In our top story for the week (well, week-ish, with an extra day due to the holiday), Executive Editor Dan Meyer writes about Nokia outsourcing its 5G cloud support and development to Red Hat. It sounds like a deal that will benefit both organizations and let each focus on what it does best, but only time will tell.
Speaking of letting time tell — we'll have to wait to find out if the recent SEC action against SolarWinds' executive officers will, as the company claims, "make the entire industry less secure by having a chilling effect on cyber incident disclosure.” Our second most-read story this week, from Security Editor Nancy Liu, makes a convincing argument that the best way to avoid personal litigation after a breach is for CISOs to have a clear reporting structure, among other things.
It might also help for CISOs to read our news stories (shameless plug), as our third and fourth top stories talk about security issues to fix ASAP to avoid potential cyberbreaches. Now, we're not saying that SDxCentral will help you avoid costly security issues, but we're also not NOT saying that. Just sayin'.
Without further ado (and so you can stop trying to unwind that last sentence), here are this week's top 5 stories.
1. Nokia unloads 5G cloud efforts to Red HatNokia is offloading primary support and ongoing development of its container and cloud infrastructure operations to Red Hat in a move that will bolster the latter’s OpenShift and OpenStack platforms to support 5G, core, open radio access network (RAN) and multi-access edge computing (MEC) services.
The deal has Nokia adopting Red Hat as its “primary cloud infrastructure platform” for the development, testing and delivery of Nokia’s core network applications. This includes Red Hat absorbing Nokia Container Services (NCS) and Nokia CloudBand Infrastructure Software (CBIS) into its container-focused OpenShift and virtual machine (VM)-focused OpenStack platforms.
2. Ex-Uber and SolarWinds CISOs are taking the legal rap for attacks (how to avoid the same fate)A recent survey from Salt Security showed nearly half (48%) of CISOs are concerned about potential personal litigation following breaches and 45% of the respondents cited increased personal risk or liability as personal challenges. These concerns aren’t baseless. In recent years, several security leaders had been held accountable or faced legal repercussions for breaches or failures in response.
3. Zscaler sees sharp increase in ransomware attacks with encryptionless extortion and RaaSZscaler’s ThreatLabz reported a nearly 40% increase in global ransomware attacks this year driven by the growth of ransomware-as-a-service (RaaS) and encryptionless extortion. The vendor recommends adopting a comprehensive zero-trust security strategy with ransomware protection measures to combat these threats.
It found that ransomware attacks increased by more than 37% compared to the previous year, with average enterprise ransom payments surpassing $100,000 and demands averaging $5.3 million.
4. Study: Orgs struggle with cloud security tools, prefer a single platformAs misconfiguration, account compromises and exploited vulnerabilities continue to allow attacks on public cloud-based networks to surge, the majority of organizations are struggling to manage multiple cloud security solutions. Check Point Software Technologies’ 2023 Cloud Security Report found most organizations prefer a single-platform approach.
The security vendor surveyed more than 1,000 security professionals worldwide and found 76% of respondents stated they are extremely or very concerned about cloud security and 24% of their organizations experienced a public cloud-related security incident in the past year.
5. VMware adds data sovereignty to Tanzu k8s management for regulated orgsVMware updated its centralized Kubernetes (k8s) management hub to include a self-managed on-premises deployment option that’s ideal for regulated industries like health care, financial services, government agencies and “any organization that needs full control over the Kubernetes control plane,” according to VMware Tanzu Product Marketing Manager Carol Pereira.
The cornerstone of Tanzu Mission Control Self-Managed is its air-gapped deployment capabilities, which help ensure outside networks can’t make unwanted connections. Targeted at platform teams, the update simplifies multi-cloud and multi-cluster Kubernetes while maintaining compliance with data sovereignty requirements.
Comments