> for Europe.</p><p>“This offering with Thales is designed to offer a rich set of Google Cloud services with GPUs to support AI workloads and is operated by S3NS, a standalone French entity,” Gallot explained. </p><p>The service is currently in preview, and has been designed specifically to meet the security and operational resilience requirements of France’s SecNumCloud standards. </p><p>Google said it has plans to expand the Cloud Dedicated footprint globally, with Germany the next location on the list. </p><h2 id="sovereignty-concerns-grow">Sovereignty concerns grow</h2><p>The move from Google comes amid a period of rising tensions on both sides of the Atlantic, with the EU in particular voicing serious concerns over the influence of US tech companies in the region. </p><p>In late April, Microsoft said it would <a href="https://www.itpro.com/cloud/cloud-computing/microsoft-says-itll-protect-eu-cloud-customers-from-shutdown-demands"><u>rigorously defend European data from American overreach</u></a>. In a blog post, president Brad Smith said the company would resort to litigation to protect EU customers from US demands to shut down services. </p><p>Microsoft’s stance on the matter comes amid the Trump administration’s apparent irritation over EU rules which it claims have negatively impacted American tech giants. </p><p>Trump signed a memorandum earlier this year pledging to defend American companies from "overseas extortion". The memorandum specifically named the EU <a href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma">Digital Markets Act (DMA)</a> as legislation which impedes US firms.</p><p>Political maneuvering aside, data sovereignty has become a key focus for enterprises operating in the EU in recent years as a result of legislation aimed at protecting consumers and bolstering data protection standards. </p><p>Analysis from OVHCloud in January this year showed 51% of UK organisations now acknowledge <a href="https://www.itpro.com/security/data-protection/data-sovereignty-a-growing-priority-for-uk-enterprises"><u>data sovereignty as a “crucial” aspect of their data management strategies</u></a>, for example.</p><p>Naturally, big tech providers have invested heavily to accommodate these evolving needs, with Oracle, AWS, Microsoft, and others all launching dedicated sovereign cloud services. </p><p>When AWS unveiled the launch of a new sovereign cloud offering in Europe last year, analysts told <em>ITPro </em>that <a href="https://www.itpro.com/cloud/cloud-computing/sovereign-cloud-services-are-now-the-bare-minimum-expected-by-customers-and-hyperscalers-are-scrambling-to-meet-demand"><u>sovereign services are now the “bare minimum” expected from customers</u></a> in the region. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/google-cloud-next-2025-enterprise-ai-adoption">Google Cloud is leaning on all its strengths to support enterprise AI</a></li><li><a href="https://www.itpro.com/infrastructure/why-google-cloud-is-betting-big-on-its-custom-chips]">‘TPUs just work’: Why Google Cloud is betting big on its custom chips</a></li><li><a href="https://www.itpro.com/cloud/cloud-security/google-cloud-wants-to-tackle-cyber-complexity-heres-how-it-plans-to-do-it">Google Cloud wants to tackle cyber complexity – here's how it plans to do it</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Enterprises are facing a ‘cloud security crisis’  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/enterprises-are-facing-a-cloud-security-crisis</link>
                                                                            <description>
                            <![CDATA[ Businesses are facing a “cloud security crisis” fueled by increasingly fragmented hybrid environments, according to security firm Rubrik. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5Z6wkMz9FzXdVT3hSjsTNY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yb9eyHXAoy7PsS6iSLFnwn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Apr 2025 09:38:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yb9eyHXAoy7PsS6iSLFnwn-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud security concept image showing digitized cloud symbol above a circuit board with secondary cloud symbols surrounding. ]]></media:description>                                                            <media:text><![CDATA[Cloud security concept image showing digitized cloud symbol above a circuit board with secondary cloud symbols surrounding. ]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud security concept image showing digitized cloud symbol above a circuit board with secondary cloud symbols surrounding. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yb9eyHXAoy7PsS6iSLFnwn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Businesses are facing a “<a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a> crisis” fueled by increasingly fragmented hybrid environments, according to security firm Rubrik.</p><p>The company, in association with Wakefield Research, interviewed 1,600 IT and security leaders for its <em>The state of data security in 2025</em> report and found 90% had suffered <a href="https://www.itpro.com/security/cyber-attacks">cyber attacks</a> in 2024.</p><p>For some, the onslaught was relentless, with almost 20% experiencing more than 25 cyber attacks during the year.</p><p>The consequences of these breaches can be serious at both a business and personal level, Rubrik warned. Of those respondents that admitted to suffering a cyber attack, 37% said their company had suffered <a href="https://www.itpro.com/security/data-breaches/357063/the-it-pro-podcast-the-myth-of-reputational-damage">reputational damage</a> and loss of customer confidence. </p><p>A further 33% said such an incident had resulted in a forced leadership change.</p><p>When it comes to the sources of attack, 28% identified cloud or <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS </a>breaches as the point of origin. This has led Rubrik to point the finger squarely at the use of<a href="https://www.itpro.com/hybrid-cloud/29599/five-obstacles-holding-your-hybrid-cloud-strategy-back"> hybrid cloud strategies</a> as a source of the problem.</p><p>“Many organizations that move to the cloud assume their providers will handle security,” said Joe Hladik, head of Rubrik Zero Labs. “The persistence of <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attacks, coupled with <a href="https://www.itpro.com/cloud/cloud-security/hybrid-cloud-environments-are-under-serious-threat-from-hackers-heres-what-you-need-to-know">hybrid cloud vulnerabilities</a> shows that threat actors are always one step ahead.”</p><p>However, this seems to overlook the fact that a similar proportion of attacks came from <a href="https://www.itpro.com/security/why-you-should-always-be-wary-of-insider-threats-a-disgruntled-employee-at-a-us-industrial-firm-deleted-backups-and-locked-it-admins-out-of-workstations-in-a-failed-data-extortion-attempt">insider threats</a> (28%).</p><p>Nevertheless, 90% of respondents said they were managing hybrid cloud environments, with 35% saying that securing data across a variety of ecosystems was their top challenge, while 29% said it was lack of visibility and control over cloud-based data.</p><p>This issue of visibility is something IT decision makers have raised repeatedly in recent years. In a <a href="https://www.darktrace.com/blog/protecting-your-hybrid-cloud-the-future-of-cloud-security-in-2025-and-beyond" target="_blank"><u>December 2024 blog</u></a>, Darktrace identified limited visibility as an emerging threat that can lead to misclassification of data in terms of sensitivity and misaligned access policies.</p><p>Similarly, research from Fortinet revealed 55% of the individuals it surveyed for its <em>2025 state of cloud security report</em> found loss of visibility and control to be a major issue when securing multi-cloud environments – another aspect of data sprawl.</p><p>Rubrik’s recommendations for how to combat these issues is to follow the fundamentals of cybersecurity in the 2020s: identify where the data is, what it is, and how sensitive it is, both in motion and at rest. </p><p>Thereafter, enterprises should implement policies to protect this data and establish what processes and procedures can be used to enforce it. Similarly, IT teams should use automation where possible to enable them to focus on things that need real human expertise to solve, rather than using up their time on drudgery. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/security-researchers-set-up-an-api-honeypot-to-dupe-hackers-and-the-results-were-startling">Security researchers set up an API honeypot to dupe hackers – and the results were startling</a></li><li><a href="https://www.itpro.com/cloud/cloud-computing/cloud-spending-financial-services-idc">Cloud spending soars in financial services</a></li><li><a href="https://www.itpro.com/cloud/cloud-security/surging-cnapp-investment-is-a-big-opportunity-for-the-channel">Surging CNAPP investment is a big opportunity for the channel</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Cloud wants to tackle cyber complexity – here's how it plans to do it ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/google-cloud-wants-to-tackle-cyber-complexity-heres-how-it-plans-to-do-it</link>
                                                                            <description>
                            <![CDATA[ Google Cloud has announced a new unified security platform for enterprises, delivering new interoperability and AI capabilities for cyber teams and reducing time spent investigating threats in enterprise cloud environments. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c7RwMsHU3s6oRrtbgZkVpK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qJMMPgyMD38BtSE5GZjnRa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Apr 2025 12:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 09 Apr 2025 18:43:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qJMMPgyMD38BtSE5GZjnRa-1280-80.jpg">
                                                            <media:credit><![CDATA[Google Cloud]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A diagram showing all the parts that make up Google Unified Security: Google Security Operations, Google Chrome Enterprise, Mandiant Expertise, Google Cloud Security Command Center, and Google Threat Intelligence, around a core of Gemini in Security and Security Data Fabric.]]></media:description>                                                            <media:text><![CDATA[A diagram showing all the parts that make up Google Unified Security: Google Security Operations, Google Chrome Enterprise, Mandiant Expertise, Google Cloud Security Command Center, and Google Threat Intelligence, around a core of Gemini in Security and Security Data Fabric.]]></media:text>
                                <media:title type="plain"><![CDATA[A diagram showing all the parts that make up Google Unified Security: Google Security Operations, Google Chrome Enterprise, Mandiant Expertise, Google Cloud Security Command Center, and Google Threat Intelligence, around a core of Gemini in Security and Security Data Fabric.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qJMMPgyMD38BtSE5GZjnRa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google Cloud has announced a new unified security platform for enterprises, delivering new interoperability and <a href="https://www.itpro.com/technology/artificial-intelligence/what-good-ai-cyber-security-looks-like-today">AI capabilities for cyber teams</a> and reducing time spent investigating threats in cloud environments.</p><p>Google Unified Security combines products, telemetry, and context from Google Threat Intelligence, <a href="https://www.itpro.com/business/careers-and-training/mandiant-exec-thinks-ai-could-boost-diversity-in-cybersecurity">Mandiant</a>, Google Security Operations, and <a href="https://www.itpro.com/cloud/cloud-security/google-clouds-new-security-ai-will-explain-how-youve-been-breached">Google Security Command Center</a>, to provide organizations with an intelligent overview of threats.</p><p>Referred to by executives as ‘GUS’, the offering is a searchable data fabric for enterprise vulnerability, tying together the data and capabilities of the above platforms for better security visibility.</p><p><a href="https://www.itpro.com/technology/artificial-intelligence/google-jumps-on-the-agentic-ai-bandwagon">Gemini AI</a> sits at the core of Google Unified Security, as a key enabler for decreasing time to detection for security teams and reducing manual workload. Google Cloud’s internal AI models will power features such as two new <a href="https://www.itpro.com/security/cyber-crime/agentic-ai-cybersecurity-risks"><u>security agents</u></a> that will work alongside human cyber workers on proactive, low-level analysis and producing reports.</p><p>A new alert triage agent, available within Google Security Operations, will continuously analyze enterprise environments for alerts and flag any activity it deems worthy of human response.</p><p>The second, a new <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> analysis agent contained within Google Threat Intelligence, will proactively scan the code for all uploaded files for <a href="https://www.itpro.com/security/disgruntled-dev-malicious-code-insider-threat">malicious code</a>. Matching this against known malware examples, it will then provide a detailed summary for security teams.</p><p>Both agents will become available to certain customers via preview in Q2 2025, with general availability at a later date.</p><p>In a demo, Payal Chakravarty, director of Product Management at Google Cloud, showed a data loss prevention (DLP) alert in Google Chrome Enterprise flagging an incident in which developer has inadvertently copied sensitive data into public LLMs through a Chrome extension.</p><p>Responding to the alert, a Gemini agent is then able to investigate the situation and confirm the leak to a high degree of confidence, making detailed logs throughout and quarantining the Chrome extension involved. The agent can then go further by updating the company’s policy on the extension to prevent any further data leaks.</p><p>Similarly, Chakravarty explained that the agent could continue to investigate and discover other vulnerabilities such as the developer accidentally exposing a <a href="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines">virtual machine (VM)</a> to the public internet. It could then correlate any suspicious traffic to the VM with known signatures from active threat actors using data from Google Threat Intelligence.</p><p>Brian Roddy, VP of cloud security at Google Cloud, explained that GUS is intended to meet the needs of businesses in an era of increasing attacks by <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier">state-backed threat actors</a> and criminal <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers">cyber gangs</a>.</p><p>“Enterprise infrastructure continues to grow in size and complexity, expanding the attack surface and making defenders’ jobs increasingly difficult and there's separate, disconnected security tools resulting in a fragmented data situation, without relevant context, leaving organizations vulnerable and reactive in the face of escalating threats.”</p><p>“So security teams tend to operate at silos, slowed by toils of workflows, making it hard to accurately assess and improve the organization's overall risk profile.</p><p>The announcement was made live at <a href="https://www.itpro.com/cloud/live/google-cloud-next-2025-all-the-news-and-updates-live">Google Cloud Next 2025</a>, the company’s annual conference held in Las Vegas.</p><h2 id="managing-ai-risk-and-common-vulnerabilities">Managing AI risk and common vulnerabilities</h2><p>Google Cloud has recognized that along with the benefits <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> presents businesses, improper use or implementation of the technology can also expose organizations to unwanted risks. </p><p>In March, Google Cloud <a href="https://cloud.google.com/blog/products/identity-security/introducing-ai-protection-security-for-the-ai-era" target="_blank"><u>announced</u></a> AI Protection, through which leaders can take stock of the <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">AI models</a> and tools they use across their environment and secure data used for AI.</p><p>Model Armor, a feature integrated within <a href="https://www.itpro.com/technology/artificial-intelligence/google-cloud-targets-ai-anywhere-with-vertex-ai-agents">Vertex AI</a>, allows leaders to apply specific controls across AI inputs and outputs across their cloud environment, across a wide range of models.</p><p>Now Google Cloud has announced new Data Security Posture Management features, which flags and labels sensitive data, puts it under suitable compliance controls, and monitors how it is used for AI directly within the Google Cloud AI portfolio and analytics tools such as <a href="https://www.itpro.com/data-insights/business-analytics/362886/google-opens-bigquery-to-small-businesses">BigQuery</a>.</p><p>Alongside this, a newly-launched Compliance Manager will work to give users better understanding of their <a href="https://www.itpro.com/business/business-strategy/keeping-up-with-the-compliance-landscape-in-2024"><u>data compliance</u></a> and help internal teams produce audits to keep on top of reporting requirements. Both features will enter preview in June.</p><p>In response to an <em>ITPro</em> question on how Google Cloud customers are tackling issues such as <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-shadow-ai-and-what-leaders-can-do-to-prevent-it">shadow AI</a>, Roddy stated that early adopters are already finding AI Protection useful for detecting unauthorized AI model use within their workplace.</p><p>“So what they want to have is the ability to control, what are really the models that are approved and tested and which ones aren't,” Roddy said.</p><p>“And in some cases they're willing to let users use more advanced models for experimental purposes. So what this is doing is just giving them a lot more control about understanding what's inside their environment and to be able to make sure that the right models are being used for the right use cases.”</p><p>Google Chrome Enterprise Premium is also set to receive new privacy controls, including data masking to automatically hide sensitive information and <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>protection to prevent <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">man in the middle (MiTM) attacks</a> in which malicious sites are disguised as legitimate web portals.</p><p>This is in addition to the rollout of existing Google Chrome Enterprise Premium features, such as copy paste prevention and URL filtering, across Android.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/cloud/live/google-cloud-next-2025-all-the-news-and-updates-live">Keep tabs on all the updates from Google Cloud Next in our rolling live coverage</a></li><li><a href="https://www.itpro.com/cloud/public-cloud/google-cloud-next-2025-all-in-one-ai-platform-enterprises">Google Cloud Next 2025 is the hyperscaler’s chance to sell itself as the all-in-one AI platform for enterprises</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/google-cloud-uk-sovereign-data-agentic-ai">Google Cloud announces UK data residency for agentic AI services</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Enterprise AI is surging, but is security keeping up? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/enterprise-ai-is-surging-but-is-security-keeping-up</link>
                                                                            <description>
                            <![CDATA[ Enterprises are ramping up the adoption of AI tools, according to new research, but the heightened security and data protection risks associated with the technology are causing serious headaches for cybersecurity professionals. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">32smoCD76gqQfbpwfbh52j</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2GtBeA8BWApHYgXH5HYBpn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Mar 2025 14:29:33 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Mar 2025 19:00:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2GtBeA8BWApHYgXH5HYBpn-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI chatbot text dialogue boxes in difference colours above a digital circuit board with lines of light emanating from it]]></media:description>                                                            <media:text><![CDATA[AI chatbot text dialogue boxes in difference colours above a digital circuit board with lines of light emanating from it]]></media:text>
                                <media:title type="plain"><![CDATA[AI chatbot text dialogue boxes in difference colours above a digital circuit board with lines of light emanating from it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2GtBeA8BWApHYgXH5HYBpn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Enterprises are ramping up the adoption of <a href="https://www.itpro.com/technology/artificial-intelligence/ai-tools-critical-thinking-reliance">AI tools</a>, according to new research, but the heightened security and data protection risks associated with the technology are causing serious headaches for cybersecurity professionals.</p><p>A new <a href="https://www.zscaler.com/campaign/threatlabz-ai-security-report" target="_blank">report</a> from <a href="https://www.itpro.com/business/acquisition/zscaler-boosts-ai-capabilities-with-dollar350-million-avalor-acquisition">Zscaler</a> showed  a 3,000% year-on-year increase in enterprise AI and machine learning (ML) adoption, based on analysis of over 536 billion AI transactions processed on its cloud platform between February and December 2024.</p><p>The US and India were found to be leading the world in terms of <a href="https://www.itpro.com/technology/artificial-intelligence/world-record-performance-for-ai-and-ml">AI/ML </a>transaction volumes, with businesses in the UK, Germany, and Japan also showing significant uptake of AI tools.</p><p>Overall, businesses around the world sent a total of 3,624 TB of data to AI tools during that period, with <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">OpenAI’s ChatGPT</a> being the most popular application, accounting for 45.2% of transactions.</p><p>But while ChatGPT was far and away the most popular tool, Zscaler noted it was  also the most widely blocked application, with security leaders stating they were concerned about the lack of visibility into how employees were using it.</p><p>AI-enhanced content creation and productivity tools tended to be the most frequently blocked by enterprises, with other commonly restricted applications being <a href="https://www.itpro.com/operating-systems/microsoft-windows/355176/microsoft-editor-goes-head-to-head-with-grammarly">Grammarly</a>, <a href="https://www.itpro.com/technology/artificial-intelligence/microsoft-copilot-review-ai-baked-into-your-apps">Microsoft Copilot</a>, QuillBot, and Wordtune.</p><p>The report found enterprises had blocked 59.9% of all AL/ML transactions, which it said signals a growing awareness of the potential risks associated with using these tools, such as data leakage, unauthorized access, and compliance issues.</p><h2 id="businesses-are-succeeding-at-reducing-ai-driven-exposures-amid-rapid-adoption">Businesses are succeeding at reducing AI-driven exposures amid rapid adoption</h2><p>An analogous <a href="https://sysdig.com/blog/sysdig-2025-cloud-native-security-and-usage-report/" target="_blank">report</a> from cloud security specialist <a href="https://www.itpro.com/business/leadership/sysdig-names-cybersecurity-veteran-william-welch-as-new-ceo">Sysdig</a> identified a similar pattern, with 75% of its customers using AI or ML packages in their environments, which has more than doubled since the previous year.</p><p>Sysdig revealed that its telemetry showed an eye-watering 500% increase in <a href="https://www.itpro.com/technology/artificial-intelligence/webinar-how-to-scale-ai-workloads-taking-an-open-data-lakehouse-approach">AI workloads</a> in the last year. This surge was mostly driven by widespread adoption of data analysis tools, the report noted, but the percentage of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> packages has more than doubled over the course of a year, rising from 15% to 36%.</p><p>Speaking to <em>ITPro, </em>Crystal Morin, <a href="https://www.itpro.com/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy">cybersecurity strategist</a> at Sysig, said that she and her colleagues felt this huge growth in AI usage was being driven in some part by <a href="https://www.itpro.com/software/development/shadow-ai-is-creeping-its-way-into-software-development-more-than-half-of-developers-admit-to-using-unauthorized-ai-tools-at-work-and-its-putting-companies-at-risk">shadow AI</a>, where employees use AI tools without explicit permission from their employer.</p><p>Morin added that businesses are paying close attention to how they are <a href="https://www.itpro.com/cloud/cloud-security/ai-is-putting-your-cloud-workloads-at-risk">securing AI workloads</a>, however, stating that the proportion of workloads that are publicly exposed to the internet without appropriate security controls has shrunk by 38% in less than eight months.</p><p>The report found 12.8% of workloads containing AI packages were publicly exposed in 2025, with only 1% of these representing <a href="https://www.itpro.com/security/26998/critical-vulnerabilities-found-in-lastpass-password-manager">critical vulnerabilities</a> and 0.5% being in use.</p><p>Morin said she felt this was largely the result of businesses and their IT teams placing added scrutiny on <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-shadow-ai-and-what-leaders-can-do-to-prevent-it">how AI is being used in their organization</a>, owing to the level prominence these tools and their associated risks have been given.</p><p>“IT and security teams know what to look for, and they are definitely prioritizing it. They’re seeing these packages pop up, they’re getting alerted, and they’re locking them down.”</p><p>The fact that such a tiny percentage of these workloads were deemed a critical vulnerability was just very reassuring and showed bolstered security efforts observed across the industry were paying off.</p><p>“It’s super exciting to see because there is very low risk of attackers being able to [exploit them], it’s still a concern but a very low risk in comparison to other concerns that we have so that’s a really great security effort there.”</p><p>Morin said it was important to emphasize the work being done in this area by <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a> professionals is paying off.</p><p>“The story I wanted to tell with this [report] is that we’re doing a good job, cloud defenders have ‘made it’ this year,” she declared.</p><p>“If we keep the momentum we can continue making progress as <a href="https://www.itpro.com/cloud/microsoft-azure/364287/microsoft-releases-defender-for-azure-cosmos-db-in-preview">cloud defenders</a>. I think we know enough about defense at this point that we can keep going, continue implementing AI for cloud defense, we know about preventative measures, we know how to defend ourselves.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/ai-agent-announcements-are-a-dime-a-dozen-right-now-heres-what-oracle-thinks-its-doing-differently">AI agent announcements are a dime a dozen right now – here’s what Oracle thinks it’s doing differently</a></li><li><a href="https://www.itpro.com/security/ai-tools-cyber-crime-application-exploits">Hackers are turning to AI tools to reverse engineer millions of apps – and it’s causing havoc for security professionals</a></li><li><a href="https://www.itpro.com/business/public-sector/dhsc-eyes-infrastructure-overhaul-amid-gbp114-million-it-spending-boost">DHSC eyes infrastructure overhaul amid £114 million IT spending boost</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI is putting your cloud workloads at risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/ai-is-putting-your-cloud-workloads-at-risk</link>
                                                                            <description>
                            <![CDATA[ Many AI deployments are defined by risky misconfigurations and access controls ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZyvE9kX7F5CmTU3rjm2W43</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZgmFXt3rmVFTgdGmCWxgUR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Mar 2025 13:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Mar 2025 15:50:20 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZgmFXt3rmVFTgdGmCWxgUR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud storage concept image showing digitized cloud symbol with data flows.]]></media:description>                                                            <media:text><![CDATA[Cloud storage concept image showing digitized cloud symbol with data flows.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud storage concept image showing digitized cloud symbol with data flows.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZgmFXt3rmVFTgdGmCWxgUR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> cloud workloads are far riskier than their traditional counterparts, <a href="https://www.tenable.com/cyber-exposure/tenable-cloud-ai-risk-report-2025?utm_medium=referral&utm_source=https://www.itpro.com/uk&utm_campaign=cmpn-00033040&utm_content=it_pro_exclusive_news_writeup">according to research from Tenable</a>.</p><p>Almost three-quarters (72%) of cloud workloads with an AI package installed contain a critical vulnerability, Tenable found, compared to only 59% of cloud workloads without one.</p><p>A key factor behind the higher incidence of <a href="https://www.itpro.com/security/rsa-encryption-keys-vulnerability">critical vulnerabilities</a> is that many AI workloads run on Unix-based systems that themselves run many different libraries, including open source.</p><p>Vulnerabilities are also made more critical as the outcome of the exploitation is riskier due to the potential for manipulation of models, tampering of data, and data leakage, the report said.</p><p>Other issues include what Tenable called “jenga-style” cloud misconfigurations, in which cloud providers are layering AI services on top of one another to create building blocks that users are unaware of. </p><p>For example, 77% of organizations have an overprivileged default Compute Engine service account attached in at least one Vertex AI Workbench notebook on <a href="https://www.itpro.com/software/google">GCP</a>. </p><p>This means that whenever a user creates a notebook instance, a Compute Engine instance is created within the user's project behind the scenes. The underlying Compute Engine’s overprivileged default configuration then puts the notebook instances at risk. </p><p>The report also found that 91% of firms using Amazon SageMaker have set up risky default administrator privileges in at least one notebook instance, meaning users can change system-critical files. </p><p>With 25% of AWS users having configured Amazon Sagemaker and 20% of CGP users having configured Vertex AI Workbench, the rising use of cloud-based AI tools should make these problems a top priority for IT leaders. </p><h2 id="cloud-security-remains-a-problem">Cloud security remains a problem </h2><p>Though Tenable’s research points the finger at AI-related issues, other analysis from the firm shows that traditional cloud security can be just as much of an issue.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DBdNsn8LSmgjraQqEmxkJF" name="The State of B2B Recommerce" caption="" alt="The State of B2B Recommerce" src="https://cdn.mos.cms.futurecdn.net/DBdNsn8LSmgjraQqEmxkJF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: B-Stock)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/the-state-of-b2b-recommerce"><em>Maintain inventory turnover and minimize holding costs</em></a></p></div></div><p><a href="https://www.itpro.com/cloud/cloud-security/are-your-cloud-resources-at-risk"><u>A report from the firm last October</u></a> found that over a third (38%) of organizations were running at least one at-risk cloud workload. Reasons for this risk included the possession of unused or longstanding access keys.</p><p><a href="https://www.itpro.com/cloud/cloud-security/organizations-warned-of-the-dangers-of-long-lived-cloud-credentials"><u>Datadog published similar statistics</u></a>, finding that “long-lived” cloud credentials are a risk for firms across all cloud providers with almost 50% of organizations using them.</p><p>"In addition to long-lived credentials being a major risk, the report found that most cloud security incidents are caused by compromised credentials," Andrew Krug, head of security advocacy at Datadog, said at the time. </p><p><a href="https://www.itpro.com/cloud/hybrid-cloud/security-and-compliance-concerns-are-driving-the-shift-to-hybrid-cloud"><u>Research from Information Services Group (ISG) earlier in 2024</u></a> found that a need for strengthened cloud security was behind a push back towards private or hybrid cloud models. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/cloud/cloud-security/10-cloud-security-tips-every-it-leader-should-know"><strong>Ten cloud security tips every IT leader should know</strong></a></li><li><a href="https://www.itpro.com/cloud/cloud-security/cloud-security-for-smbs-simple-steps-to-stay-secure"><strong>Cloud security for SMBs: Simple steps to stay secure</strong></a></li><li><a href="https://www.itpro.com/cloud/cloud-security/hybrid-cloud-environments-are-under-serious-threat-from-hackers-heres-what-you-need-to-know"><strong>Hybrid cloud environments are under serious threat from hackers – here’s what you need to know</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Wiz acquisition stakes Google's claim as the go-to hyperscaler for cloud security – now it’s up to AWS and industry vendors to react ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/wiz-acquisition-google-cloud-industry-reaction</link>
                                                                            <description>
                            <![CDATA[ The Wiz acquisition could have monumental implications for the cloud security sector, with Google raising the stakes for competitors and industry vendors. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">n8AK9MXHA69toVwNtMTsA5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QocBSERvAL8Co7sTrt3a7R-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Mar 2025 10:37:39 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Mar 2025 15:34:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QocBSERvAL8Co7sTrt3a7R-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Google Cloud, which recently announced the Wiz acquisition, pictured at Mobile World Congress 2025 in Barcelona, Spain.]]></media:description>                                                            <media:text><![CDATA[Logo of Google Cloud, which recently announced the Wiz acquisition, pictured at Mobile World Congress 2025 in Barcelona, Spain.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Google Cloud, which recently announced the Wiz acquisition, pictured at Mobile World Congress 2025 in Barcelona, Spain.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QocBSERvAL8Co7sTrt3a7R-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google’s acquisition of cloud security startup Wiz could have monumental implications for the sector, according to industry analysts, with the company raising the stakes for both key competitors and security vendors. </p><p>The acquisition, <a href="https://www.itpro.com/business/business-strategy/google-confirms-wiz-acquisition-in-record-breaking-usd32-billion-deal">announced this week as a $32 billion all-cash transaction</a>, will see Wiz bundled within the tech giant’s cloud computing division. It’s been a long time coming, as well. </p><p><a href="https://www.itpro.com/business/acquisition/google-will-need-to-find-a-new-cloud-security-champion-as-wiz-backs-out-of-dollar23-billion-acquisition"><u>Talks last year fell through at the final hurdle</u></a> amid a raft of concerns, not least of all regulatory considerations and whether it would continue as an independent entity.</p><p>Founded in 2020, Wiz has emerged as a leading figure in the <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a> space; the broader industry has become a key focus for enterprise IT leaders in recent years amidst the widespread shift to the cloud, and more recently, hybrid and multi-cloud setups. </p><p>Research from CrowdStrike in 2024, for example, noted that the cloud has become a “major battleground for cyber attacks”, highlighting the escalating threats faced by enterprises across a range of industries. </p><p>Wiz specializes in <a href="https://www.itpro.com/cloud/cloud-computing/what-is-cloud-native-and-how-can-it-generate-business-value">cloud native</a> security, providing enterprises with <a href="https://www.itpro.com/cloud/cloud-security/solving-the-cloud-native-app-puzzle-with-cnapp">cloud native application protection platforms (CNAPP)</a>, threat detection, and incident response capabilities. </p><p>It’s the CNAPP element here that will be a key differentiator for the tech giant, analysts believe. These solutions differ from traditional security tools by offering users a unified platform aimed at bolstering security across the entire lifecycle of cloud native applications. </p><p>The advantage for enterprises is that by consolidating their cloud security toolkit, they can improve visibility across their cloud estates and better secure applications. </p><p>CNAPP has been growing in appeal among IT leaders in recent years. Research from Westcon-Comstor this month, for example, revealed that <a href="https://www.itpro.com/cloud/cloud-security/surging-cnapp-investment-is-a-big-opportunity-for-the-channel"><u>84% of UK firms intend to invest in CNAPP solutions</u></a> over the next 12 months. </p><p>Similarly, the market is growing at a significant pace. <a href="https://www.prnewswire.com/news-releases/cnapp-market-to-surge-to-6-billion-by-2028-as-enterprises-play-catch-up-on-cloud-security-according-to-delloro-group-302192526.html" target="_blank"><u>Analysis from Dell’Oro Group</u></a> in July 2024 valued the CNAPP market at around $2 billion. But this is expected to surge to over $6 billion by 2028, representing a compound annual growth rate (CAGR) of 25%.</p><p>Given the value of the Wiz deal is more than five-times the expected value of the CNAPP market, it’s clear that Google is trying to capitalize on a lucrative opportunity. </p><p>Combine that with the need to ramp up multi-cloud security offerings and keep pace with competitors in the space, and the price tag attached to Wiz makes perfect sense.</p><h2 id="wiz-deal-could-be-the-key-to-pipping-customers">Wiz deal could be the key to pipping customers</h2><p>Microsoft has made significant strides in its cloud native security capabilities in recent years through notable acquisitions, according to Andras Cser, VP principal analyst at Forrester. </p><p>But Cser noted that while Google Cloud has been developing built-in CNAPP capabilities to bolster GCP security, these tools have “predominantly focused only on protecting GCP endpoints/assets”. </p><p>“After Microsoft’s 2021 early acquisition of CloudKnox and development of Defender for Cloud, Google is feeling the pressure to offer a true, multi-cloud-capable CNAPP tool given that so many organizations are multi-cloud today,” he said. </p><p>Cser added that, post-acquisition, the consultancy expects most CNAPP capabilities in GCP to be replaced by Wiz’s offering. With the firm bundled under the Google Cloud umbrella, this could become a tantalizing draw for prospective customers. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WEBINAR</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RHBoT86jw6joAzgigKGZS3" name="Maximizing Microsoft 365 Security How Cloudflare Enhances Protection And Adds Value" caption="" alt="Maximizing Microsoft 365 Security: How Cloudflare Enhances Protection And Adds Value" src="https://cdn.mos.cms.futurecdn.net/RHBoT86jw6joAzgigKGZS3.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-management/maximizing-microsoft-365-security-how-cloudflare-enhances-protection-and-adds-value"><em>Detect and isolate threats across Microsoft 365 environments</em></a></p></div></div><p>From a competition perspective, the deal also raises the stakes. With Microsoft’s acquisitions in this domain having placed pressure on Google to react, the Wiz deal will likely have the same effect on <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/362608/what-is-aws">Amazon Web Services (AWS)</a>, another key competitor in the cloud space. </p><p>AWS provides tools such as <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30853/aws-says-its-entire-cloud-is-gdpr-ready">Guard Duty</a> and Config for customers. However, Cser insisted these “fall short” of the capabilities offered by a CNAPP solution, particularly with regard to multi-cloud coverage. </p><p>“If AWS is to maintain its position in cloud infrastructure, it has to beef up its productized, multi-cloud CNAPP (with coverage for CSPM, CIEM, agent-based and agentless CWP, container security, and IaC scanning) and, in general, cloud security offerings.”</p><h2 id="the-wiz-acquisition-could-hit-vendors-hard">The Wiz acquisition could hit vendors hard</h2><p>While Google got what it wanted from the Wiz acquisition, independent vendors operating in the CNAPP space could feel immense pressure in the coming years, according to Cser. </p><p>A host of major vendors, including Fortinet, Palo Alto Networks, Rapid7, Sysdig, and Trend Micro offer CNAPP solutions, and Cser said they can not expect “fierce competition” to stay ahead in features. </p><p>“The planned acquisition plus Microsoft’s continued investments in CNAPP and app security will make it harder for these vendors to maintain and realize their growth,” he added. </p><p>Allie Mellen, principal analyst at Forrester, echoed Cser’s comments on this front, adding that this will place pressure on vendors to consolidate their offerings. </p><p>“Wiz’s key detection and response offering, Wiz Defend, takes a different approach to cloud detection and response,” she said. </p><p>“Instead of relying on built-in detection capabilities in its own cloud protection tools, it offers a unified tool solely for detection and response that takes in alerts and data from other tools and does detection engineering on them.”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/a696c78c-0d94-4bc0-b1cf-106e70c68480/"></iframe><p>All told, this reduces alert volumes from the cloud at a “critical time”, Mellen noted, thereby alleviating pressure on security practitioners and streamlining operations. </p><p>“With this acquisition, it will put pressure on other vendors to consolidate in a similar way — a big win for security operations teams.”</p><p>While some vendors will be bracing themselves in the wake of the acquisition, others are taking a more optimistic approach. Bill Welch, CEO of the aforementioned Sysdig, said there will be advantages for industry vendors. </p><p>“Regarding the potential $30B+ Google acquisition of Wiz – as Sysdig’s CEO, I say bring it on! This is great validation for the cloud security market,” he said. </p><p>Following communication with CISOs, investors, and cloud partners, Welch noted that one key talking point has emerged - mainly that “being forced into a single vendor is not good for business”. </p><p>“Most - if not all - cloud users and multi-cloud, and you can guarantee multi-cloud Wiz customers will struggle once the acquisition goes through.  With a Google acquisition, this story ends well for the VCs, founders, and employees, but the customers are the ones who ultimately lose in a deal like this.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/google-cloud-will-make-mfa-mandatory-by-the-end-of-2025-heres-what-you-need-to-know">Google Cloud will make MFA mandatory by the end of 2025</a></li><li><a href="https://www.itpro.com/cloud/cloud-security/google-clouds-new-security-ai-will-explain-how-youve-been-breached">Google Cloud’s new security AI will explain how you’ve been breached</a></li><li><a href="https://www.itpro.com/cloud/cloud-security/aws-users-are-getting-a-big-security-boost-with-passkey-support">AWS users are getting a big security boost with passkey support</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google confirms Wiz acquisition in record-breaking $32 billion deal ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/google-confirms-wiz-acquisition-in-record-breaking-usd32-billion-deal</link>
