Sonrai Security today launched a cloud permissions firewall for Amazon Web Services (AWS), Microsoft Azure and Google Cloud environments to help IT teams secure the public cloud’s true boundaries: identities, permissions and access.
Traditional cloud firewalls monitor and control network traffic while acting as a barrier around any platforms, infrastructure and applications in the cloud. These traditional firewalls aim to filter out potentially nefarious network traffic.
Sonrai Security’s cloud permissions firewall, however, monitors all permissions usage and eliminates unused permissions, identities, services and regions. “This acts as a barrier to malicious actors gaining a foothold in the cloud or executing an attack through lateral movement or privilege escalation,” Sonrai Security CEO Brendan Hannigan told SDxCentral.
Reducing time spent and security risksSpecifically, the cloud security vendor’s permissions firewall promises a 92% reduction in the cloud permissions attack surface and a 97% reduction in the time spent accomplishing least privilege when compared to seeking least privilege using cloud-native tooling.
Using disparate cloud-native tools requires manual processes for creating and implementing a least privilege policy for every identity in the cloud. The typical enterprise cloud environment houses more than 35,000 human and machine identities. And with “the ephemeral nature of the cloud, there are always new identities created which need policies,” Hannigan said.
Sonrai Security’s cloud permissions firewall centrally deploys a single policy with one click that applies least privilege to all identities. And with the firewall’s “default deny” environment, every new identity is automatically created with least privilege. The firewall also leverages a process called Permissions on Demand, which enacts permissions restrictions in minutes and prevents developer workflow disruption.
“The challenge about deleting unused identities or enforcing least privilege is we know it’s the ‘right’ thing to do, but everyone’s afraid it’ll break something or interrupt our development cycles,” Eye Care Leaders CISO Preetam Sirur said. Sonrai Security’s cloud permissions firewall “...has eliminated our hesitations. Now we just deploy – confidently,” Sirur said.
Sonrai Security customer and World Kinect CEO Josh McLean similarly noted that his company’s “transition from tedious, weeks-long tasks to accomplishing least privilege outcomes in just a few days has been remarkable,” he told SDxCentral. “This approach has saved us a tremendous amount of time while also guaranteeing the security of all critical permissions.”
The vendor's cloud permissions firewall will be generally available on April 15 for AWS and will be available for Azure and GCP following shortly after.
Comments