The digitization of global enterprise poses tough challenges for security teams tasked with keeping attack surfaces as limited as possible.
Business technology, including the cloud and artificial intelligence, are drivers for innovation. But this innovation has to go hand in hand with robust data management and security.
Cloud enables innovation by driving scalability, flexibility, and faster time-to-market. But this increased reliance on cloud technology also expands the attack surface, making it critical for IT teams to ensure that both identity management and data are robustly secured.
The need for access to applications and data any time, from anywhere, does bring risks.
“There is no longer a perimeter, and there hasn’t been for a while,” warns Karl Ots, global head of cloud security at EPAM.
“And we are facing a new generation AI-powered attackers and threats. Everything is faster, cheaper and by default connected to the internet. Attackers can exploit weaknesses much more quickly than in the past,” he says.
Unfortunately, new technologies also present an opportunity for bad actors, if organizations fail to build the right defensive measures.
“We are seeing companies actively employ new technologies, new approaches, and AI. All this changes the attack surface drastically,” cautions Dmitry Berger head of security delivery and GenAI at EPAM North America.
“And malicious sectors also employ new methods to make their attacks more ‘efficient’. Automation, AI, and other tools allow malicious actors to scale their efforts, exploit weaknesses faster, and identify blind or weak spots in your attack surface with unprecedented speed and precision.”
Layered defenses
However, security teams can counter these threats – provided businesses update their approach to security.
All too often, organizations react to a breach or to new threats by spending money on additional security tooling. But these investments are only effective when security tools work together.
In fact, CISOs will often enhance security by making better use of their existing tools.
“You don’t need another security tool. You don’t need another new dashboard,” says Ots. “Organizations tie a lot of their operations budgets to tools, but the reality is that we don’t use majority of the capabilities of existing tools. Even if you buy best in class, you won’t see the benefits of it if you are not also investing in operational efficiency.”
Organizational barriers, too, lead to security blind spots. Removing these barriers demands cultural change, but eliminating departmental silos is a highly effective way to improve defenses.
“There’s different people, different budgets, different responsibilities even within security,” says EPAM’s Ots.
“It’s already a big enough problem that security is a domain of its own, separate from digital and from IT. We don’t need to create a set of silos for application security or cloud security.”
And as organizations have modernized their technology, they have created new security roles outside the traditional CISO organization. “We need to create security systems that propagate a culture of collaboration between teams,” notes Berger.
This provides the vital business context that plugs security gaps.
Fire fighting
With security teams under constant pressure, it is hard to find the time and space to break down barriers. Here, an external adviser’s view can help.
“We notice inefficiencies and room for improvements in an environment that clients don’t notice because they’re just too deep in their processes,” says Berger.
“We’re engineers by nature at EPAM, so I think we have more authority when we talk to other engineers,” adds Ots.
Effective security today is about viewing threats in the context of the wider business.
Security leaders should partner with experts who share their vision and integrating defenses and breaking down barriers that give opportunities to attackers.