Wednesday, June 17, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Cloud Security Cybersecurity Data Security Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Threat Intelligence Threats & Breaches 

Home » Cybersecurity » Data Security » Sysdig Bids to Bolster Brittle Cloud Infrastructure Layers

Sysdig Bids to Bolster Brittle Cloud Infrastructure Layers

by Adrian Bridgwater on June 18, 2024

Cloud computing is big. We refer to the major cloud service providers (CSPs) as hyperscalers for a reason. But sections, subsections and service streams within the cloud can also be brittle, which is why we trace attack chain paths through increasingly sophisticated technology services today. With platform engineering teams taking on more responsibility for cloud estates, how can infrastructure and DevOps teams gain a higher-level view of security topographies today?

As we know, when an attacker gets access to a cloud environment, they typically use a software vulnerability or a stolen credential to get access. Once they are inside, they will try to get outside of that first environment and into other (typically more valuable) cloud systems by looking for other cloud user identities or for other misconfigurations.

The act of searching (aka performing investigations) for those issues will create data that can alert the IT team to the attacker’s presence if they know what to look for. But because most enterprise systems have been built by separate teams (often across different) hyperscalers, they throw off different log data or other information. Collating it all requires knowledge of how the different parts of the cloud all connect, so we can investigate what is wrong and how to fix it. To compound these complexities, investigations take a lot of time. Cloud security company Sysdig thinks we need to embrace cloud-native investigation tools designed to cut incident analysis time to just five minutes.

Automating Collection & Correlation

Now extending its real-time cloud security toolset to deliver at this cadence, Sysdig says that this acceleration is possible by automating the collection and correlation of events, posture and vulnerabilities to identities for even the most complex cloud attacks. The company claims legacy endpoint detection and response (EDR)/extended detection and response (XDR) solutions alongside security information and event management (SIEM) platforms lack crucial cloud context, slowing down investigations and limiting their scope.

“Traditionally, security organizations operating in on-premises environments were able to handle all aspects of threats from end-to-end. The complexities of the cloud mean that this responsibility is often shared between disparate teams,” said Shantanu Gattani, VP of product management, Sysdig.

Keys to The Castle

In real-world operations, SIEM queries may not even yield results before an attacker has the keys to the castle. To effectively detect, investigate and respond in the cloud, teams must be able to monitor and analyze cloud and log events in real-time – capabilities only afforded to them by a truly cloud-native solution. Historically, security teams have been tasked with correlating, contextualizing and evaluating threats across fragmented data feeds from disparate and complex domains. With DevOps teams needing that insight into their cloud applications, Sysdig thinks automation is the right response.

“EDR/XDR approaches lack the cloud context needed to understand the who, what, where and how of an attack before a breach can occur. Without this context, teams struggle to understand and communicate the key information they need to work together meaningfully. Also, without a shared platform, teams often operate with different information and terminology — they don’t speak the same language, making it difficult to share collaborative steps, prescriptive context and response actions across teams,” explained Gattani.

He suggests that by centralizing all data, security and platform teams can break silos and share findings to expedite investigations. 

“Rapid investigation findings enable response teams to initiate a response within five minutes, adhering to the standard outlined by the 555 benchmark. The enhanced incident debrief findings that these investigations provide (such as what misconfigurations, permissions and vulnerabilities were abused to perpetuate the attack) can then be shared to tune and harden preventive controls. This focus on perpetual improvement to preventative controls helps ensure incidents are non-recurring, reducing organizational cloud risk,” added Gattani.

Sysdig Cloud Attack Graph

By visualizing a given incident in the Sysdig Cloud Attack Graph, security analysts gain a dynamic view of the relationships between resources for a better understanding of the kill chain and potential lateral movement across a cloud environment. Overlays of detections, vulnerabilities and misconfigurations help responders discern where a threat may have originated and how a threat actor was able to perpetuate an attack. 

By automatically correlating cloud and workload events to identities, Sysdig asserts that it has unlocked a more powerful way to enhance real-time monitoring for complete incident context. Automatic correlation between cloud events and location-aware identities highlights unusual logins, impossible travel scenarios and malicious internet protocol (IP) addresses. Users gain a clearer understanding of what threat actors are doing in their infrastructure, as well as how they have and can leverage associated policies, permissions and roles to advance an attack.

By centralizing, enriching and correlating identities to events, the suggestion is that security and platform teams can break silos and readily share findings to expedite investigations, improve preventive controls and give prescriptive guidance for response actions.

Recent Articles By Author
  • Cogent: AI Exploit Developer Threats Outpace Scanner Detection On Critical Vulnerabilities
  • StrongestLayer: Top ‘Trusted’ Platforms are Key Attack Surfaces
  • F5 Strengthens, Scales & Sustains AI Security With Integrated Runtime Protection 
More from Adrian Bridgwater
June 18, 2024June 18, 2024 Adrian Bridgwater benefits of cloud security, cross platform environment, Sysdig
  • ← Reclaim Your Summer by Automating Daily IT Tasks With RMM Automation
  • Not all zero days are created equal – Blog | Menlo Security →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

True Agentic SecOps at Lakehouse Scale
Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

2 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

3 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

3 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

1 month ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams
Ten Great Cybersecurity Job Opportunities
SailPoint Acquires Entro to Continuously Detect and Monitor Non-Human Identities
Databricks Acquires Cybersecurity Startup Panther Labs to Fortify AI Defense
Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites
Iranian Cyber Group Handala Claims Cal Water Hack
CISA to Require Federal Agencies to Patch Some Vulnerabilities Within 3 Days
Claude Fable 5’s pricing makes Sonar Context Augmentation a potent cost lever
CVSS Is Officially Dead: What CISA’s BOD 26-04 Means for Everyone
How You Actually Secure Systems: Using OWASP and NIST Together

Industry Spotlight

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died
The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security
Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Uncategorized 

The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

February 18, 2026 Jack Poller | Feb 18 Comments Off on The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

Top Stories

Trying to Control AI is Like Holding Sand
AI and Machine Learning in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trying to Control AI is Like Holding Sand

June 17, 2026 Alan Shimel | 9 hours ago 0
F5 Embeds Neural Network in WAF Platform to Continuously Assess Risks
Application Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

F5 Embeds Neural Network in WAF Platform to Continuously Assess Risks

June 17, 2026 Michael Vizard | 10 hours ago 0
Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Malware Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Social Engineering Spotlight Threat Intelligence 

Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites

June 16, 2026 Jeffrey Burt | 20 hours ago 0

Security Humor

Randall Munroe’s XKCD 'Bottle'

Randall Munroe’s XKCD ‘Bottle’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
The Dangers of Open Source Software and Best Practices for Securing Code
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.