Tuesday, May 27, 2025

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
  • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Cloud Security Cybersecurity Incident Response Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X 

Home » Security Boulevard (Original) » Modernizing SecOps for Cloud: Part One

Modernizing SecOps for Cloud: Part One

by Rich Mogull on December 14, 2023

This is part one of a series.

Security operations, or SecOps for short, has been one of the more difficult security domains to modernize for cloud. It requires a combination of new subject matter expertise, new technologies, process updates, and even a slightly different mindset. Cloud impacts SecOps in ways both obvious and subtle, and since most organizations still have data centers and offices, teams need to add new skills and update operations while still supporting everything already on their plate. It’s a daunting challenge, but one that is a lot easier to tackle by distilling down the core of how cloud changes things and taking lessons from the successes of early adopters.

In this series, we will detail the impact of the cloud on SecOps, review the core technical capabilities needed to respond, and highlight techniques for successfully modernizing security operations to support cloud operations. We will finish up with example processes you can use as a template for your own operations.

Techstrong Gang Youtube
AWS Hub

Defining SecOps for Cloud

There isn’t one universal definition of SecOps, but it typically refers to detecting and responding to potential security issues like exposures or attacks, which bridge security into IT operations. In some organizations, the SecOps team is a different name for an incident response team, but others take a broader view and may include any activities where security affects and integrates with IT operations. For our purposes, we will limit ourselves to a cycle of monitoring, detecting and analyzing, communicating and responding and remediation.

We’ve based this on a combination of the NIST Cybersecurity Framework (CSF) and the NIST incident response cycle. NIST CSF includes identify, protect, detect, respond and recover. NIST CSF is meant to cover the entirety of information security domains and is thus broader than our focus. The NIST incident response lifecycle includes preparation, detection and analysis, containment, eradication and recovery and post-incident activity.

We aren’t proposing some new definition of SecOps, but we have cherry-picked phases that work well to explain the key areas we need to adapt for the cloud. We also aren’t focused exclusively on responding to attacks but include managing incidents, vulnerabilities and misconfigurations due to how these tend to overlap more in the cloud, as we will explain.

How Cloud Impacts SecOps

At a high level, there are three key ways the cloud impacts the entire range of security operations:

  • Cloud operations and management are decentralized. Different teams not only manage their own applications stacks, but their own infrastructure stacks. These are spread across multiple cloud deployments or even providers. A lot of security operations historically relied on centralized management and consolidated infrastructure that doesn’t exist in the cloud.
  • Admin functions are consolidated into unified consoles that run on the internet. While individual deployments will operate in their own decentralized cloud environments, all the administrative functions to manage those are consolidated into a single unified management plane for each provider. This management plane is on the internet and controls all infrastructure down to the literal virtual wiring of the virtual networks, and we access it with a username, password and maybe MFA. The management plane is a ripe target for attackers, and they don’t need to break Amazon, Microsoft or Google; all they need to do is steal the right credentials from one of your admins.
  • Most resources can be configured to be on the Internet. It’s called “public cloud” for a reason, and nearly any resource you can create in every provider can be configured to access or be accessed via the internet. This is a radical departure from building and deploying resources in a data center.

This combination of decentralized operations and a central management plane that’s on the internet capable of potentially exposing any assets to the internet, forces a shift in SecOps focus and priorities. The situation isn’t worse than SecOps in a data center, we gain advantages like better-centralized visibility and more agile response capabilities, but it is different. Attackers are more likely to use stolen cloud credentials and API calls to expose data directly via the management plane without ever creating a malicious packet on a monitored network.

Understanding and Embracing SecOps for Cloud

In this series, we will dig deeper into some of the technical aspects of the cloud that affect SecOps, how to expand core capabilities to ensure proper coverage, and then how to adapt SecOps processes across the cycle. Key questions we will address include:

  • Monitor: What telemetry sources does the cloud add, and what are the best ways to collect and manage them?
  • Detect and Analyze: What new kinds of detectors and activities are needed to identify cloud security issues? How do the analysis process and priorities change for the cloud?
  • Communicate: How do we organize and communicate issues and further responses?
  • Respond and Remediate: Who handles response in the cloud? How do we ensure access and coordination? Who decides and implements remediation?

Our focus will be on practical approaches that don’t require you to suddenly become a cloud unicorn. They can be integrated over time and don’t require a sudden radical re-engineering of operations. Existing processes and skills are still completely relevant since cloud incidents easily spill into traditional areas of SecOps. We will show you how to modernize, expand and integrate SecOps to improve your processes for the cloud.

