Intelligent CISO Issue 35 | Page 19

cyber trends
we do not know or see .” He stresses the difficulty of always having an up-to-date global IT asset inventory to provide greater visibility .
Adopting an open cloud platform
With the resistance to cloud migration melting away , companies need to use these new technologies to become more competitive .
“ There ’ s significant pressure on us to essentially migrate to the cloud , whether we like it or not ,” said Courtot . “ Now in that migration , we need to be very careful of not falling into the same trap that we ’ ve been falling into before . Yes , best-of-breed is still very important for the elimination of the false positives , but if we select a cloud offering , which is , in reality , another point solution but essentially built in the cloud , we are not going to solve the problem . We need to look at solutions that are more than just essentially point solutions .”
Courtot argues that the best approach is to build a platform that would allow for the acquisition of more telemetry .
Addressing new security challenges
This new security model based on open cloud platforms is at its beginning stages , but it ’ s one that Qualys has envisioned since it was founded .
“ And now of course , we need to think about the cloud and how we can really create a seamless security or build security across these environments .”
The problem with traditional solutions
As IT teams embrace cloud services , mobility , containers , DevOps and other innovations , the job of security teams gets harder . This is especially true if they have a heterogeneous stack of tools that are difficult and costly to deploy , integrate and manage .
With such a siloed and fragmented toolset , visibility into the IT environment narrows , tasks can ’ t be automated , false positives abound and security teams struggle to detect and respond quickly to threats . Courtot says the traditional best-of-breed point solutions no longer cut it and that the main reason for this is because they are siloed solutions .
Visibility
With the difficulties of having visibility across hybrid environments , Courtot says : “ We simply cannot secure what
Early on , Qualys realised that the centre of the IT universe would shift away from on-premises computing to the Internet and that security would naturally have to broaden its scope well beyond the corporate network perimeter to the cloud .
Courtot said : “ I don ’ t think we can continue doing what we ’ re doing today . We need to really move to open cloud platforms and open cloud platforms that interoperate with each other . We believe that when you have that notion of open platform that can collect all that information , that visibility on your network , then you could also now marry that with your business information . Today , security is front and centre and as we move to the cloud , we must rethink security .” www . intelligentciso . com
19