enterprisesecuritymag

siliconindia | | April 20138 | | May - Jun 20158The use of cloud computing is officially mainstream across most industries, yet many executives still worry that provider security practices remain inadequate to protect sensitive data and mission-critical workloads. It's a long-held belief--and one that's starting to change. In The Global State of Information Security®Survey 2015, we found that 55 percent of organizations worldwide now use some form of cloud computing, up from only 38 percent two years ago. While the benefits of cloud services--lower costs, greater operating efficiencies, and immediate scalability, to name a few--have fueled adoption in recent years, it seems evident that a new driver is at work. Our research shows that 59 percent of organizations that use cloud services report that doing so has improved their information security program.That's certainly worth pointing out because, for many business executives, potential threats to data security and privacy have always been the dark, untrustworthy side of the cloud. Perceptions are shifting, however, as major cloud services vendors have continued to develop and implement increasingly sophisticated security capabilities.While there has been an uptick in attacks on cloud service providers recently, it's important to note these incidents did not result in reported breaches of sensitive data. This could suggest that cloud services today have strong security controls and have proactively implemented the technologies, processes, and personnel necessary to quickly detect and mitigate incidents.Providers are investing in security and certificationsTop-tier cloud providers have been steadily investing in cutting-edge tools for data protection, threat defense, network security, and identity and access management. They are, for instance, beginning to add infrastructure capabilities such as software-defined perimeters to create highly secure platforms that can be adapted in such a way that allows mitigation of most tools, techniques, and procedures (TTPs) used by malicious actors. Should a d v er s a r i es infiltrate the network, some cloud providers employ principles of DevOps combined with communal learning and rapid-response forensics tools to reduce the time lag between detection and remediation.Furthermore, cloud providers are increasingly gaining certifications and assessments from third-party guidelines and By David Burg, Principal and Global and US Advisory Cybersecurity leader, PwCWhy the Cloud May be the Safest Place to Store Your Sensitive Data CXO-INSIGHT
< Page 7 | Page 9 >