Sumo Logic’s Dave Frampton on Creating a Cloud Security Strategy

Transcription

hi i'm james mcguire and today we're discussing cloud security and the various elements of an effective cloud security strategy to discuss that i'm joined by dave frampton vice president of security solutions at sumo logic dave hello to you and happy friday to you happy friday to you james great to be here so i i'd like to ask you where are we now with cloud security and if i can put that question in a little context i i think it's been established that cloud is safer than on-prem i'm sure not everyone would agree with that but it seemed like years ago people thought oh you know cloud is dangerous we better keep it all in-house but that's i mean we don't hear about data breaches in the cloud so much we hear about a lot of data breaches for companies the other part of that question is that you know perhaps it's enterprises that are failing to meet their side of the bargain that you know the large cloud providers have really put clear security protocols in place maybe now it's up to the enterprise to to step up and invest all that polarity say what's your take on cloud security where are we today well i think to to start with the original part of your your question observation there we're well past the tipping point um you know i think you can find your favorite statistic i saw one just the other day that said that in 18 months 60 of companies digital assets would be you know in the cloud so i think whichever you know you pick we're clearly well past a tipping point where cloud security is not the new thing and the adjunct thing is the main thing right right along with that you know there comes unnecessary awareness of the basics i mean many of these are security challenges that were faced in the old on-prem worlds as you alluded to and now they just need to be ported you know to to the cloud so you know there's a sense of okay there's visibility and scale and you know identity and all of these things i think what the cloud does is really just challenges doing the basics at scale i think that that's from a perspective of the amount of data volumes that you have to look at in order to get basic visibility uh the amount of third parties that might be chained together to execute a basic function which might have been more kind of monolithic you know in in the past so i think i think one you know if you look at sort of the the current punch list of challenges i think we're we're past we're resisting as you point out we're we're to we understand the basic issues but now we're trying to operationalize doing some of these basics at scale to the cloud and i think you hit on another big one which is just understanding the shared responsibility model i think what's interesting about that is you know even beyond just understanding what is a platform as a service responsibility versus an infrastructure as a service responsibility there's understanding within an enterprise who needs to understand that and who's responsible meaning in the old world you had one security operation center in a sock and and you know you had a dedicated team there and they were sort of you know globally responsible for everything but in emerging cloud models you have more of a federated model where you have individual lines of business that have security responsibility for in many cases software that they develop in that line of business um it was a part of digital transformation that has you know faces the internet uses you know public tooling you know to create that that software so when i hear the word federated it's a short interruption when i hear that it's federated i hear the word less secure but don't let me interrupt too much i i you know you you hit on a fault line that cesa's debate all the time i think trying to find the sweet spot for your org and your regulatory environment of how centralized and locked down you need to be and if you you centralize too much then you're slowing down the velocity of the business and so there's a ditch on that side of the road you know you distribute too much and then you lose coherence and end up with people that uh you know have responsibility that exceeds their capacity and their and their skill sets so csos debate this all the time in a cloud security context is how do i how do i educate and partner with the the lines of business in order to make sure that we identify that sweet spot that shared responsibility which is challenging enough in and of itself because you generally have to go up the stack and protected the application layer be responsible for that in a way that you maybe didn't in the on-prem world you need new skills and all of that but then you know stepping back and realizing you might have one line of business that is is far down the maturity curve of capacity in that area whereas you have four others that aren't and if they have that self-awareness are we committed as an organization to up leveling and and whatnot so i think that that's also just you know a current i think challenge of the basics that at scale federer you hit on federation a minute ago so i'll just i'll double click on that yeah and some in the long list of cloud security to spend a little more time on i think the other the other challenge is many many companies started out using a single cloud and right on amazon and said okay now my challenge is i need to learn you know how all this works in amazon all these different you know tools and services and should i use them or should i use my own and what is the logging data look like but increasingly you know for business continuity for you know economic leverage avoiding lock-in and for geographic and regulatory reasons um you know people are adopting more of a multi-cloud approach where you end up with say google and azure as microsoft as well as as amazon you have to think about well now these three environments you know they have some broad similarities but there