Forrester Data. Cloud Security Solutions
Forrester Data. Cloud Security Solutions
Controls You
Overview
The following report discusses the “Shift To The Cloud” that raises security concerns and how
traditional security tools can’t effectively monitor data moving to and from the cloud and between
cloud platforms.
While CASB is an essential element in a cloud security project, it’s important to note that cloud
security requires a holistic approach. Know more about Tata Communications’ holistic security
framework for Managed Security Services. Learn how to evaluate and select cloud security
models for multi-cloud environments to meet security and compliance requirements using the
Multi-Layered framework driven approach.
Tata Communications as both a Managed Security Services Provider (MSSP) as well as Cloud Service
Provider (CSP) is seeing noticeable trends around –
• Need to make security as flexible and scalable as IaaS consumption, but this is not easily achieved
• Data encryption is a preferred method of data protection, but the model needs to be robust around key
management controls as well as application compatibility with encryption
• Ability to layer on advanced controls including APT and Analytics based solution as more critical workloads
make their way to the Cloud
• Common orchestration and management framework around Cloud Infrastructure and security
Security is ultimately a shared responsibility between the company and the public cloud vendor. According
to Forrester, cloud success comes from mastering the “uneven handshake”. While cloud vendors are typically
responsible for securing the data center, infrastructure and hypervisor, the onus is on you, as a consumer to close
this gap with the necessary OS, users, applications, data and of course, security– in tandem with the vendor. As
we can see here, the shared security model means the organization is ultimately responsible for what happens to
their data hence this model needs to be matched by a flexible security framework and operational approach that
an address the varying needs in a multi-cloud environment. - It’s time to secure the cloud!
The integrated cloud security approach by Tata communications provides organizations with a flexible architecture
and delivery model which ensures highest security when the cloud services are consumed. We support
organizations in developing an effective security strategy to manage the “Customer Responsibility” in the cloud,
which also includes the focus around privacy, compliance, and business requirements during cloud adoption.
4
forrester.com
5
For Security & Risk Professionals
Traditional Security Tools Fall Short Create Your Cloud Security Technology Strategy
And Road Map
Cloud Security Solutions Evolve To Meet The
Challenge The Forrester Wave™: Cloud Security Gateways,
Q4 2016
Global Cloud Security Spending Will Reach $3.5
Billion By 2021
Supplemental Material
›› Security becomes more important as mission-critical apps move to the cloud. Enterprises
want the flexibility of public cloud, and Forrester sees a new phase of public cloud growth as
companies move analytics and core business applications to the cloud.2 The public cloud providers
can run data centers more efficiently and more securely than the tech managers driving the shift.
A good analogy is the number of accidents per air passenger mile versus car passenger mile: You
let the experts take care of security. Cloud security becomes increasingly essential as mission-
critical apps and workloads move to the cloud.3 While the use of cloud services has become more
mainstream, security decision makers are increasingly concerned about cloud security (see Figure
2). A security and risk (S&R) professional at a North American bank said: “Today it’s not if but
how we move to the cloud. How can I enable and secure our bank’s transitioning of our data and
workloads to the cloud?”
›› Cloud complexity requires enhanced cloud security. Enterprises typically have multiple cloud
implementations and use multiple cloud service providers.4 Public, private, and hybrid cloud all
coexist, serving different needs and applications. This complexity creates challenges for cloud
security. Challenges include monitoring data, detecting anomalies, and intercepting bad behaviors.
›› PaaS/IaaS growth creates its own security challenges. While growth in software-as-a-service
(SaaS) has slowed down a bit, we continue to see aggressive growth for infrastructure-as-a-service
(IaaS) and, to a degree, platform-as-a-service (PaaS) offerings. AWS and Microsoft Azure revenues
were up 47% and 93%, respectively, in Q4 2016, while Alibaba reported over 100% growth in its
cloud platform.5 Forrester expects 51% year-over-year growth in IaaS/PaaS in 2017.6 The growth in
cloud platforms raises security challenges as data moves among multiple cloud platforms.
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
7
FIGURE 1 The Global Public Cloud Services Market Is Growing By 22% Annually
F = Forecast
Source: Forrester Data: Public Cloud Services Forecast, 2016 To 2020 (Global)
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
8
“How concerned are you with the risk that the following initiatives or technologies
could introduce in your firm?”
