The opportunities and benefits of the cloud are well-proven. Still, the majority of modern enterprises use several clouds — whether private, public, partner or sovereign — thus hampering visibility while also increasing vulnerability to increasingly expensive, reputation-harming cyberattacks.
To help today’s businesses tackle this problem, cloud computing company VMware is rolling out expanded security capabilities in its VMware Cloud. The broadened tools were announced today at VMware Explore as the company’s estimated $69 billion acquisition by Broadcom continues to gain regulatory approval.
Lack of consistent policies and operations across clouds “creates unnecessary complexity, policy drifts, inefficient operations — not to mention IT staffs are already stretched,” Umesh Mahajan, SVP and GM for VMware’s networking and security business unit said in a pre-briefing. “This leads to greater potential for security risks and human error.”
Next-generation network and security virtualizationTo start, VMware today announced NSX+, the next generation of its NSX platform. The cloud-managed service for multicloud environments aims to normalize networking and security. The offering is delivered as SaaS and is centrally managed from a single cloud console, Mahajan explained.
He pointed to VMware research that found that 73% of enterprises use two public clouds, while 26% use three or more. Furthermore, by 2024, 81% of enterprises expect to be multicloud.
But up to this point, “consistent multicloud networking has been elusive,” said Mahajan. This hinders innovation — enterprises aren’t running in environments that make the most sense for their apps — as well as lateral security.
This creates “serious blind spots,” incident response delays, poor capacity planning and “leaves a high vulnerability to ransomware attacks.”
Visibility, segmentation, threat detectionThe expanded NSX aims to provide consistent network and security operations, centralized security policy establishment and enforcement, network and app visibility and defense with network detection and response (NDR) as-a-Service.
Infrastructure teams will have the ability to simplify operations through a central dashboard, said Mahajan, and they can enforce consistent networking and security policies across multiple regions and sites.
Multicloud visibility and segmentation for zero trust strategy can quickly identify security gaps that pose the greatest risk when deploying across multiple clouds. Furthermore, NDR detects threats based on signatures and behaviors. Signals from multiple clouds and various threat intelligence are correlated and used to identify multiple threats that could become “full-blown intrusion campaigns,” said Mahajan.
The platform “reduces the risk of ransomware by identifying potential security threats across multiple clouds,” he said.
Previously, VMware NSX has been shown to deliver more than 60% OPEX savings from service automation and reduced hardware administration and 66% savings in day zero to 2 operations, according to the company.
Full isolation of multiple tenantsEnterprises today want to deploy apps faster at cloud speed — but with guardrails based on tenancy, Mahajan noted.
To support this, VMware also today introduced NSX+ virtual private clouds (VPCs) for self-service security, networking and load balancing. This functionality provides full isolation of multiple tenants on a shared VMware Cloud infrastructure, Mahajan explained.
Developers and application teams can select clouds that are optimal for their applications and maintain supervisory control, set operational guardrails on a per-VPC basis and help ensure that changes made within VPC environments do not impact other tenants. This ultimately helps to improve IT productivity, Mahajan contended.
“It is completely agnostic to the choice of networking hardware vendor,” he said. “Application teams get cloud agility no matter where their apps reside.”
Ultimately, he summarized: “There’s no way to do multicloud without networking, security and load balancing services.”
Ransomware recovery as-a-serviceDespite efforts to the contrary, ransomware is still rampant in enterprise, with nearly three-quarters (73%) of organizations having suffered at least one ransomware attack.
“Ransomware continues to be top of mind for every customer that we talk to,” Prashanth Shenoy, who leads VMware’s cloud infrastructure business group, said in the pre-briefing.
The issue today is that most ransomware attacks employ fileless techniques — that is, those built directly into systems and don’t require attackers to install code. This makes them difficult to detect through current methods including scans of idle backups, Shenoy pointed out.
VMware now offers new features in its Ransomware Recovery as-a-Service platform, a tool designed to recover from fileless attacks using behavioral analysis of powered-on VMs in isolated, cloud-based isolated recovery environments (IREs).
Customers can run production workloads in the cloud until forensics are completed and the on-premises datacenter is fortified, Mahajan explained. This has shown to resolve unplanned downtime up to 75% faster, he asserted.
VMware also today provided a technology preview of Cybersecure Storage, which integrates ransomware recovery workflows into native snapshots. This can help identify the best snapshots to begin recovery.
“How can we make our storage solution that much more effective and trusted?” Shenoy posited. “We want to make sure security is built into our storage platforms.”
Comments