In this episode of Cyber Security Inside, Camille and Tom chat about digital transformation and security with Darren Pulsipher, Chief Solutions Architect, Public Sector at Intel. The conversation covers:
How the move to remote work has sped up not only the process of using the cloud and digital transformation, but also the willingness to dive into the idea of digital transformation.
Companies have a lot of decisions to make when it comes to security breaches, and need to consider many factors.
Who is responsible for data security and access in the cloud, and why.
How automating security might play a positive role in the future.
...and more. Don’t miss it!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
Here are some key takeaways:
With digital transformation, people often talk about the cloud. But there is more than one cloud, and they have to communicate with each other. Keeping that secure is a large part of this conversation.
Before COVID, there was a lot of confusion about whether to go to the cloud or not. But COVID accelerated the timeline of the cloud and digital transformation. The remote workforce became a necessity and an asset.
Now, it’s all about security given the number of breaches there have been over the past 18 months. And it has been new security breaches in places we weren’t expecting, such as meat plants.
Sometimes security breaches are not just about if they pay ransom or not. Sometimes it’s about who they tell and if they make it public.
When Target was breached, they made the information public quickly. Others have sat on the data for a while until after they were able to fix the breach. Those are big decisions to make, and it is about more than security - it’s also about PR.
Darren’s prediction for the future of CIOs is that they move away from being Chief Infrastructure Officers and move into being Chief Information Officers. They will be more focused on driving competition and innovation inside companies.
There is a line that companies walk concerning privacy. If they are too transparent, they would be giving information about where data is locally housed or where it is in the cloud, which could be dangerous. On the other hand, there is a desire for transparency and explainability in the public. Legal heps CIOs walk that line, and reframe the discussion to focus on the fact that the data is secure, not where it is secured.
There is misinformation about the services that cloud service providers give. They are not responsible for data security. If you are storing something in the cloud, you need to be encrypting it and managing access to it.
The type of security and cloud use completely depends on the product you are offering and the industry you are in. A bank will handle cloud access very differently than a startup trying to get people engaged.
A mentality change needs to happen to really have security embedded in development and structure. Part of this is that security needs to make it easier to secure things for developers to help them get on board, and to not slow them down as much and create as much frustration. We have to make it easy.
Hackers are getting smarter and doing more clever things to get the information they need. And our response is automation so that security can happen automatically without human interaction. We are moving away from click ops and moving more towards a fully automated security center.
Some interesting quotes from today’s episode:
“Do I go to the cloud? Do I stay on-prem? COVID hits - it’s amazing what a pandemic will do to focus. Plans they had to move everyone to Office 365 in the next three years happened in three weeks. People were now looking at the remote work force as an asset, not as a detriment.” - Darren Pulsipher
“Because of the move to cloud so much in the last 18 months, they’re okay now if something gets infected. They’ll just shut it off, and move it somewhere else. They’re concerned more about their data. Is their data going to be held ransom? Is someone going to take copies of their data and release it out into the public?” - Darren Pulsipher
“I think the big emphasis is on information management, information structure - and that doesn’t mean throwing everything into one data center. There’s just too much data everywhere. So now it’s the job of information officers to find where the data is.” - Darren Pulsipher
“It’s funny, when I talk to individuals about privacy, they get very concerned. And then I see them on Instagram sharing pictures, and I’m like, “Okay.” So there’s a perception of privacy.” - Darren Pulsipher
“I think we’re at the point now where I don’t think it really matters where, as long as it is following good security best practices.” - Darren Pulsipher
“If you have data in the cloud, you’re responsible for the security of that data. It’s not the cloud service provider. Which means you should be encrypting that data in the cloud.” - Darren Pulsipher
“If you’re not building security into the products you’re developing, and they’re bolted on afterwards, you’re still going to get these Frankenstein applications out there and security will be a constant battle.” - Darren Pulsipher
“Security postures can happen automatically without human interaction. And the companies I start seeing doing that are having quite a bit of success in deploying new applications faster and with more security.” - Darren Pulsipher