                                                                            <description>
                            <![CDATA[ Google has confirmed plans to acquire cloud security firm Wiz in a deal worth $32 billion. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uYTDbNhFnKqUhLAdsaQTjE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h9mfDS8ubs2Tgy7TqHYcz7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Mar 2025 14:01:10 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Mar 2025 17:05:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h9mfDS8ubs2Tgy7TqHYcz7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wiz logo pictured on a laptop screen.]]></media:description>                                                            <media:text><![CDATA[Wiz logo pictured on a laptop screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Wiz logo pictured on a laptop screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h9mfDS8ubs2Tgy7TqHYcz7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/google">Google</a> has confirmed plans to acquire cloud security firm Wiz in a deal worth $32 billion. </p><p>The deal marks the biggest acquisition yet for the tech giant, more than double its $12.5 billion buyout of Motorola in 2012, before selling it off again two years later for a fraction of that price. </p><p>The tech giant said the acquisition represents an investment to "accelerate two large and growing trends in the AI era" - namely cloud security and multi-cloud capabilities. </p><p>The acquisition comes less than a year after negotiations between Google and Wiz over a $23bn deal collapsed amid myriad concerns, including <a href="https://www.itpro.com/business/policy-and-legislation/doj-mulls-potential-google-services-breakup-in-monopoly-lawsuit-what-happens-next">antitrust</a> hurdles, disputes over how the company would integrate into Google, and more. </p><p>Reports at the time subsequently suggested Wiz would go public. </p><p>Another reported challenge to the last round of negotiations was whether Wiz would remain a separate company or be bundled into Google Cloud, according to reports at the time from the <a href="https://www.wsj.com/business/deals/alphabet-back-in-deal-talks-for-cybersecurity-startup-wiz-41cd3090" target="_blank"><u><em>Wall Street Journal</em></u></a>. </p><p>In a statement confirming the move, which is an all-cash transaction, Google said Wiz will join Google Cloud, confirming the firm's bundling with the cloud services wing. </p><p><a href="https://www.bloomberg.com/news/articles/2025-03-17/alphabet-in-talks-to-buy-cloud-security-firm-wiz-for-33-billion"><u><em>Bloomberg </em></u></a>reported co-founder and CEO Assaf Rappaport had previously said he hoped the company would become an independent security giant to rival <a href="https://www.itpro.com/software/development/crowdstrike-outage-2024-development-impact">Crowdstrike</a> or Palo Alto Networks. </p><p>Last year, Rappaport told a <a href="https://techcrunch.com/2024/10/28/wiz-ceo-explains-why-he-turned-down-a-23-billion-deal/"><u>TechCrunch conference</u></a> that turning down the first offer was "the toughest decision ever", adding that "saying no to such humbling offers is tough, but with our exceptional team, I feel confident in making that choice." </p><p>Founded in 2020 in Israel but now based in the US, Wiz has reported significant growth in recent years, and was among a host of firms to capitalize on the widespread shift to remote operations during the pandemic. Last year, the firm’s headcount stood at 900, and was valued at $12 billion. </p><p>The company counts nearly half of the Fortune 100 as its customers — including Google's cloud rivals <a href="https://www.itpro.com/amazon-web-services">AWS</a> and <a href="https://www.itpro.com/software/microsoft">Microsoft</a> — and has previously said it hopes to double its existing $500 million in annual recurring revenue to $1bn. </p><h2 id="why-the-wiz-deal-works-for-google">Why the Wiz deal works for Google</h2><p>The Wiz deal follows Google's 2022 acquisitions of <a href="https://www.itpro.com/security/367021/google-buys-cyber-security-firm-mandiant-for-54-billion"><u>security firm Mandiant in 2022</u></a> for $5.4bn and Siemplify for $500m, highlighting the growing importance of <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a> tools. </p><p>Building on this growing security portfolio, Wiz represents a major step forward for the tech giant. </p><p>Following the speculation over last year’s acquisition talks, analysts told <em>ITPro </em>the deal made sense for the firm given its position within the broader <a href="https://www.itpro.com/cloud/cloud-computing/cloud-spending-2025-canalys">cloud market</a> and the growing array of threats faced by enterprises using the cloud.</p><p>"I think cloud is the major battleground for <a href="https://www.itpro.com/security/cyber-attacks">cyber attacks</a> largely because the cloud is part of everybody’s IT <a href="https://www.itpro.com/infrastructure">infrastructure</a> at this point," Gartner analyst Charlie Winckless told <em>ITPro</em>. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WEBINAR</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8ZYfqjTyH38voEfveFN8V3" name="Strategies for improving security team efficiency.jpg" caption="" alt="Strategies for improving security team efficiency" src="https://cdn.mos.cms.futurecdn.net/8ZYfqjTyH38voEfveFN8V3.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/strategies-for-improving-security-team-efficiency"><em>Research findings on how to improve security efficiency</em></a></p></div></div><p>"The cloud is an increasingly critical, if not already critical part of at least 80% of organizations. And that means cloud security tools have become a must-have for large enterprises.  </p><p>"They are a necessity, whether provided by the cloud provider themselves – and each of the cloud providers provides these capabilities within their cloud – or for the many organizations that are intentionally or accidentally in a multi-cloud strategy." </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/Google-Anthropic-investment"><strong>Google will invest a further $1 billion in AI startup Anthropic</strong></a></li><li><a href="https://www.itpro.com/business/acquisition/ibm-hashicorp-acquisition-complete"><strong>IBM completes HashiCorp acquisition after regulatory approval</strong></a></li><li><a href="https://www.itpro.com/business/acquisition/servicenow-moveworks-acquisition"><strong>ServiceNow bolsters agentic AI offering with $2.85bn Moveworks acquisition</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is a secure web gateway (SWG) and next-gen SWG? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/what-is-secure-web-gateway-swg</link>
                                                                            <description>
                            <![CDATA[ Implemented correctly, a SWG can keep businesses shielded from malicious traffic and firmly enforce secure policies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GWdrtAgmRFiug4rsns3YEe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Xsk9DTvZSaeCarvPMNSoch-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Mar 2025 09:28:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Max Slater-Robins ]]></dc:creator>                                                                                                                                                                                                                                                                    <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Xsk9DTvZSaeCarvPMNSoch-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A multicolored, CGI padlock set against blue and yellow glowing slabs representing SWG and next-gen SWG in a cloud environment.]]></media:description>                                                            <media:text><![CDATA[A multicolored, CGI padlock set against blue and yellow glowing slabs representing SWG and next-gen SWG in a cloud environment.]]></media:text>
                                <media:title type="plain"><![CDATA[A multicolored, CGI padlock set against blue and yellow glowing slabs representing SWG and next-gen SWG in a cloud environment.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Xsk9DTvZSaeCarvPMNSoch-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In an age where <a href="https://www.itpro.com/security/cyber-attacks/the-new-era-of-cyber-threats"><u>cyber threats</u></a> are more sophisticated than ever, organizations should be looking at adding robust tools to safeguard their networks and users – such as a secure web gateway (SWG).</p><p>A SWG (pronounced 'swig') is a critical component of <a href="https://www.itpro.com/uk/tag/network-security"><u>network security</u></a> designed to filter malicious internet traffic and enforce web usage policies. By intercepting and analyzing web activity, SWGs protect against threats like <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>, <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a>, and data leaks, ensuring a safer online experience for employees and businesses alike.</p><p>The need for SWGs has grown significantly with the rise of remote work after the COVID-19 pandemic, <a href="https://www.itpro.com/business/business-strategy/the-top-4-byod-risks-businesses-face"><u>bring your own device (BYOD)</u></a> policies, and the increased reliance on cloud apps. Traditional security measures like <a href="https://www.itpro.com/security/data-protection/the-top-five-risks-of-perimeter-firewalls"><u>firewalls</u></a> are no longer sufficient to handle the complexities of modern internet traffic. </p><h2 id="what-is-a-swg">What is a SWG? </h2><p>A SWG acts as a protective barrier between users and the internet, including inspecting and filtering all web traffic. SWGs help organizations to safeguard against threats such as malware, phishing, and data loss, while enforcing internet usage policies.</p><p><strong>Malware detection</strong>: SWGs scan all inbound and outbound traffic for malicious content, such as viruses, <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers">ransomware</a>, or <a href="https://www.itpro.com/spyware/30001/what-is-spyware">spyware</a>, and use advanced techniques like signature-based detection to identify known threats, heuristic analysis to spot suspicious patterns, and sandboxing to safely examine unknown files.</p><p><strong>URL filtering</strong>: With URL filtering, organizations can control which websites users can access. SWGs classify websites into categories (eg., social media, gambling, or shopping) and enforce access policies accordingly. For instance, they can block high-risk sites or restrict non-productive browsing during work hours.</p><p><strong>Application controls</strong>: App control capabilities let SWGs monitor and regulate the use of cloud services, particularly those not sanctioned by IT teams (commonly referred to as shadow IT). By managing app usage, SWGs help prevent unauthorized data transfers and mitigate the risk of sensitive information being exposed through unapproved platforms.</p><h2 id="how-do-swgs-work">How do SWGs work? </h2><p><strong>Traffic inspection</strong>: First, the SWG intercepts all outbound internet requests from devices on the network. Whether users are accessing websites, cloud applications, or streaming content, the SWG acts as an intermediary.</p><p><strong>Policy enforcement</strong>: After intercepting the traffic, the SWG applies the organization’s security and compliance policies. These policies may include blocking access to certain websites or application categories, limiting <a href="https://www.itpro.com/broadband/30274/what-is-bandwidth">bandwidth</a> usage, or enforcing restrictions on file uploads and downloads.</p><p><strong>Threat analysis</strong>: The intercepted traffic undergoes rigorous analysis to detect potential risks. The SWG uses a combination of tools, such as malware detection in which it compares files users access with known threats, phishing protection, and content filtering. A SWG can be used to decrypt data This multi-layered analysis ensures that malicious activity is identified and neutralized before it can impact users.</p><p><strong>Access decision</strong>: Based on the analysis results and defined policies, the SWG either permits or denies the request. </p><p>Consider an employee attempting to download a file from an unfamiliar website. The SWG intercepts the request, scans the file for malware, checks the URL against its database of known malicious sites, and applies the company’s internet usage policy. If the file poses a risk or violates policy, it is blocked, and the user is alerted. Otherwise, the download proceeds securely.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/a696c78c-0d94-4bc0-b1cf-106e70c68480/"></iframe><p>All activity passing through the SWG is logged to provide IT teams with detailed reports on user behavior, blocked threats, and policy violations.</p><h2 id="next-gen-swgs-vs-swgs">Next-gen SWGs vs SWGs</h2><p>As cyber threats become more sophisticated and work environments grow increasingly decentralized, traditional SWGs are evolving into next-generation SWGs. </p><p>Next-generation SWGs build on the foundation of traditional gateways by offering advanced features such as <a href="https://www.itpro.com/cloud/cloud-computing/what-is-cloud-native-and-how-can-it-generate-business-value"><u>cloud-native</u></a> scalability, AI-driven threat detection, and integration with modern security frameworks like <a href="https://www.itpro.com/cloud/cloud-security/what-is-secure-access-service-edge-sase"><u>secure access service edge (SASE)</u></a>. Next-gen SWGs help to monitor all of an organization's cloud assets, identify unused or overlooked cloud applications to <a href="https://www.itpro.com/business/business-strategy/the-top-steps-to-eliminate-shadow-it">eliminate shadow IT</a>, and inspect <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted data</a> in motion to prevent threat actors from masking attacks in TLS/SSL traffic.  </p><p>By aligning with frameworks like SASE, these gateways help organizations tackle modern cybersecurity challenges such as <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary in the middle (AiTM) attacks</a> while providing the scalability needed to support a dynamic workforce. With features like AI-powered detection, <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust alignment</u></a>, and simplified deployment, next-gen SWGs are redefining what it means to secure users and data in the cloud era.</p><p>SWGs are a critical component of modern network security. By intercepting and analyzing web traffic in real-time, SWGs mitigate risks such as malware, phishing, and data leaks, ensuring compliance and productivity in increasingly complex network environments.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Surging CNAPP investment is a big opportunity for the channel ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/surging-cnapp-investment-is-a-big-opportunity-for-the-channel</link>
                                                                            <description>
                            <![CDATA[ UK enterprises plan to increase spending on cloud-native application protection platform (CNAPP) capabilities across 2025 - and they're hoping the IT channel can help streamline adoption. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uyFRSFQbcrnYZwzBNMKtaG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/R6w25DnbMVLjXCWkp7tVkh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Feb 2025 14:24:19 +0000</pubDate>                                                                                                                                <updated>Mon, 03 Feb 2025 17:19:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/R6w25DnbMVLjXCWkp7tVkh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud computing concept image showing a cloud symbol with electricity flowing to it, signifying cloud uptime capabilities. ]]></media:description>                                                            <media:text><![CDATA[Cloud computing concept image showing a cloud symbol with electricity flowing to it, signifying cloud uptime capabilities. ]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud computing concept image showing a cloud symbol with electricity flowing to it, signifying cloud uptime capabilities. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/R6w25DnbMVLjXCWkp7tVkh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK cybersecurity leaders are planning to invest in cloud-native application protection platform (CNAPP) in 2025 as part of plans to increase security spending, new research from Westcon-Comstor shows.</p><p>The technology provider and distributor quizzed 500 chief information security officers (CISOs) and senior security personnel at end-user organizations with 1,000 or more employees across the UK, France, Germany, Italy, and the UAE.</p><p>The data revealed that 84% of UK participants intend to invest in CNAPP and cloud technologies over the coming twelve months, outpacing the global average of 83%.</p><p>Designed to offer a holistic approach to securing cloud infrastructure, <a href="https://www.itpro.com/cloud/cloud-security/solving-the-cloud-native-app-puzzle-with-cnapp">CNAPP</a> technology bundles a range of security capabilities into a single, unified platform for security across the entire <a href="https://www.itpro.com/software/development/367842/the-four-major-software-development-lifecycle-models-and-how-they-work">development lifecycle</a>.</p><p>This planned investment in CNAPP forms part of a wider appetite for <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a> investment this year, Westcon-Comstor said, with large organizations looking to channel partners to help them maximize return on investment.</p><h2 id="it-channel-engagement-priorities">IT channel engagement priorities</h2><p>In terms of priorities, the data revealed the top three planned areas for investment as being AI security posture management (AI-SPM), cloud security posture management (CSPM), and application security posture management (ASPM).</p><p>In the UK specifically, security leaders also highlighted their intent to invest in software composition analysis, with 45% of survey participants singling the category out as a priority.</p><p>As organizations look to the channel for growth opportunities, the study found the majority of surveyed businesses are currently engaged with their channel partners (95%) when procuring and deploying security solutions.</p><p>Security leaders named training and enablement as the most valued benefit from channel partners, with 51% of UK participants stating it as their main requirement compared to the international average of 40%.</p><p>Elsewhere, 29% said cost-effective access to new solutions was their primary reason for engaging with partners, while 20% highlighted the ability to assist with navigating the cloud security market and identifying the best solutions.</p><h2 id="cnapp-adoption">CNAPP adoption</h2><p>Notably, the survey highlighted the main reasons organizations are looking to CNAPP specifically, with leaders highlighting the need to move away from using multiple <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> tools and instead consolidate capabilities into a unified platform. </p><p>By doing so, they benefit from reduced complexity and fewer blind spots, Westcon-Comstor said.</p><p>Other key factors include the need to seamlessly integrate security and compliance testing, as well as unification of risk visibility across cloud environments and the application development lifecycle.</p><p>As operational responsibilities continue to ‘shift left’ towards developers and architects, 81% of UK-based security leaders stated a need to adopt a <a href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important">DevSecOps</a> approach, outpacing all other markets, as well as the international average of 75%.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nMPk3hYgRaNUm4dqd8ZtSQ" name="Discover how these data centers from Germany and Australia became more resilient to disruption, while also lowering operating costs and CO2 emission" caption="" alt="Discover how these data centers from Germany and Australia became more resilient to disruption, while also lowering operating costs and CO2 emission." src="https://cdn.mos.cms.futurecdn.net/nMPk3hYgRaNUm4dqd8ZtSQ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ABB)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/discover-how-these-data-centers-from-germany-and-australia-became-more-resilient-to-disruption-while-also-lowering-operating-costs-and-co2-emission"><em>Data centers fortified with robust maintenance</em></a></p></div></div><p>“As the cloud security market continues to evolve, we’re seeing CNAPP become the go-to solution for securing cloud workloads,” commented Daniel Hurel, senior vice president of Westcon EMEA Cybersecurity & Next-Generation Solutions at Westcon-Comstor.</p><p>“Our research suggests that this presents an opportunity for the IT channel, with particularly strong demand for training and enablement. Partners who establish themselves in this high-growth area stand to reap the rewards in 2025 and beyond.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Darktrace targets cloud security gains with new acquisition ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/darktrace-targets-cloud-security-gains-with-cado-security-acquisition</link>
                                                                            <description>
                            <![CDATA[ The firm plans to combine Cado's forensic investigation technology with its ActiveAI Security Platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">y6ijkE7HQL43sjTJhmy2wR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oJWAYB4FW2CNHZ4FjsnKCA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jan 2025 11:48:21 +0000</pubDate>                                                                                                                                <updated>Fri, 10 Jan 2025 13:49:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oJWAYB4FW2CNHZ4FjsnKCA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Darktrace logo pictured in the background of a silhouetted woman holding a mobile phone.]]></media:description>                                                            <media:text><![CDATA[Darktrace logo pictured in the background of a silhouetted woman holding a mobile phone.]]></media:text>
                                <media:title type="plain"><![CDATA[Darktrace logo pictured in the background of a silhouetted woman holding a mobile phone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oJWAYB4FW2CNHZ4FjsnKCA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity</a> firm Darktrace has announced plans to acquire Cado Security, a UK-based cyber investigation and response solution provider. </p><p>Cado Security offers its services across multi-cloud, container, serverless, <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS</a>, and on-premises environments, capturing a snapshot of data stored on the device and then conducting forensic investigations to uncover signs of compromise or threats. </p><p>Darktrace says it plans to invest to accelerate the growth of Cado's existing products, while also combining Cado's forensic investigation technology with its own ActiveAI Security Platform, enhancing data collection across multiple cloud environments. </p><p>Thanks to the richer datasets the agreement will bring, Darktrace also sees benefits for its Cyber AI Analyst solution, which investigates alerts, streamlines investigations, and prioritizes incidents.</p><p>"At Darktrace, we have a clear and ambitious strategy: to develop best-in-class cybersecurity solutions for our customers that keep them safe through continuous innovation," said Jill Popelka, Darktrace chief executive officer. </p><p>"The addition of Cado's deep expertise in cloud-based data collection and forensics will enhance our ability to protect customers, ensuring they can operate securely and confidently across all areas of their business."</p><p>The deal is expected to be completed next month.</p><p>Cado was founded by James Campbell, CEO, and Chris Doman, CTO, who will join the team at Darktrace following the acquisition. </p><p>Cado's R&D teams in London and Bristol will work alongside Darktrace's established R&D centers in Cambridge, UK and The Hague, Netherlands to boost innovation in its cloud detection and response capabilities.</p><p>"Darktrace is an excellent fit for Cado, providing an opportunity for growth and innovation while allowing our team to advance their careers within a dynamic company deeply committed to R&D and to protecting its customers from growing cyber threats," said Campbell. </p><p>"Our technologies build on each other's strengths, and we are incredibly excited to work with the Darktrace team to continue to elevate AI-driven <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>capabilities for our combined global customer base."</p><h2 id="darktrace-ramps-up-cloud-security-focus">Darktrace ramps up cloud security focus</h2><p>Darktrace cites cloud and SaaS platforms as a common entry point for cybercriminals to attempt access to customers' networks. </p><p>The firm specifically pointed to recent research in which security leaders identified <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a> as the top area where defensive AI could have the greatest impact.</p><p>The acquisition comes as the cybersecurity giant looks to boost its cloud security capabilities, with the firm having invested heavily in this domain in recent years. </p><p>In October 2023, the company launched its Darktrace / CLOUD services for AWS, which it later expanded to cover <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws">Microsoft Azure</a>. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4MhoWjjKFydxNVbpwaQFTA" name="Dell PowerEdge Servers: Bringing AI to Your Data" caption="" alt="Dell PowerEdge Servers: Bringing AI to Your Data" src="https://cdn.mos.cms.futurecdn.net/4MhoWjjKFydxNVbpwaQFTA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/dell-poweredge-servers-bringing-ai-to-your-data"><em>Safely process vast amounts of data</em></a></p></div></div><p>Darktrace was founded in 2013 by Poppy Gustafsson, with the backing of the late billionaire Mike Lynch’s Invoke Capital. </p><p><a href="https://www.itpro.com/business/leadership/poppy-gustafsson-steps-down-as-darktrace-ceo">Gustafsson was replaced as CEO by former COO Jill Popelka</a> in September last year.</p><p>The announcement follows <a href="https://www.itpro.com/business/acquisition/darktrace-acquisition-dents-uk-prestige">Darktrace's acquisition by software investment firm Thoma Bravo</a> in a $5.3 billion deal that closed in October last year. </p><p>The companies said the plan was to scale the firm up to become 'a truly global player'.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is security service edge (SSE)? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/what-is-security-service-edge-sse</link>
                                                                            <description>
                            <![CDATA[ A brief guide to SSE, the security-focused framework at the heart of every SASE deployment ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7sNxjqQKfG46seJ5akC9HT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6qy4fVN2L7SChhcfmsN5sK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 22 Dec 2024 17:30:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ john@jloeppky.com (John Loeppky) ]]></author>                    <dc:creator><![CDATA[ John Loeppky ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/GJCxqX7ryKSC5XjEDLnEtU.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6qy4fVN2L7SChhcfmsN5sK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cloud computing graphic ]]></media:description>                                                            <media:text><![CDATA[A cloud computing graphic ]]></media:text>
                                <media:title type="plain"><![CDATA[A cloud computing graphic ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6qy4fVN2L7SChhcfmsN5sK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The tech world, you might argue, has too many TLA’s – What does that stand for? Three letter abbreviations. They consistently proliferate and, when you’re in the know, can be exceedingly helpful. They also do a wonderful job of confusing transcription software and new employees, alike.</p><p>One acronym currently used in cyber security is SSE, which stands for security service edge. To double down on the acronyms, SSE is a component of SASE, or secure access service edge. Edge means that these forms of architecture are operating in the cloud versus a more traditional data centre-centric approach.</p><p>Clear as mud? No problem, we’ve got you covered. Plus, if you’d like our <a href="https://www.itpro.com/cloud/cloud-security/what-is-secure-access-service-edge-sase">explainer on SASE</a> by itself, you can find it here. After all, you can never know enough acronyms, if only to make your business meetings easier.</p><h2 id="what-is-sse-in-the-context-of-sase">What is SSE in the context of SASE?</h2><p>Imagine you have a box labeled 'SASE'. Inside are a bunch of services, including network optimization tools, software optimization, and routing options. Beside these is a smaller box labeled SSE, containing tools that purely focus on security via the cloud. As a result, SASE is interested in security and networking, while SSE is focused on just the security portion of those duties. If you’re a business who needs to integrate networking and security under one proverbial roof, then SASE may be a better fit. However, some situations might mean you’re only looking for the SSE tools.</p><p>SASE came first, described by Gartner in 2019. SSE arrived later, first appearing in a 2021 report.</p><h2 id="what-does-sse-contain">What does SSE contain?</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3DzBisxyQXbBchvGQ3pWPL" name="observability_GettyImages-1399729683" alt="IT observability concept image showing cloud network symbol and virtual data points." src="https://cdn.mos.cms.futurecdn.net/3DzBisxyQXbBchvGQ3pWPL.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>In general, SSE includes tools such as <a href="https://www.itpro.com/security/what-is-zero-trust-network-access-ztna">zero trust network access (ZTNA)</a>, cloud access security broker (CASB), secure web gateway (SWG), firewall as a service (FWaas), remote browser isolation (RBI), and data loss protection (DLP). </p><p>SSE is solely designed to protect your company’s data and network and is not focused on network optimization. The consensus is that as cyber security develops, having a framework like SSE allows you to reduce the number of weak points in your company’s IT security because they are being used in a way that ensures they play off of each other, rather than against each other.</p><p>In comparison, the networking portion of SASE includes <a href="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan">software defined wide-area networks (SD-WAN)</a> alongside other components like network as a service and <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">software as a service</a> acceleration. The idea, in general, is that the two portions work in synchronization to provide an improved, two for one, approach. </p><p>Another goal of SSE is to provide a more secure, and easier to operate option compared to fragmented solutions that don’t take advantage of technological innovation in the cyber security space. Or, <a href="https://www.gartner.com/reviews/market/security-service-edge" target="_blank">in Gartner’s own words</a>:</p><p>"Security service edge provides a primarily cloud-delivered solution to control access from end users and edge devices to applications (private or delivered via SaaS) as well as websites (and to a lesser extent general internet traffic). It enables a hybrid workforce more efficiently than traditional on-premises solutions. Capabilities integrated across multiple traffic types and destinations allow a more seamless experience for both users and admins while maintaining a consistent security stance."</p><p>This consolidation of services is also intended to reduce costs and increase usability. Gartner <a href="https://www.sdxcentral.com/articles/analysis/gartner-crowns-netskope-palo-alto-networks-zscaler-as-sse-leaders/2024/04/" target="_blank">has published the companies</a> they believe provide the best SSE options. Those include Netskope, Palo Alto Networks, and Zscaler.</p><h2 id="benefits-of-sse">Benefits of SSE</h2><p>As an approach to sustaining the health of your network, SSE’s main selling point is that all of the services intertwined with it provide a broader spectrum solution than choosing individual tools piece by piece. </p><p>Proponents of this approach also point to benefits when it comes to user experience — namely decreases in latency and the ability to do away with clunky VPN options. In the current workplace environment — where employees are more likely to be working remotely and/or using their personal devices — SSE allows for an easier process when it comes to scaling and implementing your network security.</p><h2 id="the-downsides-of-sse">The downsides of SSE</h2><p>As SSE is a framework, it is a broad concept that is not always easy to integrate into your company’s workflows. Some tools that you use on a daily basis might not want to play nice with this new approach. You may struggle to implement it as you muddle through already existing security policies, and your IT staffers may be less familiar with SSE — given its relatively recent emergence on the cyber security landscape. This is similar to many IT innovations, cyber security-related and otherwise.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is secure access service edge (SASE)? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/what-is-secure-access-service-edge-sase</link>
                                                                            <description>
                            <![CDATA[ A guide to SASE, a cloud technology approach that combines aspects of networking and cyber security into one platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pyyEqNAVR2dh4wN4g8Eh2f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2AstwKwLA445ALahe3QyLN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 22 Dec 2024 17:30:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ john@jloeppky.com (John Loeppky) ]]></author>                    <dc:creator><![CDATA[ John Loeppky ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/GJCxqX7ryKSC5XjEDLnEtU.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2AstwKwLA445ALahe3QyLN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[API and cloud security concept image showing cloud symbol with a padlock.]]></media:description>                                                            <media:text><![CDATA[API and cloud security concept image showing cloud symbol with a padlock.]]></media:text>