Recent Articles By Author
  • Two Practical Examples of Modern Cloud SecOps
  • Keys to Adapting SecOps Processes for the Cloud
  • Building Core Capabilities to Modernize SecOps for Cloud
More from Rich Mogull
December 14, 2023December 18, 2023 Rich Mogull Data center, Firemon, Network Security, secops, security operations
  • ← How bullying impacts your students
  • Meet Marshall Heilman: New CEO for DTEX →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Experience at Qlik Connect 2025

Upcoming Webinars

Software Supply Chain Security: Navigating NIST, CRA, and FDA Regulations

Podcast

Listen to all of our podcasts

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

ThreatLocker

Most Read on the Boulevard

Survey Surfaces Limited Amount of Post Quantum Cryptography Progress
U.S. Authorities Seize DanaBot Malware Operation, Indict 16
RSA and Bitcoin at BIG Risk from Quantum Compute
Understanding the Importance of Incident Response Plans for Nonprofits
Unsophisticated Actors, Poor Hygiene Prompt CI Alert for Oil & Gas 
Malicious attack method on hosted ML models now targets PyPI
Cyber Heads Up: “BadSuccessor”—A Critical Active Directory Privilege Escalation Vulnerability in Windows Server 2025
Ensuring Stability with Robust NHI Strategies
When AI Fights Back: Threats, Ethics, and Safety Concerns
Feel Protected: Advances in NHI Security Techniques

Industry Spotlight

RSA and Bitcoin at BIG Risk from Quantum Compute
Analytics & Intelligence Blockchain CISO Suite Cloud Security Cybersecurity Data Privacy Data Security DevOps Digital Currency Featured Governance, Risk & Compliance Humor Industry Spotlight Most Read This Week Network Security News Popular Post Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches Vulnerabilities 

RSA and Bitcoin at BIG Risk from Quantum Compute

May 27, 2025 Richi Jennings | Yesterday 0
Signal Gives Microsoft a Clear Signal: Do NOT Recall This
Application Security Cyberlaw Cybersecurity Data Privacy Endpoint Featured Governance, Risk & Compliance Humor Incident Response Industry Spotlight Most Read This Week News Popular Post Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Signal Gives Microsoft a Clear Signal: Do NOT Recall This

May 22, 2025 Richi Jennings | May 22 0
Coinbase Says Breach May Cost $400 Million, Issues $20 Million Bounty
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Industry Spotlight Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

Coinbase Says Breach May Cost $400 Million, Issues $20 Million Bounty

May 16, 2025 Jeffrey Burt | May 16 0

Top Stories

U.S. Authorities Seize DanaBot Malware Operation, Indict 16
Cloud Security Cybersecurity Data Privacy Data Security Endpoint Featured Identity & Access Malware Network Security News Security Boulevard (Original) Spotlight Threats & Breaches 

U.S. Authorities Seize DanaBot Malware Operation, Indict 16

May 23, 2025 Jeffrey Burt | 4 days ago 0
Survey Surfaces Limited Amount of Post Quantum Cryptography Progress
Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Survey Surfaces Limited Amount of Post Quantum Cryptography Progress

May 23, 2025 Michael Vizard | 4 days ago 0
Law Enforcement, Microsoft Disrupt Operations of Popular Lumma Stealer
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Malware Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Social Engineering Spotlight Threat Intelligence 

Law Enforcement, Microsoft Disrupt Operations of Popular Lumma Stealer

May 22, 2025 Jeffrey Burt | May 22 0

Security Humor

Randall Munroe’s XKCD ‘Drafting’

Randall Munroe’s XKCD ‘Drafting’

Download Free eBook

Managing the AppSec Toolstack

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2025 Techstrong Group Inc. All rights reserved.
×

Security in AI

Step 1 of 7

14%
How would you best describe your organization's current stage of securing the use of generative AI in your applications?(Required)
Have you implemented, or are you planning to implement, zero trust security for the AI your organization uses or develops?(Required)
What are the three biggest challenges your organization faces when integrating generative AI into applications or workflows? (Select up to three)(Required)
How does your organization secure proprietary information used in AI training, tuning, or retrieval-augmented generation (RAG)? (Select all that apply)(Required)
Which of the following kinds of tools are you currently using to secure your organization’s use of generative AI? (select all that apply)(Required)
How valuable do you think it would it be to have a solution that classifies and quantifies risks associated with generative AI tools?(Required)
What are, or do you think would be, the most important reasons for implementing generative AI security measures? (Select up to three)(Required)

×