Opens in a new tab
vmblog logo 2024 wht (updated)

Lacework 2023 Predictions: The ever-evolving need for a modern security posture

Share: 

David Marshall | Published: January 11, 2023

vmblog-predictions-2023 

Industry executives and experts share their predictions for 2023.  Read them in this 15th annual VMblog.com series exclusive.

The ever-evolving need for a modern security posture: What Lacework expects from security in 2023

By Ulfar Erlingsson and Kate MacLean of Lacework

There’s no escaping it: More and more enterprises will continue going head first on cloud infrastructure in 2023, contributing to the cloud’s linear growth since its inception. But as cloud data volumes grow, so does cloud complexity. Traditional security infrastructure is no match for the constant changes, updates, and shifts that come with the cloud – let alone the rapid rise of sophisticated, malicious threats.

Lacework is the data-driven security platform for the cloud and the company’s Chief Architect Ulfar Erlingsson, and Senior Director of Product Marketing Kate MacLean believe these evolving complexities only increase the need for enterprises to commit to developing a modern security posture. Here’s what the team expects to see for the security industry in 2023.

Ulfar Erlingsson, Chief Architect

  • Shifting left will be essential and supply chain risk will continue to be a major concern. In the year ahead, there will be an increased need to understand the composition and behavior of software used throughout an organization. Specifically, where vulnerabilities exist and how to prioritize them. The phrase “shift left” describes how security is incorporated into earlier stages of the software development lifecycle. The cloud experiences continual development, whether because of newly discovered security vulnerabilities or because of new features, making shifting left mission critical for cloud software. Even if your own developers never make any mistakes, open-source software and cloud services are ever changing, creating risks that include new vulnerabilities and security issues in the latest software build. At the highest level, the software industry still struggles to address the risk of the overall software supply chain. The sooner, or the further left, risks can be mitigated, the more likely a positive security outcome.
  • Proactive risk mitigation will be required. Business leaders are expressing a desire to be truly secure. But how does that really look in practice? Rather than only having aircover for when things go wrong, being truly secure means preventing security issues from arising in the first place. It’s exciting to see companies not only motivated to take on this challenging task, but understand why it’s necessary: new, stricter security-disclosure regulations, concerns about operational stability in the face of increased security incidents (i.e., ransomware), and a new understanding (even at the board level) that preventing security issues can be more cost-effective than mere compliance. The rise of this trend means companies will look for security technologies and platforms that not only offer monitoring and reporting, but provide preventative measures, like locking down the network or making software immutable.

Kate MacLean, Senior Director of Product Marketing

  • Cloud infrastructure will continue to be an attractive target for attackers, raising the need for automated cloud security. As enterprises continue their cloud migration and digital transformation, they will realize that traditional approaches with siloed tools, rules-based policies, and disparate security data actually introduce more security risks, creating an expanded attack surface for bad actors. Containerized workloads, Infrastructure as Code, and microservices architectures running on orchestration platforms such as Kubernetes and multicloud environments create a complicated and dynamic attack surface. Misconfigurations, vulnerabilities and excessive privileges all risk on their own, but what is more frightening is that many of these combine to form dangerous attack paths for bad actors. With limited resources and cloud security skill sets, no cloud environment gets to be 100% free of evolving risks. What  matters is that organizations have mechanisms to automatically identify the greatest risks in their environment amongst a thousand alerts that they receive daily from different products from different vendors. That’s hard to do. And, organizations will never have the complete picture until and unless they  implement a solution that can automatically correlate different pieces of data natively to provide critical context that helps them prioritize risk-based remediation or watch for exploits. Point products need to be replaced and a rules-based approach can’t scale in the cloud because it is simply not possible to  write a rule to catch all the risks in the cloud.
  • Managing cloud identity and entitlements will become top priority. Excessive privileges and role identities in the cloud is a rampant problem, present in nearly all successful compromises in the cloud. User accounts as well as service accounts all have more access permissions that they necessarily need,  which makes it easier for bad actors to enter an environment and move laterally to exploit additional cloud components or assets. This can even lead to alert fatigue, given the high volume of alerts from managing cloud identity entitlements which can easily overwhelm security teams and mislead the triage and investigation processThe traditional IAM solutions designed to protect and control access to conventional static on-premises applications and infrastructure fail to be effective in today’s dynamic, ephemeral and multi-cloud environments. Every cloud environment has thousands of identity entitlements, it is not possible to scale and govern abnormal activities by rules and check alone. Organizations will be increasingly transitioning to CIEM offerings that only provide preventative capabilities to enforce consistent policies and automated guardrails across multi-cloud, and identify excessive permissions and risky  access paths to sensitive data, but can also automatically detect abnormal behaviors to help organizations minimize their attack surface and enforce least privilege access.

The cloud will constantly be evolving – that’s its nature. As a result, threats will become more sophisticated and security infrastructure needs to be ready to adapt at any given moment. Investing in a modern, data-driven security posture will not only be trending, but also an absolute necessity as we enter the new  year.

##

ABOUT THE AUTHORS

Ulfar Erlingsson, Chief Architect, Lacework

Ulfar-Erlingsson

Ulfar Erlingsson brings 25+ years of experience leading technology efforts in computer security, privacy, machine learning and distributed systems. Ulfar holds 30 plus issued U.S. patents and has authored dozens of scientific publications on computer architecture, operating systems, data-parallel processing, computer security and privacy mechanisms.

 

Kate MacLean, Senior Director of Product Marketing, Lacework

Kate-MacLean 

Kate MacLean brings more than a decade of security experience, with a specialization in SaaS, product packaging and go-to-market strategy. As a busy mom, Kate knows the importance of reducing risk, triaging situations and securing the limitless perimeter of life. Kate holds an undergraduate degree from Bentley University and her MBA from Boston University.