Palo Alto Networks added four modules to its Prisma Cloud security platform including identity-based microsegmentation from its $150 million Aporeto acquisition. The Prisma Cloud 2.0 update also added data loss prevention capabilities that provide discovery, classification, and malware detection for Amazon Web Services Simple Storage Service (AWS S3).

Web application and API security help protect web applications against Layer 7 and OWASP Top 10 threats. And identity and access management (IAM) capabilities round out the four new modules and provides customers with visibility into who has access to specific cloud resources. They also secure those resources by establishing automated least-privileged identity access.

Prisma Cloud Adds IAM Security

IAM becomes increasingly important as customers move workloads to the cloud — Palo Alto Networks 2020 State of the Cloud Native Security Report found that up to 64% of enterprise workloads will be in the cloud in the next 24 months. And as they move to the cloud, governing IAM becomes an even more critical to cloud security.

IAM policies across all cloud accounts must be constantly monitored to determine the potential risk exposure to the business because identity misconfigurations in the cloud can cost companies millions of dollars if they are exploited by hackers. Palo Alto Networks’ Unit 42 threat hunting team recently discovered two critical AWS cloud misconfigurations in a customer’s environment that, if exploited, would have led to a data breach that could have cost the customer tens of millions of dollars.

“When I tell people about the biggest risks to think about for cloud security, there’s all kinds of really cool, sexy, esoteric things that people come up with. But the reality for most organizations is there’s no reason for an attacker to have to figure out some zero-day vulnerability when the reality for most people is: they’ve got dozens of unpatched critical vulnerabilities,” said John Morello, VP of product at Palo Alto Networks. “And once the attacker gets into that, they’ve got tons of administrative accounts that just provide access to the entire kingdom.”

So while it’s important to protect against sophisticated attacks, in reality “there’s lots of very low-hanging, very juicy targets for attackers,” he continued. “And one of the most juicy ones is the ability to abuse overly permissioned accounts. That’s what the new IAM module is really designed to help customers combat.”

The data security, and web application and API security modules are currently generally available. The other two modules are available in limited preview.