(4 or 5 on a scale of 1 [not at all concerned] to 5 [very concerned])
53%
PaaS
48%
54%
SaaS
51%
›› No more chewy centers. In 2009, Forrester developed a new information security trust model
called the Zero Trust Model. “Chewy centers” refers to the old adage, “We want our network to be
like an M&M, with a hard, crunchy outside and a soft, chewy center.” For today’s digital business,
this traditional perimeter-based security model is ineffective and the shift to the cloud has further
undermined its effectiveness.7 Identity, privacy, and behavioral analytics are emerging as the key
enablers of Zero Trust in the cloud.
›› IaaS platforms don’t offer cross-platform support. An increasing number of enterprises use multiple
IaaS cloud providers. Unfortunately, individual IaaS providers don’t offer cross-platform security
support. AWS, for example, does not easily allow for centralized security management of workloads
in any other cloud than AWS. Alternatively, centralized cloud security management (CCSM) tools can
monitor the security of and prevent unauthorized changes and activity in cloud platforms.8
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
9
›› Third-party cloud security solutions are a top choice to solve the problem. We recently
asked security decision makers how they plan to manage the security of their SaaS and IaaS
operations, and about half prefer to use third-party security vendors (see Figure 3). Why? The most
common rationale is this: “If the cloud provider gets hacked, at least our data is encrypted and the
hackers have no access to the encryption keys — so our data is useless to them.” We expect this
preference for third-party solutions to help drive commercial cloud security software sales over the
next five years.
“How would your firm prefer to implement solutions that secure public
infrastructure-as-a-service and software-as-a-service?”
2014 (N = 2,903)
2015 (N = 3,221)
2016 (N = 3,158)
IaaS SaaS
46% 48%
From a third-party From a third-party
46% 47%
security vendor security vendor
48% 52%
9% 10%
From an MSP 11% From an MSP 10%
11% 11%
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
10
›› Cloud security gateways. Over the last two years, we have seen three security segments —
cloud data protection (CDP), cloud access security intelligence (CASI), and cloud data governance
(CDG) — consolidated into cloud security gateways (CSGs), also known as cloud access security
brokers (CASBs).9 Cloud security gateways enable: 1) encrypting data at use, at result, and before
it goes to SaaS applications; 2) shadow IT detection; 3) data loss prevention (DLP); 4) malware
detection; and 5) cloud access anomaly detection.
›› Centralized cloud security management. These are solutions that control security configurations
and file configuration integrity in IaaS and PaaS workloads. This can include: 1) malware protection;
2) host-based firewalls; 3) log inspection; 4) intrusion detection and prevention; 5) configuration
management and file integrity monitoring; 6) virtualization support; and 7) privilege escalation.
›› Hypervisor security. Solutions that control security in hypervisors enable their users to monitor
activity between the guest operating system (OS) and the hypervisor, encrypt disks that the guest
OS uses, and centrally manage the tasks each administrator can do (start, stop, etc.) with each
guest OS.
›› Native IaaS/PaaS platform security. Native security solutions are provided by cloud platform
providers. Typical areas include: 1) data classification and categorization; 2) data segmentation; 3)
server access control; 4) resource-based access control and access control lists; 5) user IAM and
attestation; 6) data-at-rest encryption; 7) data-in-transit encryption; 8) encryption key management;
9) logging, auditing, and anomaly detection; and 10) role-based access control.
›› CSG emerges as a consolidated offering. Our market segmentation has evolved since we last
published our cloud security solutions forecast in August 2015. Not surprisingly, over the last two
years, we have seen three security segments — CDP, CASI, and CDG — consolidated into CSGs.10
Rather than investing in several point solutions for cloud security, CSGs allow security and risk
professionals to partner with a single vendor offering a consolidated solution. We expect the CGS
market to grow at a 25.5% CAGR over the 2016-to-2021 period.
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
11
›› CCSM offers cross platform support. CCSM solutions control security configurations and file
configuration integrity in IaaS and PaaS workloads.11 These tools solve the security challenges of
diverse clouds and offer cross-platform support using centralized policy management and auditing.
We forecast 7.5% growth in CCSM solutions over the next five years.
›› Hypervisor security keeps virtual machines safe. As virtual machines’ use grows, we see a
corresponding need for increased hypervisor security. In Forrester’s latest infrastructure survey, 66%
of global infrastructure decision makers cite broad use of server virtualization as a high or critical
priority.12 We project that the hypervisor security market will grow 38.4% over the forecast period.
›› Native IaaS and PaaS security grows as cloud platforms go mainstream. The cloud platform
vendors provide native IaaS/PaaS security.13 Forrester estimates that in 2015, IaaS/PaaS
represented the equivalent of 15% of global hardware spending, and we expect this to increase to
40% by 2020.14 We expect this rapid growth in IaaS/PaaS adoption to fuel 40.9% native IaaS/PaaS
security growth over the next five years.
