My current travels in India provided me the opportunity to meet several CIOs and CTOs along with my colleagues from F5. A common theme in our discussions was the colossal impact of the recent global IT outage caused by a CrowdStrike patch update. From our collective conversations, three key themes and imperatives for every CIO/ CTO moving forward emerged:
- Evaluate Critical Infrastructure placement?(by the way, this can be considered as critical infrastructure for your company) Should your critical infrastructure continue to reside in the cloud or should you consider repatriating to your own data centres? For some, the scalability, flexibility, and advanced capabilities of the public cloud will be compelling. For others, the security, control, and compliance benefits of the on-premise infrastructure will be paramount, in line with the recent outages.
- Adopt a Multi-Vendor Cloud Strategy:?Security demands a multi-vendor cloud approach. This is non-negotiable. Remember, multi-cloud differs from mulit-vendor. Where possible, leveraging multiple vendors ensures redundancy and enhances security, reducing single points of failure. Cloud security platforms have also provided great TCO, but the efficacy for some of the multitude of controls they provide can be wanting.?
- Implement Zero-Trust for Everything: The zero-trust model should extend to every aspect of your IT environment, including security patches. Automatic Updates can pose significant risks. All updates must be thoroughly tested in a sandbox environment before deployment. This ensures that potential vulnerabilities are identified and mitigated in a controlled setting.
These are some of the steps discussed that are essential to navigate the complexities of today's IT landscape and safeguard against future outages. CTOs and CIOs must remain vigilant, proactive, strategic and consider all risks in their approach to IT infrastructure and security.
#ZeroTrust #MultiCloud #F5
-
7 个月Excellent notes Mohan. Zero Trust also requires the org to conduct TTX and BCP exercises to prepare the team for any eventual incident.