Organizations are increasingly adopting and combining multicloud (services from multiple different cloud service providers) and hybrid cloud (cloud combining public cloud and private cloud infrastructure).
Multicloud and hybrid cloud give organizations of all sizes the flexibility to deploy best-of-breed apps and development tools, rapidly scale operations, and accelerate digital transformation. By one estimate, 87% of organizations use multicloud environments, and 72% use hybrid-cloud environments.
But along with these benefits, multicloud and hybrid cloud also bring security challenges.
Security staff and DevOps or DevSecOps teams must manage security and compliance for all the components of the cloud-native applications they deploy across multiple providers’ clouds. These components include hundreds or thousands of microservices, serverless functions, containers and Kubernetes clusters.
In particular, infrastructure as code (IaC), which enables API-driven, in real time provisioning with every continuous integration and continuous delivery (CI/CD) cycle, makes it all too easy to program, distribute and perpetuate misconfigurations that leave data and applications vulnerable to security incidents and cyberthreats.