Prevent Cloud Incidents from Becoming Cloud Breaches

Ғылым және технология

The number of cloud security breaches in the headlines have been staggering lately. It seems like a week cannot go by without a massive amount of sensitive data being leaked from either AWS, Azure, or Google Cloud.
One example that would be funny if it were not so sad is the September 2023 incident where the Microsoft AI team leaked 38TB of sensitive data, including employee workstation backups and 30,000 internal Teams messages, due to a misconfigured storage configuration. How is the industry failing to use the clouds properly, let alone Microsoft, the extremely mature company who created Azure in the first place?
Join Brandon as he shares his analysis on this trend. He will discuss the unique challenges of protecting the cloud, why the cloud providers are unable to solve these problems alone, why multicloud makes matters even more difficult, and how your organization can take practical measures to mitigate the impact of cloud incidents. The presentation will include case studies of real breaches that were made much worse due to a lack of defense-in-depth. Learn how to prevent real attacks with controls that matter.
You will learn:
- Why the vast majority of breaches are in the cloud.
- Why the cloud is largely insecure by default.
- How to calculate the effort to secure multiple cloud providers.
- How you cannot solve these challenges with standardization and cloud agnosticism alone.
- About multiple cloud security incidents that went from bad to worse because of a lack of cloud controls.
- High-level best practices for mitigating the impact of cloud incidents
ABOUT THE SPEAKER
Brandon is the owner and an InfoSec Consultant at On-Brand Technologies LLC, a consultancy helping organizations secure their applications and other workloads in multi cloud environments, specializing in AWS, Azure, and Google Cloud. Prior to starting his consultancy, Brandon led the secure development training program at Zoom Video Communications. He began his career as a Software Engineer, where he worked on both the core product of a startup, later acquired by a Fortune 500 organization, and on various products spanning a multi-billion dollar enterprise. Brandon is lead author for SEC510: Cloud Security Controls and Mitigations a contributor to SEC540: Cloud Security and DevSecOps Automation, host of Cloud Ace podcast, Season 1, an analyst for the SANS Multicloud Survey, and a multi-year RSA Conference presenter. Learn more about Brandon at www.sans.org/profiles/brandon...
This webcast is based on content from SANS Institute SEC510: Cloud Security Controls and Mitigations. SEC510 provides cloud security analysts, engineers, and researchers with practical security controls that can help organizations reduce their attack surface and prevent security incidents from becoming breaches. Learn more, review the syllabus, and access the free Course Demo at sans.org/sec510
SANS Cloud Security focuses the deep resources of SANS on the growing threats to The Cloud by providing training, GIAC certification, research, and community initiatives to help security professionals build, deploy and manage secure cloud infrastructure, platforms, and applications.
SANS Cloud Security Curriculum: www.sans.org/cloud-security
GIAC Cloud Security Certifications: www.giac.org/focus-areas/clou...
LinkedIn: /sanscloudsec
Discord: www.sansurl.com/cloud-discord
Twitter: @SANSCloudSec

Пікірлер

    Келесі