                                <media:title type="plain"><![CDATA[API and cloud security concept image showing cloud symbol with a padlock.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2AstwKwLA445ALahe3QyLN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Network architecture, and its protection, is a world that is ripe for – and rife with – comparisons to architects who exist outside of a data center. After all, doesn’t the castle and moat approach to network security remind you of medieval literature as much as your own IT department? For every 15th-century comparison to 21st-century technology, there is a new innovation waiting to take up its metaphorical mantle. In this case, secure access service edge (SASE).</p><p>The term was first used by two Gartner analysts in 2019. While those same analysts were quickly criticized for describing a combination of services that already exist, the term has grown in traction as vendors and companies seek to find different ways to describe their products as they adapt to the current cyber security landscape.</p><h2 id="what-is-sase">What is SASE?</h2><p>Taking advantage of the network edge, working outside of the data center, SASE combines a number of already existing products and services to provide an all-in-one solution for network security. SASE is usually sold in the same manner as software as a service (SaaS) products.</p><p>Some of the individual components of a SASE offering include:</p><ul><li><a href="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan">Software-defined wide area network (SD-WAN)</a>: Instead of a traditional network model, which relies on routers and the data center interacting, an SD-WAN routes your web traffic to vetted existing technology providers – such as <a href="https://www.itpro.com/uk/amazon-web-services">Amazon Web Services</a> or <a href="https://www.itpro.com/tag/microsoft-azure">Microsoft Azure</a>. While increasing security and decreasing cost, this also reduces <a href="https://www.itpro.com/network-internet/31750/what-is-latency">latency</a>. If we’re extending the Middle Ages metaphor, then the SD-WAN is the drawbridge that allows traffic to enter the city that is your network infrastructure.</li><li>Secure web gateway (SWG): An SWG product is the person at the gate asking for the secret passcode. It checks all traffic for nasty elements and requires the security policies that your company has implemented be followed. Its job is to keep your data safe.</li><li>Cloud access security broker (CASB): A CASB is a product that manages your security protocols such as <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign on</a>, user authentication, and token management. In our little medieval fantasy land, a CASB is a group of squires who are charged with making sure that the leadership of the community is properly up to speed on the castle’s defences.</li><li>Next generation firewall (NGFW) and <a href="https://www.itpro.com/cloud/cloud-security/what-is-firewall-as-a-service-fwaas">firewall as a service (FWaaS)</a>: These two products filter incoming traffic and stop any that have malicious intent. Rather than a simple yes or no, an NGFW uses tools like packet filtering and VPN identification to give a deeper and better level of defense. You can think of this like a battlement, a small segment of a castle’s walls that allows you to look out and identify incoming threats.</li><li><a href="https://www.itpro.com/security/what-is-zero-trust-network-access-ztna">Zero trust network access (ZTNA)</a>: Rather than a VPN, which gives the user access to a broad network environment, a zero trust network access system gives a user access to just one application. Tired of this medieval metaphor yet? Well, we can liken a ZTNA to the secret passageways that litter many castles, areas that allow servants to dip in and out of spaces without being seen.</li></ul><p>One of the key selling points of SASE is its ability, within a cloud-native environment, to combine a wide variety of cyber security offerings into a product that can be implemented quickly and easily.</p><h2 id="the-benefits-of-sase">The benefits of SASE</h2><p>Although SASE evangelists will offer up a wide variety of benefits, most boil down to four key elements: ease of use, expandability, reliability, and efficiency.</p><p>For one, instead of relying on a data center-focused approach, an SASE solution allows a company to lean on resources that are not as constrained and costly. In a world where time is money, an SASE solution that provides reduced latency when compared to other structures can decrease infrastructure cost significantly.</p><p>Second, in a remote work environment where creating additional users, workflows, and products, is an everyday business necessity, SASE bills itself as an inherently cheaper and faster solution to keep a business both running and evolving.</p><p>Lastly, most companies selling these products point to the fact that the structure of a SASE solution — where you’re covering vast swathes of network security within one ecosystem — allows you to easily monitor network traffic (and solve problems) rather than having to work through convoluted security solutions that are difficult to scale.</p><h2 id="the-downsides-of-sase">The downsides of SASE</h2><p>Given that SASE is a term first coined just five years ago, this technology is still experiencing the growing pains that come with any developing technology. One concern is that, medieval comparisons aside, the entire topic can be confusing and cause internal chaos as it is implemented.</p><p>Another concern is that SASE can be difficult to add to a legacy environment that hasn’t been specifically crafted for newer network security. As with any cyber security solution, the cost of SASE implementation may be <a href="https://www.itpro.com/business-strategy/smb/360589/how-to-fix-the-weak-link-in-cyber-security">prohibitive for small and medium-sized businesses</a> and it’s important that companies identify which parts of a SASE solution will be useful and which ones are not needed for any individual use case. </p><p>There is also concern among some industry experts that the nature of a SASE implementation – with network and security being combined – may not fit well with an individual company's current IT staffing choices.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISA issues new directive to bolster cloud security – and Microsoft was singled out ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/cisa-issues-new-directive-to-bolster-cloud-security-and-microsoft-was-singled-out</link>
                                                                            <description>
                            <![CDATA[ The directive is a strong push towards bolstering cloud and SaaS security practices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9ybhPigeDujWR8Uw4cfxBD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kkSxF7avnLVjrNeHRABpSa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Dec 2024 12:49:48 +0000</pubDate>                                                                                                                                <updated>Thu, 19 Dec 2024 16:59:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kkSxF7avnLVjrNeHRABpSa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud computing concept image showing a cloud symbol attached to separate containers.]]></media:description>                                                            <media:text><![CDATA[Cloud computing concept image showing a cloud symbol attached to separate containers.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud computing concept image showing a cloud symbol attached to separate containers.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kkSxF7avnLVjrNeHRABpSa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new directive issued by the US <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a> has been met positively by industry experts who say it will bolster <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a>. </p><p>Announced on 17 December, the <a href="https://www.cisa.gov/news-events/alerts/2024/12/17/cisa-issues-bod-25-01-implementing-secure-practices-cloud-services" target="_blank"><u>directive</u></a> will focus on safeguarding federal information and information systems. </p><p>It requires federal civilian agencies to identify specific cloud tenants, implement assessment tools, and ensure that cloud environments are aligned with CISA’s ‘Secure Cloud Business Application (SCuBA)’ baselines. </p><p>CISA will maintain and update a detailed list of in-scope policies and cloud tenants, provide agencies with reporting instructions, and provide agencies with troubleshooting support. </p><p>As of this release, CISA has published the configuration baselines for <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a> only, but the future may see CISA release additional baselines for other cloud products and services. </p><p>In recent <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> incidents, CISA said the improper configuration of security controls in cloud environments has introduced substantial risk and has resulted in compromises and unauthorized access. </p><p>This directive will push the federal civilian enterprise to a more defensible posture in this regard, by reducing the attack surface of government networks. </p><h2 id="cisa-directive-welcomed-by-industry">CISA directive welcomed by industry </h2><p>Tech and security experts see this as a strong move from CISA, one that will reduce agency vulnerability to attack and increase security posture in the government. </p><p>“CISA’s directive highlights known cloud risks. Misconfigured systems expose agencies to threats. Setting baselines and enforcing them reduces the attack surface. This step, though unsurprising, is critical,”  Jason Soroko, senior fellow at Sectigo, told <em>ITPro</em>. </p><p>AppOmni CSO Cory Michal echoed this sentiment, calling the directive a “much-needed step” towards improving the organizational security posture of federal agencies leveraging cloud and <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">Software as a Service (SaaS)</a> tools. </p><p>“By mandating the adoption of the SCuBA Secure Configuration Baselines, the directive provides a standardized approach to securing SaaS applications and guides agencies to focus on proactive risk mitigation,” Michal told <em>ITPro</em>. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VPnxRhS2HoSuB9KizVByxG" name="GettyImages-885300380-data-center-crop.jpg" caption="" alt="A server rack inside a data center. The entire shot is lit in stark, blue light." src="https://cdn.mos.cms.futurecdn.net/VPnxRhS2HoSuB9KizVByxG.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/dell-powerstore-data-efficiency"><em>Manage growing data volumes efficiently</em></a></p></div></div><p>While it aligns with broader cybersecurity initiatives such as zero trust architecture, Michal added, the success of the directive will depend on effective implementation and deployment of appropriate security tooling. </p><p>Michal noted the requirements are reasonable and that the directive focuses on measures that are practical and actionable, such as adopting secure baselines.</p><p>“These are foundational steps that align with modern SaaS and cloud security models following the Identify, Protect, Detect and Respond methodology, allowing organizations to embrace and secure this new attack surface,” he said. </p><p>“Deadlines, lack of funding, and lack of adequate skillsets will be the main challenges in meeting these requirements,” he added. </p><h2 id="private-sector-will-take-time-to-catch-up">Private sector will take time to catch up</h2><p>Though CISA’s new directive is a boon for security in the federal or public sector landscape, the average firm will lag behind the guidance, according to Soroko.</p><p>“For a typical mid-sized business, implementing similar controls is costly - tools, consultants, and training strain budgets. They have a hard enough time understanding the merits of MFA,” Soroko said.</p><p>“They typically only have IT generalists who are motivated to keep the lights on rather than go through configurations with a fine toothed comb,” he added. </p><p>While government guidance often influences private sectors, he said, adoption lags, as many firms resist due to cost and complexity. </p><p>“Clear government standards can slowly shift industry norms, but it normally only works if it forces vendors who are selling into government contracts,” Soroko said. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Machine identity attacks will be top of mind for security leaders in 2025 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/machine-identity-attacks-will-be-top-of-mind-for-security-leaders-in-2025</link>
                                                                            <description>
                            <![CDATA[ Security leaders say access tokens and service accounts represent an increasing risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N5dDR5x5S6KXJmMBbGGixM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/44czLjHXb9wstRuFkRhVxK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Dec 2024 09:57:28 +0000</pubDate>                                                                                                                                <updated>Thu, 19 Dec 2024 16:54:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/44czLjHXb9wstRuFkRhVxK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital fingerprint with blue data streaming upwards from it]]></media:description>                                                            <media:text><![CDATA[A digital fingerprint with blue data streaming upwards from it]]></media:text>
                                <media:title type="plain"><![CDATA[A digital fingerprint with blue data streaming upwards from it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/44czLjHXb9wstRuFkRhVxK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Machine identities such as access tokens and service accounts are being tipped as the next big target for cyber attacks.</p><p>According to Venafi's latest research report, <a href="https://venafi.com/lp/cloud-native-security-report-2024/?utm_medium=prs&utm_source=mda&utm_campaign=24Q4_WW_ONL_WP_CloudNative_Dec10&utm_content=pr"><u><em>The Impact of Machine Identities on the State of Cloud Native Security in 2024</em></u></a>, 86% of organizations have had a security incident related to their cloud native environment within the last year. </p><p>As a result, more than half have had to delay an application launch or slow down production time, while 45% suffered outages or disruption to their application service. Three-in-ten said the incident meant that attackers could gain unauthorized access to data, networks, and systems.</p><p>Similarly, nearly nine-in-ten security leaders said they believe that machine identities – specifically access tokens and their connected service accounts – are the next big target for attackers. </p><p>More than half said they'd experienced a security incident related to machine identities using service accounts in the last year. </p><p>"A massive wave of cyberattacks has now hit cloud native infrastructure, impacting most modern application environments," said Kevin Bocek, chief innovation officer at Venafi.</p><p>"To make matters worse, cybercriminals are deploying AI in various ways to gain unauthorized access and exploiting machine identities using service accounts on a growing scale. The volume, variety and velocity of machine identities are becoming an attacker’s dream."</p><p>While access tokens used with service accounts topped the risk list with 56% of respondents, almost as many experienced incidents related to other machine identities, such as certificates.</p><p>Venafi attributed this to the growing complexity of cloud native environments, which makes it harder to manage and secure the machine identities that underpin access and authentication. </p><p>Three-quarters of security leaders agreed that humans are the weakest link in machine identity security, while 83% of teams say that failing to secure machine identities at the workload level renders all other security obsolete. =</p><p>Nearly seven-in-ten described delivering secure access between their cloud native and data center environments as a 'nightmare to manage', while 89% said they're experiencing challenges around managing and securing secrets at scale.</p><p>Notably, 83% said having multiple service accounts creates a lot of added complexity. Despite this, nine-in-ten agreed they make it easier to ensure policies are uniformly defined and enforced across <a href="https://www.itpro.com/cloud/cloud-computing/what-is-cloud-native-and-how-can-it-generate-business-value">cloud native</a> environments.</p><p>"Attackers are increasingly zoning in on machine identities in cloud native technologies," said Bocek. "Security teams must prioritize <a href="https://www.itpro.com/cloud/cloud-security/venafis-new-life-under-cyberark-is-all-about-end-to-end-identity-management">machine identity</a> security to the same degree as human identities."</p><h2 id="ai-poisoning-a-key-concern">AI poisoning a key concern</h2><p>Elsewhere in Venafi’s report, more than three-quarters of respondents highlighted AI poisoning as a leading new software supply chain risk. </p><p><a href="https://www.itpro.com/security/hackers-are-deliberately-poisoning-ai-systems-to-make-them-malfunction-and-theres-no-way-to-defend-against-it">AI poisoning</a> refers to techniques whereby AI data inputs and outputs are manipulated for malicious purposes. </p><p>"There is huge potential for <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>to transform our world positively, but it needs to be protected," said Bocek.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="69vPgVDk9D2V2RrxrY7DjV" name="The Business Value of Dell PowerFlex_listing.jpg" caption="" alt="A whitepaper from Dell and Intel on the business value of Dell Powerflex, with image of data  in a funnel shape" src="https://cdn.mos.cms.futurecdn.net/69vPgVDk9D2V2RrxrY7DjV.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell | Intel)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-storage/the-business-value-of-dell-powerstore"><em>Dell PowerStore could improve your business performance</em></a></p></div></div><p>"Whether it’s an attacker sneaking in and corrupting or even stealing a model, a cybercriminal impersonating an AI to gain unauthorized access, or some new form of attack we have not even thought of, security teams need to be on the front foot. </p><p>"This is why a kill switch for AI – based on the unique identity of individual models being trained, deployed and run – is more critical than ever."</p><p>Three-quarters are also worried about model theft and 73% concerned about the use of AI-led <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a>, while 72% are worried about provenance in the AI supply chain.</p><p>Despite this, six-in-ten said senior management has taken its focus off supply chain security in the last year.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WithSecure Elements Cloud Platform review: A great endpoint security all-rounder ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/withsecure-elements-cloud-platform-review-a-great-endpoint-security-all-rounder</link>
                                                                            <description>
                            <![CDATA[ Tough endpoint protection and a wealth of cloud security options priced right for mid-sized businesses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5hEqPZaxdGn7szBjfPwE5e</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/P2AU42Arw2v3trytr9n3yh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 27 Nov 2024 15:00:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/5BukGWzBsbwY54VJpZvHoi.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/P2AU42Arw2v3trytr9n3yh-1280-80.jpg">
                                                            <media:credit><![CDATA[WithSecure]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The WithSecure logo on the ITPro background]]></media:description>                                                            <media:text><![CDATA[The WithSecure logo on the ITPro background]]></media:text>
                                <media:title type="plain"><![CDATA[The WithSecure logo on the ITPro background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/P2AU42Arw2v3trytr9n3yh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Finnish company <a href="https://www.itpro.com/security/withsecure-elements-epp-and-edr-review-endpoint-protection-on-a-plate">WithSecure</a> has traditionally offered an impressive endpoint security portfolio and a key feature is all components can be centrally managed from its Elements Security Center cloud portal. The suite is also completely modular so you can pick and choose which components you require.</p><p>It includes EPP (endpoint protection) and EDR (endpoint detection and response) modules which have now been unified into the Elements Endpoint Security (EPS) solution and offered under the XDR (extended detection and response) category. Elements Collaboration Protection (ECP) enhances security for <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a> environments including Exchange, SharePoint, <a href="https://www.itpro.com/cloud/cloud-storage/363918/onedrive-review">OneDrive</a>, and Teams while Elements Exposure Management (EEM) keeps your network borders safe by providing an overview of your attack surface along with threat identification and mitigation.</p><p>There's more as Elements Identity Security protects against compromised Microsoft Entra identities. Overworked security teams may also want to consider the optional co-monitoring service where severe threats are automatically escalated to WithSecure's support teams and you can choose out-of-hours or full 24/7 cover.</p><p>That's a lot to get to grips with but WithSecure's new Luminen feature can help cut through the smokescreen. It delivers AI-powered reporting services which generate detailed summaries of security events and provide valuable assistance on remedial actions.</p><h2 id="withsecure-elements-cloud-platform-review-setup">WithSecure Elements Cloud Platform review: Setup</h2><p>Platform support is excellent as WithSecure can protect Windows and macOS workstations, Windows and Linux servers plus Android and iOS mobiles. The base product also includes patch management for Windows OSes.</p><p>Deployment is swift as we could download the relevant agent install file and place it in a central location or email links to our users directly from the portal. After installing the agent on our Windows 10/11 workstations and Windows Server 2022 hosts, it took no more than two minutes to complete the process and connect to our cloud account. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1693px;"><p class="vanilla-image-block" style="padding-top:56.23%;"><img id="R7yTowrRhxPv3hKUTcLEfa" name="Withsecure_Elements_dashboard" alt="A screenshot of the WithSecure Elements dashboard" src="https://cdn.mos.cms.futurecdn.net/R7yTowrRhxPv3hKUTcLEfa.jpg" mos="" align="middle" fullscreen="" width="1693" height="952" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>We also tested ECP and found the MS 365 authentication process straightforward with our Exchange, SharePoint, OneDrive, and <a href="https://www.itpro.com/software/33703/microsoft-teams-review-a-no-brainer-for-microsoft-shops">Teams</a> accounts added in a few minutes. The Elements cloud portal is well-designed with its home page providing a complete overview of your security posture. </p><p>Donut charts show all protected computers, servers, and mobile devices with color codes showing their overall status, another keeps you appraised on software updates while the detection and response charts show all open detections and their risk score. We received more charts below showing our MS 365 components, all detections, the top affected mailboxes, and a breakdown of security events. </p><h2 id="withsecure-elements-cloud-platform-review-security-profiles">WithSecure Elements Cloud Platform review: Security profiles</h2><p>Endpoint protection starts immediately as preconfigured security profiles are assigned to devices as soon as their agent has connected to the cloud portal. It's easy to create new ones as we used the Security Configurations page to clone the predefined ones and tweak them to our requirements.</p><p>There's a lot to play with as profiles manage real-time malware scanning, permit users to run manual scans, determine when automatic updates occur, and schedule regular systems scans. <a href="https://www.itpro.com/cloud/cloud-security/what-is-firewall-as-a-service-fwaas">Firewall</a> protection using WithSecure or Windows profiles can be enabled and device controls applied to block access to removable devices such as USB sticks. </p><p>Web protection services include reputation-based web page scanning, safe search enforcement, browser plug-ins, and content controls with a list of 32 URL categories you can block or allow. The Premium service enables application controls and WithSecure's DataGuard which uses behavioral rules to detect potential ransomware activity.</p><p>Businesses worried about the shocking impact of the CrowdStrike fiasco can rest easy as WithSecure has them covered. A feature that's always been available in its security profiles is an option to enable early access to client software updates.</p><p>It's simple to apply as we cloned our workstation and server profiles and enabled early access on them with one click. All the systems with these profiles assigned receive client updates and new features at least a week in advance of general release so we could check for stability and provide feedback to WithSecure if necessary.</p><h2 id="withsecure-elements-cloud-platform-review-detection-and-response">WithSecure Elements Cloud Platform review: Detection and response</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1693px;"><p class="vanilla-image-block" style="padding-top:56.23%;"><img id="c8Ft3ob7zTmcEeQBhnNExf" name="Withsecure_Elements_detections" alt="A screenshot of the WithSecure Elements detection interface" src="https://cdn.mos.cms.futurecdn.net/c8Ft3ob7zTmcEeQBhnNExf.jpg" mos="" align="middle" fullscreen="" width="1693" height="952" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>The portal's detection and response page provides a good overview of all security events and you can dive deeper by moving to the security events page which provides a more detailed analysis of each event and the affected systems or services. WithSecure's BCD (broad context detections) page displays a filtered view of detected threats with a full analysis and process tree of suspicious events showing how the potential malware developed and what it interacted with. </p><p>BCD shows affected systems with options to isolate them all with one click, run a device scan, and collect a forensics package. Links are provided for the Mitre ATT&CK website for more information and Luminen comes into play as it analyses events, generates a summary, and provides valuable advice on remedial actions – if more help is required, you can elevate the event to WithSecure's security teams. </p><p>Reactions to events are swift as when we ran our test app on selected workstations to generate suspicious activity, the portal logged them in seconds and email alerts were received 2-3 minutes later. To test MS 365 responses, we sent emails from Outlook with dubious attachments and suspect web links and WithSecure blocked them immediately, placed warning emails in our inboxes, and logged all events.</p><p>Rollback is a smart feature as it provides instant ransomware protection for Windows systems and can initially run in safe mode in a policy where it only reports on unauthorized changes. It tracks apps classed as unknown and if they exhibit any dubious behavior, it closes them down and automatically rolls back all the file and registry changes they made. </p><h2 id="withsecure-elements-cloud-platform-review-is-it-worth-it">WithSecure Elements Cloud Platform review: Is it worth it?</h2><p>WithSecure works primarily with partners so doesn't publish pricing on its web site. However, it advised us that the base Elements Endpoint Security costs around £37 per device/year for between 100 and 499 devices which looks good value considering how many security features this includes.</p><p>The Elements Cloud Platform delivers a remarkable range of protection measures and WithSecure has made them all very accessible in its well-designed cloud portal. Deployment is pleasingly simple, Luminen provides valuable remediation assistance and the suite's modular design means you only pay for what you need.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Organizations warned of the dangers of ‘long-lived’ cloud credentials ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/organizations-warned-of-the-dangers-of-long-lived-cloud-credentials</link>
                                                                            <description>
                            <![CDATA[ With compromised credentials behind the majority of cloud security incidents, companies need to secure identities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">A2DcX65UMVSzMzRvizoBse</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pY6qWM5GrgFHhDGkDVyDkm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Oct 2024 10:59:25 +0000</pubDate>                                                                                                                                <updated>Tue, 22 Oct 2024 14:47:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pY6qWM5GrgFHhDGkDVyDkm-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud security concept image showing a cloud symbol placed on top of a circuit board.]]></media:description>                                                            <media:text><![CDATA[Cloud security concept image showing a cloud symbol placed on top of a circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud security concept image showing a cloud symbol placed on top of a circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pY6qWM5GrgFHhDGkDVyDkm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>‘Long-lived’ cloud credentials are still a major risk for organizations across all cloud providers, according to new research from Datadog, and nearly half or organizations are using them.</p><p>These cloud credentials never expire and are a major security risk, often leaked in source code, container images, build logs and application artifacts - indeed, they're the most common cause of publicly documented cloud security breaches.</p><p>They're widespread across all major clouds, often old and sometimes even unused, with 62% of <a href="https://www.itpro.com/cloud/cloud-computing/google-cloud-platform-review-a-solid-but-expensive-service-for-cloud-infrastructure">Google Cloud</a> service accounts, 60% of AWS IAM users, and 46% of Microsoft Entra ID applications having an access key more than a year old. </p><p>"The findings from the State of Cloud Security 2024 suggest it is unrealistic to expect that long-lived credentials can be securely managed," said Andrew Krug, head of security advocacy at Datadog. </p><p>"In addition to long-lived credentials being a major risk, the report found that most cloud security incidents are caused by compromised credentials." </p><p>The good news is that more organizations are now using cloud guardrails as cloud providers start to enable them by default. Nearly eight-in-ten S3 buckets are covered by an account-wide or bucket-specific S3 Public Access Block, up from 73% a year ago.</p><p>However, more than 18% of <a href="https://www.itpro.com/cloud/370070/what-is-aws-ec2">AWS EC2</a> instances and a third of <a href="https://www.itpro.com/cloud/cloud-computing/google-cloud-doubles-down-on-ai-hypercomputer-amid-sweeping-compute-upgrades">Google Cloud VMs</a> have sensitive permissions to a project, putting organizations at risk by allowing any attacker compromising the workload to steal associated credentials and access the cloud environment.</p><p>Similarly, one-in-ten third-party integrations have risky cloud permissions, the study found, allowing the vendor to access all data in the account or to take over the whole AWS account. </p><p>Meanwhile, 2% of third-party integration roles don't enforce the use of External IDs, allowing an attacker to compromise them through a "confused deputy" attack.</p><p>"To protect themselves, companies need to secure identities with modern authentication mechanisms, leverage short-lived credentials and actively monitor changes to <a href="https://www.itpro.com/tag/application-programming-interface">APIs</a> that attackers commonly use," advised Krug.</p><p>In the wake of the study, Datadog said organizations should make use of mechanisms that provide time-bound, temporary credentials. For workloads, this can be managed with IAM roles for EC2 instances or EKS Pod Identity in AWS, Managed Identities in Azure, and service accounts attached to workloads for Google Cloud. </p><p>For humans, the most effective solution is to centralize identity management using a solution like AWS IAM Identity Center, Okta, or Microsoft Entra ID, and to avoid the use of individual cloud users for each employee, which can be highly inefficient and risky.</p><h2 id="concerns-over-risky-cloud-credentials-continue">Concerns over risky cloud credentials continue</h2><p><a href="https://www.itpro.com/cloud/cloud-security/the-biggest-cloud-security-risk-in-2024-will-be-stolen-and-exposed-credentials">Stolen and exposed cloud credentials</a> were identified earlier this year as 2024's biggest <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a> risk.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kgcj7SQ2Ko7TnJ9Tomb23P" name="7 Ways to Get More from Contractors (While Paying Less).jpg" caption="" alt="7 Ways to Get More from Contractors (While Paying Less)" src="https://cdn.mos.cms.futurecdn.net/kgcj7SQ2Ko7TnJ9Tomb23P.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Insightful)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/seven-ways-to-get-more-from-contractors-while-paying-less"><em>How to get the most from your external workforce</em></a></p></div></div><p>Managed detection and response company Expel said that identity threats accounted for nearly two-thirds of all incidents investigated by its security operations center, and that <a href="https://www.itpro.com/cloud/32378/cloud-infrastructure-spending-exceeds-on-premise-for-the-first-time">cloud infrastructure</a> incidents were up by 72% across the last year. </p><p>Notably, stolen or leaked credentials responsible for two-in-five incidents, highlighting the scale of the issue.</p><p>More than nine-in-ten of the incidents it detected or responded to occurred in AWS, with just 4%  split evenly between GCP and <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws">Azure</a>. This was despite the fact that around half the company's cloud customers use AWS, around a third use Azure, and roughly 17% use GCP.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ “We're all focused on a common enemy”: AWS CISO Chris Betz wants greater industry collaboration for the multi-cloud era ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/were-all-focused-on-a-common-enemy-aws-ciso-chris-betz-wants-greater-industry-collaboration-for-the-multi-cloud-era</link>
                                                                            <description>
                            <![CDATA[ Chris Betz spoke to ITPro about the importance of collaboration and the firm’s focus on bringing security data together ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3QGrt4pTkZPbbkL9QWJMXi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Nv62XgztGxWyKxGXeF5saF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Oct 2024 11:46:18 +0000</pubDate>                                                                                                                                <updated>Thu, 17 Oct 2024 09:10:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Nv62XgztGxWyKxGXeF5saF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AWS logo pictured at the AWS Summit Seoul 2024 at COEX Convention &amp; Exhibition Center on May 16, 2024, in Seoul, South Korea. ]]></media:description>                                                            <media:text><![CDATA[AWS logo pictured at the AWS Summit Seoul 2024 at COEX Convention &amp; Exhibition Center on May 16, 2024, in Seoul, South Korea. ]]></media:text>
                                <media:title type="plain"><![CDATA[AWS logo pictured at the AWS Summit Seoul 2024 at COEX Convention &amp; Exhibition Center on May 16, 2024, in Seoul, South Korea. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Nv62XgztGxWyKxGXeF5saF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Collaboration between cloud providers and the unification of cross-environment data will be critical to cybersecurity in the multi-cloud world, according to AWS CISO Chris Betz. </p><p>Responding to a question on how the hyperscaler approaches multi-cloud and hybrid cloud security, Betz told <em>ITPro </em>that he thinks about it in two key ways, the first being collaboration. </p><p>“One of the things that I love about the security community is how small a community it is,” Betz said.</p><p>Among fellow CISOs, there is a clear sense of being on the same side, he added. Security execs from different companies or providers are not adversaries, rather, their adversaries are threat actors. </p><p>“I frequently have conversations with my peers. I pick up the phone and talk to them on a regular basis. We share information about current threats,” Betz said. </p><p>“Because we're all focused on a common enemy, that collaboration is incredibly important,” he added. </p><p>This appears to feed into the firm’s ethos on multi-cloud. Betz noted that “the partnership between the clouds remains incredibly important because we recognize that customers operate in that space - we recognize that adversaries are outside.”</p><p>AWS has invested heavily in multi-cloud security capabilities in recent years. A key factor in this sharpened focus has been driven by the fact many customers are ramping up multi-cloud adoption as part of their cloud modernization strategies.   </p><p>AWS offers solutions that automatically go multi-cloud, Betz said, as well as environments that allow customers to bring data together from multiple clouds to bolster visibility and ensure consistent observation of environments.  </p><p><a href="https://press.aboutamazon.com/2023/5/aws-announces-general-availability-of-amazon-security-lake"><u>Released in 2023</u></a>, Amazon’s Security Lake centralizes organizational security from across AWS providers, SaaS providers, on-prem systems, and clouds into a data lake. This allows users to act more quickly and simply across hybrid and multi-cloud environments. </p><p>“We continue to build systems that allow for bringing the data together to have a consistent view of what happened,” Betz said. “And I think that's something that we're going to continue to see the industry do at large, and remain important for us and for our customers.</p><h2 id="the-multi-cloud-era">The multi-cloud era</h2><p>Betz’s comments come just weeks after <a href="https://www.itpro.com/cloud/cloud-computing/many-of-our-long-time-rivals-are-now-our-partners-why-oracle-is-doubling-down-on-multi-cloud"><u>AWS and Oracle announced a partnership</u></a> focused on supporting multi-cloud environments. The offering allows for the use of Oracle database services within AWS. </p><p><a href="https://www.itpro.com/business/business-strategy/oracle-is-entering-the-multi-cloud-era-and-partnership-is-its-rallying-cry"><u>Multi-cloud was the focus point at </u><u><em>Oracle CloudWorld 2024</em></u></a>, the event where this partnership was unveiled, and customers across the board are operating on increasingly larger cloud environments that bring together different vendors. </p><p>For example, <a href="https://corporate.ovhcloud.com/en-gb/newsroom/news/ovhcloud-uk-multicloud/"><u>research from OVHcloud</u></a> earlier this year found that 64% of IT decision-makers (ITDMs) in the UK see their use of multi-cloud increasing over the next two years. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sQhR4kmwC9LRg92mxQwdJB" name="A127056B-49A9-4752-A9E1-695DD1E43C9A_1_201_a.jpeg" caption="" alt="IBM Logo in light blue in front of black background with white binary letters behind" src="https://cdn.mos.cms.futurecdn.net/sQhR4kmwC9LRg92mxQwdJB.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/voice-of-the-customer-for-enterprise-conversational-ai-platforms"><em>The leading providers in enterprise supply chain innovation</em></a></p></div></div><p>But while multi-cloud is growing in appeal for enterprises globally, this approach can have its pitfalls, especially with regard to complexity. <a href="https://www.pwc.com/ca/en/services/consulting/cybersecurity-privacy/digital-trust-insights/secure-cloud-migration.html"><u>Research from PwC</u></a> earlier this year revealed IT leaders have grown concerned with the levels of complexity associated with multi-cloud security, for example. </p><p>“Many leaders of large organizations assume security is taken care of by cloud providers. Even if they recognize that’s not enough, many struggle to pinpoint where to invest resources to strengthen their cloud security. This is often because of the sheer complexity of their multi-cloud hybrid environments,” PwC said. </p><h3 class="article-body__section" id="section-more-from-cloudpro"><span>More from CloudPro</span></h3><ul><li><a href="https://www.itpro.com/business/business-strategy/oracle-is-entering-the-multi-cloud-era-and-partnership-is-its-rallying-cry">Partnerships are Oracle's key to success in the "multi-cloud era"</a></li><li><a href="https://www.itpro.com/hardware/storage/storage-architectures-must-change-to-meet-the-needs-of-ai-and-huawei-thinks-it-has-a-head-start-on-competitors">Storage architectures must change to meet the needs of AI</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/snowflake-ceo-many-vendors-sell-you-parts-of-a-car-and-tell-you-to-build-it-yourself-at-snowflake-we-have-a-different-philosophy-we-want-to-give-you-the-car">How Snowflake is helping customer navigate new and emerging challenges</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Are your cloud resources at risk?  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/are-your-cloud-resources-at-risk</link>
                                                                            <description>
                            <![CDATA[ Nearly 40% of organizations have high-risk workloads, and Tenable warns that they are prime attack targets for malicious actors ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5AdheqUVwUFzqmfn54qGB9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/svqQHJydYCRBsE5mYffKKU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Oct 2024 10:03:39 +0000</pubDate>                                                                                                                                <updated>Tue, 15 Oct 2024 14:05:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/svqQHJydYCRBsE5mYffKKU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A red digital cloud on a circuitboard ]]></media:description>                                                            <media:text><![CDATA[A red digital cloud on a circuitboard ]]></media:text>