are key differences amongst you know all three of those environments and you being aware of how do i understand what those differences are understand which ones i'm going to force harmonize and normalize on my end and which ones tolerate you know difference in um and this this federation challenge even extends to the data itself where it's stored you increasingly you have you know an increase in nationalism where people you know for for security and compliance reasons potentially even you know motivated by by some politics at some point you know right we'll have you know data located within certain national boundaries and in at the technology layer underneath that that creates some fundamental questions about how do we effectively search across these different federated regions so you may have regions that fragment and then you may have clouds that fragment and you know sort of as a security practitioner you know this is this is a big challenge i mean you not only have to figure out you know how to secure all of this but you have to figure it out in that that kind of fragmented um you know map across those different uh different axes so where we are to to nettle that out you ask you know where where we are in cloud security we are the tipping point this cloud security is security i think for sure um now what people are trying to do is the basics at scale and start to operationalize this recognizing that they're going to be running their businesses here and that they're going to have to partner and collaborate in a more distributed way with the lines of business uh as opposed to the old way where it was really the silo and the central security operations center that set the rules and you know in detect investigate respond all of that the new world is is far more diverse and complex than that it just requires different skill sets both at a technology level and also just at a at a leadership and collaboration level i'd say nine out of ten of the you know the late night uh complaining sessions with csos are how do how do i transform my org to to an org that has the maturity to go out and strike these alliances evangelize where appropriate build you know build trust you know with with people who maybe don't understand as much about security as they do right so it's some of this is not just technology it sort of goes beyond that into you know more of a business skill set that's becoming required and a lot of security operations as this cloud transition has uh has moved ahead yeah so it's it's an interesting challenge you you describe in that there was the old world there's sort of there was a there was a moat there was a there was a one bridge you get to cross and now of course it's federated and in that in that's in that you know spread out world there there's more people who might be putting their password on a sticky note and and tape it into the front of their pc you never know that kind of stuff it's like you never know what might be going on with that more federated routine hopefully not that bad uh sorry so that's that's the challenge if that's the challenge then then what is the solution and that how do you describe a cohesive cloud security strategy what what sort of elements need to be in place you know it's it's it's a great question in some sense going back to the previous cloud security is securities so it's a familiar checklist um right but i would say that there's a couple of areas that that become more important in a cloud context relative to a previous as you go through the checklist of you know i'm going to need to get i need my visibility i you know i need my compliance and all the usual usual things one of them i think is the the importance of the question what am i protecting and how do i um with what priority and how do i align my spend and my effort with what is most sensitive for me because it's easy in a cloud context to go down the rabbit hole of trying to go to the absolute bottom of some of these chain third-party services and and spend an enormous amount of your budget and energy uh you know on something like that but as an example if your bigger business problem and risk is fraud you know you may be you know sort of spending all of your energy in the wrong place right and i think cloud just provides more opportunities for that misalignment than there was in the previous model so i think that's a you know that's that's a big element of this i think the the second one is whether your company is there or not uh in the journey of digital transformation you have to assume that it will be there and that will be the default mechanism of business transaction uh for your business now that's not true obviously of certain isolated industries but by and large you know most of the economy will run in a very digitally transformed way in which a lot of it used to be sort of physical it will end up being digital and that would be delivered you know sort of over the internet right business gets further and further down that path what you need to protect and how you need to protect it and the skill sets and and the tooling and the budget that you need to protect it they shift pretty dramatically it's much more is this sort of higher layer application focus as opposed to the old infrastructure lay right as you point out the cloud you know provider is doing a lot of that now right so you don't worry about uh you know that as much you need to think about the business context of these applications so for example you have an analyst in the sock who's trying to deal with an alert uh that has been provided by one of the tools right old days you could take a sis admin training them up in that analyst role and you know after a little bit of experience they would be more or less self-contained and know what to do kind of how do i figure out what happened where did it spread what do i do about it that that's the sort of core workflow that goes on inside of the security operations center right