Just Say No to Firewalls (Multi-Cloud)
Transcript
[Music] hey how's it going to keep Towson from the CTO visor comm you know I I have to have a follow-up video to this Twitter conversation that we had about multi cloud and firewalls I'll put out a tweet that basically said firewalls are useless when it comes to multi cloud that's not completely true firewalls have a purpose and multi cloud but I want it to spark a conversation which I did around the chain the shifting focus of security or the nature of security and multi cloud
let's start the conversation with the private data center we've now are painfully aware that firewalls are no longer by themselves an effective means of protecting the enterprise security threats no longer just come from the outside and we can't trust a web server sitting next to a development server to be secure those two devices can be compromised and we need this concept of zero trust applications to only taught the application is that they should talk to workstations shouldn't be talking to other workstations the industry has done
a great job of reacting to these needs alumina alumina nsx Palo Alto all these solutions have all these products have solutions around what we call east-west traffic inside of the enterprise but as we extend out to public cloud we get a little gushy I mean we can take some of these concepts and we can put a firewall inside of our Amazon VPC and say that hosts one can only talk to host two of course Amazon has this natively already the only reason why we would do
this is so that our firewall administrator and private data center can leverage the same tools inside of the public cloud this is I don't want to call it lazy its effective that's what we want we don't want to recreate the wheel when it comes to security it's complicated enough however the technology and public cloud is starting to outpace the solutions that we have available to us give a scenario which I think is a legitimate real-world use case for where firewalls really don't protect you're a multi
cloud environment now you're using salesforce.com for your CRM and you're using Amazon to host web pages using s3 buckets as the datasource prospect goes to your website downloads a white paper off the s3 bucket developer says you know what I can trigger a AWS lambda event to update Salesforce automatically to let the sales team know that they need to followup with a prospect multi-cloud use case I think that's a legitimate use case where does a firewall play a rule in or play a role in that
use case it practically doesn't a firewall can't say today hey lambda rule that goes out to Salesforce or lambda cult that goes out to Salesforce that does something I can't protect against that or even let's start at the beginning the developer being able to write a lambda script off of a event in AWS how do how do we know from my identity perspective the developer has the right to even do that that's not a firewall job or firewalls capability so identity becomes a much much much
more important part of protecting in a multi cloud environment Kandice developer do these actions are the intent what are the guardrails can put in place that are centralized and easy to manage well it's not easy I'm hate to tell you the the solutions as I know aren't on the market I haven't been briefed on a developer or a software developer or product that has that capability to date a thing for point is one of those port thinking companies that's taking a bunch of different companies Cass
B solutions traditional firewalls putting some machine learning around that and around identity identity management and has a vision for it but not necessarily their VMware Nutanix they're all talking about these challenges but not necessarily products to address them so in the meantime we have to do with education we have to educate developers we have to educate security operation teams development centers DevOps folks we have to communicate and say what the policies are one so we should probably go back and rewind and create a policy what
can you what can you and can you not do when it comes to multi cloud and multi cloud services and then enabling the workforce with the skills or knowledge to know what they shouldn't shouldn't do so I'm saying just say no to firewalls at least it's your primary method of protecting a multi cloud it is a part of your strategy but not the strategy you disagree with me you think a firewall can do the job I'd love to hear your comments down in the youtube comment
session or over on linkedin where you can find me or on twitter at CTO advisor or even if you think you can pick up different use cases of where firewalls and traditional security approaches just don't work and not just multi clout but the public cloud in general I'd love for you to share that with me visit me on the web the CTO advisor until the next CTO dose I'll see you on social media talk to you then