Hi [[ session.user.profile.firstName ]]

Exposed in the Cloud: Agility Comes With Risk

According to Gartner, spending on shadow IT can exceed 40% of the formal IT spend. That’s probably not too surprising for those of us leveraging the cloud to move quickly. But it means that enterprise IT and security teams often don't know where all of their organization’s digital infrastructure and assets are, or whether they’re fully protected.

Meanwhile, attackers are constantly looking for the path of least resistance into your organization. They probe your attack surface hoping to find any oversight they can leverage to break into your high-value digital assets, steal your critical data, or freeze your digital business operations in exchange for a bitcoin ransom payment.

To stay ahead, organizations need ongoing, comprehensive visibility across the attack surface of their entire IT ecosystem, whether assets are on premises, in the cloud, at subsidiaries or in partner networks.

Join Jim Wachhaus as he discusses why attack surface visibility is a “must have” to manage and reduce digital risk in the cloud, and in general.
Recorded Oct 1 2020 49 mins
Your place is confirmed,
we'll send you email reminders
Presented by
Jim Wachhaus, Director of Technical Product Marketing, CyCognito
Presentation preview: Exposed in the Cloud: Agility Comes With Risk
  • Channel
  • Channel profile
  • Cloud Security post Covid-19, Where to Go Next Nov 3 2020 10:30 am UTC 30 mins
    Carlo Gebhardt, Managing Director, Accenture Security
    Over recent years, security and compliance have been some of the top considerations when moving to the cloud. However, as Covid-19 has served as a transformation accelerator in many aspects of our digital life, cloud consumption is skyrocketing, and cloud transformations are booming. In order to achieve a sustainable cloud experience, it is now more important than ever, that security & compliance are not sacrificed for the speed of migration.

    In this talk, we will not only investigate the current state of cloud security, but we will also elaborate on scenarios and capabilities that support organizations in rapidly and securely adopting the cloud, and in maintaining compliance once operating in the cloud.
  • GAIA-X: Current Status and Outlook – What to Expect and How to Engage Nov 3 2020 9:45 am UTC 30 mins
    Andreas Weiss, Head of Digital Business Models, eco Association of the Internet Industry
    The key objectives of GAIA-X, Community Engagement and participation via the GAIA-X Association. European Data Infrastructure as part of NextGenerationEU - based on GAIA-X.
  • The Correlation Between Security Ratings and Breach Likelihood Nov 3 2020 9:00 am UTC 30 mins
    Matthew Mckenna, VP, International Operations, Security Scorecard
    What is the value of security ratings when it comes to predicting breaches? What are the indicators that breached companies are showing that non-breached companies don’t express? This session will examine breaches that have occurred in 2020 and present those security issues most commonly found in breached companies versus control groups of companies in the finance and healthcare that have not experienced publicly notified breaches. We will look at overall ratings, factor ratings and specific security issues which are more predominant in breach groups and illustrate the correlation to breach likelihood.
  • CSA’s Perspective on Cloud Risk Management Nov 3 2020 8:00 am UTC 30 mins
    Daniele Catteddu, CTO, Cloud Security Alliance. John DiMaria, Assurance Investigatory Fellow, Cloud Security Alliance
    This session is designed to introduce the publication of CSA’s unique insights into the challenges of mastering the widespread adoption of cloud technologies. More importantly, CSA will help members understand the importance of translating identified cloud and technology risks into those risks that are crucial to achieving business success and prosperity - the true rationale for the widespread growth of cloud computing. The presentation will also reveal those hidden technical risks that can expose organizations to operational failure, regulatory non-compliance, data breaches, external attacks and supply chain disruption.
  • Automating SAML Security Tests Oct 29 2020 5:00 pm UTC 60 mins
    Ty Anderson, Application Security Researcher - Product Security Team, Adobe
    Single Sign-On (SSO) applications are becoming increasingly prevalent in organizations today. While there are many different SSO configuration types, Security Assertion Markup Language (SAML) is one of the most common in enterprise environments. Unfortunately, the current SAML 2.0 version is complex, and prone to misconfiguration, which can result in critical authentication and authorization vulnerabilities. Most large organizations likely have hundreds or thousands of applications that have been configured with SAML over the past 15 years, and many new applications still choose to incorporate SAML over other options. Because of how SAML is often incorporated into an existing environment, we are provided with a valuable opportunity to programmatically analyze each workflow and follow up with better preventative controls.

