The shared responsibility model is a long-standing standard in the cloud security industry. Used by major providers like Amazon Web Services (AWS) and Microsoft Azure, it delineates the security obligations of the cloud provider and the customer.
However, Google Cloud is charting a different course with what it calls a shared fate model, which fosters a deeper security partnership between the cloud provider and its customers, CISO Phil Venables told SDxCentral.
“The shared responsibility model [is] where a cloud provider runs the underlying infrastructure and is responsible for the security of that. And then on the other side of that line is what the customer is responsible for, in terms of maintaining and managing a secure configuration on top of the cloud,” Venables explained. “That clearly is contractually and legally correct, but it doesn't, in our opinion, embody the right philosophical approach for security.”
Google Cloud's shared fate model seeks to transcend these limitations by engaging in a partnership where both the provider and the customer are “in it together to secure the customer,” he said. “It's a stepping across that line of the shared responsibility to partner more deeply with our customers, to provide more default guidance patterns.”
Venables emphasized that the shared fate model is about ensuring customers can operate securely in the cloud by default; it's not just handing them products to secure independently.
“We're not just handing them products to be secured. We hand them secured products so they can operate securely by default,” he said. “We're going to help them operate securely in the cloud, as opposed to talking to them about how we're going to sit behind our line of responsibility and expect the customers to look after themselves.”
Examples of Google Cloud's shared fate modelVenables used four examples to explain the shared fate model as follows:
1. Secure defaults and tooling: Google Cloud puts significant effort into shipping products with secure default configurations out of the box, so customers don't have to spend as much time reconfiguring for security. The hyperscaler also provides tools to monitor and maintain that secured state. Additionally, Google defines secure architectural patterns and blueprints with actual configuration code, allowing customers to use a default set of secured products and then configure them into a “secure landing zone” environment.
2. Continuous improvement from customer incidents and feedback: When customer security incidents occur across any cloud, Google analyzes what could have been done differently, in terms of default configurations, tooling, guidance or training, to reduce the risk of similar incidents. For example, this led them to implement technology to scan for inadvertently leaked customer credentials before attackers can leverage them.
3. Discounted cybersecurity insurance: Venables noted the “ultimate expression” of shared fate is Google Cloud's Risk Protection program partnership with cybersecurity insurers like Allianz Global Corporate & Specialty (AGCS) and Munich Re. Google Cloud provides customers with tools to automatically export their configuration for these insurance companies. The insurers can then offer those customers discounted cyber insurance rates based on their demonstrated secure stance.
4. Secure the deployment of AI: As part of its Secure AI Framework, Google Cloud has embedded collective knowledge around securing artificial intelligence (AI) systems, managing privacy risks, compliance, and end-to-end governance into their AI tooling, so customers don’t have to invest in these controls themselves. Additionally, if a customer uses one of Google's AI models and gets sued for IP infringement, Google will indemnify the customer's legal risk because it stands behind the integrity of the data used to train the models.
Risk intelligence powered by MandiantVenables highlighted the integration of Google Cloud and Mandiant's threat intelligence as a key element in the shared fate model.
The tech giant acquired the security vendor Mandiant in an all-cash deal valued at around $5.4 billion in 2022. He touted that the combination arguably offers the largest collection of threat intelligence in existence.
Google Cloud uses this intelligence in two main ways: internally, it consumes the threat intelligence as a security team, identifies and responds to security vulnerabilities across its platforms and others and learns lessons from that to enhance the security of its platforms. Externally, Google feeds this intelligence to customers through automated security monitoring tools such as Chronicle Security Operations and Security Command Center, aiding in spotting and monitoring early issues in configuration or threats like credential theft.
“Our approach in this shared fate style is to get as much of our knowledge that we've built up over decades about security, plus all of our threat intelligence into our systems and tools, and getting that to customers as fast as we can, partnering with them on the shared fate of defending customers,” Venables said.
Image: Google Cloud CISO Phil Venables. Credit: Google.
Comments