new digital transformation model it may not be clear whether there's a security issue or not you you may need uh collaborate with the application teams the service reliability engineering teams and teams that really you didn't have that much interaction with in the previous model but now are essential to iteratively puzzle through is this a security issue what's the business context you know this location might have been talking to an externally risky entity with high frequency but maybe that's appropriate given the function of that part of the application was to register um inbound solicitation requests right so knowing that business context and the application context becomes more essential for the security people who are working in this model so you you get this sense um that a modern cloud security strategy needs to take into account assume that we get to that end state of digital transformation and i have to then plan my my skill sets my personnel maybe my rotation maybe i create a virtual sock maybe i rotate engineers in and out of the sock these things were just not on the table five years ago it when people thought about the sock and the skill sets that you would need and how to retain you know people and how to lock it down and control it and only give visibility to a small number of people i mean this is sort of very you need to think in your cloud strategy about even if i'm not there yet i i need to assume that i will be and then you know how do i plan ahead uh to to get there well it sounds like from from here you speak that really this this new world of cloud security is exponentially more complicated than the old world of we need to secure the data center it's like it it's it's certainly possible to be as secure as we were in the old world it's just that we were secure uh but it seems like this this new scenario is way more complicated than it used to be am i correct you're thinking no i for sure there's more complexity i think anybody would debate that i think yeah some of the complexity has shifted from one area to to another and don't forget i mean it's like the security topic is always one where you can you know obsess about the wall of worry and then you you sort of you know get a little bit too pessimistic about it realize at the same time the cloud has enabled uh some new tools uh for defenders that didn't exist uh previously so just give you an example this idea of community analytics meaning the old world you know you protected the environment on-prem in your environment you had your sock you watched carefully you tried to learn maybe get a threat feed and learn from the experiences of others but in the new world there's technology at several layers of the stock that can observationally uh look at large numbers of customers and how they're how they're behaving how they're reacting and do this in an anonymized way and then surface um actionable insights about the experience of of the many to the individual customer so for example in real in real time you're saying or is it not in real time in real time and this is why you know what our you know i would say candidly more practical applications of machine learning that existed in security in the early hype cycle days of that right because learning is very good at clustering together who should be your peer group and across large sets of data what patterns emerge that you know stand out against the noise so you can apply those techniques to large numbers of customers and then surface to individual customers um calibration of uh is something rare or not um have other people reacted to this in an immediate way or a delayed way uh how do i calibrate severity how am i different how is my environment different than uh other environments in terms of how i've organized my defense so the cloud has opened up a little bit more of a collective defense set of options that really didn't exist before so yes you're right the complexity is way up you need to retool your people you know the approach you have to let go control all of those things but it's also just you know opened up some powerful new tools automation would be another one i would throw out there that right right environments are much more adept at figuring out ways to standardize across environments so that you can automate what used to involve human intervention and and in that way dramatically increase the efficiencies of your people um and your and decrease your response times and all this so jesus one quick question about the automation don't you think that the bad guys realized oh this is an automated system i'm interacting with so i i realize that every exactly every 37 minutes they're gonna let down so i'll just wait for that 37 minute point whereas with a human you never knew but with the automated system you know how to fool it better or is it it doesn't work like that at all so you're right automation is a two-edged sword right you you have to be cognizant not only of the risk that you mentioned but you know obviously if the core automation scripting engine itself is compromised then obviously you have you know a whole new this surface uh that that comes i would just say do two things on on this one is i think this is not a choice i mean the the scale of this problem it's not a human scale problem anymore so every everyone has to automate to to have a prayer of keeping up so then the question is how do i automate with discipline how do i put in so that i mitigate the risks that you're pointing out and and others that you know we could go through uh but i think the consensus is is very broad at this point that the trick is just figuring out how do we do this as responsibly as we can you know not you know kind of dragging our feet and and will we do it i would say just for you know your audience is sort of wrestling with some of these things one thing we see customers wrestling with a lot in automation is sphere of control because oftentimes it's very clear