Is the Cloud Secure?
CSA AGM 2019 - HSBC (London)
@FrankSEC42
It’s easy if you do it smart
https://uk.linkedin.com/in/fracipo
@FrankSEC42https://uk.linkedin.com/in/fracipo
Is the Cloud Secure?
CSA AGM 2019 - HSBC (London)
@FrankSEC42
It’s easy if you do it smart
https://uk.linkedin.com/in/fracipo
Disclaimer: the pictures and the format in this presentation are under license to NSC42 Ltd
Agenda About the author
Conclusions & Take Away
Q&A
Solution to reach there
The problem and ideal
world
How things have changed
Context
@FrankSEC42
CSA Conference & Awards
www.nsc42.co.uk
About the Francesco
5
Francesco Cipollone
Founder – NSC42 LTD
I’m a CISO and a CISO Advisor, Cybersecurity Cloud Expert. Public Speaker,
Researcher and Director of Events of Cloud security Alliance UK, Researcher
and associate to ISC2.
I’ve been helping organizations define and implement cybersecurity strategies
and protect their organizations against cybersecurity attacks
FC-LinkedIn E-Mail Website Articles NSC42 LinkedIn
Security is everybody’s job
@FrankSEC42
@FrankSEC42https://uk.linkedin.com/in/fracipo
Security is challenging, we have to know inch deep and miles wide
www.nsc42.co.uk
How Things Have Changed
6
How did we evolve to reach here?
What is the impact on the security?
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Cloud Evolution
7
2005
2006
Datacentre
Land 2007
2008
2013
2010
2011
2012
2014
Cloud
Adoption
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Challenges
8
- Increasing number of breaches
- Impact on Cost (Brand, Fines, …)
- Fast change
- No collaboration teams and security
Security is everybody’s responsibility
@FrankSEC42https://uk.linkedin.com/in/fracipo
Security Challenges in cloud transformations?
www.nsc42.co.uk
Major Breaches
9
2009/
2010
2012
Microsoft
Heartland
US Military
Aol
TJMax
2013
2016
2017
2014
2015
2018
Sony PSN
NHS
Betfair
Steam
Deep Root
IRS
Anthem
Dropbox
Lastfm
Blizzard
Marriot
Twitter
MyHeritage
Uber
Quora..
Why security is everybody’s responsibility?
Myspace
Twitter
Yahoo
Linkedin
Friend Finder
Dailymotion
Mossack Fonseca
JP Morgan
Home Depo
Ebay
Yahoo(orignal)
US Retailers
Adobe
UbiSoft
Court Ventures
2012
2019
…
Because we all get affected by it…
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Major Breaches
10@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Challenges
11
- Increasing number of breaches
- Impact on Cost (Brand, Fines, …)
- Fast change
- No collaboration teams and security
Security is everybody’s responsibility
@FrankSEC42https://uk.linkedin.com/in/fracipo
Security Challenges in cloud transformations?
www.nsc42.co.uk
Ideal cybersecurity world
12
In an ideal cybersecurity world we would have infinite time, infinite
resource to do things right, and all the boring chores would be
automated
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Solutions
13
1. Cloud Responsibility Matrix
2. Cloud Foundation
3. Cloud Patterns
4. Design Security
5. Security by Design
6. Dev shift left
7. Security Testing
8. DEV-SEC-OPS + BIZ/ARCH
Security by design = everyone
participate in security
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 1 - Cloud Responsibilities
14
Customer Application & Content
Network
Security
Identity &
Access
Control
Operating
System/
Platform
Data
Encryption
The
Customer
Customer
Defines
controls
security IN
Cloud
Customer
takes care of
the security
OF Cloud
Physical
Infrastructure
Network
Infrastructure
Virtualization
Layer
Cloud platform
“Understand Shared Responsibility model Delegation and you’ll master cloud”