                                <media:title type="plain"><![CDATA[A red digital cloud on a circuitboard ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/svqQHJydYCRBsE5mYffKKU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over a third (38%) of organizations are running at least one cloud workload that is highly at risk for multiple reasons, <a href="https://www.tenable.com/cyber-exposure/tenable-cloud-risk-report-2024"><u>a report from Tenable has found</u></a>. </p><p>A combination of high privileges, <a href="https://www.itpro.com/security/critical-flaws-left-700-000-draytek-routers-exposed-but-dont-worry-theres-a-fix">critical vulnerabilities</a>, and public exposure defines these high-risk workloads, with Tenable stating that they are prime attack targets for malicious actors. </p><p>Tenable created the report by analyzing telemetry data from billions of cloud assets across various clouds, between January and June 2024. </p><p>Breaking these issues down, the report found that over three-quarters (84.2%) of organizations possess unused or longstanding access keys with highly excessive permissions – which could lead to identity-based attacks.</p><p>The report's analysis of <a href="https://www.itpro.com/amazon-web-services">AWS</a>, <a href="https://www.itpro.com/cloud/cloud-computing/google-cloud-platform-review-a-solid-but-expensive-service-for-cloud-infrastructure">Google Cloud</a>, and <a href="https://www.itpro.com/tag/microsoft-azure">Microsoft Azure</a> revealed that 23% of cloud identities, both human and not, have severely excessive permissions. This figure rises to 35% in AWS alone. </p><p>Critical vulnerabilities also persist, the report said, with CVE-2024-21626 having remained remediated in over 80% of workloads 40 days after it was published. CVE-2024-21338 was also found to be prevalent.  </p><p>The report found that 74% of organizations have publicly exposed storage assets within their IT environments, including some storage assets that secure sensitive data. This issue is linked to excessive permissions.</p><p><a href="https://www.itpro.com/cloud/cloud-computing/kubernetes-v130-has-launched-heres-everything-you-need-to-know">Kubernetes</a> was identified in the resort as a concern for this sort of exposure; 78% of organizations have publicly accessible Kubernetes API servers, around 41% of which allow inbound internet access. What’s more, 58% of organizations also have cluster-admin role bindings, giving some users unrestricted access to entire Kubernetes environments, while 44% run containers in privileged mode.  </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6gdSR75d7nGLaTFomGBvpc" name="Put AI to work for talent management_listing.jpg" caption="" alt="Whitepaper from IBM on how AI can be used for talent management, with  grey grid image and people icons" src="https://cdn.mos.cms.futurecdn.net/6gdSR75d7nGLaTFomGBvpc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/put-ai-to-work-for-talent-management"><em>Apply AI to talent management workflows</em></a></p></div></div><p>The report offers a few suggestions for managing the risk created through these issues. Businesses should closely monitor access to Kubernetes for example, and ensure containers are only privileged when necessary.</p><p>Organizations should regularly rotate credentials and avoid using access keys that last for long periods. They should also prioritize remediating vulnerabilities and minimizing exposure by reviewing public assets. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shared fate vs shared responsibility: What’s the difference and how can your business benefit? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/shared-fate-vs-shared-responsibility-whats-the-difference-and-how-can-your-business-benefit</link>
                                                                            <description>
                            <![CDATA[ Knowing where your obligations end and your cloud provider's begin isn't always straightforward in the cloud – but it is essential for proper security and compliance ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2LD8xsDvq9KazHi3f8N4U9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6J7qLSiKJDwawdKHyL5x56-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Oct 2024 12:05:22 +0000</pubDate>                                                                                                                                <updated>Tue, 15 Oct 2024 11:05:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ George Fitzmaurice ]]></dc:contributor>
                                                                                                                                                                                    <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6J7qLSiKJDwawdKHyL5x56-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud security concept image showing a digitalized cloud symbol with a padlock sitting on a circuit board.]]></media:description>                                                            <media:text><![CDATA[Cloud security concept image showing a digitalized cloud symbol with a padlock sitting on a circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud security concept image showing a digitalized cloud symbol with a padlock sitting on a circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6J7qLSiKJDwawdKHyL5x56-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When a cybersecurity incident implicates both a vendor and a customer, it’s not always clear where responsibility lies. While customers lack oversight on a tool’s underlying security, the provider lacks oversight on how securely the tool is being used. </p><p>Under the ‘shared responsibility model', the division of roles seems fairly straightforward. <a href="https://www.crowdstrike.com/en-us/cybersecurity-101/cloud-security/shared-responsibility/#:~:text=In%20its%20simplest%20terms%2C%20the,itself%20and%20its%20underlying%20infrastructure." target="_blank">Crowdstrike’s definition</a>, for example, states that the cloud provider is responsible for monitoring threats to the cloud and its infrastructure, while customers are responsible for the protection of data and assets within the cloud environment.  </p><p>Speaking to <em>ITPro, </em>Nick Godfrey, director of the office of the CISO at Google Cloud, says the answer is a new approach to responsibility in the public cloud landscape, the shared fate model. </p><p>Godfrey outlines how the shared responsibility model was developed to deal with the new territory cloud represented. </p><p>“As we shifted into the cloud, we needed to be able to draw a line to say, ‘What’s the customer responsible for?’ For example, the cloud provider would, in that model, be responsible for the physical environment, the data centers, and some of the physical networking and computing that underpin the cloud,” he explains.</p><p>“Conversely, the customer would be responsible for the identity and access management of who in their organization has access to their applications on top of the cloud. The complexity comes because the point of delineation varies depending on what type of cloud you’re using.”</p><p>The cloud ecosystem comprises a number of different technologies and depending on what the businesses have implemented, the responsibility of the cloud provider could reach deeper into the organization.</p><p>For example, Godfrey notes, <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">software as a service (SaaS)</a> solutions such as an HR portal used by employees are virtually always limited to managing identity and access data within that portal. In contrast, <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/362605/what-is-iaas">infrastructure as a service (IaaS)</a> tools often burden the customer with far greater responsibility for securing that storage and maintaining the virtual network it runs on.</p><p>Godfrey argues new complications like these have exposed the limitations of the shared responsibility model, and that the framework assigning needs to evolve to reflect this growing complexity. Although helpful, the boundaries delineated under the shared responsibility model are too rigid, Godfrey claims, which can lead to security gaps.</p><h2 id="making-the-step-from-shared-responsibility-to-shared-fate">Making the step from shared responsibility to shared fate</h2><p>The distinction between shared fate and shared responsibility models centers around the extent to which the cloud provider works alongside the customer to understand how to configure and design their cloud. Godfrey tells <em>ITPro </em>that early definitions of shared responsibility saw documentation given to customers outlining best practices but that they were largely left to defend their cloud alone.</p><p>Shared fate, by contrast, is defined by an increased focus on working with the customer, alongside tailoring one’s cloud products so that they are easier for businesses to use out-of-the box.</p><p>Godfrey breaks down where he thinks shared fate can really help organizations into three core areas:</p><h3 class="article-body__section" id="section-collaboration-on-the-entire-environment"><span>Collaboration on the entire environment</span></h3><p>The first areas in which shared fate goes beyond shared responsibility in helping businesses hit the ground running with their cloud deployment. Shared fate can help businesses hit the ground running with their cloud deployment, as vendors develop partnerships with customers, says Godfrey.</p><p>At Google Cloud, Godfrey says he’s implemented a dedicated team of cloud professionals to work with their customers on the cloud transition. In any set of circumstances, it's vital for service providers to reach out to the cyber leaders within their customer organizations to update legacy attitudes to fit modern cloud security.</p><h3 class="article-body__section" id="section-giving-customers-resources"><span>Giving customers resources</span></h3><p>Another aspect of a shared fate model is providing customers with frameworks, best practices, and resources. </p><p>This includes guidance on how they should think about identity, and how to secure specific types of workload in their cloud environment, Godfrey adds.</p><h3 class="article-body__section" id="section-changing-default-behaviors"><span>Changing default behaviors</span></h3><p>Finally, Godfrey thinks cloud providers need to put in the work behind the scenes and change how they think about the default configurations of their products. </p><p>“If the fundamental job of a customer in securing the cloud is figuring out which configurations and architectures they need to have in order to be secure, then we can do a better job as an industry by making the default configurations for the products and services that they instantiate in their environment secure by default,” he says.</p><p>“This means ensuring that if there’s a security-critical feature or function, it should be on by default.”</p><p>Most of this work needs to be done before the customer even receives the product. This is another reason for cloud providers to work actively with each customer, to understand which default settings and configurations would be most useful for them based on their processes and workflows.</p><h2 id="debunking-the-myth-that-ciso-and-cto-are-naturally-opposed">Debunking the myth that CISO and CTO are naturally opposed</h2><p>Godfrey, a former CISO, thinks one aspect of a mature cloud strategy that goes overlooked is its ability to unify the aims of security executives and technology leaders, where there can often be friction. He adds that one of the megatrends Google Cloud has identified driving cloud adoption is its ability to transform security assurance in development pipelines . </p><p>“I think cloud is an interesting opportunity for totally debunking that myth, by having both those parties sit down and agree on a set of shared outcomes they’re looking for, a shared north star,” says Godfrey.</p><p>“Because if you think about it, every CIO would like agility, the ability to provide new technologies that will feed the business needs and so on, and in order to do that, they’re incentivized with cloud to build high-quality CI/CD pipelines, lots of automation, the ability to deploy very quickly, the ability to pull it back if it didn’t work. That’s exactly the environment the CTO wants,” Godfrey notes.</p><p>Through the right shared fate model and approach to the cloud, Godfrey adds, leaders can bake security into development pipelines from the outset.</p><p>“So we actually work quite closely with CIOs as well to say that, ‘you know, actually you want the same things’, and so I genuinely think you can massively enable innovation, agility, and improve security at the same time with the same approaches.”</p><h2 id="shared-responsibility-is-creating-confusion-in-cybersecurity">Shared responsibility is creating confusion in cybersecurity </h2><p>The shared responsibility model can be applied broadly across cybersecurity.  Difficulties are created, however, when a cybersecurity incident affects both parties. If the use of a product leads to a breach or attack, then the product vendor will likely have to in some way address the issue. </p><p>Speaking at a media briefing for Proofpoint Protect London 2024, Proofpoint’s EVP of cybersecurity strategy Ryan Kalember outlined some of the complexity shared responsibility can create. </p><p>“So when everybody moved to cloud the first time and SaaS services became a thing it was ‘we're responsible for the application layer and kind of the infrastructure underlying that,’... but there are all these things that you, as an end user of that, can configure, and you're responsible for those,” Kalember says.</p><p>Within reason, any security product be poorly configured, Kalmeber adds, noting that’s created difficulties for Proofpoint in how it balances security and customer decision making. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JwVDtVsCmBqihwrKh9AvL4" name="Combine the power of IBM Storage Defender and IBM Storage FlashSystem to fight ransomware.jpg" caption="" alt="Combine the power of IBM Storage Defender and IBM Storage FlashSystem to fight ransomware" src="https://cdn.mos.cms.futurecdn.net/JwVDtVsCmBqihwrKh9AvL4.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/combine-the-power-of-ibm-storage-defender-and-ibm-storage-flashsystem-to-fight-ransomware"><em>Protect your business from data loss risks</em></a></p></div></div><p>“This is a complicated problem for us because, in this shared responsibility model, we're not going to force our customers to change configurations around their trust of Microsoft,” Kalember explains, referring to <a href="https://www.itpro.com/security/a-flaw-in-proofpoints-anti-phishing-platform-allowed-a-hacker-to-send-millions-of-spam-emails"><u>a spam campaign involving Proofpoint and Microsoft in August</u></a>.</p><p>In the spam campaign, a user configuration of Proofpoint’s platform was abused to relay emails via Microsoft 365 tenants. </p><p>“We don't want this to happen, but we also can't totally overhaul our customer's configurations without consulting them and working with them,” Kalember said.  </p><p>“We have to nudge them progressively more aggressively over time to just say, ‘Hey, we would really love you to not be doing this, because this is being bounced off of you from Microsoft and going to other people,’” he added. </p><p>How responsibility is divided then becomes a tricky problem to solve, as vendors are forced to question what role they play in managing the implementation of their tool, rather than just the security of the tool itself.</p><p>“If you let people set up what is effectively a giant data lake of very sensitive information, in most cases, behind a password and nothing more, what is your responsibility for that?” Kalember asks. </p><p>“That's exactly the sort of question that we're trying to struggle with,” he added. “We can even put it in the contract that ‘We don't want you to do this,’ but we're not going to go to the admin with a cattle prod and say, ‘You can't do this’”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=57219564&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>There are still options. Kalember said Proofpoint was having an internal discussion on how aggressive it should be in telling users they’ve made an unwise decision with their product and has considered making certain configurations “very hard to do”. </p><p>The latter option could come into play for <a href="https://www.itpro.com/cloud/amazon-s3/367664/what-is-amazon-s3">Amazon S3</a> buckets, for example, which have <a href="https://www.itpro.com/security/29907/aws-adds-default-encryption-to-leaky-s3-buckets"><u>have been notoriously left open</u></a> to enable cyber attacks. Amazon now makes it very difficult for users to configure buckets in that way. </p><p>“We're trying to adopt more of those principles when it comes to ways that our own products can be configured in a risky way,” he adds. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Venafi’s new life under CyberArk is all about end-to-end identity management  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/venafis-new-life-under-cyberark-is-all-about-end-to-end-identity-management</link>
                                                                            <description>
                            <![CDATA[ The veteran machine identity management provider could be the missing piece of the puzzle for securing growing attack surfaces ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8KhToVVvaT3pGc6MDdfaXc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MAGnLonMp9NxMbwfcJaqNj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Oct 2024 12:16:52 +0000</pubDate>                                                                                                                                <updated>Tue, 08 Oct 2024 11:49:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MAGnLonMp9NxMbwfcJaqNj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI render of a cloud glowing cloud symbol on a high-tech display, surrounded by nodes which represent the cloud market. Decorative: The cloud is encompassed by a glowing orange circle, while the nodes are blue. All are against a dark, reflective background.]]></media:description>                                                            <media:text><![CDATA[A CGI render of a cloud glowing cloud symbol on a high-tech display, surrounded by nodes which represent the cloud market. Decorative: The cloud is encompassed by a glowing orange circle, while the nodes are blue. All are against a dark, reflective background.]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI render of a cloud glowing cloud symbol on a high-tech display, surrounded by nodes which represent the cloud market. Decorative: The cloud is encompassed by a glowing orange circle, while the nodes are blue. All are against a dark, reflective background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MAGnLonMp9NxMbwfcJaqNj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Venafi’s Machine Identity Summit 2024 was both a statement of where the company is headed under its new owner and a reminder of its leadership in the machine identity space.</p><p>Taking place at the same time as <a href="https://www.itpro.com/business/acquisition/cyberark-to-acquire-machine-identity-management-specialist-venafi-for-dollar154-billion"><u>CyberArk’s $1.5 billion acquisition of Venafi</u></a> was finally made official, the event acted as a stage to justify the move and explain how customers could benefit from the combination of either company’s decades of experience.</p><p>The benefits of the acquisition for CyberArk are clear: while the firm has been doing identity security for the last 25 years, it has <a href="https://www.cyberark.com/press/cyberark-completes-acquisition-of-machine-identity-management-leader-venafi/"><u>stated</u></a> that the addition of Venafi’s portfolio will allow it to deliver “end-to-end machine identity security at enterprise scale”.</p><p>Venafi’s <a href="https://www.itpro.com/security/31775/what-is-public-key-infrastructure-pki"><u>public key infrastructure (PKI)</u></a> and machine identity solutions will complement the wider array of identity security offerings in CyberArk’s portfolio, with the promise of a single dashboard unifying the two alluring customers.</p><p>This appears to meet customer demands, with Ricardo Lafosse, CISO at Kraft Heinz, using his time on stage to repeatedly call for “one dashboard, please!” when asked for his thoughts on the acquisition. Lafosse compared the combination of CyberArk and Venafi to Terminator 2. Hyperbole and pop culture aside, what Lafosse likely meant by this was that combined, the two firms can offer a far more comprehensive identity solution.</p><p>He added that customers of the combined firm will now get a far more comprehensive picture of their security, allowing them to make <a href="https://www.itpro.com/business/business-strategy/what-does-data-driven-mean-in-business"><u>data-driven</u></a> decisions on their identity controls.</p><p>This will be the big takeaway for most customers. Gone are the days of compartmentalized identity management and security workflows, if CyberArk’s claims are to be taken at face value.</p><h2 id="hybrid-and-multi-cloud-will-cause-headaches-for-identity-management">Hybrid and multi-cloud will cause headaches for identity management</h2><p>At its event, Venafi unveiled specific updates to its Control Plane for Machine Identities solution aimed at improving the overall experience for customers. This, it says, will be central to any unified solution coming down the line.</p><p>Another major theme of the conference was highlighting how increased adoption of hybrid and multi-cloud environments was fuelling an explosion in the number of machine identities firms need to manage.</p><p>Jeff Hudson, CEO at Venafi and now CEO emeritus under the new CyberArk umbrella, said the combination of <a href="https://www.itpro.com/cloud/cloud-computing/aws-says-enterprises-are-moving-back-on-prem-but-does-cloud-repatriation-really-threaten-hyperscalers"><u>on premise</u></a> and <a href="https://www.itpro.com/cloud/public-cloud/public-cloud-investment-surged-nearly-20-in-2023-and-analysts-predict-global-spending-will-reach-dollar16-trillion-by-2028"><u>public cloud</u></a> distributed across multiple providers has created innumerable new silos. Across all of these, he added, firms will need to track machine identities.</p><p>The ongoing embrace of CNCF has also drastically changed the types of identities being generated, as well as their lifecycle, only exacerbating the complexity for security practitioners.</p><p>Venafi wants to capture the corresponding demand from enterprises for visibility across these silos, as well as provide automation to help deal with the sheer volume of assets whose identities need to be monitored, rotated, and secured.</p><p>At its 2024 Summit, its announcement of new additions to TLS Cloud Protect that will now allow security teams to natively integrate it across AWS, Azure, and GCP, should go some way in doing that.</p><h2 id="actively-securing-identities-is-the-next-challenge-venafi-wants-face">Actively securing identities is the next challenge Venafi wants face</h2><p>Hudson made some bold remarks on stage in Boston, claiming we are entering a new era of identity and cyber security in which Venafi will focus on securing identities over simply managing those identities moving forward.</p><p>Future-facing aspects of the event included repeated discussion of the post <a href="https://www.itpro.com/technology/artificial-intelligence/dell-cto-ai-nothing-compared-to-the-oncoming-quantum-storm"><u>quantum threat</u></a>, which Venafi thinks should now be taken seriously by businesses. Specifically, consideration of the quantum threat at Machine Identity Summit 2024 centered on the considerable threat quantum poses to the underlying <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption"><u>encryption</u></a> techniques underpinning the majority of identity systems in use today.</p><p>Speaking onstage at the Summit, Colin Soutar, MD of risk & financial advisory at Deloitte & Touche LLP, pointed to expert projections that there is a finite probability we see a quantum computer within the next decade.</p><p>Firms should not be burying their heads in the sand on this threat, however nebulous it may appear, and Venafi wants to show it is keenly aware of how identity security is threatened by potential quantum-based attacks.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zkAybazkBjA99BUjhMDSem" name="Modern enterprise cybersecurity.jpg" caption="" alt="Modern enterprise cybersecurity" src="https://cdn.mos.cms.futurecdn.net/zkAybazkBjA99BUjhMDSem.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: BT)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/modern-enterprise-cybersecurity"><em>Enable digital transformation while protecting your workforce</em></a></p></div></div><p>Accordingly, Venafi announced new post-quantum cryptography integrations looking in Control Plane, including support for the new <a href="https://www.itpro.com/security/nist-aims-to-quantum-proof-encryption-with-new-algorithms"><u>NIST-approved</u></a> post-quantum <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm"><u>algorithms</u></a> in the latest versions of TLS Protect and COdeSign Protect.</p><p>Kevin Bocek, chief innovation officer at Venafi said overall, the new strategy outlined by Hudson was very much driven by the threat landscape, in which <a href="https://www.itpro.com/security/cyber-attacks/the-rise-of-identity-based-cyber-attacks-and-how-to-mitigate-them"><u>identity-based attacks</u></a> are core to many hugely disruptive malicious campaigns.</p><p>Leaders must reorient their approach towards identity security, according to Bocek, to ensure they have an active process to manage the security of identities at all times.</p><p>Venafi, in its new role within the CyberArk ecosystem, is in a good place to leverage its new partners’ long history in securing these identities. When it comes to fending off theoff the identity-based attacks of the future. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hybrid cloud environments are under serious threat from hackers – here’s what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/hybrid-cloud-environments-are-under-serious-threat-from-hackers-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Storm-0501 has been carrying out data exfiltration, credential theft, tampering, persistent backdoor access and ransomware deployment ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">f2LVdxt2vczEC69NUN5ckn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pY6qWM5GrgFHhDGkDVyDkm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Oct 2024 09:17:40 +0000</pubDate>                                                                                                                                <updated>Mon, 07 Oct 2024 09:18:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pY6qWM5GrgFHhDGkDVyDkm-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud security concept image showing a cloud symbol placed on top of a circuit board.]]></media:description>                                                            <media:text><![CDATA[Cloud security concept image showing a cloud symbol placed on top of a circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud security concept image showing a cloud symbol placed on top of a circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pY6qWM5GrgFHhDGkDVyDkm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft says it's identified a financially motivated cyber criminal group that uses open source tools to target hybrid cloud environments.</p><p>Known as 'Storm-0501', the group has been hitting a range of US organizations, including government, <a href="https://www.itpro.com/security/359492/cyber-attacks-on-manufacturing-up-300-in-a-year">manufacturing</a>, transportation, and law enforcement, carrying out data exfiltration, <a href="https://www.itpro.com/security/phishing/360714/credential-theft-most-prevalent-threat-to-corporate-inboxes">credential theft</a>, tampering, persistent backdoor access, and <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attacks.</p><p>First spotted in 2021, the group first targeted US school districts, but later moved on to more opportunistic attacks as a ransomware as a Service (RaaS) affiliate. </p><p>It's been using a number of ransomware payloads developed and maintained by other threat actors over the years, including Hive, <a href="https://www.itpro.com/security/ransomware/everything-we-know-so-far-about-the-rumored-alphv-takedown">BlackCat</a> (ALPHV), Hunters International, <a href="https://www.itpro.com/security/ransomware/lockbit-remains-most-dangerous-ransomware-despite-fall-in-attacks">LockBit</a>, and most recently, Embargo ransomware. It has also recently been targeting hospitals.</p><p>"Storm-0501 is the latest threat actor observed to exploit weak credentials and over-privileged accounts to move from organizations’ <a href="https://www.itpro.com/cloud/cloud-computing/359904/on-premises-vs-cloud-which-is-better-for-your-business">on-premises environments</a> to cloud environments," Microsoft said in an advisory. </p><p>"They stole credentials and used them to gain control of the network, eventually creating persistent backdoor access to the cloud environment and deploying ransomware to the on-premises."</p><p>The group's access techniques include the use of stolen credentials and known exploits to find over-privileged accounts - for example through known vulnerabilities in Zoho ManageEngine, Citrix NetScaler and ColdFusion 2016 applications.</p><p>"After gaining initial access and code execution capabilities on the affected device in the network, the threat actor performed extensive discovery to find potential desirable targets such as high-value assets and general domain information like Domain Administrator users and domain forest trust," Microsoft said. </p><p>"Common native <a href="https://www.itpro.com/penetration-testing/30697/kali-linux-comes-to-windows-10-handing-hacking-tools-to-pen-testers">Windows tools</a> and commands, such as systeminfo.exe, net.exe, nltest.exe, tasklist.exe, were leveraged in this phase." </p><p>Stolen credentials have allowed Storm-0501 to move laterally across the network to reach a domain controller, and then deploy ransomware across the devices in said network.</p><p>It's been spotted exfiltrating sensitive data from compromised devices by using the open source tool Rclone and renaming it to known Windows binary names or variations of them, such as svhost.exe or scvhost.exe.</p><p>The renamed Rclone binaries were used to transfer data to the cloud using a dedicated configuration that synchronized files to public cloud storage services such as MegaSync across multiple threads. </p><p>Once the group achieved sufficient control over the network, successfully extracted sensitive files, and managed to move laterally to the cloud environment, it deployed the Embargo ransomware across the organization. </p><p>"Embargo ransomware is a new strain developed in Rust, known to use advanced encryption methods. Operating under the <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">RaaS</a> model, the ransomware group behind Embargo allows affiliates like Storm-0501 to use its platform to launch attacks in exchange for a share of the ransom," Microsoft explained. </p><p>"Embargo affiliates employ double extortion tactics, where they first encrypt a victim’s files and threaten to leak stolen sensitive data unless a ransom is paid."</p><p>Microsoft said it's recently implemented a change in Microsoft Entra ID that restricts permissions on the Directory Synchronization Accounts (DSA) role in Microsoft Entra Connect Sync and Microsoft Entra Cloud Sync. </p><p>This, the tech giant said, helps prevent threat actors from abusing Directory Synchronization Accounts in attacks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is firewall as a service (FWaaS)? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/what-is-firewall-as-a-service-fwaas</link>
                                                                            <description>
                            <![CDATA[ Amid the increasing complexity of distributed work and data sprawl, FWaaS can step in as a scalable, cloud-based solution that improves on traditional firewalls ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S9h9qPRQG2HFLB32B9z7d8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TpZfVyvznScP9xuqDKBM2L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Sep 2024 12:06:15 +0000</pubDate>                                                                                                                                <updated>Fri, 27 Sep 2024 11:18:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Avya Chaudhary ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/9feK3t7cKTsDFyTxTM5kfi.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TpZfVyvznScP9xuqDKBM2L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital render of a hologram of a shield bearing a tick symbol representing firewall as a service (FWaaS). Decorative: the hologram is hovering above a lightly-blurred dark touchscreen bearing glowing red, green, and blue lights.]]></media:description>                                                            <media:text><![CDATA[A digital render of a hologram of a shield bearing a tick symbol representing firewall as a service (FWaaS). Decorative: the hologram is hovering above a lightly-blurred dark touchscreen bearing glowing red, green, and blue lights.]]></media:text>
                                <media:title type="plain"><![CDATA[A digital render of a hologram of a shield bearing a tick symbol representing firewall as a service (FWaaS). Decorative: the hologram is hovering above a lightly-blurred dark touchscreen bearing glowing red, green, and blue lights.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TpZfVyvznScP9xuqDKBM2L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Brazil's Public Defender's Office for Human Rights is one of the many organizations that has jumped on the firewall bandwagon and it’s easy to see why. Thanks to its hybrid mesh firewall setup, the office faced <a href="https://www.fortinet.com/customers/defensoria-publica-da-uniao"><u>99%</u></a> fewer suspicious emails and practically non-existent security incidents that once climbed to 500+ a year. </p><p>It's not just a one-off success story — firewalls have been our first line of defense against <a href="https://www.itpro.com/security/world-economic-forum-warns-of-growing-cyber-insecurity-amid-heightened-threat-landscape"><u>cyber threats</u></a> since the 1980s and are still going strong, even with a flood of other <a href="https://www.itpro.com/business/business-strategy/why-msps-are-switching-their-focus-to-cybersecurity-solutions"><u>cybersecurity solutions</u></a> on the market. </p><p>But how do firewalls fit into today’s remote-first, distributed, and cloud-driven IT world where networks are constantly shifting, threats are more sophisticated, and <a href="https://www.itpro.com/infrastructure/data-centres/why-frankfurt-is-clamping-down-on-data-center-sprawl"><u>data is sprawling</u></a> across multiple environments? </p><p>The answer is firewall as a service (FWaaS)— a cloud-based solution that centralizes traffic inspection by combining next-generation firewall (NGFW) capabilities with <a href="https://www.itpro.com/security-appliances/26453/choosing-the-right-utm-appliance"><u>unified threat management</u></a> (UTM).</p><p>Traditional firewalls are built to handle traffic within physical office spaces. FWaaS moves your firewall to the cloud where it can scale up or down to fit modern IT needs. It also helps take a lot of the heavy lifting off your IT team's shoulders with built-in <a href="https://www.itpro.com/business-intelligence/28220/what-is-data-analytics"><u>advanced analytics</u></a> and real-time, granular visibility across multiple micro-perimeters. </p><p>It’s an approach garnering a lot of enterprise interest right now, with the global FWaaS market valued at $2.53 billion (£1.92 billion) by <a href="https://www.grandviewresearch.com/industry-analysis/firewall-as-a-service-market-report" target="_blank"><u>Grand View Research</u></a> in 2022 and expected to grow to $12.2 billion (£9.27 billion) by 2030.</p><h2 id="how-does-fwaas-work">How does FWaaS work?</h2><p>FWaaS directs all network traffic—whether from in-house systems, remote users, or cloud-based resources—through a cloud-based firewall. </p><p>Brian Soby, a former Salesforce security director and partner at Freefly Security raves about FWaaS, calling it a "Swiss Army knife" for security. </p><p>“FWaaS integrates intrusion prevention systems (IPS), firewalls, and <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/367994/vpn-or-virtual-private-networks-what-businesses"><u>virtual private networks (VPNs)</u></a> into one powerful tool for improved threat detection," he tells <em>ITPro</em>. This all-in-one approach is a big selling point when you're talking to people about cybersecurity.” </p><p>The integrated firewall <a href="https://www.itpro.com/network-internet/34780/network-monitoring-what-every-admin-should-be-looking-out-for"><u>scrutinizes network traffic</u></a> with deep packet inspection and creates a strong perimeter defense. Later, an IPS detects policy violations and protocol anomalies inside the network that manage to bypass those barriers, while the VPN ensures secure, remote access to employees over the cloud. </p><p>Unlike traditional firewalls that require individual configuration, FWaaS provides a unified console where IT teams can control security policies and enforce compliance across the entire network. </p><p>FWaaS also gatekeeps the IT network by employing a software-defined perimeter (SDP) for a dynamic and secure boundary around your internal resources. The idea is built on <a href="https://www.itpro.com/security/what-is-zero-trust-network-access-ztna"><u>zero trust network access (ZTNA)</u></a> where only authenticated and authorized users can access your network. </p><h2 id="the-benefits-of-fwaas">The benefits of FWaaS</h2><p>Even though its still nascent, <a href="https://www.itpro.com/cloud/cloud-computing/what-is-cloud-native-and-how-can-it-generate-business-value"><u>cloud native</u></a> FWaaS is working its way into organizations' security setups, thanks to ease of management and dynamic threat protection. </p><p>One of the biggest long-term benefits of FWaaS is its ability to create a resilient and cost-effective IT environment. “FWaaS shifts IT from a CapEx to an OpEx model, making it more cost-effective,” explains Lloyd Hopper of AlgoSec.</p><p>This shift means IT admins don’t have to spend on physical appliances or deal with the headaches of repairs, and replacements. Oliver Page, CEO at CyberNut adds to this, noting, "The providers handle security updates and management, which translates to lower maintenance costs for us."</p><p>Here’s a look at some of the other benefits of FWaaS:</p><ul><li><strong>Flexibility: </strong>FWaaS helps by breaking the network into smaller, isolated zones using micro-segmentation, each with its own security rules. This setup makes it harder for threats to move around within the network and handles the complexities of distributed and multi-cloud environments. Traditional firewalls, however, are usually built for a single, static perimeter and don’t offer this kind of flexibility.</li><li><strong>Deep integrations: </strong>FWaaS takes a flexible approach to network security by teaming up with cloud-native tools like Terraform. This means teams get <a href="https://www.itpro.com/security/ai-security-tools-promise-to-supercharge-productivity-but-experts-worry-cyber-pros-could-become-too-reliant"><u>automated security</u></a> policy management, <a href="https://www.itpro.com/business/digital-transformation/what-is-infrastructure-as-code-iac-and-what-are-its-benefits"><u>infrastructure as code (IaC)</u></a>, and smooth updates across cloud environments.</li><li><strong>Hardware-free scalability: </strong>FWaaS can autoscale based on traffic load and sudden spikes without needing new hardware. It also handles auto-updates and integrates smoothly with <a href="https://www.itpro.com/cloud/367974/what-is-cloud-orchestration-software"><u>cloud orchestration tools</u></a> so IT teams can tweak security policies and settings in real-time, based on cloud capabilities and incoming traffic.</li><li><a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><strong>Zero trust</strong></a><strong> security: </strong>Unlike traditional firewalls, which rely on a static perimeter approach and assume internal traffic is safe, FWaaS enforces granular, policy-based access controls to continuously validate user identities, device health, and access requests.</li></ul><p>Things can more smoothly as IT teams harness the power of <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a>. Page notes that FWaaS, when combined with AI and <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning (ML)</a>, can offer better prevention. This is because AI can analyze vast amounts of data and use it to detect and block threats, an advantage traditional firewalls cannot offer.</p><h2 id="where-does-fwaas-sit-within-sase">Where does FWaaS sit within SASE?</h2><p>Secure access service edge (SASE) brings together FWaaS, WAN, <a href="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan"><u>SD-WAN</u></a>, and security service edge (SSE) to secure distributed teams and remote users with a global firewall policy. IT teams can now break down <a href="https://www.itpro.com/business-strategy/data-insights/370274/taking-back-control-of-the-data-silos-holding-your-business"><u>security siloes</u></a> by enforcing the same set of security rules consistently across all users, no matter where they're located.</p><p>“Both FWaaS and SASE are cloud-based and work well with other cloud services and applications to offer a cohesive, decentralized security solution,” explains Page.  </p><p>FWaaS also offers <a href="https://www.itpro.com/cloud/31389/what-is-edge-computing">edge</a>-based deployment that aligns well with SASE’s principle of providing security closer to the network edge. Placing the firewall closer to users and devices allows it to inspect and regulate traffic at its source to enable secure communications right from the point of entry. </p><p>Alongside other SASE security tools, FWaaS can enable real-time, 360-degree visibility into network traffic and identify patterns, or anomalies that might make IT systems vulnerable. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="geFJcvQLtqYxEoQi2GuWXM" name="Modern management_ The future of MDM (1).jpg" caption="" alt="Modern management: The future of MDM" src="https://cdn.mos.cms.futurecdn.net/geFJcvQLtqYxEoQi2GuWXM.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Jamf)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/modern-management-the-future-of-mdm"><em>Secure and seamless device experience</em></a></p></div></div><p>For example, FWaaS alerts the ZTNA system to temporarily restrict data access if any suspicious activity is detected from an employee's device. Or if it identifies a website that shows signs of a <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370366/social-engineering-attacks-generative-ai-soar-135"><u>social engineering attack</u></a>, the system notifies a secure web gateway to block site access for everyone on the network. </p><p>Another benefit of FWaaS is that it can dynamically learn from threats. By analyzing the data and feedback it collects from SASE-enabled tools, FWaaS can continuously improve its own detection <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm"><u>algorithms</u></a> and reduce the risk of false positives.</p><p>“FWaaS-SASE integration is valuable in today’s increasingly distributed and cloud-centric environments, providing effective threat prevention and data protection while supporting the dynamic needs of modern businesses,” says Hopper. </p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=56586877&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How is hybrid cloud security evolving? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/how-is-hybrid-cloud-security-evolving</link>