    In this webcast we will explain how an organization can gather an inventory of SAML-based applications, test for vulnerabilities in each workflow, and then effectively validate and report those findings with minimal false positives. We will also shed light on common mistakes that can complicate and slow down a project and provide useful tips and tricks that can help avoid these pitfalls.
  • STAR 1000 - The reason behind the STAR Program success story Oct 27 2020 5:00 pm UTC 60 mins
    Daniele Catteddu, CSA and John DiMaria, CSA
    The cloud has come to dominate the technology landscape and revolutionize the market, creating a tectonic shift in accepted practice contributing to a massive advancement in technology. With an increase in business demand for cloud computing, also comes increased security and privacy concerns. How organizations evaluate Cloud Service Providers (CSPs) has become key to providing increased levels of assurance and transparency, better risk management and ultimately trust

    The STAR Program, the CSA program for cloud assurance, transparency, and accountability, was established in 2011 with the exact purpose of improving the level of trust in the cloud ecosystem and since it’s instantiation has evolved into the leading cloud-specific program for governance, risk, and compliance.

    In 2020 we are celebrating the achievement of the 1000 cloud services evaluated according to the principles of the STAR Program.

    Join us during this historic session where we bring together a top expert panel that includes the key innovators in the evolution of CSA STAR, along with CSA members that utilize the STAR Registry to communicate to their current and potential customers.

    Sponsored by Whistic.
  • Public Cloud Database Security: Using Others’ Mistakes to Stop Attacks Recorded: Oct 22 2020 59 mins
    Aaron C. Newman Founder, SecureCloudDB
    Hacks and breaches occur regularly. It can take months to find and contain an incident. According to Gartner, 99% of cloud security failures will be the cloud customer’s fault. Why is that?

    Join us as we
    - Dissect cloud database security — it’s different from on-prem
    - Get acquainted with cloud database hacking — real-world examples put the practice into perspective
    - Provide guidance on how to prevent breaches and stop attacks in their tracks — learn from what others didn’t do

    Leave with actionable takeaways regarding how to defend against dynamic threats.

    More about the presenter:
    Aaron Newman is an acclaimed international speaker and serial entrepreneur who has founded six successful startups including Cloud Storage Sec, SecureCloudDB, CloudCheckr, Techrigy, Application Security, Inc. and DbSecure. Aaron authored the books Enterprise 2.0, printed by McGraw-Hill, and the Oracle Security Handbook, published by Oracle Press. He has presented at hundreds of database conferences and user groups on technology topics and has been awarded multiple patents in cloud and database security.
  • The Current & Future of Cloud Security Strategy Recorded: Oct 22 2020 56 mins
    Ken Low, Subhajit Deb, Alex Ng, Noordin Yusuff Marican
    Join fellow CISOs for this panel discussion about Cloud Security strategy in 2020 and beyond. Where should you place your bets (and your budget)? How can you protect your organization from the new threats? And perhaps, most importantly, what do you say to the CEO who comes looking to you for cloud security answers?

    This session is moderated by Ken Low, Cybersecurity Industry Leader and Former Chairman, APAC Executive Council, CSA.