Consider what are you are getting yourself into in a cloud migration. Cloud
is not natively secure or insecure
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 1 - Cloud Pizza
15
IaaS, PaaS, SaaS, …
Who cares give me pizza!
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 2 – Foundation
16
How do you build a solid
house?
You don’t skip the foundation!
How do you build a solid
cloud?
You don’t skip the foundation!
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 2 – Foundation
17
1. Management Support
2. Disruption and strategy
3. Security as part of the cloud journey
4. Skills shortages
5. Architecture patterns & Re-use
How do you build a solid cloud (security) foundation?
Cultural, Management support and skills
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 2 – Foundation
18
What Tools do you use for the solid cloud (Security)
Foundation?
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 3 – Cloud Patterns
19
- Account Isolation
- Controls Traditional vs cloud
- Logging and monitoring
- Identity and access management
- Key Management
“There is no such a thing as free lunch…
but leverage on patterns as starting point”
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 4 – Design Security
20
“How would expand the security team without expanding the team?”
Train Software Engineers on security and you’ll have ‘extended
security team’”
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 5 – Security by Design
21
“So what would the software engineer do with the security hat on?”
“gamification…remember to have fun when doing your job”
How do we make threat security fun?”
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 6 – Shift left in DEV
22
“Security as early as possible: Integrate security in the software
development pipeline”
Keep Threat or fraud model exercise concise and fun! Don’t overcomplicate
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 7 – Security in Test
23
“Security (Testing) as early as possible”
Security testing as bug bounty program! Make it fun and rewarding
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Step 8 - DEV–SEC–OPS(BIZ)
24
What kind of animal is the DEV-SEC-OPS?
Integrate security into the OPS team (and add a spark of BIZ)
Security is everybody responsibility.
@FrankSEC42https://uk.linkedin.com/in/fracipo
Reward security effort with -> Low cost High Impact
Integrating Security
www.nsc42.co.uk
The Future
25
“Cybersecurity due diligence will remain the
same regardless of the technology chosen”
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Conclusions
26
- Evolution & Challenges
- Ideal world and step to reach it
- What’s in the future
Security in the journey to the Cloud not at destination
Security is everybody’s job
@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Mentoring
Research
Events
Networking
Twitter: @csaukchapter
LinkedIn: https://www.linkedin.com/groups/3745837/
CSA-UK - We need you
27@FrankSEC42https://uk.linkedin.com/in/fracipo
Join!
Every Fortnight 1.30 PM UK
Time
#MentoringMonday Call
@FraSEC42
Cyber Security Awards 2019
Cloud Security Influencer of the Year
Submission – 10 of May 2019
Ceremony 4 July
2019
#CYSECAWARDS19https://cybersecurityawards.com/
https://cloudsecurityalliance.org.uk
Submit: info@cybersecurityawards.com
Info:
www.nsc42.co.uk
Q&A
30@FrankSEC42https://uk.linkedin.com/in/fracipo
www.nsc42.co.uk
Contacts
31
Get in touch:
https://uk.linkedin.com/in/fracipo
Francesco.cipollone (at) nsc42.co.uk
www.nsc42.co.uk
Thank you
WHEN YOU ARE CYBERSAFE WE ARE CYBERHAPPY
@FrankSEC42
@FrankSEC42https://uk.linkedin.com/in/fracipo

