Hybrid Cloud Improves Data Management But Presents New Security Risks
CISA said moving to hybrid cloud also reduces cybersecurity complexity.

Shifting from on-premise IT infrastructure to hybrid cloud solutions comes with new security risks but also new security and data management benefits, according to the Cybersecurity and Infrastructure Security Agency (CISA).
Grant Dasher, Identity and Cloud Engineer with the Office of the Technical Director for Cybersecurity at CISA, said the agency leverages multiple cloud capabilities for data analytics.
โWe also work closely with the private sector organizations on cyber information-sharing so we have systems that leverage the benefits of cloud and also the benefits of premise technologies in a hybrid fashion to combine all those data sets and try to make them helpful for our mission,โ Dasher said during the FedInsider Hybrid Cloud: Adopt for the Flexibility, Stay for the Security Webinar on Tuesday.
Dasher believes agencies can reap many security benefits through hybrid cloud applications.
โConcretely, the cloud services โ that managed service characteristic of it, and the ability of the provider to scalably patch their infrastructure, in many cases, up to the compute and storage layers that you depend on without you having to take any action โ that is a huge cybersecurity benefit,โ Dasher said during the webinar. โJust to reduce the complexity around patching and vulnerability management โ now obviously itโs not reduced to zero, agencies still have to do those activities in some cases โ but the burden sharing is quite different.โ
Data management and network security look different in on-premise infrastructure versus the cloud.
โThe cloud is a programmable surface area. The infrastructure is programmable and creates new security risks, but also opportunities for increasing things like immutable workloads,โ Dasher said. โItโs such a radical shift that it requires fundamentally different approaches, and in other cases just adjustments. But in general, if cloud is done well, it can be a strength from a security point of view.โ
Common threats such as phishing attacks can harm hybrid cloud environments, but Dasher wants to call attention to the way organizations connect user identities between on-prem environments and the cloud.
โItโs important to have a team in an organization that feels they own the cloud platform in terms of providing capabilities out to the business, and to answer strategic questions like how much authority needs to be delegated into the business teams versus retained centrally,โ Dasher said.
Dasher also feels itโs important from a security important point of view to make sure those governance structures are in place both organizationally and in technology.
โI think focusing on that structural set of governance topics and the base foundational capabilities of your hybrid cloud environment, and making sure that you have a way for the business team to fit into that framework with the right level of authority given to the business that works for your organization,โ Dasher said. โThatโs a critical maturity level that people need to work towards.โ
Dasher added, โKeeping those principles in the back of your mind as youโre working through your cloud journey, I think thatโs critical to ending up in a secure state where you can leverage the security benefits of the cloud, especially hybrid environments.โ
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
Human-AI Collaboration is Key to Secure Government Systems
Former CIA security chief emphasizes training and international standards for effective AI implementation.
23m watch -
Air Force, Coast Guard Talk Data Security Efforts for AI Development
The services' AI initiatives include efforts like creating clean training data, countering data poisoning and bridging siloed teams.
4m read -
Software Factories Accelerate Federal Modernization Outcomes
IT leaders from Nutanix and SAIC explain how software factories streamline tech development, modernize legacy systems and accelerate adoption of emerging technologies like AI.
20m watch -
Powering Defense with Transparent AI
AI and data innovation are transforming the Defense Departmentโs operations through cutting-edge initiatives.
20m read