$3.5
Native IaaS/PaaS security
Hypervisor security $3.1 $1.1
F = Forecast
Source: Forrester Data: Cloud Security Solutions Forecast, 2016 To 2021 (Global)
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
12
›› Financial services represent the largest market today. A few years ago, the idea of using cloud
services would have been controversial, and even radical, at most financial services companies.15
Today — to reduce costs and stay competitive among their peers — financial services companies
are migrating applications and integrating legacy assets into the cloud. Security is paramount to
keep customers comfortable with online banking tools and to protect personal financial data. To
keep those assets safe, we estimate that financial services companies are the largest users of
cloud security solutions in 2016 and will continue to be the largest market segment in 2021. We
expect the financial services sector to grow by 19.6% over the next five years.
›› Retailers embrace cloud security to protect personal data. While Amazon is the leader in
one-click shopping, today many retailers allow customers to store credit card and other personal
information on their eCommerce sites to speed up the shopping process. In parallel with the shift
of fraud management solutions from on-premises to the cloud, we expect retailers to adopt cloud
security solutions to protect not only credit card data but also other personal information such as
home address, email address, cell phone, and buying histories. Data breaches can be extremely
costly to retailers in terms of long-term damage to their brand. We expect the retail segment to be
one of the largest users of cloud security solutions by 2021, growing by 29.7% annually.
›› Government use is growing rapidly. Government agencies are traditionally laggards in technology
adoption — however, the US government’s proactive FedRAMP initiative to codify cloud security
requirements was ahead of other verticals.16 The shift of government resources to the cloud brings
with it not only a proliferation of special, government-specific IaaS data center zones but also a
need for additional security protections. We have seen government use of cloud services tick up
over the last few years, and we expect growth in use of cloud security tools to follow.17 Government
will be one of the fastest-growing sectors, at a 38.7% CAGR.
›› Professional services embrace the cloud. Professional services include a diverse mix of firms
such as consultants, law firms, advertising agencies, and realtors who are adopting cloud. In March
2017, Deloitte acquired Day1 Solutions, a cloud consulting business, to accelerate its clients’
digital transformation.18 We project that the professional services sector will grow by 39.6% over
the 2016-to-2021 period.
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
13
2016 2021
US
$675
Europe
$573
Source: Forrester Data: Cloud Security Solutions Forecast, 2016 To 2021 (Global)
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
14
4,000
Education and
social services
3,500 Transportation
Media, entertainment,
and leisure
3,000 Healthcare
Government
2,500 Retail and wholesale
Professional services
2,000 (incl. construction)
Utilities and
telecommunications
1,500 Financial services
and Insurance
Manufacturing
1,000
500
0
2014 2015 2016 2017(F) 2018(F) 2019(F) 2020(F) 2021(F)
Source: Forrester Data: Cloud Security Solutions Forecast, 2016 To 2021 (Global)
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
15
To help you put research Translate research into Join our online sessions
into practice, connect action by working with on the latest research
with an analyst to discuss an analyst on a specific affecting your business.
your questions in a engagement in the form Each call includes analyst
30-minute phone session of custom strategy Q&A and slides and is
— or opt for a response sessions, workshops, available on-demand.
via email. or speeches.
Learn more.
Learn more. Learn more.
Supplemental Material
Forecast Methodology
ForecastView is a syndicated subscription service delivering access to more than 40 forecasts annually
across North America, Europe, Asia Pacific, and Latin America.
Our forecasts employ a unique methodology: By leveraging business and technology leader demand-
side data balanced with company supply-side metrics, we provide a highly detailed understanding of
each market. Forrester’s ForecastView service provides reliable insight into the business technology
markets. It offers a framework for understanding market drivers and inhibitors and helps clients to plan
and prioritize investment decisions. ForecastView provides detailed data and market metrics from our
major forecast models over a five-year period for the markets of eCommerce, digital marketing, mobile,
and business technology.
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
16
As part of the forecast modeling, Forrester develops comprehensive historical and base-year market
size estimates based on a variety of sources, including public financial documents, executive
interviews, Forrester’s proprietary primary business technology research and surveys, and analysis of
global companies’ distribution and growth.
All of Forrester’s forecasts are designed by a dedicated team of forecasting analysts who build the
models, conduct extensive industry research, and manage the process of formally building consensus
among Forrester’s analysts. Forecast analysts have backgrounds in investment banking, management
consulting, and market research, where they developed extensive experience with industry and
company forecasting.
