THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Luca Piezzo, Head of Cloud Center of Excellence, Banca IfisWhen it comes to Cloud Computing there are still some myths to be busted. Above all, the Security in all its shapes is still the key concern for several Enterprises across the Globe – is that still a point?
Security as we know it changed dramatically in the last decade. Back in the days there were firewalls but when Digital and Internet-exposed services arose, plenty of threats started becoming nightmares of most Enterprises (e.g. Ransomware, Social Engineering, Identity Exposure etc.).
Market perception of security has changed also due to regulations (e.g. GDPR, PSD2 etc.), increasing the security expenditure of Top Executive to comply to these requirements. All the services of Cloud Majors born certified with the highest standards available to support their clients in this transition and maintain their reputation aligned to market expectation since the beginning of cloud era.
How is possible that doubts about security are still there when talking about Cloud though?
Well, shifting the Operating Model to both benefit from technological standpoint and improving at the same time the Security Posture is not working as smoothly as expected. Maybe because Cloud is not just “another technology” or “someone else’s datacenter”, it’s clearly more pervasive and requires a deep organization transformation to effectively benefit from its adoption.
Cloud Security among other benefits is definitely not plug-and-play as it seems. You are not improving your posture migrating workloads onto Cloud. Of course, you might have secured the perimeter – your Datacenter can’t be safer than MAG’s ones (MAG – Microsoft, Amazon & Google – avg 1.2M$ per year of investments on security), but what about the remaining topics regarding Security? As discussed several times for other benefits of Cloud Computing (e.g. Scalability, Business Agility etc.), you have to change the way of working to enable all the Security Benefits of Cloud.

Standardize, Automate and Industrialize – these three steps are essential to cope with future security and technology challenges. No matter what is the service you are about to provision, you should always consider it as an IT product withing a Catalogue – Platformization and Product-based organizations are consolidated trends that will lead the market offering in the next years thanks to tangible benefits on TCO and Business Agility enabling Composable Enterprises as well.
Only by reducing human errors in core tasks you can improve Cloud Security significantly, moving then towards a Continuous Vulnerability Detection and Continuous Security Remediation it’s easy to understand how recurring processes are embedded in the “runtime Operations” of Applications and underlying Infrastructure. A.I is also changing the shape of the entire Security Market landscape, since introducing Machine Learning helps detecting events before they even occur and ISVs are migrating their offers in SaaS-based with deep integrations with A.I and Cloud Platforms (Marketplace) to support this transformation with a comprehensive offer, but as said above for Cloud their benefits are not plug-and-play – technology must be always interpreted to fully understand their benefits and what to do to properly enable them.