In the hybrid and multicloud world, a major security challenge organizations face is consistency, Wendy Nather, Head of Advisory CISOs for Cisco Secure, pointed out.

“A lot of the technology that we have for security today is either built for legacy, or let's call it heritage, applications and technology that's still on premises; or it's built cloud first or cloud native,” Nather told SDxCentral. “But there's very little in the middle to bridge those two very different worlds.”

Plus, “cloud providers are not necessarily consistent in their security or in their configuration settings,” she added. “Things that are set one way for [Microsoft] Azure are not the same way that AWS necessarily does it, or Google Cloud, or so on.”

Since most companies are using multiple public clouds, and some of them are still running their own private clouds, “this rolls up to a consistency problem and an orchestration problem,” Nather said.

And every time new technologies come up, the industry will go through a wave of orchestration. “I think we're in that phase right now of trying frantically to orchestrate and consolidate before the next wave of technology comes along,” she said. 

Cisco Works on Consistency

Consistency is one of the issues Cisco works hard to tackle, Nather noted. During this year’s RSA conference, Cisco unveiled its unified platform, dubbed Security Cloud, to integrate security and networking services across hybrid multicloud environments for the entire IT ecosystem. 

Cisco Security Cloud is a set of cloud-based services that provides threat detection and prevention, minimizes cyber risks, and integrates breach response and remediation with machine learning technology, Jeetu Patel, EVP and GM of security and collaboration at Cisco, told SDxCentral in an earlier interview.

The networking giant created this framework to bridge the gap between heritage and cloud environments. “There are certain parts of the security that should be shared architecture for cloud-native environments,” Nather said. “We are focusing on cloud delivery of those shared services and that shared architecture that everybody should be using as they go along.”

Looking ahead, there are many opportunities to build consistency for the hybrid cloud environment. That’s why Cisco rolled out a proof of concept tool called Panoptica to engage with the community to find what works best, she said. 

Panoptica, the Cisco Secure application cloud, was developed by its emerging technology and incubation section to target technology orchestration and smooth out visualization of users’ cloud-native configurations and check security posture against consistency rules, according to Nather.

“I don't think anybody is going to come out with one model and say this is going to work for everybody all the time,” she argued. “I think it involves a lot of engagement in conversation with our peers and with our customers to find out how this is going to work best because simplifying something complex is really hard.”