say for a security uh you know analyst hey i need to take some quick remediation action as a result of this threat i need to quarantine these users just as lots of examples right um but you know based on the way the it infrastructure is set up i may need to get you know buy-in and approval from you know an engineering team you know an i.t you know leader uh or a line of business leader in order to take some automated action you know in in in the middle of the night right that has lots of consequences that maybe i don't understand as a security analyst maybe we were about to product launch the next morning and i not knowing this you know i shut down the you know some critical part of the website that was supposed to go live right i mean so i just say on on the automation front there's a there's a technology question we were on before which is hey how do i make sure i do this thoughtfully so the hackers can't compromise it and we have the lion but there's also this sort of organizational and policy governance question that usually is thought about too late in the process and i just you know for people out there that are struggling with this type of thing try and get ahead of that um if you start thinking about the ways to harness automation um you know which are more numerous in the cloud as as we were talking about them than they used to be and really the only way you can keep up um you know i i i really it's super interesting i'd like to get your sense of uh where we're going in the future and you've talked about that somewhat but if it's if we're looking at cloud security in the year 2024 uh which is frighteningly close uh what's going to be going on and how could we be ready for that now we're trying to get ready for what's gonna be going on now what's your prediction i think maybe this is even you know a broader time span than just the the next few years but i think yeah all three things as i think about you're sort of in the the next you know five to ten years in sure and really securing the first one is is something we haven't talked about so far in the in the podcast here which is the the economics of this i mean the nation of most security defenses is core visibility right it's pretty straightforward if you can't see it then you know you're obviously providing you know a level of opportunity for your adversary it right into is i need to collect a lot of telemetry a lot of data whether it's it's you can call it logs or metrics or event data or context or pick your favorite you know for all of that and the amount of that data that i need to collect is growing at a pretty exponential rate because of the creation of all of these different modular software development processes all of these different specialized you know sas tools and sure and so so there's a question how do i how do i how do i ingest all of that data how do i store it for a long enough period of time to do analytics uh you know that i need to do to catch these kind of low and slow attacks that you know only develop over over a long period of time right the economics that are very challenging for for customers and and i think there is it will be a big frontier of innovation and disruption and creativity uh how people choose to deal with that that problem um it's too expensive is what you're saying is that am i hearing you're right it's too expensive uh is probably uh number one there's also a scaling issue of uh can i bring all that data into one place and you know analyze it or do i need to distribute the processing of all of this data it's a little bit sort of down the weeds technically but right i think in the in the big picture people are going to start looking for alternative models and moving away from some of the legacy models where a lot of this uh was bundled together in a single kind of monolith like we want to solve your security problems so we'll just give you eight layers of the of the stack and there's some cost in this layer but we'll monetize it in that layer but you won't know the difference because we're just going to kind of put it all together you know i think this this notion of what is the data lake that that is going to be cost effective enough and high performance enough to support the core visibility is going to be a big big battleground lots of tough choices lots of great innovation but i think that's going to be a big part of keeping up uh with with the cloud the the community analytics thing i think the next step of that if i arced out more to 2024 and beyond i think people are very uh these these models of data analytics whether they're ml or ai or what have you they'll model them with large-scale simulation because then that's really the the only mechanism to keep up with you know the pace of the attackers and and the amount of you know adaptive change that that they can bring to bear in so many different places at the same time is you have to do something which avoids the manual human processes of learning from your experience and then upgrading your defense and and doing that it's just too slow so right figuring out how to marry advanced analytics and then simulation to basically you know apply that analytics on real data on uh similar data on community data and then bring that back into your own environment i think is going to be really the one of the two or three pivotal ways that the defense has to adapt um in in the next um and the last one is i think we hit well but it's just the automation i mean the pace of all this will increase to the point that you're gonna have to refactor the budgets around engineering and security so that they're much less concentrated in human capital right and we're going to think about this process very very holistically between engineering and security to automate this inside the product and then outside and around the product the product being the digitally transformed you know sort of business app that that is the core engine of the company in in a way