jervis hui - no tradeoffs: cloud security & privacy dont need to be at odds

22
No Tradeoffs Cloud Security and Privacy Don’t Need To Be at Odds Jervis Hui, Product Marketing Manager

Upload: centralohioissa

Post on 23-Jan-2018

828 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

No TradeoffsCloud Security and Privacy

Don’t Need

To Be at Odds

Jervis Hui, Product Marketing Manager

Page 2: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

There are 10,000 enterprise

apps today (and growing).

Page 3: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

© 2015 Netskope. All Rights Reserved. 3

Actual:

917

IT estimate:

40-50

IT is blind to 90%

of cloud apps

>90% of apps are not

enterprise-ready

App Redundancy:

• 62 Marketing

• 37 Collaboration

• 28 HR

• 34 Finance

• 27 Productivity

• 23 Cloud StorageImpacts

CISO, CIO, and CFO

Page 4: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

© 2015 Netskope. All Rights Reserved.

How Do Cloud Apps Get In?

4

IT-led

Business-led

User-led

10%

70%

20%

Mostly

Unsanctioned

Sanctioned

Page 5: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

5

apps

• 917+ cloud apps

per enterprise

• 94% are not

enterprise-readyusers

• Malicious or

non- intentional

• 15% of corporate

users have had their

account credentials

compromised

data

• 18% of files in cloud

apps constitute a

policy violation

• 22% of those files are

shared publiclyactivities

• Cloud makes it

easy to share

• When is an activity

an anomaly?

Page 6: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

Catch-22

Page 7: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

Allow is the new block (allow is new block green light slide)

7

Page 8: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

© 2015 Netskope. All Rights Reserved.

What about

privacy?

8

Page 9: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

© 2015 Netskope. All Rights Reserved.

Dr. Cavoukian’s Privacy by Design Framework

9

Proactive not

reactive;

preventative

not remedial

Privacy as the

default setting

Privacy

embedded into

design

Full

functionality:

positive-sum,

not zero-sum

End-to-end

security; full

lifecycle

protection

Visibility and

transparency –

keep it open

Respect for

user privacy –

keep it user-

centric

Page 10: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

7 Requirements for Mitigating

Cloud Usage Risk(while maintaining privacy)

Page 11: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

REQ #1Find all cloud apps

running in your

environment and

assess enterprise-

readiness

Page 12: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

Privacy Best

Practice #1

Bypass selected

cloud apps

Page 13: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

REQ #2Understand Cloud

Usage Details

v

v

Bob in

accounting

From his

mobile phone

vUploading

customer data

to Dropbox

v

Bob’s

credentials

have been

compromised

Page 14: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

Privacy Best

Practice #2

Obfuscate personal

details in UI and do

it per role

v

v

Bob in

accounting

From his

mobile phone

vUploading

customer data

to Dropbox

v

Bob’s

credentials

have been

compromised

Page 15: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

REQ #3Use surgical

precision in

your policies,

leveraging

contextual

data

Page 16: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

Privacy

Best

Practice #3

Differentiate

between

corporate and

personal

cloud usage

Page 17: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

REQ #4Enable right-sized

admin privileges SharePoint

Admin

User

Email

Page 18: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

REQ #5Find sensitive

data tied to an

activity or stored

in a cloud app

Page 19: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

REQ #6Enforce

policies by

source and

destination

country

Page 20: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

REQ #7Don’t leave users in the dark.

Coach them on safe usage.

Page 21: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

5:Find sensitive data tied to an

activity or stored in a cloud

app

3:Use surgical precision in your

policies and leverage context

2:Understand cloud usage

details

4:Enable right-sized admin

privileges1:Find all cloud apps and

assess enterprise-readiness

6:Enforce ppolicies by source

and destination country.

Bypass selected cloud apps

Obfuscate personal details in UI

Differentiate between personal and

corporate cloud usage 7:Don’t leave users in the dark.

Coach them on safe usage.

Page 22: Jervis Hui - No Tradeoffs: Cloud Security & Privacy Dont Need To Be At Odds

THANK YOU!

To learn more, visit the Netskope booth and see a live demo