How to Secure an 800-App Multi-Cloud Migration

40 views
•
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How to Secure an 800-App Multi-Cloud Migration

TL;DR

Standardize cloud controls, reusable code, deployment processes, and audit mappings before migrating applications at scale. Swiss Re’s cloud-agnostic framework supported the conversion of more than 800 applications across providers and geographies while improving security consistency, reducing rework, accelerating development, and cutting operating costs by as much as $40 million annually in some cases.

Transcript

Thank you, everyone. Um, so one thing Colin and I believe is that there are three types of people, those who can count and those who can't. Okay. Wake up, guys. Um, uh, in any case, we did, we did have a third co-author, um, the chief security officer of Swiss Re, and unfortunately, due to travel restrictions, he wasn't able to make it today. So Co... Read More

Key Insights

  • The migration covered more than 800 applications and supported Swiss Re’s ambition to move entirely into the cloud by 2025. Completing that transition required faster development, lower costs, stronger security, and a repeatable approach suitable for a global financial institution.
  • Cloud security failures are frequently connected to misconfigurations and poor operational practices. Swiss Re therefore treated developers and operators as owners of security and compliance rather than relying exclusively on controls supplied by cloud service providers.
  • A cloud-agnostic control framework creates consistent requirements across AWS, Azure, Alibaba, GCP, and other environments. Provider-specific deployment details can vary, but the underlying objectives, security threshold, audit approach, and expected evidence remain repeatable.
  • Standardized deployments reduce the inconsistency created when teams independently configure cloud environments. Swiss Re used repeatable requirements, controls, reusable code, and processes to eliminate rework and let developers focus on application features instead of repeatedly building security components.
  • The shared-responsibility boundary separates cloud-provider services from the components Swiss Re can control. Applications, platforms, and orchestration remained within Swiss Re’s control, while cloud providers were enabled to manage the infrastructure elements for which they were responsible.
  • Regulatory harmonization reduces duplicated compliance work by mapping common cloud controls back to the expectations of multiple authorities. The Swiss Re Cloud Security Framework was designed for consistent auditing across providers and was mapped to more than 30 global regulations.
  • Continuous monitoring supports secure cloud operations by identifying open storage buckets, missing encryption, inappropriate access changes, and manual configuration adjustments. Detected deviations can then be corrected while logs and operational data help teams identify exfiltration or illegal activity.
  • Standardization can improve security while lowering both delivery and operating expenses. Reduced rework shortened development time and brought applications to market sooner, while uniform security implementations across providers produced operating-cost savings reaching $40 million annually in some cases.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can a company secure a large multi-cloud migration?

A company can secure a large multi-cloud migration by defining cloud-agnostic requirements, standardizing deployments, reusing approved code, and mapping security controls to regulatory obligations. It should also distinguish responsibilities controlled by the organization from services maintained by each cloud provider. Continuous monitoring should detect open buckets, encryption failures, improper access changes, and manual configuration changes so deviations can be corrected consistently.

Q: Why did Swiss Re need a cloud-agnostic security framework?

Swiss Re operated across many geographies and needed to use multiple cloud providers, including AWS, Azure, Alibaba, and GCP. It also wanted the option to move workloads between providers for improved performance or lower commercial cost. A cloud-agnostic framework allowed the organization to apply consistent requirements and control objectives everywhere while adapting each deployment to the controls available in a particular cloud environment.

Q: How did standardization shorten cloud application development?

Standardization shortened development by giving teams repeatable requirements, reusable code, and established deployment processes. Developers no longer needed to recreate common security components, such as another firewall implemented through code, for every application. This reduced rework and development cost, saved developers time and frustration, and allowed them to concentrate on more creative application work while maintaining a consistent security implementation.

Q: How does the framework support regulatory compliance?

The framework connects security controls to the compliance requirements of regulatory authorities and enables those controls to be audited consistently across individual cloud providers. Its approach drew on prior work harmonizing controls for financial institutions and was mapped to more than 30 global regulations. This reduces the need to report substantially similar security information separately in a different format for every regulator.

Q: What cloud configuration problems should organizations monitor?

Organizations should monitor for open storage buckets, resources that are not properly encrypted, inappropriate access-management changes, and manual configuration adjustments made directly in cloud environments. The approach described also emphasizes obtaining the correct logs and operational data. These records help security teams maintain control, detect possible data exfiltration or illegal activity, and correct deviations from approved configurations.

Q: How did Swiss Re involve developers in cloud security?

Swiss Re treated developers and operators as owners of security and compliance, then supported them with reusable controls, code, and processes. The framework saved developers time by removing repeated security engineering tasks and reducing deployment headaches. That practical benefit encouraged developer participation and contributions, creating a self-reinforcing system in which standardized security made delivery easier while developer adoption improved consistency.

Q: How does multi-cloud standardization improve cyber resilience?

Multi-cloud standardization improves resilience by building repeatable security and recovery expectations into cloud operations from the beginning. The presenters emphasize that resilience includes more than deploying an application. Teams must also be able to revert to another state when an incident occurs. This is particularly important for Swiss Re systems that require very high availability and should avoid downtime.

Q: What financial benefits came from the Swiss Re framework?

The framework reduced development costs by eliminating substantial rework and shortened development time, allowing applications to reach the market and produce revenue sooner. Consistent security implementations across cloud service providers also reduced security operations costs. The presenters report that operating-cost savings reached as much as $40 million per year in some cases while development was accelerated and security consistency was increased.

Summary & Key Takeaways

  • Swiss Re planned to move more than 800 applications from on-premises infrastructure to the cloud by 2025. Its global footprint, sensitive information, diverse regulatory obligations, and use of several cloud providers created a need for consistent security requirements that could accelerate development without weakening compliance or operational resilience.

  • BCG and Swiss Re developed a cloud-agnostic security framework that separated customer-controlled application, platform, and orchestration responsibilities from services maintained by cloud providers. Common requirements and control objectives could therefore be applied across AWS, Azure, Alibaba, GCP, multiple geographies, and different applications while accommodating each provider’s implementation details.

  • The framework linked cloud security controls to regulatory requirements and supported consistent auditing across providers. Reusable code, standardized deployments, automated monitoring, and developer participation reduced repeated engineering work, detected unauthorized configuration changes, improved logging and resilience, and lowered development and security operations costs, including annual savings of up to $40 million in some cases.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