This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Meeting the Challenges of a Multicloud World – Privileged Access & Identities

Download resources

About this session

Chris Hills, chief security strategist at BeyondTrust and a former PAM owner at Charles Schwab, walks through the privileged-access risks of running across IaaS, PaaS and SaaS. He frames the multicloud problem as siloed identity stores, platform-specific tools and conflicting shared responsibility models, then uses the Cloud Security Alliance's 'egregious eleven' to detail the threats: misconfiguration (open S3 buckets, the typo that took AWS S3 down for hours), privilege sprawl across control planes and ephemeral machines, credential misuse behind most cloud breaches, long-lived API keys, shadow IT, incompatible tooling, remote workers on unhardened devices, vendor access and break-glass needs during outages. He then maps seven best practices onto PAM: discover cloud assets, manage control-plane and SaaS admin accounts, broker and audit remote access without exposing RDP or SSH, enforce least privilege with just-in-time access, secure DevOps and CI/CD secrets, monitor every privileged session, and unify management. The closing third presents BeyondTrust's three pillars: password and session management, endpoint privilege management for Windows, Mac, Unix and Linux, and secure remote access via bastion hosts and an isolated browser with credential injection.

Today, most organizations aren’t merely in the cloud—they’re in many clouds (PaaS, IaaS), and their end users regularly consume dozens, or even hundreds, of different SaaS applications. The great cloud migration is enabling the successes of increased remote working and is propelling a renewed embrace of digital transformation initiatives. Yet, more clouds can also mean more
challenges. In addition to the fundamental cloud security issues, there’s the additional complexity and interoperability issues arising from siloed identity stores, native toolsets, and conflicting shared responsibility models between cloud providers. This creates an expanded attack surface that is attractive to threat actors seeking ways into your environment. The identity challenge is the most important security problem for organizations
to solve across cloud and on-premises environments. This is best accomplished by standardizing the management and security controls across the entire IT ecosystem.  

Key takeaways

  • Bring every cloud control plane and SaaS admin console under PAM; a compromised console account can spin up or destroy thousands of instances.
  • Replace standing privileges with just-in-time, role-based elevation so vendors and admins hold rights only in the window they need them.
  • Stop exposing RDP and SSH to the internet for cloud servers; broker access through a bastion or proxy that injects credentials and records the session.
  • Treat API keys and CI/CD service accounts as privileged credentials: discover them, vault them and rotate them at DevOps speed.
  • Fix default cloud settings and misconfigurations first; they, not exotic exploits, cause most cloud breaches.

Speakers

Chris Hills
Chris Hills
Chief Security Strategist · BeyondTrust

Resources

Tags

More from GoSec 2021

Also from Chris Hills

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.