More Related Content

PPTX
Nsc42 - is the cloud secure - is easy if you do it smart Cybersecurity&Cloud ...
PPTX
Nsc42 - is the cloud secure - is easy if you do it smart UNICOM
PDF
Guy Rombaut - Security in the IoT generation & End of Cloud - Codemotion Mila...
PDF
ESA - Hacking the aerospace industry - should we worry ?
PDF
Fowa2010 progressive-enhancement
PDF
Why conquering complexity is a critical component of an effective security pr...
PDF
A New Zero-Day Vulnerability Discovered Every Week in 2015
PDF
Ab cs of software security
Nsc42 - is the cloud secure - is easy if you do it smart Cybersecurity&Cloud ...
Nsc42 - is the cloud secure - is easy if you do it smart UNICOM
Guy Rombaut - Security in the IoT generation & End of Cloud - Codemotion Mila...
ESA - Hacking the aerospace industry - should we worry ?
Fowa2010 progressive-enhancement
Why conquering complexity is a critical component of an effective security pr...
A New Zero-Day Vulnerability Discovered Every Week in 2015
Ab cs of software security

Similar to Nsc42-CSA AGM is the cloud secure - is easy if you do it smart (20)

PPTX
Nsc42 - is the cloud secure - is easy if you do it smart ECC Conference
PDF
Building Security Into Your Cloud IT Practices
PPTX
CSA - Nsc42 - London chapter keynote - cloud transformation security challenges
PPTX
Nsc42 security knights slayer of dragons 0-5_very_short_15m_share
PDF
Cloud Security Demystified
PPTX
Cloud computing 10 cloud security advantages and challenges
PPTX
A Throwaway Deck for Cloud Security Essentials 2.0 delivered at RSA 2016
PPTX
I am sharing 'Unit-2' with youuuuuu.PPTX
PPTX
Cloud application security (CCSP Domain 4)
PPT
cloud-computing-security.ppt
PDF
How to get started in cybersecurity
PPTX
Cloud Security By Dr. Anton Ravindran
PPTX
Cloud security for banks - the central bank of Israel regulations for cloud s...
PDF
Cloud Security - Kloudlearn
PDF
Cloud01: Best Practices for Virtual Cloud Security - H. Del Castillo, AIPMM
PPTX
Practical Security for the Cloud
PDF
Resetting Your Security Thinking for the Public Cloud
PDF
Security Teams & Tech In A Cloud World
PPTX
Shared responsibility - a model for good cloud security
PPTX
Governance and Security in Cloud and Mobile Apps
Nsc42 - is the cloud secure - is easy if you do it smart ECC Conference
Building Security Into Your Cloud IT Practices
CSA - Nsc42 - London chapter keynote - cloud transformation security challenges
Nsc42 security knights slayer of dragons 0-5_very_short_15m_share
Cloud Security Demystified
Cloud computing 10 cloud security advantages and challenges
A Throwaway Deck for Cloud Security Essentials 2.0 delivered at RSA 2016
I am sharing 'Unit-2' with youuuuuu.PPTX
Cloud application security (CCSP Domain 4)
cloud-computing-security.ppt
How to get started in cybersecurity
Cloud Security By Dr. Anton Ravindran
Cloud security for banks - the central bank of Israel regulations for cloud s...
Cloud Security - Kloudlearn
Cloud01: Best Practices for Virtual Cloud Security - H. Del Castillo, AIPMM
Practical Security for the Cloud
Resetting Your Security Thinking for the Public Cloud
Security Teams & Tech In A Cloud World
Shared responsibility - a model for good cloud security
Governance and Security in Cloud and Mobile Apps
Ad

Recently uploaded (20)

PDF
STKI Israel Market Study 2025 version august
PDF
sustainability-14-14877-v2.pddhzftheheeeee
PDF
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
PDF
sbt 2.0: go big (Scala Days 2025 edition)
PPT
Module 1.ppt Iot fundamentals and Architecture
PDF
Credit Without Borders: AI and Financial Inclusion in Bangladesh
PDF
OpenACC and Open Hackathons Monthly Highlights July 2025
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
Two-dimensional Klein-Gordon and Sine-Gordon numerical solutions based on dee...
PDF
A proposed approach for plagiarism detection in Myanmar Unicode text
PPTX
Custom Battery Pack Design Considerations for Performance and Safety
PDF
Hindi spoken digit analysis for native and non-native speakers
PPTX
Chapter 5: Probability Theory and Statistics
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
Produktkatalog für HOBO Datenlogger, Wetterstationen, Sensoren, Software und ...
PDF
Flame analysis and combustion estimation using large language and vision assi...
PDF
CloudStack 4.21: First Look Webinar slides
PDF
Zenith AI: Advanced Artificial Intelligence
DOCX
search engine optimization ppt fir known well about this
STKI Israel Market Study 2025 version august
sustainability-14-14877-v2.pddhzftheheeeee
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
sbt 2.0: go big (Scala Days 2025 edition)
Module 1.ppt Iot fundamentals and Architecture
Credit Without Borders: AI and Financial Inclusion in Bangladesh
OpenACC and Open Hackathons Monthly Highlights July 2025
Enhancing emotion recognition model for a student engagement use case through...
1 - Historical Antecedents, Social Consideration.pdf
Two-dimensional Klein-Gordon and Sine-Gordon numerical solutions based on dee...
A proposed approach for plagiarism detection in Myanmar Unicode text
Custom Battery Pack Design Considerations for Performance and Safety
Hindi spoken digit analysis for native and non-native speakers
Chapter 5: Probability Theory and Statistics
A comparative study of natural language inference in Swahili using monolingua...
Produktkatalog für HOBO Datenlogger, Wetterstationen, Sensoren, Software und ...
Flame analysis and combustion estimation using large language and vision assi...
CloudStack 4.21: First Look Webinar slides
Zenith AI: Advanced Artificial Intelligence
search engine optimization ppt fir known well about this
Ad