    Panelists include:
    Subhajit Deb, CISO, Dr. Reddy’s Laboratories,
    Alex Ng, Director, Insyghts Security,
    Md. Noordin Yusuff Marican, Global CISO, Circle.Life,
  • Watching the STARs Recorded: Oct 22 2020 36 mins
    Sanjeev Gupta, Director, Certification Partners Global
    We review what Certification means, in the most important
    criterion for a business, sales. How does a Certification Program
    achieve this? And what are the costs, not just direct. How should an
    Organisation begin this process, what to look out for, and what do you
    get at the end? We also review the differences of the CSA STAR with other Cloud Security programs.
  • Coronavirus, Computer Virus, Cyber Threats: A False Sense of Security Recorded: Oct 22 2020 37 mins
    Ekta Mishra, APAC Membership Director & Country Manager - India & Dr. Ngair Teow-Hin, CEO, SecureAge Technology
    With most office workers working from home due to Coronavirus pandemic, computer virus attacks on home computers are now a major issue facing the world. In this talk, we discuss the history of computer virus, cyber threat and why enterprises can be insecure due to having a false sense of cyber security. We also discuss how computer users can get infected by computer virus and what they can do about it.
  • The Rise and Importance of Digital Identity Recorded: Oct 21 2020 28 mins
    Chris Bailey, VP of Strategy and Business Development, Entrust
    One of the factors that drives innovation is the demand for convenience and efficiency while maintaining security in our digital lives. Certification authorities (CAs) enable secure encryption and provide ownership identification in their digital certificates for websites that ask for sensitive personal data, such as passwords and credit card numbers – but only some digital certificates include confirmed website ownership information, while others do not and allow websites to operate anonymously. This has already resulted in an explosion of anonymous encrypted phishing websites imitating authentic websites and stealing user information. This analysis explores how the current security landscape was shaped, and how proposed changes will impact the brands and the security of users who interact with them moving forward.
  • There is no more enterprise perimeter. Now What? Recorded: Oct 21 2020 33 mins
    Bob Flores, Satyavathi Divadari, Sandip Kumar Panda & Keith Prabhu.
    With more and more emphasis on cloud computing, the traditional enterprise perimeter is being redefined. This means enterprises must think differently when considering cybersecurity protection. The panel will explore changes enterprises should consider for risk management.

    This session will be moderated by Bob Flores, Founder and CTO of Applicology Inc. Panelists include:
    Satyavathi Divadari, ​​ Chairman, CSA Bangalore Chapter
    Sandip Kumar Panda, Co-Founder & CEO, Instasafe
    Keith Prabhu, Chairman, CSA Mumbai Chapter.
  • Zero Trust and Identity as a Service Recorded: Oct 21 2020 28 mins
    Nya Alison Murray, CEO, Trac-Car Technology
    As the threat landscape and cybersecurity risks are an ever present threat in 2020, it is clear that measures have to be taken to be more mindful of what end users, people, applications and IOT device connections we allow through the virtual network defences into the platform and software services. As malware continues to evolve, accidental misconfigurations grow with application complexity, and new forms of operations hacking emerge, and the top three attack vectors were Phishing (31 percent), Scan and Exploit (30 percent) and Stolen Credentials (source IBM X-Force), it is clear that Identity Management and Access Control require attention to ensure they effectively protect data centre resources. It is clearly time for a new approach to identity services allowing or denying access, particularly for insecure network connections.
  • SDP & 'Black-Cloud' Protection Recorded: Oct 21 2020 28 mins
    Juanita Koipillai, Founder & CEO, Waverley Labs
    Security has become of paramount importance in recent times, especially due to the advent of cloud computing and virtualization. With so many devices in the mix, users have the choice of working from anywhere they want. The rapid increase in global IP traffic have challenged network service providers to scale and improve infrastructure to meet this new demand. We explore the merits and performance of Software Defined Perimeters to withstand DDoS attacks in multiple network implementations including hybrid cloud applications, network function virtualization and software defined networks.
  • SASE Economics: The New Frontier of Cloud Security Recorded: Oct 21 2020 35 mins
    Dr. Hing-Yan Lee EVP APAC, CSA & Jonathan Andresen, Senior Director Marketing, Asia-Pacific & Japan Bitglass
    Secure Access Service Edge (SASE) has become one of the hottest topics in the IT industry. Fueled by cloud services, the rise of BYOD and fast tracked by the new reality of remote working, direct-to-cloud platforms radically disrupt the economics of traditional IT security. By 2024, Gartner predicts that 40% of companies will adopt a SASE architecture.

