APAC CIOOutlook

Advertise

with us

  • Technologies
      • Artificial Intelligence
      • Big Data
      • Blockchain
      • Cloud
      • Digital Transformation
      • Internet of Things
      • Low Code No Code
      • MarTech
      • Mobile Application
      • Security
      • Software Testing
      • Wireless
  • Industries
      • E-Commerce
      • Education
      • Logistics
      • Retail
      • Supply Chain
      • Travel and Hospitality
  • Platforms
      • Microsoft
      • Salesforce
      • SAP
  • Solutions
      • Business Intelligence
      • Cognitive
      • Contact Center
      • CRM
      • Cyber Security
      • Data Center
      • Gamification
      • Procurement
      • Smart City
      • Workflow
  • Home
  • CXO Insights
  • CIO Views
  • Vendors
  • News
  • Conferences
  • Whitepapers
  • Newsletter
  • CXO Awards
Apac
  • Artificial Intelligence

    Big Data

    Blockchain

    Cloud

    Digital Transformation

    Internet of Things

    Low Code No Code

    MarTech

    Mobile Application

    Security

    Software Testing

    Wireless

  • E-Commerce

    Education

    Logistics

    Retail

    Supply Chain

    Travel and Hospitality

  • Microsoft

    Salesforce

    SAP

  • Business Intelligence

    Cognitive

    Contact Center

    CRM

    Cyber Security

    Data Center

    Gamification

    Procurement

    Smart City

    Workflow

Menu
    • Security
    • Cyber Security
    • Hotel Management
    • Workflow
    • E-Commerce
    • Business Intelligence
    • MORE
    #

    Apac CIOOutlook Weekly Brief

    ×

    Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

    Subscribe

    loading

    THANK YOU FOR SUBSCRIBING

    • Home
    • Security
    Editor's Pick (1 - 4 of 8)
    left
    The Organization's Responsibility for its Own Protection

    Michael Wallmannsberger, Chief Information Security Officer, Wynyard Group

    Don't Rush to Hire an Anti-DDoS Expert!

    Barry Greene, Co-founder and Chief, Technical Officer, GETIT

    Attaining the Needs of Infrastructure Investment

    Yong Chiang Neo, CIO

    Constructing a Marketing IT Collaboration

    Jenny Williams,

    The Organic Adaptability of IT

    Pedro Sttau,

    The Weakest Link Is Your Strongest Security Asset

    Christian Anschuetz, CIO & Security Practitioner, UL

    Achieving Greater Business Value with Innovation

    Denise A. Saiki, CIO& VP Enterprise Business Services, Lockheed Martin

    Using Data Analytics for Loss Prevention

    Jonathan Lowsley, CIO, ADrive

    right

    Secure Your Cloud

    Sherry Ryan, VP & CISO, Juniper Networks

    Tweet
    content-image

    Sherry Ryan, VP & CISO, Juniper Networks

    Today, moving to the cloud is a business imperative. Cloud enables the scalable, flexible, and cost-effective solutions that enterprises need. But in the realm of cloud, there is still a great deal of uncertainty and hesitation regarding security. Not surprisingly, as Chief Information Security Officer (CISO), one of the most frequent questions I’m asked is “is there a step-by-step approach to keep the cloud secure?”

    The short answer is yes. But I would add a caveat: “…but it requires a disciplined, rigorous, and relentless approach–that begins before migration to the cloud takes place.” The approach can be broken into steps, but these steps should be completed in parallel and are iterative.

    “Before moving to any cloud environment, be sure that you really understand the vendor’s security strategy, resources, and SLA’s”

    Step: Complete a Risk Analysis

    Conduct a detailed analysis of today’s real risks and vulnerabilities, as well as tomorrow’s potential risk and vulnerabilities. Consider macro threats, but also consider threats that are specific to your industry or business. Consider worst-case scenarios and consider as many “what-if” scenarios as possible. Collect input not just from your security team members, but also from the business. What’s keeping the business up at night? This analysis provides insight that will inform all decisions. It may even lead you to the decision not to move something to the cloud.

    Step: Develop a Prioritized Plan

    A plan needs to come before selecting any particular tool or application. If you begin with the tool, you will just find yourself looking for ways to use it.

    Your prioritized plan may need to be reviewed and approved all the way to the board level, since security is increasingly a board-level consideration. And even for a critical requirement like cloud security, there are only finite resources available. Prioritization and prudent risk mitigation are the name of the game. Your plan will guide you in your tool selection and in allocating your resources appropriately.