Nsc42-CSA AGM is the cloud secure - is easy if you do it smart

  • 1. Is the Cloud Secure? CSA AGM 2019 - HSBC (London) @FrankSEC42 It’s easy if you do it smart https://uk.linkedin.com/in/fracipo
  • 3. Is the Cloud Secure? CSA AGM 2019 - HSBC (London) @FrankSEC42 It’s easy if you do it smart https://uk.linkedin.com/in/fracipo
  • 4. Disclaimer: the pictures and the format in this presentation are under license to NSC42 Ltd Agenda About the author Conclusions & Take Away Q&A Solution to reach there The problem and ideal world How things have changed Context @FrankSEC42 CSA Conference & Awards
  • 5. www.nsc42.co.uk About the Francesco 5 Francesco Cipollone Founder – NSC42 LTD I’m a CISO and a CISO Advisor, Cybersecurity Cloud Expert. Public Speaker, Researcher and Director of Events of Cloud security Alliance UK, Researcher and associate to ISC2. I’ve been helping organizations define and implement cybersecurity strategies and protect their organizations against cybersecurity attacks FC-LinkedIn E-Mail Website Articles NSC42 LinkedIn Security is everybody’s job @FrankSEC42 @FrankSEC42https://uk.linkedin.com/in/fracipo Security is challenging, we have to know inch deep and miles wide
  • 6. www.nsc42.co.uk How Things Have Changed 6 How did we evolve to reach here? What is the impact on the security? @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 8. www.nsc42.co.uk Challenges 8 - Increasing number of breaches - Impact on Cost (Brand, Fines, …) - Fast change - No collaboration teams and security Security is everybody’s responsibility @FrankSEC42https://uk.linkedin.com/in/fracipo Security Challenges in cloud transformations?
  • 9. www.nsc42.co.uk Major Breaches 9 2009/ 2010 2012 Microsoft Heartland US Military Aol TJMax 2013 2016 2017 2014 2015 2018 Sony PSN NHS Betfair Steam Deep Root IRS Anthem Dropbox Lastfm Blizzard Marriot Twitter MyHeritage Uber Quora.. Why security is everybody’s responsibility? Myspace Twitter Yahoo Linkedin Friend Finder Dailymotion Mossack Fonseca JP Morgan Home Depo Ebay Yahoo(orignal) US Retailers Adobe UbiSoft Court Ventures 2012 2019 … Because we all get affected by it… @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 11. www.nsc42.co.uk Challenges 11 - Increasing number of breaches - Impact on Cost (Brand, Fines, …) - Fast change - No collaboration teams and security Security is everybody’s responsibility @FrankSEC42https://uk.linkedin.com/in/fracipo Security Challenges in cloud transformations?
  • 12. www.nsc42.co.uk Ideal cybersecurity world 12 In an ideal cybersecurity world we would have infinite time, infinite resource to do things right, and all the boring chores would be automated @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 13. www.nsc42.co.uk Solutions 13 1. Cloud Responsibility Matrix 2. Cloud Foundation 3. Cloud Patterns 4. Design Security 5. Security by Design 6. Dev shift left 7. Security Testing 8. DEV-SEC-OPS + BIZ/ARCH Security by design = everyone participate in security @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 14. www.nsc42.co.uk Step 1 - Cloud Responsibilities 14 Customer Application & Content Network Security Identity & Access Control Operating System/ Platform Data Encryption The Customer Customer Defines controls security IN Cloud Customer takes care of the security OF Cloud Physical Infrastructure Network Infrastructure Virtualization Layer Cloud platform “Understand Shared Responsibility model Delegation and you’ll master cloud” Consider what are you are getting yourself into in a cloud migration. Cloud is not