Uncovering Cloud Workload Trends – Greg Notch, Expel
Expel CISO Greg Notch dives into a survey conducted by the Cloud Security Alliance (CSA) that finds IT teams are repatriating a surprising number of cloud workloads back into on-premises IT environments.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Greg Notch, who's CSO for Expel, and we're talking about cloud repatriation and how come we're seeing more of it these days?
Hey, Greg, welcome to the show. Thank You for having me. You guys did a survey with the Cloud Security Alliance that found a number of things, but one of the more intriguing aspects is that workloads are moving back from the cloud to on-premise.
What do you think is driving that? Um, frankly, I was somewhat surprised by it. Um, the, the, i, I have a background in DevOps and infrastructure, and I was surprised to see the repatriation by, uh, uh, by a bunch of vendors.
I think there's maybe a few things. Uh, you know, maybe the, the promise of moving everything to the cloud hasn't been realized. And folks realized that they had kind of, they were gonna have both environments for an indefinite amount of time, as opposed to we're just gonna get all of our infrastructure to the cloud.
Um, and that's sort of forced to rethink in terms of cost. 'cause the, the cloud is more expensive in some ways. And so the, you know, the shifting landscape of, well, if I'm gonna have both on-prem and cloud for a much longer runway than I anticipated, maybe I better do some harder thinking about which, what stuff goes where.
Do you think also that covid played a factor in this? Because I think a lot of workloads went up in the cloud regardless of their attributes during, you know, at a time when we didn't have access to on-premise environments, and people are now starting to realize the cost factors and doing a little deeper dive. I think that's true.
I also think the, you know, there's the oper, like the DevOps and operational side was, well, if you're gonna have to maintain both environments, that cost is the same, and then you have security concerns. And frankly, the technology improved for getting remote employees access to on-prem, such that it's not wildly different than what, than getting them access to resources in the cloud. And so I think both of those were e you know, it, it re the cost benefit calculus changed a little bit in terms of like, well, I need to put it in the cloud because my people are remote.
And I think people question that as a first principle. Do you think that on premise is more secure than the cloud or just maybe differently insecure? And the two environments have different attributes, and you need to think through what the security parameters are, depending on the workload.
They're different. Um, and I think there's a tension between them. So there's, with the cloud, you have, you've sort of have a shared responsibility model where the cloud provider provides hopefully very excellent security up to a certain layer of the infrastructure.
You're not generally worried about network security the same way you are when you're running, when you're running data centers on-prem for that, you pay the premium and the tax of the cloud, the, if you're running on-prem, you're there. The, there's a lot more mature tooling for, and because you have more control over the infrastructure, but with that control comes the responsibility of managing. So it depends on like where in the stack you wanna like focus your security sho resources.
So I, I, uh, I'm reticent to say more or less it's just different and what skills you need and what tools you need change, depending on which environment you're talking about. Part of the issue seems to me it's not so much the cloud platforms as much as it is the processes we use to provision those, uh, resources. A lot of times developers with very little cybersecurity expertise are used in infrastructure as code tools and surprise, surprise mistakes get made.
So how security do you think the cloud really is these days as it relates to the platform versus the processes we're using? Well, I mean, if the valuations of CSPs and synaps are, are any indication, this is not a cottage industry, right? The, the, I I don't know that I'm willing to blame the developers because I, I think cloud introduces a different kind of complexity than they're traditionally used to.
It gives them freedom, right? They have a lot more control over the deployment of their applications, um, which is was the great promise of DevOps. But at the same time, like the tooling wasn't there to help keep them on the garden path.
And so I think we've seen a whole proliferation of tooling that that sort of helps, you know, you know, build paved roads for that. The problem is that complexity is significant. Um, take for example, a technology like Kubernetes, um, that is, you know, you could deploy on-prem, you could deploy in the cloud using this.
It's, you know, it's, it's what the promise of it is. Cloud agnosticism. However, if you run your own Kubernetes clusters, anybody who's ever tried to do that will tell you that is a, a herculean effort.
Um, and the benefit of doing so is dubious. And so that's where like the promise of the tooling and the complexity introduced by Cloud Native Tech actually does itself a disservice, I think is the, you know, the choices of these advanced technologies sometimes make, uh, make, make for difficult security and difficult operational outcomes. Are we entering a new phase?
I feel like the first phase of the cloud was a lift and shift of monolithic applications into a cloud environment, otherwise known as, you know, you're mess somewhere else, but it feels like we're moving to these cloud native architectures, and so does the security paradigms that I lifted and shifted into the cloud along with those workloads service well, or do we need to rethink this whole thing? I think you, I think like every security decision it needs to be tuned to the application and the business goal that you have. Like the, you know, it needs to be tuned to the amount of risk it needs to be tuned to the type of application.
So if you wanna put up, uh, you know, sort of a low impact application that you want to quickly iterate on, go to the cloud. If you have a high security application where you want a proliferation of controls and you want a lot more, you know, eyes on and, uh, restrictions, you, you may find value in, in deploying it on-prem, uh, I think the, the, it's, it, it is not an all or nothing and it's not a one size fits all, uh, choice. And I think that was the false dichotomy of the lift and shift thing.