    But what exactly is SASE and will it make enterprise data more secure? How will organizations secure their data in a cloud-first world when the user and information are completely outside the enterprise boundary? This presentation cuts through the hype to explain the fundamentals of SASE, and how it compares to typical network and cloud security architectures. It will cover real-world use cases for securing SASE, and the benefits of moving to a cloud-first SASE platform.
  • Collaborating for Inclusion & Equality in Cybersecurity Recorded: Oct 20 2020 45 mins
    Larry Whiteside, Jr., Co-Founder & President ICMCP and Illena Armstrong, Industry Strategy Advisor, CSA
    Diversity, inclusion and equality strategies and practices have always been integral to organizations’ daily operations and future growth. The need for executive leaders to genuinely embrace, evolve and continually hone their strategies this front has, indeed, become an even more acute differentiator and positive, constructive attribute of leading organizations. And while the cybersecurity industry, as a whole, has made some solid inroads to drive and nurture diversity, inclusion and equality efforts, more can and must be done. To be truly impactful in the long-term committed and continuous collaboration will be required. In this spirit, the Cloud Security Alliance and the International Association of Minority Cybersecurity Professionals are teaming up to support their respective members and the wider industry to aid them in further refine and reinforcing their inclusion and equality programs and long-term strategies.
  • A Practical Guide to Securing Container, Docker Host, and Kubernetes Environment Recorded: Oct 20 2020 43 mins
    Carson Sweet, CEO and Cofounder & Bryan Jones, Solutions Architect, CloudPassage
    As organizations implement container-based and microservice architectures in the cloud, the number of containers to secure is growing exponentially. Traditional security approaches will not work for containers due to their dynamic, distributed, and ephemeral nature. 

    Join this educational session with a demonstration that will cover:
    - Popular container deployment architectures 
    - Security requirements of container-related components including IaaS accounts, images, image registries, container runtimes-as-a-service, and container hosts
    - A best-practice demonstration of shifting security left by automating container security in the CI/CD pipeline
  • International Data Transfer Recorded: Oct 20 2020 61 mins
    Neil Thacker, Netskope; Nathaly Rey, Google; Marc Lueck, Zscaler; Giuseppe Brizio, Qualys; Nick Gross, OneTrust; Linda Strick
    Join this panel discussion with experts from the CSA GDPR Center of Excellence.
    What does the ruling of the European Court of Justice on the Privacy Shield mean in practice? What are the realistic possibilities for companies to have customer data processed outside the EU?
  • Modeling Against the Top Threats in Cloud Recorded: Oct 20 2020 31 mins
    John Yeoh, Global Vice President of Research, CSA
    Since 2010, the CSA Top Threats report has revealed major security concerns in cloud computing from top industry professionals. John shares how the report can be used to protect against the latest attacks and high profile breaches of the past year. Leveraging the latest Deep Dive attack model, popular breaches are broken down into the threats, risks, and vulnerabilities that were exposed. Critical mitigations and controls are also shared to make sure your organization is prepared for these types of attacks.
  • State of Cybersecurity 2020: Cloud Security Threats and Security Practices Recorded: Oct 20 2020 33 mins
    Phoram Mehta, President, ISACA Singapore Chapter.
    For the last 3+ years ISACA has been conducting member surveys around the world on State of Cybersecurity. The latest report based on survey conducted in Q4 2019 focuses on the threat landscape, the measures security professionals employ to keep their enterprises safe, and key trends and themes in the practice of security.

    This presentation will focus on Cloud security specific findings and analyse key threats and defense strategies being employed in areas of audit, risk management, security and governance of Cloud programs.
Educational series on cloud computing, security and privacy.
CSA CloudBytes was launched as a webinar series to help us educate the industry on all matters related to the cloud. Our channel is designed to inform our audience about trending topics, new technologies, and latest research. It also allows audience members the opportunity to earn (ISC)2 CPE Credits.

Learn more at cloudsecurityalliance.org. Join the Cloud Security Alliance on LinkedIn and follow us on twitter: @cloudsa

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Exposed in the Cloud: Agility Comes With Risk
  • Live at: Oct 1 2020 5:00 pm
  • Presented by: Jim Wachhaus, Director of Technical Product Marketing, CyCognito
  • From:
Your email has been sent.
or close