                                                                            <description>
                            <![CDATA[ With increasingly complex cloud environments, cyber security tools are constantly changing to meet the needs of growing businesses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">shmjiMCQEbEgk8HaFpwzfk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M5csFvNWDEuWjzvggZ8GVL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Sep 2024 16:06:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M5csFvNWDEuWjzvggZ8GVL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital data security padlock on futuristic circuit board]]></media:description>                                                            <media:text><![CDATA[Digital data security padlock on futuristic circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[Digital data security padlock on futuristic circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M5csFvNWDEuWjzvggZ8GVL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More and more businesses are opting for the hybrid cloud approach, meaning they share the burden of their cloud storage requirements across both cloud - whether public or private - and on-prem.</p><p>This sort of environment works well for several reasons, allowing enterprises to reap the benefits of different systems simultaneously while also minimizing their relevant downsides.</p><p>With firms such as Atlassian <a href="https://www.itpro.com/cloud/cloud-computing/atlassian-wont-push-on-cloud-migrations-in-savvy-move-for-the-enterprise-market"><u>altering their business strategies</u></a> to reflect this surge in hybrid cloud popularity, it’s worth noting exactly why this approach is so popular.</p><p>For example, hybrid cloud users benefit from both the enhanced scalability and flexibility of a public cloud provider while also ensuring their more sensitive data can remain in a centralized on-premise location. </p><p>Splitting workloads between two very different systems has its disadvantages, though. Keeping on top of complexity across different environments can be difficult, especially concerning security. </p><p>Hybrid cloud security can cause a world of problems for the typical IT decision-maker (ITDM), as threat levels grow exponentially the more spread out the ecosystem is and the more application or data sprawl is present.</p><p>Just as the relevant threats are evolving though, so too is hybrid cloud security. Cyber security systems are ever-changing and adapting to meet the needs of enterprise customers operating on a hybrid cloud. </p><h2 id="the-hybrid-cloud-problem-xa0">The hybrid cloud problem </h2><p>Data management is a fundamental concern from a security perspective in a hybrid cloud world. Any enterprise will need to work with a vast array of different data streams, some more sensitive or security-intensive than others. </p><p>Where businesses may wish to process some of the more sensitive data in private clouds or on-premises data centers, they will also likely want to process other data through the public cloud in the interest of efficiency. </p><p>Problems occur when navigating between these different environments. Any security decisions made regarding a business&apos;s public cloud must be reflected in some way in the business&apos;s private cloud or on-premises systems. </p><p>This doesn’t mean that security decisions in different environments will be the same, it just means that one will have to take the other into account in order to be at its most effective. </p><p>Hybrid cloud environments are also complex by their very definition, making security and visibility difficult. Experts have <a href="https://www.itpro.com/business-strategy/automation/357533/hybrid-cloud-complexity-fuelling-appetite-for-automation-says"><u>lamented the growing complexity of hybrid cloud environments</u></a> for years now and they’re only getting more difficult to manage as size increases. </p><p>Findings <a href="https://www.itpro.com/hybrid-cloud/29668/what-is-hybrid-cloud"><u>from </u><u><em>451 Research</em></u></a> showed that over half (51.8%) of respondents consider hybrid cloud storage to be less secure, putting poor security at the top of this technique&apos;s disadvantages. </p><p>“Hybrid cloud at its peak has on-premises and public cloud workloads operating as one cohesive identity. But achieving this is near impossible, as architectures are vastly different,” according to <a href="https://www.forrester.com/blogs/hybrid-cloud-is-hard-to-manage/"><u><em>Forrester</em></u><u> analyst Tracy Woo</u></a> in a blog post from last year.</p><h2 id="hybrid-cloud-security-evolution-xa0">Hybrid cloud security evolution </h2><p>Luckily, CIOs and CISOs looking to secure their hybrid cloud environments have many, ever-evolving options to choose from when it comes to implementing secure frameworks in their systems.</p><p>Companies are constantly innovating in terms of solution provision for hybrid cloud. Take a recent announcement from <em>Dell</em>, which <a href="https://www.itpro.com/cloud/hybrid-cloud/dell-unveils-new-apex-cloud-platform-for-azure-in-bid-to-simplify-hybrid-cloud-shift"><u>promised to “simplify” hybrid cloud management</u></a> with its Apex Cloud platform. </p><p>Other, more security-focused innovations and developments are also prevalent in the industry, and independent bodies and analysts offer a wealth of advice on how best to achieve a secure hybrid cloud environment. </p><p>The US National Security Agency (NSA), for example, advises <a href="https://www.itpro.com/cloud/cloud-security/10-cloud-security-tips-every-it-leader-should-know"><u>standardizing vendor-agnostic cloud tools</u></a> to help organizations monitor security across different environments. </p><p>This helps mitigate the risk of silos and skill gaps across multiple systems, where discrepancies between configurations and unnecessary data flows can create added security issues. </p><p>Forrester’s Woo advises that businesses go further than simply adopting hybrid cloud strategies. Instead, they should set up an internal “cloud center of excellence” that can focus on training users in managing hybrid cloud environments.</p><p>Enterprises should also try to build “reusable assets” that “avoid reinventing the wheel.” This means that assets should be written in low-code formats that can be easily adapted as businesses move forward.  </p><p>There are also various <a href="https://www.itpro.com/cloud/cloud-management/368576/best-cloud-management-software"><u>cloud management solutions to choose from</u></a>, designed to encourage collaboration between a business&apos;s different environments. These can help to control endpoint security more easily, as well as ease the burden of IT management overall. </p><h2 id="ai-and-hybrid-cloud-security-xa0">AI and hybrid cloud security </h2><p>As with every technology in the current landscape, AI promises to breathe new life into the management of hybrid cloud security by offering tools that help to automate complex security processes. </p><p><a href="https://www.itpro.com/security/ai-security-tools-promise-to-supercharge-productivity-but-experts-worry-cyber-pros-could-become-too-reliant"><u>AI already shows great promise in overhauling security as a whole</u></a>, with tools from many of the big names in tech offering solutions to the already overburdened CISO through visibility and workflow optimization.</p><p><a href="https://www.itpro.com/cloud/cloud-security/why-the-wiz-acquisition-makes-perfect-sense-for-google"><u>Google’s intended acquisition of security firm Wiz</u></a> is a clear example of this, despite it being called off by the latter. The move showed a clear desire on behalf of Google to increase its offerings in the cloud security market, suggesting that it’s top of mind for the tech giant.  </p><p>The industry will no doubt see more tools geared towards hybrid cloud environments specifically, with solutions designed to manage risks across both public and private clouds, as well as within on-premise storage. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How is hybrid cloud security different from multi-cloud or single cloud security? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/how-is-hybrid-cloud-security-different-from-multi-cloud-or-single-cloud-security</link>
                                                                            <description>
                            <![CDATA[ Hybrid cloud offers marked benefits for enterprises, but there are key security considerations that separate this approach from its public and multi-cloud counterparts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yW6xTnvpUAs8bS7hBRmAob</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rcggK9pkAbTthEnDrC7pPh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Sep 2024 16:04:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rcggK9pkAbTthEnDrC7pPh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a blue cloud made up of jigsaw parts to illustrate hybrid cloud]]></media:description>                                                            <media:text><![CDATA[An image of a blue cloud made up of jigsaw parts to illustrate hybrid cloud]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a blue cloud made up of jigsaw parts to illustrate hybrid cloud]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rcggK9pkAbTthEnDrC7pPh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hybrid cloud has surged in popularity in recent years amidst a widespread enterprise shift toward incorporating both public and private storage capabilities. </p><p>During the early days of the global cloud shift, public cloud reigned supreme. But increasingly, hybrid and multi-cloud approaches have gained traction among enterprises globally. </p><p>Multi-cloud, for example, which includes organizations using a combination of two or more cloud service providers, has also been gaining traction. Research from OVHCloud found nearly two-thirds (64%) of enterprises expect their use of this approach to increase in the next two years. </p><p>Meanwhile, <a href="https://www.cisco.com/c/en/us/solutions/hybrid-cloud/2022-trends.html"><u>Cisco’s 2022 </u><u><em>Global Hybrid Cloud Trends</em></u></a> report found that 82% of IT leaders had adopted a hybrid cloud approach. This method has a number of key advantages, not least of all flexibility, enabling organizations to host workloads both in the cloud and on-prem depending on their individual business needs. </p><p>There’s more to hybrid cloud than just flexibility, however. <a href="https://www.oracle.com/a/ocom/docs/cloud/oracle-451-research-advisory-blog-adopting.pdf"><u>Analysis from 451 Research</u></a> notes that enterprises adopting a hybrid approach can also unlock cost benefits and heightened operational resilience. </p><p>“More enterprises are finding that a hybrid environment - one that uses on-premises resources in coordination with public cloud services - offers the best of both worlds,” it said. </p><p>Notably, hybrid cloud can enable organizations to reduce risk by running certain applications on private infrastructure, rather than in the public cloud. In regulated industries, in particular, enterprises may seek to air gap applications or workloads, or to maintain data residency and compliance. </p><p>The 2024 ISG <em>Provider Lens Private/Hybrid Cloud – Data Center Services</em> report, for example, found that hybrid cloud adoption is being <a href="https://www.itpro.com/cloud/hybrid-cloud/security-and-compliance-concerns-are-driving-the-shift-to-hybrid-cloud"><u>driven by heightened security and compliance risk concerns</u></a> among enterprises. </p><p>Cisco’s <em>Global Hybrid Cloud Trends</em> report also specifically highlighted these considerations as key contributory factors to the appeal of hybrid cloud. </p><p>“One factor in the maturing of cloud operations is managing risk by being selective about where workloads and data are placed,” the report states. </p><p>“Hybrid environments can give security teams options that allow them to balance placement, putting some workloads in public clouds while keeping others on-prem, or using different regions for data residency requirements.”</p><p>Air-gapping, in particular, has come to the fore since the emergence of generative AI in late 2022. Employing a hybrid cloud approach has become a <a href="https://www.itpro.com/cloud/cloud-computing/netapp-ceo-hybrid-cloud-will-be-the-only-way-to-capitalize-on-generative-ai"><u>key tactic for organizations adopting the technology</u></a>, allowing them to experiment and tinker with applications in public cloud environments, and thereafter bringing them on-prem to bolster security and safety. </p><p>But while hybrid cloud does offer marked benefits, it does pose unique cybersecurity challenges for enterprise IT leaders. </p><h2 id="increased-complexity">Increased complexity</h2><p>Cloud security in a broader sense has become a major focus for enterprises globally in recent years, with research showing a significant rise in the volume of attacks targeting cloud environments. </p><p>Thales’ 2024 <em>Cloud Security</em> report found nearly half (44%) of organizations have experienced a cloud data breach, and 14% reported a breach in the year between June 2023 and June 2024 alone.</p><p>Practitioner sentiment on cloud-related security threats is also growing, according to the ISC2 2024 <a href="https://www.isc2.org/-/media/5C011B9E35624F309CB4D00EA1A22FED.ashx"><u><em>Cloud Security Report</em></u></a>. </p><p>The majority (96%) of respondents expressed “significant concerns” over security within the public cloud specifically, marking an increase from 95% in the year prior. </p><p>With the public cloud, security teams typically contend with a single, uniform environment. Multi-cloud and hybrid cloud approaches, however, which include environments spanning multiple cloud providers - or a combination of on-prem and off-prem workloads and applications - add a degree of complexity that many enterprises aren’t prepared for.</p><p>Managing security across disparate or siloed environments poses serious challenges about data governance, compliance, and identity management in particular.</p><p><a href="https://cloudsecurityalliance.org/blog/2020/07/14/understanding-common-risks-in-hybrid-clouds"><u>Research from the Cloud Security Alliance (CSA),</u></a> for example, specifically highlighted identity and credential management as a key risk for hybrid cloud operators. </p><p>“The lack of a decentralized and unified identity management solution may cause account information inconsistency between clouds, resulting in discontinuous log audits and failures to trace resource misuse.”</p><p>Similar <a href="https://www.itpro.com/cloud/cloud-security/the-biggest-cloud-security-risk-in-2024-will-be-stolen-and-exposed-credentials"><u>research from Expel in January 2024</u></a> found two-in-five cloud infrastructure incidents were directly attributed to compromised credentials. </p><p>With this in mind, the <a href="https://cloudsecurityalliance.org/blog/2023/08/21/five-core-principles-for-hybrid-cloud-security-how-to-build-an-effective-scalable-and-affordable-strategy"><u>CSA recommends</u></a> organizations adopt a “unified identity strategy” to ensure that cloud identities do not exist in disparate directories or systems. </p><p>This should be underpinned by robust multi-factor authentication (MFA) practices for privileged accounts, the CSA noted, while automated monitoring tools for cloud accounts. </p><p><a href="https://www.itpro.com/cloud/361113/the-rise-of-cloud-misconfiguration-threats-and-how-to-avoid-them"><u>Misconfiguration is also a leading concern for security teams</u></a> operating in a hybrid cloud environment, research shows. Managing multiple environments can increase the likelihood of errors, thereby creating the potential for additional vulnerabilities. Analysis from Thales, for example, highlighted cloud misconfigurations as the <a href="https://www.itpro.com/cloud/cloud-security/enterprises-need-to-get-a-firm-grasp-on-attack-surfaces-as-cloud-breaches-surge"><u>leading cause of breaches for organizations</u></a> last year.</p><p>The complexity of hybrid cloud environments is further exacerbated by a distinct lack of visibility for security teams, with one-quarter of organizations unable to identify the root cause or source of a breach, according to <a href="https://www.gigamon.com/campaigns/hybrid-cloud-security-survey.html"><u>research from Gigamon</u></a>. </p><p>Again, this combination of on-prem and off-prem environments can create a clouded picture for security teams responding to threats. Gigamon’s research noted that one-third of respondents cited blind spots as one of their top concerns. </p><p>Organizations pursuing a hybrid cloud approach are increasingly turning to zero trust practices to bolster security capabilities and improve visibility within cloud and on-prem environments, research shows. </p><h2 id="skills-deficits-are-hampering-hybrid-cloud-security-capabilities">Skills deficits are hampering hybrid cloud security capabilities</h2><p>The global cybersecurity skills shortage has become ubiquitous across the global technology landscape. ISC2’s 2023 <a href="https://www.isc2.org/-/media/Project/ISC2/Main/Media/documents/research/ISC2_Cybersecurity_Workforce_Study_2023.pdf"><u><em>Global Workforce Study</em></u></a> found the workforce gap has reached a record high, with four million security professionals needed to fill this gap. </p><p>When it comes to cloud security skills the situation is equally dire, according to ISC2. Around 93% of respondents to ISC2’s 2023 Cloud Security Report said they were  “moderately to extremely concerned” about a growing cloud-related skills deficit. </p><p>This issue isn’t limited to hybrid cloud, however, with organizations operating in a public and multi-cloud approach also contending with skills shortages. </p><p>What separates hybrid cloud though again lies with the inherent complexity of this approach. Managing security across multiple environments requires a wide range of skills, and a lack of expertise in one - or more - of these domains could potentially increase exposure. </p><p>“Embracing a hybrid or multi-cloud strategy requires a robust framework for managing complexity, ensuring data protection across environments, and a broader skill within security teams,” the report notes. </p><p>“The security skills shortage not only impacts the ability to defend against cyber threats effectively but also constrains organizations’ capacity to innovate and leverage cloud technologies fully.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to identify and mitigate cloud-based cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/how-to-identify-and-mitigate-cloud-based-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ Sprawling IT estates with a vast network of endpoints need a strong security strategy, advanced threat detection, and, ultimately, a human touch ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GDpPZj867kGcsTeZenbr8f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M7naUc3oqHsL76vq9v5o6H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Sep 2024 15:55:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Bobby Hellard) ]]></author>                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M7naUc3oqHsL76vq9v5o6H-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cloud security]]></media:description>                                                            <media:text><![CDATA[cloud security]]></media:text>
                                <media:title type="plain"><![CDATA[cloud security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M7naUc3oqHsL76vq9v5o6H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber attacks may be an inevitable part of modern life but that doesn’t mean that businesses simply have to put up with them. Indeed it is possible to have both a proactive and reactive stance when it comes to securing your organization. The reality is that this does take hard work and constant evolution of strategy to move from theory to reality and remain safe from harm. </p><p>Take this year’s hack on <a href="https://www.itpro.com/security/new-york-times-confirms-source-code-leak"><u>The </u><u><em>New York Times</em></u></a> for instance; It was a GitHub repository that was breached at the start of the year after a 4Chan user claimed to have stolen “basically all source code belonging to The New York Times Company”. That cache was estimated to be around 273GB of data including IT documentation, infrastructure tools, email marketing campaigns, ad reports, and source code for other NYT-owned platforms like Wordle. </p><p>This example highlights that there are many ways to get inside a modern company, and knowing how to identify the risks and mitigate cloud-based cyber threats is the best way to keep your organization and its data safe.</p><h2 id="cloud-based-security-xa0">Cloud-based security </h2><p>When people talk about cloud security, they are generally referring to securing cloud-based computing systems such as online storage platforms, and SaaS applications – essentially anything that uses, stores, or transfers data. Making sure these systems are safe requires a host of different elements, some strong government-level regulation, and every person in the company adhering to best practices at all times.</p><p>Cloud providers that host services on their servers via ‘always-on’ internet connections will have a responsibility to maintain a high level of security – particularly as it builds trust among its customers. However, cloud security is also the responsibility of the client and an understanding of both is key to a healthy cloud security setup.  </p><p>At a very basic level,  this will include data security and data retention, identity and access management, IT governance, and legal compliance. It will cover backend systems like servers and also include all endpoints used within an organization, such as laptops and desktops. With large enterprises, this is often an ever-growing map of possible entrances for unauthorized parties to test. </p><h2 id="expect-the-worst">Expect the worst</h2><p>Historic and emerging/evolving threats were a key focus for the <a href="https://cloudsecurityalliance.org/press-releases/2024/08/06/cloud-security-alliance-releases-top-threats-to-cloud-computing-2024-report"><u>Cloud Security Alliance’s (CSA) recently published  top threats for 2024 report</u></a></p><p>“It’s tempting to think that the reason the same issues have remained in the top spots since the report was last issued stems from a lack of progress in securing these features. The larger picture, however, speaks to the importance placed on these vulnerabilities by organizations and the degrees to which they are working to build ever more secure and resilient cloud environments,” said Michael Roza, co-chair, <a href="https://cloudsecurityalliance.org/group/top-threats/">Top Threats Working Group</a>, and one of the paper’s lead authors.</p><p>The top threats in listed order were:</p><p>“Given the ever-evolving cybersecurity landscape, it’s difficult for companies to stay ahead of the curve and mitigate their financial and reputational risks. By bringing attention to those threats, vulnerabilities, and risks that are top-of-mind across the industry, organizations can better focus their resources,” said Sean Heide, the CSA’s technical research director. </p><p>As negative as it may sound, planning for the worst possible scenario is arguably the best advice when it comes to cybersecurity. If you have a plan in place you will give yourself every chance of fighting off whatever comes your way – and trust us, something will come up eventually. Having a strategy in place for the worst-case scenario(s) will help to fortify defense systems and protocols, and also enable a robust response should a threat surface.</p><p>But where should you start? Detection systems that monitor network traffic or system activities, particularly those of a malicious nature, are a great first to have on the list. These will give you generated alerts and can even trigger automated responses, taking the burden away from thinly stretched IT teams.</p><p>Endpoint detection and response services are also key. These are designed to protect individual endpoints such as the computers, laptops, and mobile devices your staff uses, as well as the myriad IoT devices in your network. However, when we talk about endpoints, we also mean the communication apps that you access through them. Here, users are in the firing line for phishing attacks via email or Whatsapp, but a good threat detection program can monitor those activities. The end user will have a report button, but a detection system can spot the patterns and see whether there is a significant volume for a targeted attack, and stop it as early as possible. </p><h2 id="managed-detection-and-response-xa0">Managed detection and response </h2><p>A managed detection and response (MDR) service offers a more holistic approach to endpoint security. An MDR is an outsourced service that identifies and responds to threats as soon as they’re discovered – here it can address the significant problems that cause today’s businesses the most headaches. </p><p>It also helps with skill shortages and tight budgets; while larger organizations may be able to properly train or hire security professionals, smaller and medium-sized businesses may lack the skills to directly deal with complex threats. Enterprise companies may also face challenges when deploying complex endpoint detection systems, particularly if they’re short on time and expertise. A good MDR suite, however, will integrate EDR tools into its security implementation and make them an integral part of the detection, analysis, and response protocol. </p><p>Even enterprises that have the necessary budget to hire professionals to tackle cyber threats still struggle to recruit enough people. An overlooked issue in cybersecurity is the sheer volume of alerts that IT teams receive daily, making it nearly impossible to spot all the malicious ones. Forget trying to correlate those threats and see the wider patterns, as they’ll be unable to keep up. Smaller teams will be completely overrun.  </p><p>An MDR, however, is designed to mitigate gaps in cybersecurity skills by taking the weight off in-house teams. That’s not to say that you won’t need any trained professionals, however. An MDR service will provide recommendations for changes based on its interpretation of security incidents. A skilled professional will be needed to contextualize the threat and dig deeper into the hows and whys of the event – a human touch is still an important part of the security strategy. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How hackers target the cloud ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/how-hackers-target-the-cloud</link>
                                                                            <description>
                            <![CDATA[ With more business assets in the cloud than ever, understanding the risk of cloud misconfiguration, malware, and credential theft to your business is critical ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gbex9EjwkurS57xqbN7EVV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ccsAVwFQbSaYr4mLvqAxBX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Sep 2024 15:54:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ccsAVwFQbSaYr4mLvqAxBX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud hack]]></media:description>                                                            <media:text><![CDATA[Cloud hack]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud hack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ccsAVwFQbSaYr4mLvqAxBX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There’s never been a more important time to understand how hackers target the cloud. While the cost and scalability benefits of the cloud are undeniable, it’s also a vast attack surface that opens any firm - regardless of size, industry, or even geographical location - up to the interest of hacking groups. </p><p>Almost every business now has a cloud environment to worry about, with PwC’s 2023 <a href="https://www.pwc.com/us/en/tech-effect/cloud/cloud-business-survey.html"><u><em>Cloud Business Survey</em></u></a> finding that 78% of business executives had extended cloud across the majority or the entirety of their business. With this in mind, leaders must know the main avenues of attack for the cloud and the myriad strategies threat actors may explore to breach, infect, or destroy their valuable cloud assets.</p><p>A chain is only as strong as its weakest link and when it comes to valuable cloud assets it really is imperative that leaders know where and how their attack surface can come under strain.</p><h2 id="vulnerabilities-leave-the-door-unlocked">Vulnerabilities leave the door unlocked</h2><p>Extending the metaphor of that weak link, existing vulnerabilities within a business’ cloud environment are the first port of call for any hacker.</p><p>Cloud misconfiguration is of particular concern, as it could allow sensitive data to be leaked onto the public internet, or allow hackers to enter systems outright without the need for authorized access.</p><p>In Splunk’s <a href="https://www.splunk.com/en_us/form/state-of-security/thanks.html"><u><em>State of Security 2024</em></u></a> report, misconfigured systems were identified as the most frequent threat vector with 38% of attacks arising from these mistakes. These user errors can be simple to overlook but enable serious attacks on the cloud</p><p>For example, <a href="https://www.itpro.com/security/misconfigured-saas-applications-led-to-the-home-depot-data-breach-and-experts-say-its-no-surprise"><u>Home Depot recently suffered a data breach</u></a> that arose from a misconfigured <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas"><u>software as a service (SaaS)</u></a> application and researchers have discovered misconfigured access controls <a href="https://www.itpro.com/security/netsuite-vulnerability-could-leave-thousands-of-websites-exposed"><u>within NetSuite’s SuiteCommerce</u></a> which could allow hackers to steal customer data. </p><p>Misconfigurations are the path of least resistance for hackers – once identified, threat actors can launch successful attacks in <a href="https://www.itpro.com/cloud/cloud-security/cyber-attacks-in-the-cloud-take-less-than-ten-minutes-to-launch"><u>less than ten minutes</u></a>. </p><p>To stay ahead of the threat, it’s important that IT teams keep a close eye on cloud configurations, using third-party tools if necessary to help them monitor potential weak points and close gaps in their defensive wall before hackers take notice.</p><h2 id="attacks-driven-by-subterfuge">Attacks driven by subterfuge</h2><p>An effective attack vector for targeting the cloud is <a href="https://www.itpro.com/cloud/cloud-security/cloud-security-breaches-surge-on-a-wave-of-stolen-credentials"><u>credential theft</u></a>. Login details for company accounts can be obtained directly through data breaches, <a href="https://www.itpro.com/security/data-breaches/a-treasure-trove-for-adversaries-10-billion-stolen-passwords-have-been-shared-online-in-the-biggest-data-leak-of-all-time"><u>found on hacking forums</u></a> in the wake of a breach, or stolen through targeted <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself"><u>social engineering</u></a> and <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> attacks on employees.</p><p>Credential theft can be especially difficult to detect because attackers will appear to be legitimate users. Identifying which accounts have been subject to credential theft can be as simple as checking whether users have been implicated in recent data breaches to the trickier task of identifying which user accounts are exhibiting anomalous behavior.</p><p>One of the main ways in which businesses can combat this threat is via identity management protocols as well as through investing in <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business"><u>identity and access management (IAM)</u></a> solutions. These can automatically identify anomalous behavior and be used by security teams to strip users of certain privileges from a central console.</p><p>Just because your organization hasn’t been noticeably breached doesn’t mean that it’s safe. Some threat groups choose to quietly breach firms and then <a href="https://www.itpro.com/security/data-breaches/breached-for-years-how-long-term-cyber-attacks-are-allowed-to-linger"><u>skulk in their IT estates for years</u></a>. </p><p>During this time, hackers gather data on users to identify who has privileged access, what behaviors will and will not fly under the radar, and the times of day that their victim will be most vulnerable to attack.</p><p>Attackers can benefit from entering systems as quietly as possible to do more damage down the line, using the interim to collect more information or identify potential vulnerabilities that they can exploit to steal valuable information or disrupt cloud services.</p><p>Once attackers have breached an enterprise cloud environment, they are often able to move laterally throughout systems to wherever their attacks will do the most damage. </p><p>It&apos;s in situations like these that businesses can benefit from <a href="https://www.itpro.com/security/what-is-zero-trust-network-access-ztna"><u>zero trust network access (ZTNA)</u></a>, in which no one user profile is treated as automatically safe as a matter of policy. </p><h2 id="malware-and-other-forceful-attacks">Malware and other forceful attacks</h2><p>Once inside a network, attackers will often seek to spread <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> such as <a href="https://www.itpro.com/cloud/367210/what-is-cloud-ransomware"><u>cloud ransomware</u></a> is a top threat to businesses. </p><p>One of the main reasons hackers will target the cloud with ransomware is because it makes for excellent leverage with which to pry a payment from their victims. Not all businesses may choose to pay the ransom demanded by their attackers – but threat actors know that few businesses can stand cloud downtime for too long without reputational damage and severe loss of profits.</p><p>A growing concern of the past few years has been the lowering barrier to entry for would-be ransomware groups, as the <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware"><u>ransomware as a service (RaaS)</u></a> becomes more entrenched. This allows any hacker to purchase effective strains of ransomware via the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web"><u>dark web</u></a> and then use it against victims’ infrastructure and cloud. </p><p>Hackers can also use dark web services such as <a href="https://www.itpro.com/security/hacking/368756/what-is-dark-utilities-c2-as-a-service-c2aas"><u>Dark Utilities C2</u></a> to launch other campaigns such as <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack"><u>distributed denial of service (DDoS)</u></a> attacks.</p><p>Undoubtedly the most blunt way hackers opt for when targeting the cloud is a DDoS attack. This approach sees threat actors overwhelm a website or cloud instance with a massive number of access requests to knock it offline. Like cloud ransomware, this attack methodology is all about maximum damage, and bouncing back will hinge on whether a business has a concrete backup strategy. </p><p>But even cloud ransomware comes with the promise – however untrustworthy – of data decryption if the price is paid. DDoS attacks tend to be far more two-dimensional, the downtime being the entire point rather than the means to a profitable end for the perpetrators.</p><p>Often, attackers will leverage the combined output of a <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet"><u>botnet</u></a>, a horde of infected devices they control around the world. Using these zombie IoT networks, they wield DDoS capabilities measured in the millions of requests per second (rps) – Google Cloud <a href="https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps"><u>measured a 398 million rps</u></a> attack in 2023.</p><p>Some firms offer mitigation against DDoS attacks, but they remain an effective avenue of attack for threat actors and <a href="https://www.itpro.com/security/ddos-attacks-are-still-growing-and-there-are-new-threats-on-the-horizon"><u>are on the rise</u></a>.</p><p><a href="https://www.itpro.com/security/cyber-attacks/how-to-recover-from-a-ddos-attack-and-what-they-can-teach-businesses"><u>Recovering from a DDoS attack</u></a> can be a complex process. On the one hand, leaders will be keen for their systems to be brought back online as quickly as possible to stem reputational damage and loss of revenue – a particular concern if the attack successfully knocked out front-end systems like the homepage of your company’s website. </p><p>Leaders must also ensure their cloud environment is restored intact and give security teams the time to have complete confidence that everything is configured correctly when it’s stood back up.</p><p>This cuts to the heart of the problem for businesses looking to thrive in the cloud. Operating in this modern environment is a constant balancing act of making the most of the expansion and tools at your disposal and keeping one eye on how each cloud instance could be compromised.</p><p>Knowing what’s out there is essential, but this process never ends. Leaders must constantly refresh their understanding of threats and bad actors and keep their employees trained to deal with the latest cloud threats.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What are the benefits of unified cloud security? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/what-are-the-benefits-of-unified-cloud-security</link>
