Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Security Infrastructure

Surviving Your Digital Transformation

Digital Transformation Without an Equivalent Security Transformation is Leaving Organizations More Vulnerable 

Digital Transformation Without an Equivalent Security Transformation is Leaving Organizations More Vulnerable 

2018 is lining up to be the year of Digital Transformation. Just about every organization looking to remain viable in the growing digital marketplace has some sort of digital transformation in progress or one in the planning stages for this year. These projects range from implementing basic applications to better interact with online consumers, to converging OT and IT networks, or even pushing their entire infrastructure to the cloud.

But digital transformation without an equivalent security transformation is leaving organizations more vulnerable than ever. The results are alarming. According to Gartner, nearly $90 billion was spent on information security in 2017 and is expected to top a trillion dollars over the next five years. But cybercrime over that same period is expected to continue to rise. In spite of our efforts, we are falling further and further behind.

Part of the problem is the expanding human attack surface. Over half of the world’s population is now online, with a growing percentage of consumers that don’t remember a time before the Internet. And that number is expected to hit 6 billion by 2022. It is this group that is driving digital transformation, whether they want real time access to data, transactions, and services as consumers, or are demanding highly flexible and dynamic tools and solutions as employees.

The other part of the problem is the expanding digital attack surface. The growing adoption of IoT devices and networks, the geometric growth of traffic driven by applications and big data, the creation of complex and highly elastic multi-cloud environments, and the number of highly mobile users demanding network access from anywhere on any device has pushed IT resources to their limit. 

Of course, in addition to the expanded network becoming more complicated, IT is also under pressure due to a growing cybersecurity skills shortage. By 2021 there will be 3.5 million cybersecurity positions open, and only a fraction of skilled candidates capable of filling them. Which means our current method of filling security gaps with yet another device that requires additional resources to manage and maintain in order to simple keep up with the geometric expansion of our networks is not sustainable.

And finally, all of this is being compounded by the second phase of digital transformation, which is the convergence of traditionally separate systems. We aren’t just building cloud infrastructures. We are adding them to our traditional networks. Think about smart phones, smart cars, or smart cities. Applications and physical resources are being combined in ways that may streamline services, but that also have seriously complicated consequences when it comes to security. Critical infrastructure and key resources like energy are now being actively and automatically managed in response to events.

Smart businesses are also being actively developed. In order to increase efficiencies and profitability, traditionally isolated OT systems are starting to be converged with IT networks to do things like tying manufacturing floors to global market data to automatically support just-in-time inventory and flexible, on-demand production. 

Advertisement. Scroll to continue reading.

Digital transformation is also creating a whole new set of risks that, especially where critical infrastructure is involved, could have potentially devastating consequences. 

Part of this problem is our own fault. We tend to approach changes to our infrastructure as individual projects rather than as part of a holistic transformation. We implement new systems and technologies, and tend to deploy isolated, one-off security solutions to address a new challenge in a new environment. Unfortunately, most sophisticated attackers take advantage of the seams that exist between these projects, exploiting vulnerabilities in one part of the network to gain access to another.

Building a Secure Digital Business Infrastructure 

To solve this challenge, we need to see security transformation as a critical component of digital transformation. We start by assuming that everything will, one way or another, eventually be connected to everything else. Addressing the security challenges of digital transformation requires simplicity rather than compounding its complexity. You can start by building your digital business infrastructure around the following six security principles:

1. Develop a holistic security plan with unified policies and protocols that looks deep into the future and stick to it. Revisit this plan on a regular basis.

2. Build your security around open standards so everything can connect to everything else, even as plans and solutions evolve. Any solution being considered that can’t also actively contribute to the larger security picture needs to be reconsidered.

3. Establish single-pane-of-glass visibility for centralized management and orchestration. This should also include an active inventory of all devices on the network, as well as an assessment of their state of vulnerability tied to indicators or compromise, and an active plan to patch, protect, or replace at-risk devices. Centralized coordination also allows your security system to expand and adapt dynamically as network systems and resources shift and evolve.

4. Share and correlate threat intelligence, both local and global, so that every device is tuned to the latest threats. This needs to include things like SIEMs and sandboxing in order to detect complex or day zero threats.

5. Use your open standards-based security framework to enable active coordination between devices in order to respond to a threat, regardless of where it occurs across your distributed and elastic network. 

6. Apply automation and artificial intelligence everywhere possible – because your cyber adversaries are. The time between breach and compromise is dropping by the day, and will soon be measured in microseconds. We no longer have the luxury – or resources – to hand correlate data and then manually respond to a threat. 

Digital transformation is impacting every aspect of our professional and public lives. If we set aside our usual way of doing things and approach it from a consistent and holistic fashion, it will transform our society. That’s not hyperbole. It’s a simple fact. Likewise, if we continue on our current trajectory of piecemeal solutions and haphazard security, the results could be catastrophic, and organizations that don’t approach this carefully, right from the beginning, are not likely to survive.

Written By

John Maddison is EVP of Products and CMO at Fortinet. He has more than 20 years of experience in the telecommunications, IT Infrastructure, and security industries. Previously he held positions as general manager data center division and senior vice president core technology at Trend Micro. Before that John was senior director of product management at Lucent Technologies. He has lived and worked in Europe, Asia, and the United States. John graduated with a bachelor of telecommunications engineering degree from Plymouth University, United Kingdom.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

Former DoD CISO Jack Wilmer has been named CEO of defensive and offensive cyber solutions provider SIXGEN.

More People On The Move

Expert Insights

Related Content

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Security Infrastructure

Security vendor consolidation is picking up steam with good reason. Everyone wants to improve security efficiency and effectiveness while paying for less.

Management & Strategy

Hundreds of companies are showcasing their products and services this week at the 2023 edition of the RSA Conference in San Francisco.

Cloud Security

The term ‘zero trust’ is now used so much and so widely that it has almost lost its meaning.

Security Infrastructure

Instead of deploying new point products, CISOs should consider sourcing technologies from vendors that develop products designed to work together as part of a...

Funding/M&A

Responding to Cyber Threats Against Critical Infrastructures: Wired Business Media Acquires Long Running ICS Cybersecurity Conference Series

Security Infrastructure

Comcast jumps into the enterprise cybersecurity business, betting that its internal security tools and inventions can find traction in an expanding marketplace.

Audits

The PCI Security Standards Council (SSC), the organization that oversees the Payment Card Industry Data Security Standard (PCI DSS), this week announced the release...