Trustwave Unveils New Offerings to Maximize Value of Microsoft Security Investments. Learn More

Trustwave Unveils New Offerings to Maximize Value of Microsoft Security Investments. Learn More

Services
Capture
Managed Detection & Response

Eliminate active threats with 24/7 threat detection, investigation, and response.

twi-managed-portal-color
Co-Managed SOC (SIEM)

Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.

twi-briefcase-color-svg
Advisory & Diagnostics

Advance your cybersecurity program and get expert guidance where you need it most.

tw-laptop-data
Penetration Testing

Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.

twi-database-color-svg
Database Security

Prevent unauthorized access and exceed compliance requirements.

twi-email-color-svg
Email Security

Stop email threats others miss and secure your organization against the #1 ransomware attack vector.

tw-officer
Digital Forensics & Incident Response

Prepare for the inevitable with 24/7 global breach response in-region and available on-site.

tw-network
Firewall & Technology Management

Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.

Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Microsoft Exchange Server Attacks
Stay protected against emerging threats
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
About Us
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Security Operations Platform
Trustwave Security Colony
Partners
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats

What Are the Risks of Hosting Data in the Cloud?

For all kinds of organizations, the shift toward the cloud is accelerating. In fact, Gartner predicts that by 2022, 75% of all databases will be deployed or migrated to a cloud platform, with only 5% ever considered for repatriation to on-premises.

Of course, along with this great migration come even greater risks – and the obligation to defend against them. To understand a little more about both topics, we talked with Mark Trinidad, a senior product manager at Trustwave.

Why are so many organizations moving towards hosting data in the cloud?

Mark:  There are a variety of factors that are driving this change, and I would say that the first is cost savings. As organizations move from traditional data centers, to using public clouds, they are saving money by eliminating the need to host large data centers – from racking and stacking to paying for the electricity. So, as they are migrating their infrastructure, the data will naturally follow.

Another reason is flexibility. The cloud offers so many different ways that your data can be hosted – along with easier ways to offer access – that it’s really so much more advantageous to most organizations, versus a traditional data center.

How secure do you consider cloud platforms to be?

Mark:  Potentially very secure… but that answer is highly dependent on each organization’s unique circumstances. Cloud platforms offer the ability for you to have a secure environment. That’s a way of saying that the cloud has embraced security upfront. Public cloud providers know that they’re going to have different customers with different regulatory requirements, so they know that they need to adopt a security-first mindset, with very secure functionality.

Organizations need to understand what those security features are, though. Just because cloud providers offer built-in security functionality, organizations still need to know what they are, how to use them properly, and understand the gaps to know what other solutions they need to bring to meet their security goals.

What are the top risks that organizations should consider?

Mark:  For the cloud, many of the risks are the same. You have the security risks, the business risks and the governance risks. The shift is in understanding how those risks apply to the cloud. And that’s a difference for many organizations, because for years they’ve understood all those risks from a procedural, technological and staffing point of view, but now they need to see it from a new paradigm. So – to figure out their top risks – organizations must learn to apply their existing risk controls to the cloud environment. 

In your experience working with clients, are there any commonly overlooked risks?

Mark:  Yes – many organizations assume that it’s the cloud provider’s responsibility to provide security, which is not true. So, organizations begin moving data into the cloud and essentially leave it all on the default configuration, without “reading the manual” and understanding all the features. And that’s understandable, because so many of the public cloud platforms make it so simple to get set up and stand up an environment – in some cases you can even try it free before fully committing. But while default settings may allow users to get up and running quickly, they lack the secure configurations. Cloud providers want to make it very easy to spin up environments through scripts that organizations can take advantage of, but they need to be cautious, because very security settings are not enabled in those scripts.

How can organizations best protect themselves?

Mark:  By understanding what their current security environment is—and how it’s going to grow. Very few organizations are going to be cloud only, or on-prem only, there’s usually going to be some sort of hybrid. So, as a basic best practice they need to consider what’s most important to protect in this hybrid world. Whatever security technologies and practices they have in place need to be adopted to the new environment. There needs to be a shift in mindset, a shift in skills, along with a shift in actual technology.

So, organizations can best protect themselves by looking at every single aspect of their program. Because each cloud platform will have its own security controls, finding a solution that helps with security and governance across all platforms, including on premises, will be best. Ensure that you understand what security the cloud platform provides and understand your risks to help ensure your data is protected no matter where it lives. Use tools that give visibility into your data across all platforms.


15951_database-security-in-the-cloud-cover
WHITE PAPER

Database Security in the Cloud

Many organizations are moving to cloud-based IT infrastructures as a means of solving scalability, performance, availability and cost problems. However, they often fall short in ensuring the security of their data and assets as they move to the cloud. In this white paper, Trustwave experts share best practices to help you secure your databases in the cloud.

Latest Trustwave Blogs

Why Vulnerability Scanning is an Offensive Security Program’s Secret Weapon

Knowing what you don’t know is the key to keeping an organization safe and the best method of doing so is with an offensive security approach that includes vulnerability scanning. By being proactive...

Read More

Upcoming Trustwave Webinar: Maximizing the Value of Microsoft E5

Many organizations license Microsoft 365 E5 to obtain its productivity features, which makes perfect sense because that is what the tool is known for. However, E5 also shines in the security realm...

Read More

Comparably Honors Trustwave with Leadership and Career Growth Awards

Comparably, the leading workplace culture and compensation monitoring employee review platform has recognized Trustwave with two major awards: 2024 Best Companies for Career Growth and 2024 Best...

Read More