Opens in a new tab
vmblog logo 2024 wht (updated)

Key Trends in Cloud Access Security Brokers: Now and Looking Forward

Share: 

David Marshall | Published: November 16, 2022

By Chun Li, Senior Manager, Technical Marketing, Hillstone Networks

The rise of cloud computing has led to a transformation of the IT industry. Enterprises, government entities, small companies, and even individuals have all been swept up by the wave. Traditional information systems require CAPEX- and OPEX-intensive hardware and software, leading more and more organizations to migrate to the cloud rather than building out IT infrastructures themselves. However, migrating business systems to the cloud requires handing over sensitive data to untrusted third-party cloud platforms. 

This results in the organization losing a great degree of control over the security of the data. Further, in most cloud services models, security is a shared responsibility between the providers and their customers. The cloud provider is typically responsible only for their own infrastructures – not customers’ data, applications, users, or devices, for example. Compounding the problem is that cloud services are intrinsically designed to be easily accessible, making them a convenient target for attackers.

A cloud access security broker (CASB) is an emergent technology that’s purpose-built to address many of the security issues in using cloud computing services. However, as CASBs and the cloud itself continue to evolve, what can we expect to see in the future?

The Current State of CASBs

First defined by analyst firm Gartner in 2011, cloud security access brokers have become somewhat standardized across four key functionalities:

Visibility: A CASB can perform discovery of all cloud resources used throughout an organization – whether IT-authorized or those operating as ‘shadow IT.’ The latter can be a huge problem for organizations because without IT policies in place, safeguards may not be correctly implemented to secure sensitive data. CASB visibility may also turn up instances of unintentional sprawl or overlap in authorized cloud services that are wasteful or not fully compliant with security policies.

Security: CASBs extend security controls into the cloud, allowing consistency of policies across the entire ecosystem. Identity and access management (IAM) can govern user access based on role, department or other specification to allow only users with appropriate privileges to access data. Single sign-on helps improve the user experience. And mapping can help identify anomalous behaviors and potential security vulnerabilities, while new unauthorized cloud usage can be quickly identified to limit shadow IT attempts.

Compliance: The move to the cloud also expands the data surface that must be held compliant with governmental and other regulations and requirements. A CASB can enforce standard compliance policies across the entire cloud environment and can even be customized by region if needed to meet specific compliance needs.

Threat Defense: Through its visibility into cloud deployments, a CASB can monitor traffic for indicators of threat or compromise like anomalous behaviors and user accesses. The use of machine learning and behavioral analytics allows extremely fine-grained identification of threats.

A cloud access security may operate in one of three modes, or in a multimode arrangement, to support and protect a wide variety of cloud applications and services. Forward proxy usually relies upon a client on each user device and may interoperate with a VPN, while reverse proxy does not require a client and may more flexible depending on the endpoints in use. API mode utilizes cloud apps’ native interface mechanism for what can be a tighter integration; however, it often requires more time to set up and maintain than other modes.

What Does the Future Hold for CASB?

A recent survey by the Cloud Security Alliance found that 89% of respondents were either already using or considering using CASB. Analyst firm Research and Markets predicted a compound annual growth rate for CASB at 16.2%, with the market expected to grow to $16.5b in 2027.

Further, CASBs are a part of Gartner’s secure access service edge (SASE) concept, proposed to ease the pain points of edge and cloud security in the years to come. Given the relative newness of the technology, and the high stakes involved in protecting data and resources in the cloud, we foresee a number of critical developments in CASB in the not-so-distant future.

  • While cloud computing is quite mature with solidly grounded and theoretical concepts, within the realm of cloud security products it is necessary to further distinguish between concepts, ideas, visions and functions to coalesce to core CASB technologies.
  • Cloud access threat detection and response based upon machine learning will be a key research topic. In order to enhance the accuracy of behavior analysis and improve the identification rate of threats and risk behaviors, it is necessary to have a strong behavior database and knowledge base.
  • Although CASBs provide deep visibility and can identify areas of concern, they currently cannot automatically address these issues on their own. Greater interaction with technologies within or outside of the SASE framework will be needed to automate remediation processes and relieve burden on security teams.
  • In the same vein, in order to achieve the full potential of the SASE vision CASBs will need to achieve full integration with other SASE elements like ZTNA, SWG and SD-WAN. Integration with cloud workload protection platforms (CWPPs) is a particularly relevant focus that would harness the visibility and threat detection of CASBs with the vulnerability management and microsegmentation of CWPPs.

Cloud access security brokers are designed to address many of the security problems associated with growing reliance on cloud computing. While the technology is still comparatively young, future developments can further refine and expand CASB capabilities to support the continuous evolution of the cloud ecosystem.

##

ABOUT THE AUTHOR

Chun Li, Senior Manager, Technical Marketing, Hillstone Networks

Chun-Li

Chun Li is Senior Manager of Technical Marketing at Hillstone Networks. In his role, he leads the global strategic planning and Go-to-Market execution of products and solutions as well as technology evangelism. Before Hillstone, Chun worked at Cisco Systems in both product management and technical marketing roles.

During his tenure in technical marketing, Chun has been responsible for driving go-to-market initiatives, as well as product development, and evangelizing new products and solutions, in close alignment with customers and end users. Chun holds a Master’s Degree in Electronic & Communication Engineering from Zhejiang University, China, and is a featured speaker for events and webinars worldwide.