Four essential cloud security concepts

July 2019 Information Security, Infrastructure

Possibly the most important attribute of the cloud is that critical business applications can be deployed, managed, and distributed faster and easier than by any other method, giving employees and customers real-time access to important information – wherever they are located and on whatever device they are using. That requires nimble resources that can scale and move, and applications that are simple and intuitive to use, have access to real-time data, and can be quickly updated to meet constantly evolving trends.

Doros Hadjizenonos.
Doros Hadjizenonos.

Security is just as critical a component of any cloud environment – especially as cybercriminals look to exploit the rapidly expanding attack surface. But to be effective, it needs to be as agile and dynamic as the cloud infrastructure being protected.

Effective security not only needs to protect connections between data and users, but also secure literally every connection to every physical or virtual device across the distributed infrastructure.

In such an environment, complexities arise from the use of different security solutions, as deploying security solutions that are only available on a single cloud platform may not be available on others, and may have functional limitations. Such deployments have actually imposed limits on the true potential of the cloud.

To address these challenges, organisations need to incorporate the following four security concepts into their cloud development strategies:

Security-led cloud development

Security breaches tend to be the result of a determined cybercriminal exploiting the weakest link in an organisation’s attack surface. And for many organisations, the adoption of the cloud has expanded their attack surface exponentially. Eliminating those weak links requires security to be enforced consistently everywhere, even when the infrastructure is in a state of constant flux.

Because infrastructures are expanding and changing so rapidly, it is essential that an overall security plan become the foundational requirement for any network changes. Mandating that proper security tools, policies, and procedures are in place before any new resources are spun up allows security to adapt in sync with infrastructure and application changes. This requires selecting security tools that understand the infrastructure in which they have been placed, and that can also operate consistently across all environments – including multi-cloud – to enforce policies and ensure visibility that enables secure applications and connectivity from data centre to cloud.

Cloud-native security

Since data and workflows will need to move throughout the infrastructure and to the cloud, security needs to function consistently. Selecting a cloud firewall from the same vendor that is protecting the organisation’s physical assets will not necessarily solve that problem. There is a need for these solutions to interact seamlessly with cloud services and subscribe themselves to these services as well as identify cloud-based resources in the same logical way that they identify other resources.

That said, the underlying technology used for protecting networks is very different from the tech used for protecting cloud-based resources, but the practice of managing security needs to remain similar. That is why native integration into the cloud infrastructure is critical.

Multiple form factors

Consistent security enforcement depends on the same security solutions being deployed across as many platforms and in as many different form factors as possible. Applications, for example, should be able to make calls to a cloud-based security solution to identify and protect specific data and transactions. Container-based applications should have access to containerised security tools in order to easily integrate security functionality into the application chain. And ideally, these tools should be operated in the exact same way as solutions deployed everywhere across your distributed infrastructure, including at branch offices and edge devices.

However, don’t fall into the trap of thinking that a virtual version of your network firewall will be adequate for your cloud or container deployment.

Central management

One of the biggest complaints from network administrators is that they cannot see and manage their entire network through a single console that extends visibility across physical and virtual networks. A management solution that can see and close the gates against an attack in one area of the network but not in another is likely to lead to a compromised infrastructure. To eliminate gaps in security enforcement, organisations need a single pane of glass to gain visibility and define consistent security policies throughout the entire infrastructure to effectively manage risk. Security solutions need to share and correlate threat intelligence, receive and implement centrally orchestrated policy and configuration changes, and coordinate all resources to respond to detected threats.

Rethink your security

Traditional security models where devices are placed at a network gateway to monitor predictable traffic and devices are obsolete. Today, security needs to span your distributed infrastructure, dynamically scale when application resources grow, and automatically adapt as the infrastructure continuously adjusts to changing demands. And just as important, it also needs to ensure consistent functionality and policy enforcement regardless of its form factor or where it is deployed. Achieving that may require you to rethink your current security infrastructure.

If the cloud is going to play a significant role in the future of your organisation, you may be better off finding a single vendor that supports your overall application lifecycle and infrastructure roadmaps and expansion plans – especially a solution that provides consistent protection and functionality across multiple public and private cloud domains, even if that means replacing the traditional security hardware you have deployed on-premise.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Service robot technology for residential complexes
Suprema AI & Data Analytics Infrastructure Residential Estate (Industry)
Suprema has signed a three-party memorandum of understanding (MOU) with Hyundai Motor Group Robotics LAB and Hyundai Engineering & Construction (Hyundai E&C) to collaborate on advancing residential complexes through service robot technology.

Read more...
95% do not have full trust in cybersecurity vendors
Information Security Security Services & Risk Management
Trust in cybersecurity vendors is fragile, difficult to measure, and increasingly shaping risk posture at both operational and board levels. Lack of verifiable transparency undermines cybersecurity decision-making, according to Sophos-backed research.

Read more...
Proactive estate security in Cape Town
neaMetrics OneSpace Technologies Technews Publishing SMART Security Solutions Fang Fences & Guards ATG Digital Editor's Choice News & Events Integrated Solutions Infrastructure Residential Estate (Industry)
SMART Security Solutions started the year with our annual SMART Estate Security Conference in Cape Town on 26 February 2026. Held at Anna Beulah Farm, the conference saw a number of delegates enjoying the farm’s excellent cuisine, while listening to outstanding presenters.

Read more...
AI projects are failing at alarming rates
AI & Data Analytics Infrastructure
As organisations around the world accelerate their investments in artificial intelligence, digital transformation and data analytics, a growing number of industry experts are warning that many companies are still approaching these initiatives in fundamentally flawed ways.

Read more...
Africa’s largest Zero Trust platform
NEC XON Information Security Commercial (Industry)
Africa has reached a significant cybersecurity milestone with the successful deployment of the continent’s largest Palo Alto Networks Prisma Access and Prisma Access Browser Zero Trust environment, supporting secure remote access for more than 40 000 users for a large enterprise in Africa.

Read more...
Supply chain attacks top threat over 12 months
Information Security
Supply chain attacks have become the most prevalent cyberthreat confronting businesses over the past year, according to a new Kaspersky global study, with nearly one-third of companies worldwide experiencing a supply chain threat in the past year.

Read more...
From vibe hacking to flat-pack malware
Information Security AI & Data Analytics
HP issued its latest Threat Insights Report, with strong indications that attackers are using AI to scale and accelerate campaigns, and that many are prioritising cost, effort, and efficiency over quality.

Read more...
NEC XON secures mobile provider’s hybrid identities
NEC XON Access Control & Identity Management Information Security Commercial (Industry)
For a leading South African telecommunications operator, identity protection has become a strategic priority as identity-centric attacks proliferate across the industry. The company faced mounting pressure to secure both human and non-human identities across complex hybrid environments.

Read more...
Cloud security in visitor management and access control
SA Technologies Access Control & Identity Management Infrastructure Residential Estate (Industry) Commercial (Industry)
Cloud has become the default platform for modern security operations, from visitor management portals and remote access control to incident logging, reporting, analytics, and integrations. But “in the cloud” does not mean “someone else is securing it for us”.

Read more...
Microsoft 365 security is a ticking time bomb
Information Security
Across boardrooms and IT departments, a dangerous assumption persists that because data is stored in Microsoft 365 and Azure, it is automatically secure. This belief is fundamentally flawed and fosters a false sense of protection.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.