To keep up with the speed and the scale of the cloud-first era, Verizon VP of Enterprise Cyber Services Martin Kessler recommended organizations adopt three cyber resilience strategies — cloud security by design, by default, and as code; multi-layer backup strategy; and software-as-a-service (SaaS) security program, during SDxCentral and Dell'Oro Group’s Security in the Cloud-First Era digital event. 

Those strategies are based on the findings and insights from this year’s Verizon Data Breach Investigations Report (DBIR), which analyzed 23,986 security incidents and 5,212 data breaches.

“Key themes from the 2022 DBIR include the human element, phishing credentials, supply chain breaches, ransomware, and errors,” Kessler said. “The primary motivation in this year's report was once again financial gain, with organized crime accounting for 80% of breaches.”

He added that the results also showed external threats are more common than internal threats that include human errors and misuses, but cyberdefenders have to prepare for both. 

The best way to address human errors and drifts in security posture is to apply automation, Kessler noted. Before deployment, DevSecOps teams should ensure that security is configured as part of the automated resource provisioning process; post-deployment, he recommended spanning auto-remediation across accounts from a central control account that monitors all others in the cloud; the last tenant is ongoing compliance monitoring to ensure any configuration drifts are managed appropriately. 

Verizon's Enhanced 3-2-1 Backup Rule

This year’s Verizon DBIR also cited a 13% increase in ransomware breaches in the past five years, and a 25% increase in this past year alone. 

“We all know there's no silver bullet in security, ransomware will strike and we will either rise or will fall based on our backup and recovery capabilities,” Kessler said. 

He presented an enhanced 3-2-1 backup rule, meaning “three copies of the data on two media with one copy of the data in an air-gapped account.” 

Organizations should have a backup copy of their data in their local region for fast recovery; then backup the data to a different disaster recovery region to protect data remotely; and protect the backup by copying the primary backups and snapshots to an immutable target that no one can alter or delete; and lastly, separate the data plane from the control plane through an air gap.

Kessler also suggests building a one-click recovery mechanism as an abstraction layer adding on to this 3-2-1 backup rule, while conducting tabletops and live ransomware recovery exercises to test the preparedness and identify improvement opportunities.

Zero Trust for SaaS Assets

When companies start to build out their cloud security programs, Kessler said they should secure their SaaS cloud assets in addition to the ones in the public clouds. 

“Take a full lifecycle approach to risk management: initial contracting, onboarding, setting up zero trust access, and fortifying the environment, and then ongoing continuous monitoring,” he said. 

During the onboarding process, organizations should implement controls to ensure authorized usage and suitable-protected data. Kessler listed single sign-on and multi-factor authentication as zero-trust measures to protect the user experience.

“It's important to continuously monitor a few areas related to the SaaS provider, this includes logging usage, and monitoring for anomalies such as excessive data downloads, or the opening of APIs to unauthorized third parties,” as well as any threat intel and news of data breaches, he added.

“Why are these three strategies must-haves? Because they all protect and enable the amazing business transformation that's fueled and made possible by the cloud-first era,” Kessler concluded.