                                                                            <description>
                            <![CDATA[ As cloud adoption accelerates, the complexity of managing multi-cloud environments presents significant security challenges. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ffCLj4uVJhTzoh3pHr8zAT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6zvLhxX6fpdjzFD8FCfGAN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Sep 2024 15:47:27 +0000</pubDate>                                                                                                                                <updated>Mon, 02 Sep 2024 15:50:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rene Millman) ]]></author>                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6zvLhxX6fpdjzFD8FCfGAN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Multi-cloud concept art showing digital cloud symbol surrounded by several other cloud symbols.]]></media:description>                                                            <media:text><![CDATA[Multi-cloud concept art showing digital cloud symbol surrounded by several other cloud symbols.]]></media:text>
                                <media:title type="plain"><![CDATA[Multi-cloud concept art showing digital cloud symbol surrounded by several other cloud symbols.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6zvLhxX6fpdjzFD8FCfGAN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As cloud computing continues to reshape the landscape of modern business, the surge in cloud adoption is accompanied by growing concerns about security. A recent survey by the<a href="https://cloudsecurityalliance.org/artifacts/the-state-of-security-remediation-survey-report"> <u>Cloud Security Alliance (CSA) in February 2024</u></a> found that more than 77% of organizations feel unprepared to handle the security threats that cloud environments present. This sentiment is compounded by the fact that many organizations struggle to achieve full visibility in their cloud environments, with only 23% reporting optimal transparency.</p><p>“As cybersecurity threats evolve, organizations must adapt by seeking better visibility into their code-to-cloud environment, identifying ways to accelerate remediation, strengthening organizational collaboration, and streamlining processes to counter risks effectively,” says Hillary Baron, senior technical director for research at the CSA. </p><p>As cloud infrastructures become the backbone of modern enterprises, safeguarding these environments is crucial. This is where unified cloud security comes into play—a holistic approach designed to provide comprehensive protection across complex, multi-layered cloud environments.</p><p>This strategy promises to streamline operations, enhance threat detection, and simplify compliance across multi-cloud landscapes. With the complexity of managing different cloud services and providers, the unified approach is no longer a luxury but a necessity. As cyber threats grow in sophistication, organizations must rethink their security strategies, ensuring they are equipped to handle emerging risks.</p><h2 id="understanding-unified-cloud-security">Understanding unified cloud security</h2><p>Unified cloud security refers to an integrated approach that consolidates security measures across various cloud environments, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). This model centralizes security management, enabling organizations to monitor and control their cloud resources from a single platform. Unlike traditional security models, which often operate in silos, unified cloud security offers a comprehensive view, breaking down barriers between different cloud services​, according to the <a href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-product-and-services/security/pdf/2024-State-of-Multicloud-Security-Risk-Report.pdf"><u>2024 State of Multicloud Security Report by Microsoft</u></a>. </p><p>"Ultimately, multi-cloud security has multiple considerations that security teams must account for. It is not a check-the-box endeavor," says Andrew Conway, vice president, Security Marketing at Microsoft.</p><p>"Rather, security teams must continuously enforce best practices from the earliest stages of development to runtime, identity and access management, and data security. Not only must these best practices be enforced throughout the full cloud lifecycle, but they must also be standardized across all cloud platforms."</p><p>Key components include centralized management, integrated threat intelligence, and automated compliance checks. The goal is to provide seamless protection across multiple cloud providers and environments, ensuring that security policies are consistently applied. As organizations increasingly adopt multi-cloud strategies, the complexity of managing disparate security solutions has become apparent. A unified approach simplifies security operations and enhances the ability to detect and respond to threats in real time, making it an essential strategy for modern enterprises.</p><h2 id="the-growing-need-for-unified-cloud-security">The growing need for unified cloud security</h2><p>With the rapid adoption of cloud technologies, businesses face new security challenges. A recent study by Microsoft revealed that the average multi-cloud environment has 351 exploitable attack paths, highlighting the complexity of managing security across diverse platforms​. Multi-cloud strategies offer flexibility and resilience, but they also introduce fragmented security practices, increasing the risk of breaches. </p><p>The <a href="https://cpl.thalesgroup.com/cloud-security-research"><u>Thales Cloud Security Study</u></a> (published March 2024)reports that 44% of organizations experienced a cloud data breach in the past year, underscoring the urgency of a unified security approach​. As organizations deploy more SaaS applications, with over 60% using more than 25 apps, managing security becomes even more complex​. </p><p>"Compliance is key. In fact, companies that had a good hold over their compliance processes and passed all their audits were also less likely to suffer a breach,” says Sebastien Cano, senior vice president at Thales Cloud Protection and Licensing. </p><p>“We’ll start to see more compliance and security functions coming together. This would be a huge positive step to strengthen cyber defenses and build trust with customers." </p><p>Unified cloud security addresses these challenges by offering a centralized management system that provides visibility and control across all cloud environments. By integrating security tools and processes, businesses can reduce vulnerabilities and improve their overall security posture, ensuring they are better prepared to tackle the evolving threat landscape.</p><h2 id="key-benefits-of-unified-cloud-security">Key benefits of unified cloud security</h2><p>Unified cloud security offers several critical advantages that address the challenges posed by modern cloud environments. Firstly, it provides centralized management, allowing security teams to monitor and control cloud assets from a single dashboard, reducing complexity and enhancing efficiency​. This centralization simplifies the management of security policies and ensures consistent application across all cloud platforms. </p><p>Secondly, integrated threat intelligence enhances threat detection and response capabilities. By consolidating data from multiple sources, organizations can quickly identify and respond to potential threats​. Thirdly, automated compliance checks streamline regulatory compliance, reducing the burden on IT teams and minimizing the risk of human error​. As regulatory requirements become more stringent, automated tools ensure organizations remain compliant without manual intervention. </p><p>Finally, unified cloud security solutions are designed to be scalable and flexible, adapting to the changing needs of businesses. This scalability is essential for organizations looking to grow their cloud environments while maintaining robust security measures.</p><h2 id="challenges-considerations-and-best-practice">Challenges, considerations, and best practice</h2><p>Implementing unified cloud security has its challenges. Misconfigurations are a leading issue, accounting for <a href="https://go.crowdstrike.com/global-threat-report-2024.html"><u>36% of cloud breaches</u></a> due to human error and inadequate change control mechanisms. Effective management tools are essential to prevent unauthorized access and data exposure. Another critical challenge is identity, credentials, access, and key management. With 80% of breaches involving compromised credentials, weak password policies, and lack of multi-factor authentication remain vulnerabilities that need addressing​.</p><p>What’s more, the dynamic nature of cloud environments introduces complexities as new assets and services are continuously added, necessitating continuous monitoring and adaptation to emerging threats​. The widespread adoption of cloud services often outpaces the development of comprehensive security architectures. This gap is exacerbated by a shortage of skilled professionals in cloud security, increasing the risk of misconfigurations and ineffective security measures​. Organizations must prioritize training and strategic alignment to overcome these hurdles effectively.</p><p>To strengthen cloud environments, unified cloud security demands an integrated approach, blending various defensive strategies. Centralized security management is crucial, enabling enhanced visibility and control across disparate cloud resources from a single platform. This central oversight is complemented by robust identity and access management policies that ensure only authorized personnel can access critical systems and data, often fortified by multi-factor authentication and stringent access controls. </p><p>Additionally, encrypting data both at rest and in transit forms a fundamental barrier against unauthorized access. Regular security assessments, including audits and vulnerability scans, are essential to identify and address potential risks promptly. Moreover, maintaining compliance with evolving regulatory standards helps organizations navigate the legal complexities of digital data management, ensuring they meet industry standards and avoid penalties. These practices, when consistently applied, significantly strengthen the security posture of cloud-based infrastructures.</p><h2 id="embracing-a-unified-future">Embracing a unified future</h2><p>Unified cloud security is essential in the face of increasing cloud adoption and sophisticated cyber threats. By providing centralized management and integrating advanced threat detection capabilities, unified security solutions enhance an organization&apos;s ability to protect its digital assets. However, challenges such as misconfiguration, identity management, and expertise gaps must be addressed to fully realize the benefits​.</p><p>Real-world examples from the finance and healthcare sectors illustrate the tangible advantages of adopting a unified approach, showcasing improvements in efficiency, compliance, and resilience against threats. As businesses continue to expand their cloud environments, prioritizing unified security solutions is crucial to safeguarding their operations and maintaining customer trust. Moving forward, organizations must invest in training and strategic alignment to stay ahead in the ever-evolving cloud security landscape​.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Enterprises beware, your LLM servers could be exposing sensitive data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/enterprises-beware-your-llm-servers-could-be-unintentionally-exposing-sensitive-data</link>
                                                                            <description>
                            <![CDATA[ New research lays bare the lack of robust security protections on the servers hosting many businesses’ AI services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">w65WPcGppdeVfBRuVoyR3G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jtFdkp7DfZ2KyuCDJChFiL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Sep 2024 11:03:34 +0000</pubDate>                                                                                                                                <updated>Mon, 02 Sep 2024 16:32:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jtFdkp7DfZ2KyuCDJChFiL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract technology image of running program code on digital data wave.]]></media:description>                                                            <media:text><![CDATA[Abstract technology image of running program code on digital data wave.]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract technology image of running program code on digital data wave.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jtFdkp7DfZ2KyuCDJChFiL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Publicly accessible <a href="https://www.itpro.com/technology/artificial-intelligence/the-costs-of-building-generative-ai-platforms-are-racking-up">AI platforms</a> may be exposing your corporate data on the internet, new research warns.</p><p>Legit Security recently published an <a href="https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services#conclusion" target="_blank"><u>investigation</u></a> into security issues affecting the infrastructure underpinning many businesses’ <a href="https://www.itpro.com/business/acquisition/datastax-wants-to-create-a-one-stop-generative-ai-application-stack-with-langflow-acquisition">AI applications</a>, suggesting these systems could also be susceptible to data leakage and data poisoning.</p><p>The research highlighted risks associated with two popular types of publicly accessible AI services: vector databases and <a href="https://www.itpro.com/technology/artificial-intelligence/google-shows-off-new-smaller-generative-ai-tools-and-an-ai-agent-on-your-phone">LLM tools</a>. </p><p>Vector databases used to store unstructured data for <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> applications, allowing the systems to search the database according to similarity instead of exact matches.</p><p>Researchers found these databases often lack basic <a href="https://www.itpro.com/security/jailbreaking-chatgpt-researchers-swerved-gpt-4s-safety-guardrails-and-made-the-chatbot-detail-how-to-make-explosives-in-scots-gaelic">security guardrails</a>, highlighting  a number of cases where they found publicly accessible instances allowing anonymous access with no permission enforcement. </p><p>This meant that anyone with network access to the server would be able to read sensitive data inside, including metadata, as well as the embeddings – the numerical representations of words, images, or videos used by <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models#:~:text=What%20are%20large%20language%20models,produce%20contextually%20relevant%20text%20outputs.">LLMs</a>.</p><p>These embeddings could be used by attackers to reverse engineer the transformer used by the model to recover input data, according to <a href="https://arxiv.org/pdf/2305.03010" target="_blank"><u>research</u></a> from the Hong Kong University of Science and Technology.</p><p>These systems are also vulnerable to data poisoning attacks, the report noted, whereby attackers alter <a href="https://www.itpro.com/tag/databases">databases</a> so it changes the behavior of the AI applications built on that dataset.</p><p>Legit Security offered a number of examples of how this attack could unfold. For example, hackers could modify a vector database and make a client-facing chatbot instruct customers to download and install <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> on their devices.</p><p>Another example suggested <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369979/chatgpt-vs-chatbots-whats-the-differencehttps://www.itpro.com/networking/27171/what-is-a-chatbot">chatbots</a> used for <a href="https://www.itpro.com/technology/artificial-intelligence-ai/354520/how-ai-can-improve-medical-diagnosis">medical consultations</a> with access to historical patient data could be manipulated into providing false or dangerous advice.</p><p>In addition, researchers warned the software installed on servers hosting these vector databases contain vulnerabilities that attackers could potentially exploit to exfiltrate or <a href="https://www.itpro.com/security/hackers-are-deliberately-poisoning-ai-systems-to-make-them-malfunction-and-theres-no-way-to-defend-against-it">poison the data</a> they contain.</p><h2 id="almost-half-of-scanned-flowise-servers-vulnerable-to-x201c-simple-authentication-bypass-vulnerability-x201d-xa0">Almost half of scanned Flowise servers vulnerable to “simple authentication bypass vulnerability” </h2><p>Legit Security’s investigation used scanning tools to identify a number of publicly accessible <a href="https://www.itpro.com/big-data-analytics/34532/structured-vs-unstructured-data-management">vector database </a>instances, checking for required authentication and whether it was possible to extract data from the system.</p><p>The researchers found around 30 servers with evidence of corporate or private data, such as <a href="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services">private company emails</a>, customer PII, <a href="https://www.itpro.com/business/business-strategy/369616/msg-giant-ajinomoto-chipmaking-foray-financial-records">financial records</a>, and prospect resumes and contact information. </p><p>It found some of these servers were susceptible to data poisoning, including one storing patient information for a medical chatbot, company Q&A data, and a real estate agency’s property data.</p><p>In each of these cases, the attackers would not have needed to <a href="https://www.itpro.com/security/exploits/360411/top-30-most-exploited-vulnerabilities">exploit a vulnerability</a> or use specific tools to read the data, and were able to use the REST-API or Web UI to modify or delete data.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4NRugTirU23u982cbhNrue" name="AI demands new ways of data management 2.jpg" caption="" alt="Shipping dock with container units" src="https://cdn.mos.cms.futurecdn.net/4NRugTirU23u982cbhNrue.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/ai-demands-new-ways-of-data-management"><em>Ensure that applications run with optimal performance</em></a></p></div></div><p>In addition to vector databases, the report found publicly exposed LLM tools suffered from a similar lack of security layers, highlighting one particular tool – Flowise – a <a href="https://www.itpro.com/software/development/369154/why-low-code-and-no-code-can-be-a-route-through-recession">low-code</a> LLM automation service.</p><p>Tools like Flowise have access to a wide range of sensitive data including private company information , <a href="https://www.itpro.com/security/data-breaches/359637/misconfigured-cloud-services-exposed-100-million-android-users-data">application configurations</a>, and prompts. </p><p>Many businesses integrate these tools with external services like the <a href="https://www.itpro.com/business/business-strategy/370170/openai-launches-chatgpt-api-for-businesses-at-competitive-price">OpenAI API</a>, <a href="https://www.itpro.com/technology/artificial-intelligence/aws-invests-dollar4-billion-in-anthropic-to-improve-bedrock-experience">AWS Bedrock</a>, Confluence, or <a href="https://www.itpro.com/software/development/everything-you-need-to-know-about-github-models-the-new-ai-testing-playground-for-developers">GitHub</a>, the report noted, meaning any credential leakage related to the integrations could lead to an even wider breach upstream.</p><p>Researchers scanned for public instances of Flowise servers and found the majority were password-protected, but warned it found a number of “simple vulnerabilities” in early versions of the platform. </p><p>For example, 45% of the 959 servers assessed by the researchers were found to be vulnerable to an <a href="https://www.itpro.com/security/seven-asus-routers-impacted-by-critical-authentication-bypass-flaw">authentication bypass vulnerability</a> (CVE-2024-31621).</p><p>Moreover, scanning the data in the servers it found a “couple dozen secrets”, including <a href="https://www.itpro.com/technology/artificial-intelligence/openais-regulatory-probes-explained">OpenAI</a> API keys, GitHub access tokens, URLs with database passwords, as well as API keys for Pinecone vector databases. </p><p>Businesses should reevaluate what platforms their developers are using, Legit Security advised, and should immediately implement a strict permissions system to prevent anonymous access. </p><p>“If possible, do not publicly expose these services, and manage access through <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/367994/vpn-or-virtual-private-networks-what-businesses">private networks</a>,” the report added.</p><p>Another precaution the report suggested is to ensure that any client PII and other sensitive information are removed from the data used by their AI services, to avoid potentially costly data leakage.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the Wiz acquisition makes perfect sense for Google ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/why-the-wiz-acquisition-makes-perfect-sense-for-google</link>
                                                                            <description>
                            <![CDATA[ Bringing Wiz under the Google umbrella would markedly improve the tech giant’s cybersecurity capabilities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DWrS5x8mfER59HHRSykCr5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wTLVoqdkRzNqygsM3KpFBJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Jul 2024 09:04:05 +0000</pubDate>                                                                                                                                <updated>Wed, 17 Jul 2024 11:16:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wTLVoqdkRzNqygsM3KpFBJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wiz logo pictured on a laptop screen.]]></media:description>                                                            <media:text><![CDATA[Wiz logo pictured on a laptop screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Wiz logo pictured on a laptop screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wTLVoqdkRzNqygsM3KpFBJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google’s rumored acquisition of cyber security startup Wiz makes sense for the tech giant and would represent a bold effort to bolster its cloud security capabilities, analysts have told <em>ITPro</em>. </p><p>Speculation over a potential move began circulating over the weekend, with initial reports from the <a href="https://www.wsj.com/business/deals/google-near-23-billion-deal-for-cybersecurity-startup-wiz-622edf1a" target="_blank"><em>Wall Street Journal</em></a> suggesting the deal could be worth $23 billion, making it Google’s most expensive acquisition ever.</p><p>This alone speaks volumes, according to Charlie Winckless, VP analyst for cloud security at Gartner. He told <em>ITPro</em> that an acquisition of this size represents a major signal of intent for Google.</p><p>“It’s an <em>extremely</em> large acquisition,” he said. “And it’s very much tied into Google’s cloud approach. It’s [Wiz] a very strong brand with strong capabilities in the cloud native application protection platform (CNAPP) space.”</p><p>Notably, Winckless said the valuation touted for this deal is larger than the estimated market capitalization of the CNAPP market.</p><p>Specializing in <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a>, Wiz is a relatively young company, having been founded in 2020. The company’s flagship tools provide users with a cloud native security platform that offers threat prevention and rapid incident response capabilities.</p><p>With organizations shifting en-masse to the cloud during the onset of the Coronavirus pandemic, a sharp demand for cloud security services saw the company expand rapidly. In the space of four years, the New York-headquartered firm’s headcount has grown to around 900, and earlier this year it was valued at $12 billion.</p><p>It boasts around 40% of Fortune 100 companies as its clients and works with a number of leading brands including Salesforce, BMW, as well as AWS and Microsoft – Google’s leading competitors in the cloud space.</p><p>This rapid growth underlines the insatiable appetite for cloud security tools in the enterprise, Winckless noted.</p><p>“They are a necessity, whether provided by the cloud provider themselves – and each of the cloud providers provides these capabilities within their cloud – or for the many organizations that are intentionally or accidentally in a multi-cloud strategy,” he said.</p><p>“These tools provide consistent visibility across major hyperscaler environments. bring together many of the components of cloud risk.”</p><p>Google Cloud CEO Thomas Kurian is believed to be the key proponent of a move to acquire the startup, according to the <a href="https://www.nytimes.com/2024/07/14/technology/google-wiz-deal.html"><em>New York Times</em></a>, which again highlights where the company’s intentions lie.</p><p>Any potential acquisition would markedly improve the tech giant’s capabilities amidst what is an increasingly perilous time for organizations operating in the cloud.</p><p><a href="https://www.itpro.com/cloud/cloud-security/cloud-security-breaches-surge-on-a-wave-of-stolen-credentials">Cloud security threats</a> have increased rapidly in recent years. With enterprises now hosting much of their critical data in the cloud, these environments are viewed by threat actors as a highly lucrative target - especially sophisticated, state-backed <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> groups.</p><p>Research from CrowdStrike earlier this year, for example, noted that rapid growth in this domain means the cloud is <a href="https://www.itpro.com/cloud/cloud-security/cloud-security-breaches-surge-on-a-wave-of-stolen-credentials">becoming a “major battleground for cyber attacks”.</a></p><p>With this in mind, it makes sense that Google would want to further add to its portfolio and provide cloud customers with a wider array of tools to contend with rising threats.</p><p>“I think cloud is the major battleground for cyber attacks largely because the cloud is part of everybody’s IT infrastructure at this point,” Winckless said. “The cloud is an increasingly critical, if not already critical part of at least 80% of organizations.</p><p>“It’s newer and requires the same security outcomes but must be delivered with different tools and different approaches. That means there’s an exposure there for organizations.”</p><h2 id="wiz-acquisition-will-x201c-jump-start-x201d-google-x2019-s-cloud-security-goals">Wiz acquisition will “jump-start” Google’s cloud security goals</h2><p>Notably, Winckless said this acquisition will “jump-start Google’s presence” in the cloud security market. The company already boasts an impressive roster with regard to cybersecurity, having <a href="https://www.itpro.com/security/367021/google-buys-cyber-security-firm-mandiant-for-54-billion">acquired Mandiant in 2022 as part of a $5.4 billion deal</a>.</p><p>That same year saw Google acquire Israeli startup Siemplify in a $500 million deal to further bolster its ‘Chronicle’ cloud security initiative.</p><p>What this acquisition also signals heavily, however, is the company’s continued efforts to improve <a href="https://www.itpro.com/hybrid-cloud/34384/multi-cloud-vs-hybrid-cloud-whats-the-difference">multi-cloud</a> security capabilities. While public cloud still dominates the industry, enterprises are increasingly moving toward a <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud">multi-cloud</a> approach, whereby they use two or more major cloud providers.</p><p>Earlier this year, the firm expanded its Security Command Center Enterprise to provide users with extended security capabilities across multi-cloud environments, such as AWS. With this acquisition, Google will essentially be hedging its bets by expanding security tools to work across a wider range of providers.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ycFBZF6KciPyuBFsmPxQJ7" name="Insights on SAP_ How cloud, data, and AI are transforming ERP.jpg" caption="" alt="Insights on SAP: How cloud, data, and AI are transforming ERP" src="https://cdn.mos.cms.futurecdn.net/ycFBZF6KciPyuBFsmPxQJ7.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/insights-on-sap-how-cloud-data-and-ai-are-transforming-erp"><em>Enable foundation model customization</em></a></p></div></div><p>“Wiz has better coverage and moves into Azure,” Winckless said. “So it really moves them very far forward in this and associates them with a strong brand in the security space. Mandiant was, and is, a very strong brand.”</p><p>Google’s counterparts in the <a href="https://www.itpro.com/627952/what-is-cloud-computing">cloud computing</a> space have been expanding their multi-cloud security capabilities, Winckless noted, which may be a key motivating factor in this deal.</p><p>“We have seen efforts from the other cloud providers, Microsoft in particular, to expand their coverage of other clouds with Microsoft Defender CSPM. And this really puts Google head to head with that offering in that space.”</p><p>Dr Marc Manzano, general manager for <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> at SandboxAQ, echoes Winckless’ thoughts in this regard, adding that Google has traditionally lagged behind AWS and <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws">Azure</a> on this front.</p><p>“Following its acquisitions of Mandiant and Siemplify, the potential acquisition of Wiz highlights Google&apos;s ambition to dominate the cloud security space,” he said.</p><p>“Wiz&apos;s technology can be utilized to protect infrastructure across AWS, Azure, and other cloud platforms, so this move would enable Google to build connections to other cloud providers"</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Critical OpenSSH vulnerability leaves over 14 million servers potentially at risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/first-openssh-vulnerability-in-nearly-two-decades-leaves-over-14-million-servers-potentially-at-risk</link>
                                                                            <description>
                            <![CDATA[ Researchers have uncovered the first security flaw affecting OpenSSH in almost two decades, and it's a big one – here’s what you need to know ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ggzx8Y8cUGweavQ9qEETyg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RQtnodCCRZfLsvPx4M93P-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Jul 2024 15:39:52 +0000</pubDate>                                                                                                                                <updated>Tue, 02 Jul 2024 10:01:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RQtnodCCRZfLsvPx4M93P-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity concept image showing digitized padlock resting on top of circuit boards.]]></media:description>                                                            <media:text><![CDATA[cybersecurity concept image showing digitized padlock resting on top of circuit boards.]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity concept image showing digitized padlock resting on top of circuit boards.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RQtnodCCRZfLsvPx4M93P-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers at cybersecurity platform Qualys have <a href="https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server" target="_blank"><u>uncovered</u></a> a critical security flaw in OpenSSH’s server (sshd) in glibc-based <a href="https://www.itpro.com/software/linux">Linux</a> systems, which could potentially impact over 14 million <a href="https://www.itpro.com/server-storage/network-attached-storage-nas/361938/qnap-warns-ransomware-targeting-nas-devices">internet-facing servers</a>.</p><p>CVE-2024-6387 is an unauthenticated <a href="https://www.itpro.com/security/32215/remote-code-execution-flaw-found-in-cisco-webex">remote code execution</a> (RCE) vulnerability that could grant threat actors full <a href="https://www.itpro.com/android/28295/how-to-unroot-androidhttps://www.itpro.com/software/linux/362069/pwnkit-12-year-old-linux-root-privilege-flaw-hiding-plain-sight">root access</a> if exploited successfully.</p><p>The <a href="https://www.qualys.com/regresshion-cve-2024-6387/" target="_blank"><u>blog</u></a> noted this flaw marks the first security vulnerability affecting <a href="https://www.itpro.com/security/cyber-attacks/openssh-vulnerability-uncovered-by-researchers-rce-exploit-developedhttps://www.itpro.com/security/cyber-security/359457/what-are-ssh-keys">OpenSSH</a> in nearly two decades, and is especially dangerous by virtue of the number of enterprises that rely on the tool for remote <a href="https://www.itpro.com/business-strategy/automation/370029/automation-the-key-to-optimised-server-management">server management</a>.</p><p>Qualys’ Threat Research Unit (TRU) labeled the flaw the ‘regreSSHion bug’ due to the fact it is a regression of a <a href="https://www.itpro.com/security/cyber-attacks/novel-china-linked-linux-backdoor-exploits-organizations-that-fail-to-patch-old-vulnerabilities">previously patched vulnerability</a> CVE-2006-5051, initially reported in 2006. </p><p>Regression here refers to the mechanism by which a security vulnerability, once fixed, is reintroduced into an environment through a subsequent <a href="https://www.itpro.com/marketing-comms/e-commerce/361661/smbs-urged-to-update-software-ahead-of-black-friday">software update</a>.</p><p>This regression bug was reintroduced in October 2020 in OpenSSH 8.5p1, according to Qualys, and highlights the importance of rigorous <a href="https://www.itpro.com/desktop-software/28859/what-is-regression-testing">regression testing</a> to prevent the resurrection of <a href="https://www.itpro.com/security/patch-management-why-firms-ignore-vulnerabilities-at-their-own-risk">known vulnerabilities</a>.</p><p>CVE-2024-6387 affects the default configuration of OpenSSH and does not require any user interaction, therefore posing a significant risk of exploitation.</p><p>Using services like <a href="https://www.itpro.com/security/cisco-zero-day-vulnerability-hits-40000-devices-in-a-matter-of-days">Censys</a> and <a href="https://www.itpro.com/cloud-storage/32484/unsecured-server-leaks-details-of-32-million-sky-brazil-subscribers">Shodan</a>, Qualys identified over 14 million potentially vulnerable OpenSSH server instances exposed to the internet. </p><p>Furthermore, anonymized data from Qualys’ attack surface management cloud service CSAM 3.0 revealed approximately 700,000 external internet-facing instances are vulnerable. </p><p>This would make up 31% of all internet-facing instances of OpenSSH in Qualys’ global customer base.</p><h2 id="x201c-about-as-bad-as-they-come-x201d-cve-2024-6387-is-triply-dangerous">“About as bad as they come” - CVE-2024-6387 is triply dangerous</h2><p>Ray Kelly, fellow at the Synopsys Software Integrity Group, said the combination of RCE, root access, and broad distribution makes this vulnerability particularly worrying, and patching all vulnerable instances is not going to be a simple task.</p><p>“This vulnerability is about as bad as they come. A trifecta of Remote code execution, root access, and a widespread distribution across Linux servers makes this a <a href="https://www.itpro.com/security/cyber-attacks/email-still-the-top-vector-for-attackers">hot target for threat actors</a>,” he explained.</p><p>“Although an OpenSSH patch is available, deploying it across all affected systems—potentially impacting 14 million OpenSSH instances—poses a significant challenge.  This vulnerability could persist for a long time, reminiscent of the <a href="https://www.itpro.com/security/369419/second-ever-openssl-critical-vulnerability-teased-10-years-after-heartbleed">Heartbleed vulnerability</a> in OpenSSL from 2014."</p><p>Synopsys’ principal consultant, Thomas Richards, added he predicts there will be a spike in exploitations of IoT systems as a result, as systems are increasingly treated like one-time-use devices and are not updated frequently.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WEBINAR</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cY5fMMqGypyVeYVaEHdyTk" name="Protect Your Attack Vectors From Emerging Threats.jpg" caption="" alt="Protect your attack vectors from emerging threats" src="https://cdn.mos.cms.futurecdn.net/cY5fMMqGypyVeYVaEHdyTk.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/protect-your-attack-vectors"><em>Tips on how to reduce your attack surface</em></a></p></div></div><p>"I suspect we’ll see a rise in compromises of embedded and IoT systems, as many consumer models are meant to be disposable and rarely get updates. A vulnerability like this could be used by attackers over a long period of time, as older systems do not get updates or as organizations are slow to patch."</p><p>Qualys recommends enterprises immediately apply patches for OpenSSH, limiting SSH access through network-based controls to reduce the risk of attack, as well as implementing robust network segmentation to minimize the disruption a successful intruder could cause.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Enterprises need to get a 'firm grasp' on attack surfaces as cloud breaches surge ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/enterprises-need-to-get-a-firm-grasp-on-attack-surfaces-as-cloud-breaches-surge</link>
                                                                            <description>
                            <![CDATA[ A surge in cloud breaches means organizations needs to get a tighter grip on attack surfaces, researchers have warned ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nKokMbzEz4Hfvc8Uc3EDaf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bVfwdN9N9AcRT3fun4mohN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Jun 2024 10:31:12 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Jun 2024 13:50:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bVfwdN9N9AcRT3fun4mohN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Public Cloud concept image showing digitized cloud image looming over map of Europe with multiple separate cloud images surrounding it.]]></media:description>                                                            <media:text><![CDATA[Public Cloud concept image showing digitized cloud image looming over map of Europe with multiple separate cloud images surrounding it.]]></media:text>
                                <media:title type="plain"><![CDATA[Public Cloud concept image showing digitized cloud image looming over map of Europe with multiple separate cloud images surrounding it.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bVfwdN9N9AcRT3fun4mohN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloud breaches have been rising steadily in recent years, according to a new report from Thales, with nearly half of firms having recorded a serious incident. </p><p>Analysis by Thales shows that 14% of firms experienced a cloud breach in the last year, and the most common <a href="https://www.itpro.com/cloud/361113/the-rise-of-cloud-misconfiguration-threats-and-how-to-avoid-them">cause was human error and misconfiguration</a>.</p><p>The firm warned that threat actors are also ramping up exploitation of known vulnerabilities, with 28% of all recorded breaches due to this. Similarly, a failure to use <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA) </a>was behind around 17% of all breaches.</p><p>The main targets were <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS</a> applications, cited by 31%, followed by <a href="https://www.itpro.com/cloud-storage/29761/our-5-minute-guide-to-hybrid-cloud-storage">cloud storage</a> at 30%, and cloud infrastructure at 26%.</p><p>These <a href="https://www.itpro.com/security/cyber-security/369983/what-is-attack-surface-management">attack surfaces</a> are increasing, Thales warned, which involved a survey of nearly 3,000 organizations with revenues of between $100 million and $250 million.</p><p>Two-thirds of organisations are now using more than 25 SaaS applications, and nearly half of corporate data is rated as being sensitive. Despite this, however, data encryption rates remain low, with fewer than 10% of enterprises encrypting 80% or more of their sensitive cloud data.</p><p>"The scalability and flexibility that the cloud offers is highly compelling for organizations, so it’s no surprise it is central to their <a href="https://www.itpro.com/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy">security strategies</a>," said Sebastien Cano, senior vice president for cloud protection and licensing activities at Thales.</p><p>"However, as the cloud attack surface expands, organizations must get a firm grasp on the data they have stored in the cloud, the keys they’re using to encrypt it, and the ability to have complete visibility into who is accessing the data and how it is being used."</p><h2 id="data-sovereignty-considerations-boom-amid-rise-in-cloud-breaches">Data sovereignty considerations boom amid rise in cloud breaches</h2><p>Cano added that new considerations such as <a href="https://www.itpro.com/cloud/367052/data-sovereignty-a-boon-for-msps">data sovereignty</a> and growing scrutiny of privacy practices means it’s vital that organizations bolster cloud security capabilities moving forward.</p><p>Nearly half of organizations said it&apos;s more difficult to manage compliance and privacy in the cloud, compared with on-premises.</p><p>Companies are modernizing and increasing their investments to meet these new security challenges, however. For those that prioritize digital sovereignty as an emerging security concern, most chose to refactor applications to logically separate, secure, store, and process cloud data ahead of other measures such as repatriating workloads back to on-prem.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WEBINAR</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7Kp8C82FgtJ4XYZ3pQ2yoH" name="Protect Your Attack Vectors From Emerging Threats (1).jpg" caption="" alt="Protect Your Attack Vectors From Emerging Threats" src="https://cdn.mos.cms.futurecdn.net/7Kp8C82FgtJ4XYZ3pQ2yoH.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/protect-your-attack-vectors"><em>An effective way to reduce your attack surface</em></a></p></div></div><p>Future-proofing cloud environments was the leading driver behind digital sovereignty initiatives, cited by more than three-in-ten organizations, while adhering to regulations came in at a distant second at 22%.</p><p>The rise in cloud attacks comes amid a renewed focus on cloud migration among enterprises globally. In a recent study by Gartner, the consultancy predicted that by 2027 more than 70% of enterprises will use industry cloud platforms.</p><p>This marks a sharp increase compared to the 15% recorded in 2023, Gartner noted.</p><p>As a result of this, the consultancy said it expects <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a> investment to grow by 24% in 2024.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How the UK’s Ministry of Defence is overhauling its internal cloud with a secure by design approach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/how-the-uks-ministry-of-defence-is-overhauling-its-internal-cloud-with-a-secure-by-design-approach</link>