that i think we've started just we've just scratched the surface on now right with devsecops and all of this this is like anything number two in a nine-inning game to think about how horizontally and how much automation we're gonna have to build in you know to really secure the environment as you as you look out in these longer time frames now some of these things i'm talking about maybe a little little out past 2024 but but the to your question of you know what do i think about and hear about from thought leaders and customers as they kind of think about okay big picture in the next longer cycle those three the economics and simulation analytics and automation are probably the three that come up yeah the simulation one is really cool it's like it's it's the idea of creating a model so you sort of like model it out you know you game it out ahead of time which seems like that is going to be a very necessary piece you can't just put the castle wall up there and wait for the attackers you want to model it out is that the idea and right now back to the the nine inning game and you know where are we i don't know why baseball this is probably baseball season right now i think so there you go it's terribly outdated but it's you you think about the common mainstream practices okay we're gonna we're gonna do a red team exercise right so i'm gonna i'm gonna pay some external firm they're gonna come in and you know probe the environment and you know not tell people we're doing it then we'll do an after-action report see what we found not all of that so this is a great practice if you think about that you know there are people you know that monetize you know the insight and the capital to be able to apply those tools in a one-time fashion on on your environment but it doesn't require a leap of imagination to say if we looked at that differently and we were able to economically simulate our own environment completely and then 24 7 continuously attack that with a simulator and then assess the weaknesses in our defense and then automate the closing of the holes in those defense like that this is this is where this needs to go not like the board gave me an extra budget this year to hire the red team consulting firm that you know that i put in so you're absolutely right that one i i really think that's one of the only paths to scale this well all right then that that leads me to one last question i know we're running late but i find that fascinating based on what you just said because it's sort of like you you simulate it out and then you automate the attack or you maybe automate the defense be or automate both but and that gives you a big advantage having that simulation and having that automation gives you a big advantage all that as you mentioned is going to be very expensive so sort of like we look ahead to this world where we can get into some very sophisticated security situations with the simulation and the automation but it's going to be pricey so it's going to perhaps correct me if i'm wrong created this this digital haven't have not where they're really people with the deep pockets really can protect themselves from cyber attackers but without those deep deep pockets you really can't or will this filter down be become democratized and really even like joe's pizza joint can have you know simulation and automation of you know whatever you heard my uh my aspiration earlier with the community analytics i think you know my hope is on the democratization um of this and yeah i mean keep in mind too that the people with the the deep pockets they have the burden of being the ones that are getting targeted by the attackers scanned casually by the middle so there's sort of a you know there's almost a matching effect there that goes with the wrist right i think that like many tech technologies in security and otherwise in it you know the early versions of this are are going to be prototyped and borne out both on the vendor side and and on the enterprise side you know by people that have those extra resources but i think if you look at the history of the economics of a lot of the technologies that we now use as mainstream in the defense including for example since this is about cloud security i mean look at look at the amount of security that you know the three cloud providers you know provide for free as a part of their very inexpensive service and their free massive portfolio of security tools that are available to joe i think you said joe's parlor or whoever it was pizza yeah right and imagine if you had backed up the clock 10 years and i mean for joe's pizza to have access to those technologies at those near you know points would have been kind of my a little bit mind-blowing so obviously you know the the truth is somewhere in the middle but but there's at least some evidence to not despair that it will degenerate into full have and have not i think i think this this will be something that that and the cloud providers back to your theme of the uh you know of the show here you know they have a big role to play in this i mean they'll be able to absorb and assimilate and not let some of this innovation just be captured in high premium you know sort of vendor monetization models i'm going to help this this process along as well well it's reassuring uh dave i very much appreciate your sharing expertise today i i learned a ton it's super interesting uh thank you very much james it's great to talk to you great to be here

This transcript was generated automatically from the video's captions and may contain errors.

Written By
James Maguire
James Maguire
Published: Aug 25, 2021
Updated: Nov 19, 2024
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

I spoke with Dave Frampton, VP of Security Solutions at Sumo Logic, about the new threat surfaces that companies need to focus on protecting – and how companies can strategize for the best cloud security

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.