Skip to main content
Cloud Security Architecture – A different
Approach
• Cloud Security Architect
• Microsoft MVP | CISSP | CISM | CCISO | MCSE
| PMP………….
• EC-Council CCISO Advisory Board
• CISO100 and CISO50 Award Winner
• Speaker (ITCamp, MS Ignite Tour, CISO Africa,
SharePoint Saturday, CSCAMP…….)
@ITCalls_ANabil
/in/ahmednabilmahmoud/
https://itcalls.net/
What is Cloud Computing
cyberhygiene@nist.gov
NIST Definition
Moving to cloud, are we secure now ?
How it happened
Attacker is thought to have exploited a server‐side request 
forgery (SSRF) vulnerability to trick an internal web 
application firewall (WAF) into executing remote commands 
with the WAF’s privileges. As the WAF was misconfigured 
with excessive privileges, the attacker was able to use it to 
read the contents of sensitive documents in private AWS 
object storage.
How it might have been prevented
• Include SSRF threat scenarios in server configuration 
planning (such defenses are NOT necessary included by 
default)
• Apply the principle of least privilege for both human and 
machine access
• Involve security practitioners skilled in the platform and 
technologies used
• Conduct regular security audits to catch insecure drift from 
secure baselines
What happened
Personal information of some 100 million individuals was stolen from Capital One’s AWS cloud estate
Sources: https://krebsonsecurity.com/2019/08/what‐we‐can‐learn‐from‐the‐capital‐one‐hack/
https://www.reddit.com/r/devops/comments/cl50q6/a_technical_analysis_of_the_capital_one_hack/
Summer 2019
Threat evolution is accelerating
Your enterprise in transformation
Running Dual Perimeters, This will run for long time
ATTACKERS USING IDENTITY TACTICSATTACKERS USING IDENTITY TACTICS
MODERN PERIMETER
(Identity Controls)
FULLY ZERO TRUSTFULLY ZERO TRUST
Information security is in transformation
Cloud/Customer Shared Responsibility Model
•
•
•
•
•
•
Information Protection
• Define what to classify
• Define where to classify
• Define conditions
• Create classification policies
• Start with Classification only
• Monitor and accelerate remediation
Start
simple
•
•
•
Identity and Access Management
•
•
•
•
Clients - PC and Mobile Devices
Native Cloud Tools (CASB vs CWPP vs CSPM)
Source: https://medium.com/@davidmoremad/securing‐your‐cloud‐with‐cspm‐303d6c6b6a78
Cloud Drivers/Challenges
Risk Assessment
Source: https://www.equinix.com/resources/analyst‐reports/gartner‐seven‐best‐cloud‐strategy‐practices/
Cybersecurity through a CxOs Lens
Aware of risks to reputation, bottom line, non-compliance
Effectiveness - Are we doing it well?
Increase Cost of Attack
• Ruins ROI for opportunistic attackers
• Lowers ROI of determined attackers
Decrease Mean Time to Remediation (MTTR)
• Reduces opportunity to do damage
• Increases overall cost of attack
Efficiency—How much is enough?
Most attackers have a supply chain
Yes, attack services are inexpensive
Loads (compromised device)
average price ranges
• PC - $0.13 to $0.89
• Mobile - from $0.82 to $2.78
Spear phishing services
range from $100 to
$1,000 per successful
account take over
0days price range
varies from $5,000
to $350,000
Ransomware:
$66 upfront
Or
30% of the profit (affiliate model)
Proxy services (evade IP
geolocation) prices vary
As low as $100 per week
for 100,000 proxies.
Denial of Service
(DOS) average prices
day: $102.05
week: $327.00
month: $766.67
Compromised accounts
As low as $150 for 400M.
Averages $0.97 per 1k.
Cybersecurity is a challenging space
Cyber Resiliency
Aligned - Align and Integrate cybersecurity with business strategy, processes, and initiatives
Cost of Attack Mean Time To Remediation (MTTR)
Cloud Cost
Source: https://www.equinix.com/resources/analyst‐reports/gartner‐seven‐best‐cloud‐strategy‐practices/
Change Role of IT and Security
Source: https://www.equinix.com/resources/analyst‐reports/gartner‐seven‐best‐cloud‐strategy‐practices/
Carefully select & monitor cloud providers
Recommendations
• Cloud Strategy should follow Business
Strategy
• Establish Cloud Security Policy
• Cloud Usage based on Risk domains
• Cost Optimization
• Resiliency
• Portability
• Cloud selection and monitoring
References
4. https://outpost24.com/blog/find-the-differences-between-CASB-CSPM-and-
CWPP
5. https://www.cloudvisory.com/cloudvisory-cspm-cwpp-solution.html
@ITCalls_ANabil
/in/ahmednabilmahmoud/
https://itcalls.net/