It was like, well, all right, we're just gonna go all to the cloud and the, you know, uh, well, why some applications, and if you're just, if you have a cloud native application, this makes a lot of sense. But if you're just picking up VMs from your VMware cluster and putting them in a w s like maybe the, you've lost controls in a lot of ways, and maybe the unit economics don't make sense, Aren't we gonna see workloads continue to move back and forth? I mean, it seemed like, you know, back in the good old days, workload went somewhere and it kind of just stayed there.
But are workloads dynamically moving between the cloud and on-premise as we go forward? Um, I mean, that was the, so when I talked about multi-cloud in previous roles, my, my, my multi-cloud strategy was effectively on-prem and multiple cloud providers. It was, uh, the, the kind of data centers and infrastructure that I was responsible for building lend didn't lend itself to, like putting everything in the cloud.
So I actually think we are gonna see workloads move back and forth, I think for business continuity reasons, I think for scaling reasons, you'll see some folks go for the cost consistency of running infrastructure on-prem, but if they have a burst of traffic, they want the ability to, to, to go from effectively CapEx to opex dollars in order to meet business needs. So I think you'll see some of that for more static, non movable workloads. I think it's, there'll be the cost benefit, um, i, you know, analysis for those particular workloads.
I think what's interesting is that the businesses are choosing to pay for both, like both the skill sets required to manage both of those, the security technology stacks required to secure both. I mean, they, they're fundamentally different tooling in a lot of ways. And it's interesting to me that the, the business choice is, well, it's worth it to manage security and manage operations in both of these areas if that's cheaper than paying the cloud tax for everything.
Or they, or they, so they believe, So the survey covers a lot of ground. So what else leaped out at you in this survey as you kind of walk through it a little bit? Is there anything else that you go, wow, just didn't think I'd see that either?
I mean, I think that was the biggest surprise. Most of the rest of it was, I, like, I felt like it, it was on trend for like, you know, folks that are moving to the cloud, but now we're thinking about the financial part of it a little bit more. Um, what was, but that was that, that took me aback because I honestly didn't think we would see that pendulum swing for, for quite some time.
And so I, you know, I wonder how folks are gonna operationalize this across their business. You know, the, the, the people who are skilled that, that operate in cloud infrastructure might not be network engineers that can run things on-prem. So how, like, how the, the blend of what your operations teams and frankly what your security teams and what tech you buy is, is gonna be the, the interesting outcome.
I think here, of Course, we have a shortage of cybersecurity skills and we have an even greater shortage of people who know the cloud and cybersecurity. So how will we kind of address all this hybrid cloud computing environments with the lack of resources we currently are struggling with? Um, well, uh, there's a bunch of, I'm, we're hoping for automation, right?
Like, that is, that's been the, the, the great equalizer for DevOps and network operations for the years. Um, so I think you'll see some of that in security. I think you'll see outsourcing, um, I think you'll see the tooling consolidate.
You know, there's a lot of point products in the security market right now, and you'll start to see some, some platform plays start to emerge in the market. Um, certainly vendors like us will, will help customers make those journeys and help them with their workloads regardless of whether they put them on-prem or put them in the cloud. And I think, you know, or they choose to use agnostic technologies like Kubernetes, like, I think that will, there'll be demand for that because hiring all of the people that you need to manage that is not a, it's not a sustainable thing for a lot of businesses.
Like, even if you could find the people LA cost us product, You cannot walk down the street without somebody telling you about their great new AI thing. Will AI in this case, save us from ourselves? Um, I think, you know, there's been a lot of chatter around this.
I think where I net out is AI's a dual use technology like every other, um, it, you know, it, it brings, uh, it brings advantages to the defender, um, and it brings significant advantages to the attackers, both, I think in the short term it'll bring advantages to the attacker, but in the long run, it brings more advantages to the defender. You can view more logs, you can cover more surface, you can, you can, uh, build detections and response capabilities automatically. Like there's a, there's a bunch of advantages if you're sitting on the pile of response data that, that most security teams are.
But it might be a while before the, the dream is realized, so to speak. And I think in the short term, it might favor the attackers. Right?
So what's your best advice to folks who are, you know, clearly dealing with an expanded attack surface? I mean, it's the cloud, it's on premise stuff's moving to the network edge. How do we cope?
Find vendors you can partner with, find, um, like make sure that you're making business and risk decisions about what, what workloads you put where like it's, it's not a one size fit all. Like, carefully look at what's in this workload, what's it doing, how fast is it changing? And then decide, you know, what security controls it requires and then you can make better decisions about where it needs to, where it needs to live.
It should be, it should be a, a, a combination of sort of a financial security and an operational decision. That's, you gotta look at it that way. And there's plenty of vendors, um, that are out there that are, that are willing to help you.
All right, folks, you're heard to hear much like the workloads, the security needs to be fit for purpose. So you need to figure out what to do when and where, based on the risk and the type of workload that's running and also what hardware it's on. In some ways things never change.
It is just, there's a lot more of these decisions to be made. Hey, Greg, thanks for being on the show. Thank you so much for having me.
All right, back to you guys in the studio.