                                                                            <description>
                            <![CDATA[ With the goal of consolidating its internal network, the MoD has turned to automated threat detection and questioning the effectiveness of practices such as air gapping ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PaUhz5GHzGF8TMRLEGxtJE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bzzyFXtajtFRL2hJnDABTQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Jun 2024 12:43:17 +0000</pubDate>                                                                                                                                <updated>Thu, 20 Jun 2024 14:54:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Peter Ray Allison ]]></dc:creator>                                                                                                                                                                                                                                                                    <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bzzyFXtajtFRL2hJnDABTQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Peter Ray Allison]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Harry Gazzard, a solutions architect working for the MoD on its digital transformation project, speaking at a panel at Infosecurity Europe 2024.]]></media:description>                                                            <media:text><![CDATA[Harry Gazzard, a solutions architect working for the MoD on its digital transformation project, speaking at a panel at Infosecurity Europe 2024.]]></media:text>
                                <media:title type="plain"><![CDATA[Harry Gazzard, a solutions architect working for the MoD on its digital transformation project, speaking at a panel at Infosecurity Europe 2024.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bzzyFXtajtFRL2hJnDABTQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s Ministry of Defence (MoD) is developing a strategic cloud project, with the aim of consolidating its existing network architecture and preparing for full-scale cloud adoption in the future.</p><p>Harry Gazzard, a solutions architect contractor working for the MoD, presented its approach to developing this cloud network at InfoSecurity Europe 2024.</p><p>There are a multitude of threat actors, from <a href="https://www.itpro.com/security/after-a-string-of-high-profile-cyber-gang-takedowns-is-the-cyber-crime-industry-about-to-get-a-lot-more-fragmented"><u>organized crime groups</u></a> to <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier"><u>state-sponsored cyber attackers</u></a>, who would seek to breach the MoD’s cloud network. Therefore, security is naturally a key focus for the project’s development.</p><p>The MoD is following the <a href="https://www.itpro.com/security/367722/mod-pledges-resilience-to-all-known-vulnerabilities-by-2030"><u>&apos;secure by design&apos;</u></a> approach, a UK government framework produced in collaboration with the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>. It seeks to ensure projects take cyber security into account from the design phase onward and that those responsible for projects are accountable for secure upkeep and the elimination of outdated practices.</p><p>Instead of relying on established techniques or making assumptions, the team behind the MoD’s cloud transformation has gone back to basics by asking themselves ‘What does secure by design actually mean?’ </p><p>Although the sensitive nature of the MoD&apos;s work prevents the team from being entirely transparent development throughout the process, Gazzard stresses the MoD&apos;s <a href="https://www.itpro.com/security/encouraging-a-security-first-mindset"><u>security-first</u></a> design strategy will ensure a secure platform is built. Some form of independent oversight can still be implemented under this system, with the appropriate non-disclosure agreements in place. </p><h2 id="a-root-and-branch-approach-to-attack-vectors">A root and branch approach to attack vectors</h2><p>One of the key risks facing the cloud platform is <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>. In 2020, Anne Neuberger, who was then the director of the cyber security directorate for the US <a href="https://www.itpro.com/tag/nsa"><u>National Security Agency (NSA)</u></a>, identified that 92% of all malware was delivered through the <a href="https://www.itpro.com/domain-name-system-dns/30228/what-is-dns"><u>domain name system (DNS)</u></a>. Malware has become an ever-evolving threat vector, with older malware being re-weaponised. Code from older malware can be shared – or stolen – and used in the creation of new malware attacks.</p><p>Rather than focusing on attacking the malware directly, the cloud architects are targeting the traffic distribution systems in order to block the malware before it can be deployed within the network.</p><p>The DNS is a naming database in which domain names are located and translated into <a href="https://www.itpro.com/infrastructure/network-internet/358606/static-ip-vs-dynamic-ip-whats-the-difference">IP addresses</a>. Most activities over the internet rely on the DNS to connect users to remote hosts. The mapping of DNS is distributed across the internet, with governments and other organizations typically having their own assigned ranges of IP addresses and domain names. As such, the DNS became a key focus for deploying cyber security: without a secure DNS platform, the integrity of any cloud architecture could be undermined.</p><p>As the MoD <a href="https://www.itpro.com/security/what-is-an-air-gap-and-why-do-security-teams-use-them"><u>air-gaps</u></a> its critical systems from the wider infrastructure to ensure they remain secure, it is less concerned about direct attacks. But with its secure by design approach at heart, it recognizes there is always value in adding additional protection.</p><p>Though its systems are air-gapped, this does not mean they do not talk to other systems at all. For example; <a href="https://www.itpro.com/security/patch-management-why-firms-ignore-vulnerabilities-at-their-own-risk">critical patches</a> and updates still need to be deployed. Although updates may be uploaded through optical disks or <a href="https://www.itpro.com/server-storage/flash-storage/360883/the-benefits-and-drawbacks-of-flash-storage-today">flash drives</a>, the air-gapped systems are still effectively connecting to the outside world, albeit in a controlled manner. There is also the risk of a compromised device being brought into the premises and connecting to the network.</p><p>The potential threats facing <a href="https://www.itpro.com/cloud/367935/best-cloud-computing-services-in-2022"><u>cloud platforms</u></a> also include indirect attacks, such as <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack"><u>distributed denial of service (DDoS)</u></a> attacks and DNS poisoning (otherwise known as DNS spoofing and DNS cache poisoning). DNS poisoning is a cyber attack in which attackers insert false information into the DNS to redirect users to a malicious website.</p><p>In regard to control channels for screening data packets, one particular challenge is that DNS can be effectively rendered blind if the packets are no longer transparent. This is especially the case with <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security"><u>HTTPS</u></a>. It is designed to protect users by <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption"><u>encrypting</u></a> DNS data, but this also prevents oversight.</p><h2 id="greater-automation-for-threat-monitoring">Greater automation for threat monitoring</h2><p>The MoD is taking a proactive approach to security; focusing on detection and prevention by automating processes for advanced DNS Protection, to enable a swifter response to <a href="https://www.itpro.com/technology/artificial-intelligence/ai-threats-the-importance-of-a-concrete-strategy-in-fighting-novel-attacks"><u>emerging threats</u></a>. There is continual monitoring, as the <a href="https://www.itpro.com/security/world-economic-forum-warns-of-growing-cyber-insecurity-amid-heightened-threat-landscape"><u>threat landscape is constantly changing</u></a>.</p><p>Gazzard highlights the challenges the project faces, most notably the struggle of  creating a platform that is secure whilst simultaneously meeting the needs of multiple departments. With this in mind, the MoD is expanding its <a href="https://www.itpro.com/cloud/private-cloud/363378/ministry-of-defence-turns-to-private-cloud-for-secure-internal-apps">internal cloud</a>, with multi-tenant architecture that has the ability to scale, whilst remaining compartmentalized to prevent information leakage.</p><p>Many of its existing networks are shifting from being on premise platforms to ones that use shared cloud architecture. The MoD is enabling the different groups within them to build their own platform within the cloud.</p><p>Part of its threat monitoring will be reviewing remote system logs that can report emerging threats. This allows cyber security analysts to identify <a href="https://www.itpro.com/security/ransomware/life-after-lockbit-a-fragmented-landscape-and-wayward-affiliates-will-still-cause-chaos-for-enterprises">emerging trends within the threat landscape</a> and to adapt their security posture accordingly.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sXtrpAAP2RRT7DEVkoQH6X" name="The economics of penetration testing for web application security (1).jpg" caption="" alt="The economics of penetration testing for web application security" src="https://cdn.mos.cms.futurecdn.net/sXtrpAAP2RRT7DEVkoQH6X.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Outpost24)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-economics-of-penetration-testing-for-web-application-security"><em>Get the most value from your security solution</em></a></p></div></div><p>In recent years, hacking has become industrialized, with DNS being used by malicious actors as a tool to profile users. Awareness of these multifarious threats has meant the UK’s MoD can develop a global cloud platform with a robust end-point security protocol that can protect the organization from attacks.</p><p>Updating systems presents several challenges for developing the cloud architecture, as there are stringent policies in regard to importing and exporting data. There are also devices with <a href="https://www.itpro.com/business/digital-transformation/legacy-it-infrastructure-accounts-for-more-than-a-third-of-enterprise-power-consumption-and-its-creating-a-sustainability-nightmare-for-it-leaders"><u>legacy hardware</u></a> requirements that will need software updates or to be replaced with a newer version.</p><p>Rather than relying on an annual security review, it is shifting to ongoing security assessments, whereby systems are continually assessed to ensure they are adequately protected. Any systems that are identified as being outdated will require investment to become compliant with the new systems, whilst retaining functionality.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AWS users are getting a big security boost with passkey support ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/aws-users-are-getting-a-big-security-boost-with-passkey-support</link>
                                                                            <description>
                            <![CDATA[ AWS is adding passkey support in a bid  to tighten up security controls for cloud users ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JMiZ78FRsWdX74L5N5bK7Q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HLWwp3S6DByc3JXnJ3PHUc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Jun 2024 15:15:57 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Jun 2024 11:27:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Ranger ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/gFeXmAxutpTpGN7c98ZAwJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HLWwp3S6DByc3JXnJ3PHUc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AWS logo pictured during the Viva Technology show at Parc des Expositions Porte de Versailles on May 22, 2024 in Paris, France.]]></media:description>                                                            <media:text><![CDATA[AWS logo pictured during the Viva Technology show at Parc des Expositions Porte de Versailles on May 22, 2024 in Paris, France.]]></media:text>
                                <media:title type="plain"><![CDATA[AWS logo pictured during the Viva Technology show at Parc des Expositions Porte de Versailles on May 22, 2024 in Paris, France.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HLWwp3S6DByc3JXnJ3PHUc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/amazon-web-services">Amazon Web Services (AWS)</a> is adding support for FIDO2 passkeys as a multi-factor authentication (MFA) option, as the cloud giant prepares to boost the security requirements around more user accounts.</p><p>Back in October last year, AWS said it would begin to require <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">MFA</a> for the most privileged users on an AWS account, starting with AWS Organizations management account root users.</p><p>Starting next month, root users of standalone accounts (by which AWS means those that aren’t managed with AWS Organizations) will be required to use MFA when signing in to the AWS Management Console.</p><p>This policy change will start with a small number of customers and increase over a period of months. Customers will have a grace period to allow them to upgrade to MFA, and they will be reminded about it at sign-in.</p><p>AWS said this change does not apply to the root users of member accounts in AWS Organizations. It said there will be more information about the MFA requirements for remaining root user use cases, such as member accounts, later in the year.</p><p>MFA can come in many forms but generally means going beyond the classic user-name-and-password combination which, it has turned out, is a pretty flimsy way of securing accounts online. That’s because passwords are too easy to crack or re-use across different services.</p><p>They’re easily shared, lost or stolen, all of which is why many data leaks and hacks often start with attackers being able to access systems with some form of legitimate but compromised credentials. Stolen credentials or leaked credentials has been seen as one of the biggest risks to cloud infrastructure.</p><p>As <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a> improves, attackers are finding that obtaining valid credentials is an easier route. According to research by IBM earlier this year, cloud account credentials make up 90% of the for-sale cloud assets on the dark web.</p><p>As AWS extends the need for customers to use MFA it is also giving them another option to choose from in the form of FIDO2 passkeys.</p><p>“When used as MFA, passkeys provide enhanced security for human authentication in a user-friendly manner. You can register and use passkeys today to enhance the security of your AWS console access,” said Arynn Crow, senior manager of user authentication products for AWS Identity.</p><p>“This will help you to adhere to AWS default MFA security requirements as those roll out to a larger group of customers starting in July.</p><p>“We strongly encourage you adopt some form of MFA anywhere you’re signing in today, and especially phishing-resistant MFA, which we’re excited to enhance with FIDO2 passkeys.”</p><p>Passkeys are already used widely to improve account security (you can already use them to secure your Amazon shopping account for example). Passkeys are FIDO2 credentials, which use public key cryptography to provide strong, <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>-resistant authentication, but can be backed up and synced across devices and operating systems rather than being stored on physical devices like a USB-based key.</p><p>Whether you want to use passkeys or something else, AWS said that any type of MFA is better than no MFA at all.</p><p>“MFA is one of the simplest but most effective security controls you can apply to your account, and everyone should be using some form of MF,” the firm said.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="EQ4STk5CqYdPof9Vy6YVCX" name="The economics of penetration testing for web application security.jpg" caption="" alt="The economics of penetration testing for web application security" src="https://cdn.mos.cms.futurecdn.net/EQ4STk5CqYdPof9Vy6YVCX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Outpost24)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-economics-of-penetration-testing-for-web-application-security"><em>Learn about the economics of pen testing </em></a></p></div></div><p>AWS points out that phishing and <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> attacks that target users who use one-time codes for MFA, like the ones sent to your phone, have increased.</p><p>Because using this option means you need to read the number or code from the device and enter it manually, attackers can also try to get users to read the code out to them instead, thereby bypassing the value of MFA. Passkeys aren’t vulnerable to this.</p><p>AWS said that if your organization is already using another form of MFA like a non-syncable FIDO2 <a href="https://www.itpro.com/hardware">hardware</a> security key or authenticator app, the question of whether or not you should migrate to syncable passkeys is dependent on your or your organizations’ uses and requirements.</p><p>“Because their credentials are bound only to the device that created them, FIDO2 security keys provide the highest level of security assurance for customers whose regulatory or security requirements demand the strongest forms of authentication, such as FIPS-certified devices,” the cloud giant said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco unveils first product integrations since Splunk acquisition ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/cisco-unveils-first-product-integrations-since-splunk-acquisition</link>
                                                                            <description>
                            <![CDATA[ Cisco said the combination of observability technologies will enable customers to spot infrastructure problems faster ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qPFvFPn6ARTomrWca6Gtm4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/obsBzbFgxMoQGzTF8RzBQ5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Jun 2024 07:30:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Ranger ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/gFeXmAxutpTpGN7c98ZAwJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/obsBzbFgxMoQGzTF8RzBQ5-1280-80.jpg">
                                                            <media:credit><![CDATA[Cisco]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cisco Live 2024 keynote theatre banner with Cisco logo and branding. ]]></media:description>                                                            <media:text><![CDATA[Cisco Live 2024 keynote theatre banner with Cisco logo and branding. ]]></media:text>
                                <media:title type="plain"><![CDATA[Cisco Live 2024 keynote theatre banner with Cisco logo and branding. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/obsBzbFgxMoQGzTF8RzBQ5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/infrastructure/networking/everything-you-need-to-know-about-cisco">Cisco</a> has unveiled the first fruits of its <a href="https://www.itpro.com/business/acquisition/cisco-set-to-acquire-splunk-in-dollar28-billion-deal">$28 billion acquisition of Splunk</a>, with a series of integrations combining the duo’s observability technologies.</p><p>Cisco completed acquisition of Splunk – its biggest ever – earlier this year. Spunk’s products collect security information and event management across a customer’s enterprise technology infrastructure to spot any sort of anomalous behavior.</p><p>Now, Cisco has started some integrations between its monitoring tools and those from Splunk. Observability tools collect and analyze data from infrastructure and networks to spot – and hopefully – resolve issues before they impact the business.</p><p>In the keynote on the second day of Cisco Live, Tom Gillis, general manager for security products at Cisco, said the combination of Cisco and Splunk will unlock data that’s invisible to security teams right now.</p><p>Network security was services that came in a box, but that is now being broken up into smaller pieces nearer to the user – secure access services edge (SASE). But the next step for security is even more fine-grained security controls aimed at unlocking more internal data with technologies like Cisco’s recently announced Hypershield product, he told the audience in Las Vegas.</p><p>Diving deeper into data and applications will also create three orders of magnitude more data than security teams are looking at today, Gillis said. This, he noted, is where Splunk comes in.</p><p>Cisco said that, as a result of integrating these tools, organizations would have improved visibility across their environments including on-premises, hybrid, and <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud">multi-cloud</a>, while using real-time analytics for faster, more accurate detection, investigation, and response.</p><p>“By bringing together Splunk and Cisco observability solutions, customers now have unified visibility across their entire digital footprint so they can detect, investigate and resolve problems faster to create a reliable, resilient experience for their users,” said Tom Casey, SVP and GM for products and technology at Splunk.</p><p>“Having full control over their data helps them make more targeted, effective and smarter investments in their digital systems and services, allowing them to better leverage their entire digital footprint to attract more business and grow the company.”</p><p>Cisco said new unified experiences across Cisco and Splunk observability products enable better efficiency and accuracy in troubleshooting hybrid environments.</p><p>For example, a new <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a> feature will help simplify and streamline shared workflows between Cisco AppDynamics and Splunk products.</p><p>Meanwhile, the introduction of context-aware deep linking will enable Cisco AppDynamics customers to switch straight to logs in the Splunk Platform as part of their troubleshooting workflow, which should result in faster mean time to resolution. </p><p>Single Sign-on and Log Observer Connect for Cisco AppDynamics, part of the preview of the Unified Observability Experience, will be generally available in the third quarter of 2024</p><p>Cisco also showcased a raft of other integrations during the day-two keynote. This included the launch of Splunk Log Observer Connect for Cisco AppDynamics. Available in July, this combines the Splunk Platform with Cisco AppDynamics APM to drive faster, in-context troubleshooting across on-premise and hybrid environments.</p><p>Cisco said this integration allows SaaS and on-premises customers to analyze logs when troubleshooting application performance issues.</p><p>Similarly, the <a href="https://www.itpro.com/strategy/27968/cisco-snatches-up-37bn-appdynamics-in-cloud-push">Cisco AppDynamics</a> integration with Splunk Enterprise/Splunk Cloud and Splunk ITSI will allow users to correlate application metrics and events from AppDynamics with other data about systems and services in Splunk Enterprise and Splunk Cloud.</p><p>Cisco AppDynamics will also be available on <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws">Microsoft Azure</a>, the company told attendees. This expansion of cloud-hosted observability brings Cisco AppDynamics APM service.</p><h2 id="cisco-ai-integration-with-splunk-gathers-pace">Cisco AI integration with Splunk gathers pace</h2><p><a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> has been a key topic so far at <a href="https://www.itpro.com/news/live/cisco-live-2024-all-the-announcements-from-the-opening-keynote">Cisco Live</a> 2024, so it was inevitable that there were going to be some Splunk integrations in this domain. </p><p>At the day-two keynote, the firm unveiled the launch of Cisco AI Assistant for Cisco AppDynamics. Integrated into the AppDynamics Help Center, the new AI Assistant uses <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> technology to help identify and support the workflows used by security teams.</p><p>Advanced AI in Splunk IT Service Intelligence (ITSI) was also revealed by the networking giant. This uses AI and <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning</a> capabilities to help teams quickly and easily configure and implement dynamic, adaptive thresholds, and manage and optimize configurations.</p><p>This means, for example, users will be able to fine-tune alerts with machine learning and look at slowly changing dimensions in KPIs that humans might not spot. The updated Splunk TA for AppDynamics and Splunk ITSI App for Content Packs will be generally available in June.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WithSecure takes a fluff-free approach with its 'co-security' vision and AI limitations ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/withsecure-takes-a-fluff-free-approach-with-its-co-security-vision-and-ai-limitations</link>
                                                                            <description>
                            <![CDATA[ With a clarity of purpose not seen since its F-secure demerger, WithSecure has worked to demonstrate its value in the enterprise security space with a particular focus on the mid-market ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MK8BJSQUXsHzUBgy9s2pj8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TKJZ9oZ5iWo2oyZtAZRg4V-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 30 May 2024 13:04:15 +0000</pubDate>                                                                                                                                <updated>Thu, 30 May 2024 15:54:41 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TKJZ9oZ5iWo2oyZtAZRg4V-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Interim CEO Antti Koskela on stage at SPHERE24]]></media:description>                                                            <media:text><![CDATA[Interim CEO Antti Koskela on stage at SPHERE24]]></media:text>
                                <media:title type="plain"><![CDATA[Interim CEO Antti Koskela on stage at SPHERE24]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TKJZ9oZ5iWo2oyZtAZRg4V-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Throughout its Sphere 2024 event in Helsinki, WithSecure has worked to paint a clearer picture of its path in the enterprise security space, with a focus on restoring confidence in the mid-market through a modular package of cloud security solutions and services.</p><p>Beginning his opening keynote Antti Koskela, interim CEO at WithSecure, says he wanted to do something different with the company’s events, epitomized by its ‘co-security unconference’ tagline.</p><p>Elaborating on this in conversation with <em>ITPro</em>, he explains he wanted WithSecure’s event to stand out from the crowd with a more pronounced focus on the cyber security big picture. This was evident from the beginning of Sphere 2024, with the keynote lineup dominated by thought leaders from outside the organization.</p><p>The term ‘co-security’, has received some scrutiny in the past for lacking a clear definition. But at <a href="https://www.itpro.com/news/live/withsecure-sphere-2024-live-all-the-news-and-updates-as-they-happen">Sphere 2024</a>, the company leaned into this as emblematic of its collaborative approach with its partners and customers. Through its announcements at the event, WithSecure has laid out its strategy and emphasized the opportunities it can leverage along the way – a far cry from the company&apos;s <a href="https://www.itpro.com/security/enterprise-security/367815/withsecure-major-rethink-to-survive-in-enterprise-security">lack of direction just two years ago</a>.</p><h2 id="co-security-as-a-unique-selling-point">Co-security as a unique selling point</h2><p>The major product launches at the event added context to the term, all of which fall under the company’s flagship, <a href="https://www.itpro.com/cloud/cloud-computing/what-is-cloud-native-and-how-can-it-generate-business-value"><u>cloud-native</u></a> Elements Cloud platform. Each was framed in terms of how they fit into this vision of collaboration between WithSecure, its partners, and the end user.</p><p>Koskela outlines how the Elements Cloud embodies their co-secure objectives through a collaborative, modular security platform targeting mid-sized organizations. He believes this approach differentiates WithSecure’s offerings from some of its larger competitors.</p><p>“Often in security, in the large company playbook, you buy tools and you hire teams who work 24/7 and then you have a massive security operations center. So the minimum is usually seven people and the cost for that would be anywhere between $700,000 to $1,000,000 just for the people cost, and these mid-sized companies don&apos;t have that kind of money.”</p><p>In contrast, Koskela explains, WithSecure is targeting a model where these medium-sized organizations have access to their co-security services as modular capabilities as part of Elements Cloud, while still able to offer the software as a standalone solution for those who don’t need the extra support.</p><p>“The key word is modularity, so we adjust our model to the way our partner wants to work,” he tells <em>ITPro</em>. “Some of our partners are pure <a href="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service"><u>[managed service providers] (MSPs)</u></a>, they are security providers and they don’t need anything from us, they just take the software – and that’s perfectly fine.”</p><p>Koskela contrasts this approach with that of WithSecure’s larger competitors, which he says lock customers into paying for a complex web of products they lack the personnel to properly leverage.</p><p>“[Organizations] in the mid-market usually have maybe one IT  person that looks after them,” he notes, adding “When you buy large bundled licenses … you are alone and end up buying a lot more for the services..</p><p>“Because once the licensing guy has sold it, you never see them again, and then you need to contact the service partner to actually run a [security operations center] (SOC) for you, and that’s going to cost you”.</p><p>Moving forward, Koskela says, WithSecure will work to position itself as the more flexible enterprise security option for medium-sized companies. Its modular approach and ongoing support will be available either in-house or through partners.</p><p>In this sense, WithSecure’s efforts to clarify where it sees the future of the business have been largely successful.  The strategy itself looks to put the company in a good position within the security market, considering the ongoing issues smaller businesses are experiencing with managing a <a href="https://www.itpro.com/security/ruthlessly-prioritize-whats-critical-check-point-expert-on-cisos-and-the-evolving-attack-surface"><u>complex attack surface</u></a> in an increasingly hostile <a href="https://www.itpro.com/security/world-economic-forum-warns-of-growing-cyber-insecurity-amid-heightened-threat-landscape"><u>threat landscape</u></a>.</p><p>The company’s other verticals – WithSecure Consulting and Cloud Protection for Salesforce, leftover from the split with F-Secure in 2022 – are separate from their Elements strategy. Koskela adds that WithSecure will continue to look for strategic options in this area and doesn’t rule out the potential for divestment in the future.</p><h2 id="a-limited-by-design-approach-to-generative-ai">A limited by design approach to generative AI</h2><p>The biggest announcement of Sphere 2024 was the official launch of <a href="https://www.itpro.com/security/generative-ai-security-tools-are-a-risky-enterprise-investment-withsecure-wants-to-change-that"><u>WithSecure’s generative AI platform Luminen</u></a>, which Koskela says will be a core part of the company&apos;s mid-market appeal.</p><p>Luminen will be natively embedded into Elements Cloud and promises to bring intuitive human user experience to security dashboards, to boost situational awareness through natural language explanations of security events.</p><p>This sounds much like many of the other <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> plays we have seen in the security industry over the past few years, such as <a href="https://www.itpro.com/security/microsoft-says-its-copilot-for-security-tool-is-a-powerful-weapon-in-the-fight-against-hackers-heres-why"><u>Copilot for Security</u></a> or <a href="https://www.itpro.com/news/live/google-cloud-next-2024-all-the-news-and-announcements-live"><u>Gemini in Security Command Center</u></a>. But WithSecure’s approach aims to largely sidestep the AI hype and direct comparisons with hyperscaler AI tools, with a focus on cost-effective value. </p><p>Carefully dubbed a generative AI ‘experience’, Koskela explains that WithSecure doesn’t want to be seen as adding to the <a href="https://www.itpro.com/technology/artificial-intelligence/youre-going-to-have-an-ai-copilot-for-everything-you-do-and-youll-probably-hate-it"><u>pile of yet another security AI copilots</u></a> in what is already a crowded market. Luminen is intended to bring a more integrated experience without the security risks associated with chatbots.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xpNYiJJxGwySYf5kG2WrE5" name="2024 State of the phish report (2).jpg" caption="" alt="Blue text that says 2024 State of the phish report" src="https://cdn.mos.cms.futurecdn.net/xpNYiJJxGwySYf5kG2WrE5.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Proofpoint)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/2024-state-of-the-phish-report"><em>Prevent risky behavior that can compromise your cybersecurity</em></a></p></div></div><p>To achieve this, WithSecure says it will ‘take ownership of the prompt’, with Luminen disallowing users from entering custom prompts to lessen the risk of <a href="https://www.itpro.com/security/hackers-are-taking-advantage-of-ai-hallucinations-to-sneak-malicious-software-packages-onto-enterprise-repositories">hallucinations</a>. Instead, customers choose internally generated prompts rooted in their enterprise data.</p><p>Not only does this remove the chance for malicious actors to jailbreak the system using <a href="https://www.itpro.com/technology/artificial-intelligence/this-engineering-discipline-was-hailed-as-the-next-big-thing-but-ai-has-killed-it-before-it-even-started">prompt engineering</a> techniques, it also ensures Luminen’s capabilities are only being pushed when really needed. </p><p>The rush to get in on the generative AI boom has led to a number of products hitting the market without a clear business use case, and Koskela said he didn’t want  Luminen to fall into the same trap, noting the <a href="https://www.itpro.com/business/business-strategy/building-a-sustainable-business-model-in-tech">sustainability</a> concerns associated with generative AI and its <a href="https://www.itpro.com/infrastructure/data-centres/us-data-center-power-consumption-is-set-to-double-by-2030-amid-soaring-ai-demands">intense data demands</a>.</p><p>It’s a refreshing approach in an incredibly saturated space, reflecting a wary attitude around new technologies lacking precise value propositions. It’s clear  that WithSecure is looking to meet the worries of its customers when it comes to the security or energy impact of generative AI, having made a point of limiting Luminen to vital and valuable tasks.</p><p>This has been echoed throughout Sphere 2024, as WithSecure executives worked to avoid vague promises of what could be possible in the future.</p><p>WithSecure’s considered approach to entering the generative AI market reflects a newfound clarity around its co-security strategy. With its Elements Cloud targeting mid-sized enterprises through a flexible cloud security software and services ecosystem and its straightforward generative AI platform aiming to simplify security management, WithSecure has made significant progress in demonstrating a viable strategy to compete in the enterprise security space.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WithSecure’s generative AI focus could be the key to cracking its mid-market push  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/withsecures-generative-ai-focus-could-be-the-key-to-cracking-its-mid-market-push</link>
                                                                            <description>
                            <![CDATA[ After a turbulent period trying to fight for a seat at the enterprise security table, WithSecure looks to cement its niche in the cloud security middle-market and drive AI adoption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N5oLVDVaePRMqGjJBTSAYj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EGj8kGUdF8yvbwDJhP4sdU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 May 2024 15:32:18 +0000</pubDate>                                                                                                                                <updated>Wed, 29 May 2024 20:19:41 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EGj8kGUdF8yvbwDJhP4sdU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital cloud with sitting on abstract representation of data fabric]]></media:description>                                                            <media:text><![CDATA[Digital cloud with sitting on abstract representation of data fabric]]></media:text>
