Essentials for Automating Security Across Hybrid Cloud
Download resourcesAbout this session
Sattwik Gavli, director of cloud products at Tufin, lays out three essentials for automating security across hybrid and multi-cloud environments. He argues that agility, not cost, now drives cloud adoption, and that legacy on-prem tactics do not transfer: firewalls remain necessary but cannot catch the misconfigurations, over-permissive IAM policies and open ports that Gartner blames for the overwhelming majority of cloud breaches. He traces those misconfigurations to human error, lack of visibility, fragmented silos and the skills gap, and to a second layer of shared responsibility inside the organisation, where security, cloud ops and now developers all own part of cloud security. His three essentials are visibility (you cannot secure what you cannot see, at asset and application level across on-prem and cloud), automation (change-flow automation for firewalls plus policy checks wired into CI/CD pipelines, CloudFormation and Terraform templates so security shifts left instead of becoming a bottleneck), and a vendor-agnostic, cloud-native approach with a single source of truth for policy. He illustrates each with customer examples, describes Tufin's crawl-walk-run model toward continuous compliance, shows how the product surfaces risky ports, exposed S3 buckets and Kubernetes connections and can generate policy YAML, and closes with a free 30-day assessment.
Today’s networks are expanding beyond on-prem to include cloud and hybrid deployments. While enterprises seek to balance agility and security, they are also faced
with skills shortages and the need to work with the technology of multiple vendors. Automation is key to addressing these challenges while offering cloud,
network and security teams the ability to drive efficiencies and reduce risk across their heterogenous environment. Join us to understand the essentials for automating security without compromise. During this discussion we'll discuss:
" • How to gain visibility and control of security policies across hybrid clouds;
• The role of automation in meeting business
and compliance requirements; and
• Strategies for bridging skills gaps while balancing security and agility."
Key takeaways
- Do not carry on-prem tactics into the cloud: firewalls still matter but cannot catch misconfigurations, over-permissive IAM policies and open ports, which cause the vast majority of cloud breaches.
- Get visibility first at both asset and application level across on-prem and every cloud, since fragmented silos leave no single team the context to see what is exposed.
- Shift security left by checking policies in the CI/CD pipeline and in CloudFormation or Terraform templates before deployment, so security stops being an end-of-cycle bottleneck.
- Keep policy in one source of truth (for example a git repo) that developers check against continuously, so violations are caught before security ever sees them.
- Choose vendor-agnostic, cloud-native tooling so you can adopt new cloud features without rebuilding policy for every new control plane.
Speakers

Sattwik is the Director of Cloud Products at Tufin. Prior to working at Tufin, Sattwik helped enterprises with their digital transformation journey into the cloud while working for companies like Oracle, Ribbon Communications, and most recently for… Read moreRead less
Sattwik is the Director of Cloud Products at Tufin. Prior to working at Tufin, Sattwik helped enterprises with their digital transformation journey into the cloud while working for companies like Oracle, Ribbon Communications, and most recently for a cloud-native security startup, Privafy Inc. At Tufin, Gavli continues to work with Fortune 1000 companies to accelerate their adoption of security policy management in cloud.