    Step: Communicate Security Policies

    An important process at all times, but especially as you migrate to the cloud, is to develop, publish, and enforce clear security policies and procedures. Provide access only as required. Use encryption. Enforce password policies. Too often we get over involved in the very technical aspects of cloud security, but forget that one of the most important threats facing us is our very natural behavior to avoid certain behaviors, even though they can keep us better protected. Relentless communication and education on these policies and procedures is critical and this is a job that can never be considered “done”. Think your enterprise knows all the policies and procedures? Try sending out a “test” phishing email to your enterprise–the results may surprise you.

    Step: Select Your Provider

    Selecting your cloud provider is a critical step in your security strategy. Major cloud providers such as Microsoft, Google, and Amazon, have extraordinary security teams working for them. They are continuously monitoring for any attacks, are able to respond incredibly quickly, and are often aware of vulnerabilities well before they are announced. However, only some cloud providers have this level of resources. Before moving to any cloud environment, be sure that you really understand the vendor’s security strategy, resources, and SLA’s. Select a reliable, serious cloud provider whose reputation and business credibility are riding on its ability to keep you secure. Not all cloud providers can--or will.

    Step: Prepare a Crisis Plan

    One step that is too often forgotten is ensuring your crisis process and communication plans are robust enough for a cloud security issue. Even with the best planning, the best tools and the best team, you need to realistically acknowledge that a security issue could occur. Your task is to ensure that everything is in place to not only learn about the breach quickly and resolve it quickly, but to also alert all impacted stakeholders with clear, actionable information. Delays or mis-steps in communication about a security breach can be as detrimental to the business as the breach itself.

    Once you have migrated to the cloud, maintaining security requires relentless vigilance. All of the steps outlined above need to be repeated and refreshed on a regular basis– proactively. Complacency is the enemy of security. Keep analyzing the threat profile, revisit your plan, update your policies and procedures, maintain your crisis plan, and monitor and audit your cloud provider regularly. Keeping all of this fresh also keeps your team alert and engaged.

    You need to move to the cloud. And you need to be secure. Taking a disciplined, rigorous and relentless approach is critical.

    tag

    Information Security

    Weekly Brief

    loading
    25 Most Promising Enterprise Security Solutions Providers
    ON THE DECK

    I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

    Read Also

    Advancing Retail through E-Commerce, Cloud and Cyber security

    Advancing Retail through E-Commerce, Cloud and Cyber security

    John Gaspar Antonio, CIO/Vice President for Information Technology & E-Commerce / Data Protection Officer, Metro Retail Stores Group
    From Code To Impact: Leading Enterprise Ai With Purpose

    From Code To Impact: Leading Enterprise Ai With Purpose

    Jingting Cher, Deputy Director, Data Science, Sp Group
    Reimagining Pension Services Through Responsible Innovation

    Reimagining Pension Services Through Responsible Innovation

    Maz Mirza, Chief Digital Officer, KWAP Malaysia
    Maritime: Beyond Systems, Beyond Seas

    Maritime: Beyond Systems, Beyond Seas

    Ron Fong, Cio, Station Satcom
    Human-Centered Innovation in the GenAI Era

    Human-Centered Innovation in the GenAI Era

    CJ Meadows, Head of Innovation-Asia, Executive Education Designer, Professor & Head of Mbaconsulting, S P Jain School Of Global Management
    The Art and Science of Selling

    The Art and Science of Selling

    Scott White, Senior Manager Sales and Marketing Operations, Airbus
    Responsible Data Leadership in an AI-Driven World

    Responsible Data Leadership in an AI-Driven World

    Gemma Dias, Head of Data Governance, Tyro Payments
    Driving Guest-Centric IT Innovation in Integrated Resorts

    Driving Guest-Centric IT Innovation in Integrated Resorts

    Ching Yip, Vice President of Information Technology, Hoiana Resort & Golf
    Loading...
    Copyright © 2025 APAC CIOOutlook. All rights reserved. Registration on or use of this site constitutes acceptance of our Terms of Use and Privacy and Anti Spam Policy 

    Home |  CXO Insights |   Whitepapers |   Subscribe |   Conferences |   Sitemaps |   About us |   Advertise with us |   Editorial Policy |   Feedback Policy |  

    follow on linkedinfollow on twitter follow on rss
    This content is copyright protected

    However, if you would like to share the information in this article, you may use the link below:

    https://security.apacciooutlook.com/cxoinsights/secure-your-cloud-nwid-279.html