Why is Public Cloud Security so Hard?

4:19 · Watch on YouTube ↗

Transcript 529 words · about 4 min to read

Auto-generated captions from YouTube, not hand-corrected, so names and technical terms may be imperfect. The video is authoritative.

[Music] hey how's it going it's Keith Townsend from the CTO of Viacom but today's CTO dose I'm here to ask what seems like a basic question but it's really tough to operationalize the solution which is why is public cloud securities so hard FedEx recently announced that they had a wide open s3 bucket and a bunch of personal data was compromised and you have to ask yourself why are we seeing this same thing happen over and over again in large enterprises I recently well not recently a

little bit over a year ago I published a Pluralsight course on AWS security fundamentals AWS has all the locks guards biometrics physical security security at the hypervisor controls there's this huge security control panel you can go to to do encryption keys they allow you to manage your own encryption keys the the tools are there to secure your data why is it so hard to actually do it why do we keep seeing what seems like easy mistakes being made throughout these really large enterprises and I think

a lot of this goes to again is about people process technologies and this is definitely a people and process problem versus a technology problem I see this time and time again inside large enterprises you have this mentality that inside of your four walls everything is secure you're protecting the world from the outside if a employee has access to data they probably shouldn't have access to it for the most part you trust your employees sure you're gonna try and lock down Network shares and ensure database rights

reflect what the reality is you're going go through audits but still as a fallback you have the four walls of your data center to ensure that data doesn't get into malicious hands at least from a high level in the cloud we don't have that the good and bad part of the cloud is that it gives the power of compute and data and IT into the in users hands and end-users are not very good at security so the solution the solution is more education if you're going

to take a cloud first approach developers in users consumers of cloud have to be made aware of the risk associated with securing data the types of data that needs to be secured where that data can be accessed data protection how should that data be backed up etc if you're going to give distribute rights to cloud capabilities you need to train people technology solutions no come as the industry catches up we'll start to see solutions to integrate your arm premises IT approach to securing data to your

cloud assets but keep in mind if your on-premises solutions are broke now if employees who shouldn't have access to data have access to data when you put that data on to the cloud it exasperates the problem and now the public has access to data potentially that they shouldn't have access to that's it for this CTO dose follow me on the web the CTO visor comm on twitter at CTO visor talk to you next CTO dos