                                <media:title type="plain"><![CDATA[Digital cloud with sitting on abstract representation of data fabric]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EGj8kGUdF8yvbwDJhP4sdU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Since <a href="https://www.itpro.com/security/enterprise-security/367151/f-secure-launches-withsecure-spinning-off-entire-enterprise"><u>spinning out</u></a> from its consumer-focused parent company F-secure in 2022, <a href="https://www.itpro.com/security/enterprise-security/367815/withsecure-major-rethink-to-survive-in-enterprise-security">WithSecure</a> has struggled to carve out a distinct lane in the <a href="https://www.itpro.com/tag/enterprise-security">enterprise security</a> space.</p><p>Facing an uphill battle against well-established competition, WithSecure has repeatedly fallen short of profitability and missed this goal at the end of its FY 23.</p><p>Despite this, the firm has a potential path to profitability by expanding its cloud security platform as organizations look to consolidate their security portfolios, which have become <a href="https://www.itpro.com/security/enterprises-are-bogged-down-with-disparate-cyber-tools-heres-why-a-platform-security-approach-could-tackle-growing-complexity">increasingly complex</a> as a result of the <a href="https://www.itpro.com/technology/artificial-intelligence/tangible-business-value-from-cloud-transformation-remains-elusive">cloud transformation</a>.</p><p>WithSecure’s <a href="https://www.itpro.com/security/endpoint-security/369700/withsecure-elements-endpoint-protection-review-holistic">Elements</a> cloud security products have given the firm something of a foundation on which to build on since being launched in 2021, but its beleaguered <a href="https://www.itpro.com/cloud/cloud-computing/on-premises-in-cloud-or-hybrid-the-risk-of-status-quo">on-premises</a> segment and consultancy services have continued to decline.</p><p>But with the advent of generative AI in late 2022, WithSecure could finally be on the road to finding its niche. The demand for <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>-powered security tools has accelerated rapidly over the last year, and with use-cases on the potential of <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> in security showing promising signs, this represents an opportune moment for the firm to capitalize.</p><p>The firm predicts the majority of cyber risks associated with the adoption of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> tools come from how these models are integrated into systems and workflows, rather than the models themselves. </p><p>Accordingly, WithSecure could find a happy hunting ground in helping organizations integrate <a href="https://www.itpro.com/security/cyber-crime/what-is-hackbot-as-a-service-and-are-malicious-llms-a-risk">LLMs</a> into their IT systems securely, providing services around <a href="https://www.itpro.com/technology/artificial-intelligence/ai-governance-for-responsible-transparent-and-explainable-ai-workflows">AI governance</a>, AI risk modeling, and penetration testing for LLM applications and infrastructure underpinning the models.</p><p>As businesses, especially those without the resources of large enterprises, contend with ongoing <a href="https://www.itpro.com/cloud/cloud-computing/cloud-skills-shortages-are-pushing-developer-teams-to-breaking-point">skills shortages</a> stifling their access to the technical expertise needed to implement <a href="https://www.itpro.com/technology/artificial-intelligence/dell-unveils-generative-ai-solutions-and-services-in-collaboration-with-nvidia">generative AI solutions</a>, this could leave an opening for WithSecure to firmly establish itself in the enterprise cloud-consulting space.</p><p>WithSecure showed its bullishness on generative AI with two recent announcements, the first offering partners early access to its new exposure management technology that uses LLMs to prioritize and recommend steps customers can take to <a href="https://www.itpro.com/security/patch-management-why-firms-ignore-vulnerabilities-at-their-own-risk">remediate vulnerabilities</a> and reduce their threat exposure. </p><p>The second is the launch of Luminem, WithSecure’s new generative AI ‘experience’ that will be available through the Elements Cloud. Much like analogous security copilots on offer from some of its larger competitors, Luminem will offer a variety of  <a href="https://www.itpro.com/tag/automation">automation</a> and optimization capabilities to streamline security workflows. </p><p>At SPHERE24, WithSecure will need to demonstrate where the unique value of its solution lies, and why Luminem is more than just them catching up with similar solutions from <a href="https://www.itpro.com/news/live/cisco-live-2024-all-the-announcements-from-the-opening-keynotehttps://www.itpro.com/tag/cisco">Cisco</a>, <a href="https://www.itpro.com/security/fortinet-will-want-to-forget-last-week-after-botched-vulnerability-disclosures-and-a-war-of-words-over-an-electric-toothbrush-caused-chaos">Fortinet</a>, and <a href="https://www.itpro.com/security/security-has-to-work-together-cyber-collaboration-as-a-mission-at-check-point-experience-2024">Check Point</a>. </p><h2 id="withsecure-needs-to-clear-up-its-messaging">WithSecure needs to clear up its messaging</h2><p>WithSecure still suffers from a lack of clarity around its vision for co-security, a <a href="https://www.itpro.com/security/cyber-security/368087/cyber-security-companies-must-remember-who-the-enemies-are">buzzword</a> it has bandied around for the last few years as a differentiator for the business in the crowded enterprise security ecosystem.</p><p>Co-security was the talk of the town at <a href="https://www.itpro.com/security/ransomware/367932/industry-needs-to-target-ransomware-supply-chain-withsecure">SPHERE22</a>, <a href="https://www.itpro.com/security/cyber-security/368087/cyber-security-companies-must-remember-who-the-enemies-are"><u>without necessarily a clear vision of what it actually meant</u></a> apart from a vague sense that the security community needs to embrace collaboration. This, WithSecure proposes, is necessary to manage interwoven IT estates and contend with an increasingly hostile threat landscape. </p><p>Over the course of 2023, WithSecure introduced a series of products to expand upon its co-security vision, one of these being a co-monitoring service launched March 2023 which promises to alleviate some of the burden of staying on top of network alerts by using WithSecure’s inhouse team to deliver 24 hour monitoring. </p><p>Yet without more substance behind the concept, the firm could struggle to get buy-in from customers. Generative AI, however, gives WithSecure the chance to flesh out the concept moving forward.</p><p>It’s clear WithSecure has not given up on its cyber consultancy services, despite stiff competition from competitors like <a href="https://www.itpro.com/security/357669/mcafee-75-million-attacks-on-cloud-accounts-recorded-in-q2">McAfee</a> or <a href="https://www.itpro.com/tag/trend-micro">Trend Micro</a>, and the AI explosion could present a lifeline it desperately needs, but if it is to keep its head above water, its cloud portfolio will need to continue to prop up its revenue generation.</p><h2 id="cloud-will-remain-withsecure-x2019-s-cash-cow-as-it-looks-to-expand-its-exposure-management-capabilities">Cloud will remain WithSecure’s cash cow as it looks to expand its exposure management capabilities</h2><p>Since the demerger, WithSecure’s route to stability was seen to be <a href="https://www.itpro.com/security/enterprise-security/367815/withsecure-major-rethink-to-survive-in-enterprise-security"><u>targeting mid-sized companies with its cloud security platform</u></a>. This is a path to capturing the growing demand from the industry from cloud infrastructure solutions, which has only grown in demand since generative AI became widespread.</p><p>WithSecure updated its strategy in October 2023 to formalize its effort to push its Elements Cloud portfolio to mid-market customers through its <a href="https://www.itpro.com/business-operations/human-resources-hr-software/369469/ukg-unveils-new-invite-only-partner-network">partner network</a>. It stated it was exploring strategic options that included a full or partial divestment from its underperforming cyber consulting and Cloud Protection for <a href="https://www.itpro.com/tag/salesforce">Salesforce</a> segments.</p><p>At SPHERE23, WithSecure built out its Elements platform unveiling a new Cloud Security Posture Management (CSPM) product, a tool that will give enterprises automated identification and remediation tools for risks associated with their <a href="https://www.itpro.com/cloud/cloud-storage/369493/cloud-infrastructure-and-management">cloud infrastructure</a>.</p><p>Identifying the established trend of companies moving towards <a href="https://www.itpro.com/hybrid-cloud/29668/what-is-hybrid-cloud">hybrid</a>, <a href="https://www.itpro.com/business/business-strategy/362840/multi-cloud-looking-after-more-than-one-cloud">multi-cloud</a> infrastructure, and anticipating the rush to adopt generative AI technologies, WithSecure’s CPSM solution aims to help customers eliminate breaches caused by misconfiguration of cloud assets.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="imxPNEUfV7dDShMhBnvu9H" name="Forrester_ Sustainable Monitors.jpg" caption="" alt="Forrester: Sustainable monitors" src="https://cdn.mos.cms.futurecdn.net/imxPNEUfV7dDShMhBnvu9H.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/monitors/forrester-sustainable-monitors"><em>Discover how employee hardware influences sustainability</em></a> </p></div></div><p><a href="https://www.itpro.com/business-operations/30577/gartner-25-of-customer-service-operations-will-use-chatbots-by-2020">Gartner</a> predicted that through 2025, 90% of organizations that fail to control how they use the public cloud will “inappropriately share sensitive data”. On top of this, the well established digital skills gaps will mean many firms lack the in-house expertise to ensure their systems are configured properly.</p><p>Continuing to expand its security solutions for cloud infrastructure and meeting the demand for these tools at <a href="https://www.itpro.com/business/careers-and-training/majority-of-mid-market-firms-struggle-to-retain-it-talent-for-more-than-two-years-research-shows">mid-sized organizations</a> will be integral to WithSecure’s continued success.</p><p>Whether or not this will happen remains to be seen, and the company’s reliance on its cloud security arm suggests that if WithSecure is not able to capture the new demand from the medium-sized enterprises, it’s path to recovery could be rocky.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ VMware discloses flaws in Workstation and Fusion Pro products after making them free for personal use ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/vmware-discloses-flaws-in-workstation-and-fusion-pro-products-after-making-them-free-for-personal-use</link>
                                                                            <description>
                            <![CDATA[ VMware has warned customers of a series of high severity flaws affecting the Workstation Pro and Fusion Pro hypervisor products ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7hxQJBCsmpsnA784prvUVJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4VeRaTDnXkmkUK9NbMZFiL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 May 2024 13:03:22 +0000</pubDate>                                                                                                                                <updated>Tue, 21 May 2024 11:25:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4VeRaTDnXkmkUK9NbMZFiL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[VMware logo on a phone sitting on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[VMware logo on a phone sitting on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[VMware logo on a phone sitting on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4VeRaTDnXkmkUK9NbMZFiL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/virtualisation/29279/everything-you-need-to-know-about-vmware">VMware</a> has issued a security advisory detailing critical flaws in its Workstation and Fusion hypervisor products after making them available to individuals for free.</p><p>On 14 May, VMware <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">disclosed</a> a series of <a href="https://www.itpro.com/security/cyber-attacks/top-12-most-exploited-security-vulnerabilities-revealed-by-national-cyber-security-agencies">security vulnerabilities</a> in the two <a href="https://www.itpro.com/604830/vmware-sets-its-hypervisor-free">hypervisor</a> solutions, providing workarounds and warning customers to patch their systems as soon as possible.</p><p>The first and most serious of these was CVE-2024-22267, a critical use-after-free vulnerability in the products’ vbluetooth device. The flaw has a <a href="https://www.itpro.com/security/vulnerability/356281/hackers-primed-to-exploit-cvss-10-rated-flaw-in-palo-altos-pan-os">CVSS</a> rating of 9.3, the company revealed.</p><p><a href="https://www.itpro.com/tag/vmware">VMware</a> warned that a hacker with local administrative privileges on a virtual machine could exploit the flaw to execute code as the <a href="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines">virtual machine’s</a> VMX process running on the host.</p><p>The second security issue, CVE-2024-22268, is a heap <a href="https://www.itpro.com/security/26060/linux-vulnerability-leaves-thousands-open-to-dns-attack">buffer-overflow vulnerability</a> affecting the Shader functionality in Workstation and Fusion, rated 7.1 on the CVSS. </p><p>If exploited correctly, the flaw could give an unauthorized actor with access to a <a href="https://www.itpro.com/cloud-security/24606/vm-user-watch-out-for-venom">VM</a> with <a href="https://www.itpro.com/610606/google-brings-3d-to-web-browsers">3D graphics</a> enabled the ability to force the target system into a <a href="https://www.itpro.com/613672/need-to-know-denial-of-service">denial of service</a> (DoS) condition.</p><p>Also rated 7.1 on the CVSS, VMware disclosed another <a href="https://www.itpro.com/security/369739/high-severity-vulnerabilities-uncovered-in-three-quarters-of-operational-technology">high-severity vulnerability</a> – CVE-2024-22269 – which is an information disclosure flaw in the bluetooth device that could allow an attacker with admin privileges on a VM to read <a href="https://www.itpro.com/data-breaches/33307/disaster-victims-sensitive-information-exposed-through-fema-data-breach">sensitive information</a> contained in the hypervisor memory.</p><p>Finally, CVE-2024-22270, is another <a href="https://www.itpro.com/vulnerability/31797/flaw-in-fiserv-banking-platform-exposed-personal-data">information disclosure vulnerability</a> with a 7.1 CVSS rating that could give attackers access to information in the hypervisor memory, this time in Workstation and Fusion’s host guest file sharing (HGFS) functionality. </p><h2 id="not-the-best-timing-for-vmware">Not the best timing for VMware</h2><p>The day before it warned customers of the <a href="https://www.itpro.com/security/why-software-security-debt-is-becoming-a-serious-problem-for-developers">security problems</a> affecting the two hypervisor products, VMware also <a href="https://blogs.vmware.com/workstation/2024/05/vmware-workstation-pro-now-available-free-for-personal-use.html" target="_blank">announced</a> it would be making Workstation Pro and Fusion Pro free for personal use.</p><p>Workstation Pro is VMware’s hypervisor solution for <a href="https://www.itpro.com/software/microsoft/windows">Windows</a> and <a href="https://www.itpro.com/software/linux">Linux</a> devices, whereas Fusion covers customers using <a href="https://www.itpro.com/software/apple">Mac</a> systems.</p><p>They allow users to build ‘local virtual’ environments to install a variety of <a href="https://www.itpro.com/tag/operating-systems">operating systems</a> (OS) to <a href="https://www.itpro.com/business-strategy/automation/358766/automate-your-software-builds-with-jenkins">build and test software</a>.</p><p>The move has been touted as a gesture of goodwill by Broadcom amidst continued <a href="https://www.itpro.com/cloud/cloud-computing/broadcoms-attempts-to-quell-vmware-unrest-arent-cutting-it-as-the-war-of-words-escalates"><u>controversy over changes made since its acquisition of the firm last year</u></a>. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VU28Ead3W78QipWSefQkPZ" name="Building intelligent, resilient and sustainable supply chains_listing.jpg" caption="" alt="Whitepaper cover with title and blue, green, and pink circular arrow line graphics overlapping" src="https://cdn.mos.cms.futurecdn.net/VU28Ead3W78QipWSefQkPZ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/supply-chain-management-scm/369373/building-intelligent-resilient-and"><em>Connect processes and data across your supply chain</em></a></p></div></div><p>The acquisition has received <a href="https://www.itpro.com/cloud/virtualisation/broadcom-slammed-by-cloud-trade-group-amid-claims-its-holding-the-sector-to-ransom-with-vmware-license-changes"><u>stern criticism</u></a> from various stakeholders due to Broadcom’s decision to <a href="https://www.itpro.com/cloud/cloud-computing/broadcom-ceo-hock-tan-knows-vmware-customers-are-concerned-but-insists-the-first-100-days-have-been-a-strong-start">overhaul the licensing structure</a> for many of VMware’s most popular products.</p><p>Shortly after the acquisition in November 2023, Broadcom wasted no time announcing it would be <a href="https://www.itpro.com/cloud/cloud-computing/vmware-axes-another-saas-product-as-broadcom-ramps-up-its-relentless-subscription-model-push"><u>axing over 50 standalone cloud services</u></a> from VMware, including its popular Aria SaaS offering.</p><p>With its Workstation Pro and Fusion Pro announcement, VMware said the motivation behind the move was to “simplify how we bring VMware Desktop Hypervisor apps to market”, while ensuring both free and paid users received regular support and maintenance.</p><p>Enterprise users will find VMware has reduced its product group offerings down to a single stock keeping unit (SKU) for users who need licensing for commercial use. This simplification will eliminate over 40 other SKUs which VMware hopes will make quoting and purchasing their desktop hypervisor apps easier than ever.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the channel needs to take a lead on zero trust ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/why-the-channel-needs-to-take-a-lead-on-zero-trust</link>
                                                                            <description>
                            <![CDATA[ Channel partners need to bridge the gap between concept and implementation on zero trust, as escalating attack sophistication demands a more robust security framework ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WuSf3vyXj9TfXyXQ3o8xaP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TopTU2fuLE2dniuiCDadQ5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 May 2024 12:12:17 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 19:25:30 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jon Kane ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/xAhd4gLzyM9Fu8Nnxu2CaN.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TopTU2fuLE2dniuiCDadQ5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Pixelated cloud symbol on hexagonal shapes]]></media:description>                                                            <media:text><![CDATA[Pixelated cloud symbol on hexagonal shapes]]></media:text>
                                <media:title type="plain"><![CDATA[Pixelated cloud symbol on hexagonal shapes]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TopTU2fuLE2dniuiCDadQ5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Each day, <a href="https://www.itpro.com/security/cyber-security/370114/nearly-half-cyber-leaders-leave-roles-mounting-stress">security leaders</a> read about how cybercriminals’ tactics are becoming ever more sophisticated. <a href="https://www.itpro.com/security/369243/real-time-deepfakes-are-becoming-a-serious-threat">Deepfakes</a> and AI-powered <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing scams</a> deliver <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> campaigns that are more convincing than ever. Bad actors conceal their malware with encryption, hiding their movements with the same tools used by organizations to preserve data security. In this landscape, the case for <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero trust </a>has never been higher.</p><p>In a recent survey of UK security leaders, almost half (47%) cited attaining zero trust as critical to <a href="https://www.itpro.com/business/public-sector/misguided-public-sector-security-confidence-placing-organizations-at-risk">security confidence</a>, and more than 8 in 10 (85%) report having open conversations around zero trust at the <a href="https://www.itpro.com/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy">board level</a>. And yet, skepticism remains around how this can be achieved, with one third of respondents describing zero trust as ‘unattainable’.</p><p>The result is a tableau of <a href="https://www.itpro.com/business-operations/marketing-comms/365279/comptia-it-channel-companies-cautiously-optimistic">cautious optimism</a>. Although the majority of security professionals are embracing the tenets of zero trust, many remain aware of the complex journey that lies ahead of them. <a href="https://www.itpro.com/security/how-channel-partners-support-customers-in-a-challenging-security-landscape">Channel partners</a> have a critical opportunity to demonstrate their expertise and finally fulfill their customers’ security goals.</p><h2 id="understanding-the-necessity-for-zero-trust">Understanding the necessity for zero trust</h2><p>Since its inception in 2010, the <a href="https://www.itpro.com/security/361919/how-to-build-a-zero-trust-model">zero trust model</a> of ‘never trust, always verify’, has split opinion. After its initial reception as a revolutionary best practice, the complexity of implementing zero trust, complete with macroeconomic pressures, led many to see the model as an unattainable ‘buzzword’.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MHz3WBWYw8bysiJL9KTjQY" name="B0362EB7-05DB-476D-BEA4-6A8CF16FD8C4_1_201_a.jpeg" caption="" alt="Hands held out palms up with business analytics graphics overlayed above them" src="https://cdn.mos.cms.futurecdn.net/MHz3WBWYw8bysiJL9KTjQY.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/why-you-cant-rely-on-traditional-managed-service-providers">Why you can’t rely on traditional managed service providers</a></p></div></div><p>With zero trust being written into <a href="https://www.itpro.com/security/security-compliance-obligations-are-exhausting-uk-organizations">compliance</a> policies, organizations are increasingly aware of the need to implement and demonstrate their <a href="https://www.itpro.com/security/zero-trust-more-than-security-foundation-for-digital-transformation">zero trust infrastructure</a> to stakeholders, investors, and partners. The question now is, how?</p><p>It’s a scenario akin to the cloud revolution that played out over the last two decades. </p><p>Organizations understood that the <a href="https://www.itpro.com/cloud">cloud</a> presented <a href="https://www.itpro.com/cloud/31922/four-ways-to-keep-cloud-costs-under-control">cost savings</a>, <a href="https://www.itpro.com/infrastructure/backup/how-leo-a-daly-embraced-cloud-backups-for-scalability-and-security">scalability</a>, and efficiency, but laying out a strategy for cloud adoption and hybrid cloud security was far more than a tick box exercise. It required a mammoth <a href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">digital transformation</a> effort – one that many businesses are still adapting and enacting today.</p><p>Zero trust presents a similar journey, and there has always been a knowledge gap for end users around what zero trust truly is and how to achieve it. Except, unlike cloud, zero trust is not a market category, nor a segmentation. Instead, it is a way of thinking and structuring networks and protocols that can center around a number of authentication methodologies, from <a href="https://www.itpro.com/security/why-mfa-why-now">MFA</a> and <a href="https://www.itpro.com/security/29705/what-are-biometrics">biometrics</a> to device certification. </p><p>A <a href="https://www.itpro.com/security/what-is-zero-trust-network-access-ztna">zero trust network architecture</a> means zero trust principles are built into the very network of an organization in order to be fool proof. This stack of complementary monitoring and security solutions, built to satisfy each organization’s specific risk register and appetite for friction, comes together to make zero trust a reality.</p><p>Just as the channel supported organizations with the cloud, partners are now essential to the success of zero trust as a mindset, guiding these strategies from start to finish.</p><h2 id="lighting-the-path">Lighting the path</h2><p>So how can <a href="https://www.itpro.com/cloud/cloud-computing/how-the-channel-can-harness-cloud-opportunities-through-adaptation">channel vendors</a> and partners alike support their end-users in achieving this vital and elusive framework?</p><p>True zero trust networks need to focus on three core pillars: deep <a href="https://www.itpro.com/cloud/369995/solarwinds-hybrid-cloud-observability-review-the-big-network-picturehttps://www.itpro.com/cloud/cloud-management/gaining-observability-in-cloud-native-applications">observability</a>, <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">authentication</a>, and segmentation. The first pillar is especially crucial for this exercise. No zero trust strategy can operate effectively so long as there are security blind spots for bad actors to exploit. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KqLT92K6DieJcn5JtJEBr3" name="25FF3E92-5554-40D2-9390-FF91DD9A7C9E_1_201_a.jpeg" caption="" alt="Business man moves hand toward coin stack with data graphics overlayed on top" src="https://cdn.mos.cms.futurecdn.net/KqLT92K6DieJcn5JtJEBr3.jpeg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/do-you-know-your-datas-worth">Do you know your data’s worth?</a></p></div></div><p>Many organizations overestimate the level of visibility that they have within their organization: 39% of UK organizations report having the visibility to support zero trust, and yet just 29% can decrypt and inspect encrypted traffic – a common vehicle for malware. True zero trust rests on a foundation of real-time, network-level <a href="https://www.itpro.com/endpoint-security/30038/three-key-pillars-of-threat-visibility">visibility</a>, and this includes monitoring east-west traffic for behavioral anomalies between sub-perimeters and insights into <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted data</a> in transit.</p><p>The recent push towards <a href="https://www.itpro.com/channel/364228/the-importance-of-partner-specialisation">vendor specialization</a> will be an asset for partners in this climate. With expert, in-depth knowledge, partners can map out stacks of effective and complementary products that can build out a zero trust architecture without requiring a massive <a href="https://www.itpro.com/technology/artificial-intelligence/currys-eyes-cloud-overhaul-in-a-bid-for-generative-ai-adoption">technological overhaul</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5cYgwwq9QAhi8WxvdngGWf" name="Onward_How security drives business opportunity_listing.jpg" caption="" alt="A whitepaper from CDW on how Windows 11 Pro devices can improve security and drive business opportunities" src="https://cdn.mos.cms.futurecdn.net/5cYgwwq9QAhi8WxvdngGWf.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CDW | Microsoft)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/onward-how-security-drives-business-opportunity"><em>Make security a business enabler</em></a></p></div></div><p>If they aren’t already, channel partners need to start asking their vendors about their zero trust capabilities and compatibilities to ensure that they are meeting their customers’ true goals and displaying their expertise to inspire confidence. For vendors, embracing ‘coopetition’ could facilitate a smoother zero trust journey, in which customers are offered best-of-breed capabilities without being limited by incompatible solutions.</p><h2 id="restoring-faith-in-zero-trust">Restoring faith in zero trust</h2><p>For the partners equipped to support their end users’ zero trust journeys, customers’ ambitions spell an opportunity to grow revenue whilst nurturing end users and vendors alike. With consolidation at the forefront of all levels of the channel, successfully tailoring IT advisories and implementations to customers’ needs can not only reduce risk but also security spend. At a time when skepticism is high and budgets are tentative, this is an invaluable way to build trust with customers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Q79Ri8hYyzQtuyvYsiJCEn" name="69.jpeg" caption="" alt="Business man using phone as global netowrking graphic appears above his hand" src="https://cdn.mos.cms.futurecdn.net/Q79Ri8hYyzQtuyvYsiJCEn.jpeg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/consolidate-to-simplify-application-security-why-this-is-a-business-imperative">Consolidate to simplify application security: Why this is a business imperative</a></p></div></div><p>Zero trust is an area of ambition at best and a topic of deep uncertainty at worst, but the delay between zero trust becoming mainstream as a concept and its widespread, real-world adoption is an indicator that businesses need support and guidance. As IT infrastructure experts, channel partners who hone in on bridging this gap will be able to foster even greater trust, demonstrate their understanding of complex implementations, and ensure a baseline of security confidence for their customers.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft Defender for Business review: Feature-filled enterprise security for small businesses ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/microsoft-defender-for-business-review-feature-filled-enterprise-security-for-small-businesses</link>
                                                                            <description>
                            <![CDATA[ A comprehensive endpoint security management solution for smaller organizations with a painful setup process ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tgpVaUNK5bGZDVbcFFMxah</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iBRLUZjpKdYga6LWPiYeDX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 May 2024 09:00:00 +0000</pubDate>                                                                                                                                <updated>Sat, 11 May 2024 16:00:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/HdKafzrfv3Z6M5axRN8fhh.jpeg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iBRLUZjpKdYga6LWPiYeDX-1280-80.jpg">
                                                            <media:credit><![CDATA[Microsoft Press Kit]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Microsoft Defender for Business icon on the ITPro background]]></media:description>                                                            <media:text><![CDATA[The Microsoft Defender for Business icon on the ITPro background]]></media:text>
                                <media:title type="plain"><![CDATA[The Microsoft Defender for Business icon on the ITPro background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iBRLUZjpKdYga6LWPiYeDX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft&apos;s Defender for Business (MDB) is its Defender for Endpoint system, rebranded for businesses with fewer users. How does it stack up?</p><p>Microsoft has been selling variations of its Defender product for almost 20 years, but it has evolved considerably since its first release. The product began in 2005 as Microsoft AntiSpyware, a rebranded version of GIANT Company Software, which Microsoft had acquired the previous year.</p><p>Microsoft made its relabelled version freely available for Windows XP and up and quickly relabelled it as <a href="https://www.itpro.com/desktop-software/26635/how-to-turn-on-windows-defender">Windows Defender</a>, which was released for general availability in 2006 with a rewritten core engine. It eventually became a full antivirus product, rather than just an anti-spyware offering, and took over from Microsoft Security Essentials.</p><p>As Microsoft is wont to do, it continued rebranding over the years. In 2017, it renamed the product to Windows Defender Antivirus, and then ditched the Windows Defender brand altogether a year later, replacing it with Microsoft Defender to reflect its new-found support for other systems.</p><p>Now there are different versions of <a href="https://www.itpro.com/software/microsoft-defender-antivirus-review-defender-does-the-job-as-well-as-anything-else">Microsoft Defender</a> targeting different needs. Microsoft Defender for Endpoint targets businesses with Microsoft 365 E3 and E5 licenses, restricting it to customers with over 300 seats. There is also a version for customers with under 300 users, bundled into a Microsoft 365 Business Premium license.</p><p>Individual users also have choices; If the free Microsoft Defender Antivirus product included in Microsoft&apos;s operating system is not enough, they can buy Microsoft Defender for Individuals as a consumer product, bunched with <a href="https://www.itpro.com/business-operations/productivity/355642/microsoft-365-is-more-than-a-name-change">Microsoft 365 </a>Personal or Family licenses.</p><p>This left a key group out in the cold: smaller organizations with multiple endpoints to administer which were unwilling to pony up for a premium productivity software license. These companies might have a single admin responsible for everything, from provisioning machines to securing them, so any product that they use had better be simple enough to suit people limited on time. In 2022, Microsoft expanded support for that group by launching a version of Microsoft Defender as a standalone product for businesses with multiple users. Microsoft Defender for Business (MDB) was born.</p><h2 id="microsoft-defender-for-business-setup">Microsoft Defender for Business: Setup</h2><p>MDB is simply Microsoft Defender for Endpoint (MDE) with a new label, as is evident by the MDE branding still in the documentation. There was an MDE lab to help admins evaluate the product, but Microsoft shuttered it in January 2024. Instead, you&apos;ll have to jump straight into MDB with a free trial. After signing up, you can deploy according to which architecture model you have, ranging from cloud-native through to on-premises deployment or even evaluation without management tools in a small demilitarised zone (DMZ). You can deploy the Defender agents to several client types: Windows servers; <a href="https://www.itpro.com/software/364316/windows-vs-linux-vs-mac-the-channel-comparison">Windows, MacOS, or Linux</a> clients; or iOS/iPad OS and Android mobile devices. This extension of support for different platforms has been a big move for Microsoft, which wants to provide security information about your devices no matter whose software they&apos;re running.</p><p>Depending on your client, you can choose deployment via group policy or simply by running a local script, among others. You can also onboard devices already enrolled with Microsoft&apos;s Intune mobile endpoint manager, which was our chosen route.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nkJY2faZ4P9fjuCkSx3EiA" name="nkJY2faZ4P9fjuCkSx3EiA.jpg" caption="" alt="Whitepaper on unified endpoint management and security,with image of female working remotely at a laptop on her sofa" src="https://cdn.mos.cms.futurecdn.net/nkJY2faZ4P9fjuCkSx3EiA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369803/unified-endpoint-management-and-security-in-a-work-from-anywhere"><em>Find a security solution that works for you</em></a></p></div></div><p>Enrolling devices in Intune works seamlessly by running Microsoft&apos;s Company Portal app on the client, but our experience subsequently enrolling devices with Defender was patchy. While Intune supported our Windows Home installation, MDB did not (it will support Pro and Enterprise versions, though). That could be limiting for small businesses that might want to allow staff to access business resources from their home devices.</p><p>We were also able to register an iPhone and control it via Intune, but after setting up connectors between Intune and MDB we couldn&apos;t make the iPhone appear as a managed device in Defender. Doubtless, the fault was on our side, but we noticed similar complaints on Reddit, with one person noting that the success of iOS enrolment in MDB was "a coin flip". After diligently following the documentation and spending hours troubleshooting, we couldn&apos;t help but wonder how a harried admin wearing multiple hats in a small business IT department might fare.</p><p>We were eventually able to register a Mac with both Intune and MDB, although we were forced to download not just one installer file for the Mac but several policy files from Intune to get it MDB-ready.</p><h2 id="microsoft-defender-for-business-features">Microsoft Defender for Business: Features</h2><p>Assuming you can get past the setup niggles, there&apos;s a wealth of information available via the MDB interface, which features a dashboard-style setup displaying top-level information at a glance.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2355px;"><p class="vanilla-image-block" style="padding-top:56.09%;"><img id="cHhDzC9AgPTbf6idfYpswR" name="defender-welcome.png" alt="A screen shot of the welcome page on Microsoft Defender for Business" src="https://cdn.mos.cms.futurecdn.net/cHhDzC9AgPTbf6idfYpswR.png" mos="" align="middle" fullscreen="" width="2355" height="1321" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>You can move these cards around and add others, configuring an admin dashboard that makes sense for you. If you want to drill down, you can access the sidebar to see detailed information on various aspects of your security environment. Incidents and alerts flag up worrisome occurrences on your fleet of devices that might need further investigation. Another, Exposure management, offers a top-down view of your fleet&apos;s weakest points, with the ability to explore your attack surface visually, and summarise your overall performance in areas ranging from ransomware protection best practices to the number of vulnerable endpoints that have been involved in incidents.</p><p>This section also lets you further investigate your security score, which is an overall metric that Microsoft gives you based on a range of factors. As you can see, our fake company has a long way to go, although we did get more points after updating the security profiles on our Mac.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2399px;"><p class="vanilla-image-block" style="padding-top:56.90%;"><img id="UBsrfE2K5jgcN22aFuVnYV" name="defender-score.png" alt="A screen shot of the monitoring page on Microsoft Defender for Business" src="https://cdn.mos.cms.futurecdn.net/UBsrfE2K5jgcN22aFuVnYV.png" mos="" align="middle" fullscreen="" width="2399" height="1365" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>You can also drill down into specific devices, getting recommendations for actions to better secure them. If that version of Mozilla running on your PC is looking a little long in the tooth, MDB will let you know about it:</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2399px;"><p class="vanilla-image-block" style="padding-top:56.90%;"><img id="mn5G49a7BWaqRqmpWUe9kZ" name="defender-bad-mac.png" alt="A screen shot of the notification page on Microsoft Defender for Business" src="https://cdn.mos.cms.futurecdn.net/mn5G49a7BWaqRqmpWUe9kZ.png" mos="" align="middle" fullscreen="" width="2399" height="1365" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Another section, Actions and submissions, lets you review suspicious emails, files, and URLs submitted by users. Having these in one place gives admins a useful foundation for investigating what could be an attack campaign targeting their organization.</p><p>MDB also has a threat intelligence feed that gives you insights into ongoing threats out in the wild, along with a learning hub that offers training in various administrative tasks.</p><h2 id="microsoft-defender-for-business-is-it-worth-it-xa0">Microsoft Defender for Business: Is it worth it? </h2><p>There is lots to use here, if you have better luck onboarding your devices than we did. It&apos;s also worth noting that although MDB does a lot more than simply detect viruses, Microsoft&apos;s core client antivirus engine has also earned respect in the market. <a href="https://www.itpro.com/software/microsoft-defender-antivirus-review-defender-does-the-job-as-well-as-anything-else">Defender Antivirus</a> client that communicates with MDB garnered a Best Advanced Protection accolade from the AV Test Institute in 2022, notably for its excellence in warding off more sophisticated ransomware attacks. However, it lost its crown in the 2023 awards.</p><p>MDB is a feature-filled tool for security admins and provides a single view of your organization&apos;s endpoint security across the board, but we found setup a little more painful than many other Microsoft enterprise tools that we&apos;ve tried. You might find yourself working a little harder to deploy it across some non-Windows platforms, but if you&apos;re mostly a Microsoft shop, it might be for you. Its availability as a component in a <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a> Business Premium license is a good way to build more security visibility across a user base that will already be using Microsoft products and services extensively across their systems.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>