Cybersecurity has become a cornerstone and a challenge for enterprises seeking to balance innovation with resilience. Businesses are incorporating cutting-edge technologies, such as artificial intelligence and cloud-native platforms, while many look to simplify the developer experience.
For some, there’s been a goal to ensure a secure by default philosophy. That goal comes through eliminating common vulnerabilities, such as open ports, default credentials and insecure configurations, according to Ty Sbano (pictured), chief information security officer of Vercel Inc.
“We’re dealing with a secure by default experience that you just go, ‘You know what? I want a web app. It’s on the web. I don’t have to think about did I leave administration access open or not,’” Sbano said.
Sbano spoke with theCUBE’s Dave Vellante at the NYSE CXO series, and the interview was rerun at the recent Cyber Resiliency Summit, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed the importance of a secure-by-default approach and the evolving challenges of trust and safety in modern hosting platforms.
Enhancing the developer experience with built-in security
Adopting regulated industry best practices in less structured environments requires designing security into systems from the start. It’s often said that infrastructure is code, and everyone wants it to be true, according to Sbano.
“We talk about ephemeral infrastructure as well, so it’s not long-lived,” he said. “If there’s something bad that happens, like a zero-day or a CBE — common vulnerability enumeration — that is out there that people need to go fast and fix, well, for us, it could just be an asset that is static and temporary, and then all of a sudden, it’s torn down and rebuilt.”
Cloud providers excel at their part of the shared responsibility model, but many assumed the cloud handled all security aspects. This misconception left developers burdened with unexpected security responsibilities, often detracting from their primary focus of writing code.
“If everyone’s the security expert, no one’s the security expert. That’s the challenge with that overly shared responsibility. You do need people on point,” Sbano said.
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE Research’s coverage of the Cyber Resiliency Summit:
Photo: SiliconANGLE
Your vote of support is important to us and it helps us keep the content FREE.
One click below supports our mission to provide free, deep, and relevant content.
Join our community on YouTube
Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.
THANK YOU
Source link
lol