natively secure or insecure @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 15. www.nsc42.co.uk Step 1 - Cloud Pizza 15 IaaS, PaaS, SaaS, … Who cares give me pizza! @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 16. www.nsc42.co.uk Step 2 – Foundation 16 How do you build a solid house? You don’t skip the foundation! How do you build a solid cloud? You don’t skip the foundation! @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 17. www.nsc42.co.uk Step 2 – Foundation 17 1. Management Support 2. Disruption and strategy 3. Security as part of the cloud journey 4. Skills shortages 5. Architecture patterns & Re-use How do you build a solid cloud (security) foundation? Cultural, Management support and skills @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 18. www.nsc42.co.uk Step 2 – Foundation 18 What Tools do you use for the solid cloud (Security) Foundation? @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 19. www.nsc42.co.uk Step 3 – Cloud Patterns 19 - Account Isolation - Controls Traditional vs cloud - Logging and monitoring - Identity and access management - Key Management “There is no such a thing as free lunch… but leverage on patterns as starting point” @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 20. www.nsc42.co.uk Step 4 – Design Security 20 “How would expand the security team without expanding the team?” Train Software Engineers on security and you’ll have ‘extended security team’” @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 21. www.nsc42.co.uk Step 5 – Security by Design 21 “So what would the software engineer do with the security hat on?” “gamification…remember to have fun when doing your job” How do we make threat security fun?” @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 22. www.nsc42.co.uk Step 6 – Shift left in DEV 22 “Security as early as possible: Integrate security in the software development pipeline” Keep Threat or fraud model exercise concise and fun! Don’t overcomplicate @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 23. www.nsc42.co.uk Step 7 – Security in Test 23 “Security (Testing) as early as possible” Security testing as bug bounty program! Make it fun and rewarding @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 24. www.nsc42.co.uk Step 8 - DEV–SEC–OPS(BIZ) 24 What kind of animal is the DEV-SEC-OPS? Integrate security into the OPS team (and add a spark of BIZ) Security is everybody responsibility. @FrankSEC42https://uk.linkedin.com/in/fracipo Reward security effort with -> Low cost High Impact Integrating Security
  • 25. www.nsc42.co.uk The Future 25 “Cybersecurity due diligence will remain the same regardless of the technology chosen” @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 26. www.nsc42.co.uk Conclusions 26 - Evolution & Challenges - Ideal world and step to reach it - What’s in the future Security in the journey to the Cloud not at destination Security is everybody’s job @FrankSEC42https://uk.linkedin.com/in/fracipo
  • 28. Every Fortnight 1.30 PM UK Time #MentoringMonday Call @FraSEC42
  • 29. Cyber Security Awards 2019 Cloud Security Influencer of the Year Submission – 10 of May 2019 Ceremony 4 July 2019 #CYSECAWARDS19https://cybersecurityawards.com/ https://cloudsecurityalliance.org.uk Submit: info@cybersecurityawards.com Info:
  • 31. www.nsc42.co.uk Contacts 31 Get in touch: https://uk.linkedin.com/in/fracipo Francesco.cipollone (at) nsc42.co.uk www.nsc42.co.uk Thank you WHEN YOU ARE CYBERSAFE WE ARE CYBERHAPPY @FrankSEC42 @FrankSEC42https://uk.linkedin.com/in/fracipo

Editor's Notes