Survey Methodology
For the Forrester Data Global Business Technographics® Applications And Collaboration Workforce
Survey, 2016, we conducted an online survey fielded from October to November 2016 of 7,249
information workers located in Australia, Brazil, Canada, China, France, Germany, India, New Zealand,
the UK, and the US from companies with two or more employees.
For the Forrester Data Global Business Technographics Infrastructure Survey, 2016, we conducted
an online survey fielded from June to July 2016 of 3,503 business and technology decision makers
located in Australia, Brazil, Canada, China, France, Germany, India, New Zealand, the UK, and the US
from companies with two or more employees.
For the Forrester Data Global Business Technographics Security Survey, 2016, we conducted an online
survey fielded from March to May 2016 of 3,588 business and technology decision makers located
in Australia, Brazil, Canada, China, France, Germany, India, New Zealand, the UK, and the US from
companies with two or more employees.
For the Forrester Data Global Business Technographics Software Survey, 2016, we conducted an
online survey fielded from August to September 2016 of 3,582 business and technology decision
makers located in Australia, Brazil, Canada, China, France, Germany, India, New Zealand, the UK, and
the US from companies with two or more employees.
Forrester Data Business Technographics provides demand-side insight into the priorities, investments,
and customer journeys of business and technology decision makers and the workforce across
the globe. Forrester collects data insights from qualified respondents in 10 countries spanning the
Americas, Europe, and Asia. Business Technographics uses only superior data sources and advanced
data-cleaning techniques to ensure the highest data quality.
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
17
Endnotes
1
See the Forrester report “The Public Cloud Services Market Will Grow Rapidly To $236 Billion In 2020.”
2
See the Forrester report “Brief: Systems Of Record Projects Are Poised To Drive New Cloud Growth.”
3
For more discussion of the issues associated with moving mission-critical apps to the cloud, see the Forrester report
“SAP Customers Have Four Paths To The Cloud.”
4
In the Forrester Data Global Business Technographics Infrastructure Survey, 2016, over 50% of respondents reported
four or more public cloud implementations, and 9% reported 10 or more cloud implementations. Source: Forrester
Data Global Business Technographics Infrastructure Survey, 2016.
5
On February 2, 2017, Amazon reported its results for the quarter ending December 31, 2016. AWS revenue of $3.5
billion was up 47% year-over-year. Source: “Amazon.com Announces Fourth Quarter Sales up 22% to $43.7 Billion,”
Amazon press release, February 2, 2017 (http://phx.corporate-ir.net/phoenix.zhtml?c=97664&p=irol-newsArticle_
Print&ID=2241835).
On January 26, 2017, Microsoft reported its results for the quarter ending December 31, 2016. Microsoft Azure
revenue was up 93% year-over-year. Source: “Earnings Release FY17 Q2,” Microsoft press release, January 26, 2017
(https://www.microsoft.com/en-us/Investor/earnings/FY-2017-Q2/press-release-webcast).
On January 24, 2017, Alibaba Group reported its results for the quarter ending December 31, 2016. Revenue from
cloud computing was US$254 million, up 115% year-over-year, and paying customers were up 100% year-over-
year to 765,000. Alibaba Cloud provides services including elastic computing, data storage, web hosting, and cloud
security services. Source: “Alibaba Group Announces December Quarter 2016 Results,” Alibaba Group press release,
January 24, 2017 (http://www.alibabagroup.com/en/news/press_pdf/p170124.pdf).
6
See the Forrester report “The Public Cloud Services Market Will Grow Rapidly To $236 Billion In 2020.”
7
See the Forrester report “No More Chewy Centers: The Zero Trust Model Of Information Security.”
8
For more insight on scaling security to a large number of IaaS workloads, see the Forrester report “Market Overview:
Cloud Workload Security Management Solutions — Automate Or Die.”
9
For more insight, see the Forrester report “Brief: The Emergence Of The Cloud Security Gateway.”
10
For more insight, see the Forrester report “Brief: The Emergence Of The Cloud Security Gateway.”
11
For more information on centralized cloud security management, see the Forrester report “Market Overview: Cloud
Workload Security Management Solutions — Automate Or Die.”
12
Source: Forrester Data Global Business Technographics Infrastructure Survey, 2016.
13
Native IaaS/PaaS security is provided by the cloud platform vendors. For example, AWS launched Amazon Inspector
and AWS Config Rules in October 2015. Source: Paul Stamp, “New Security Services Launched at AWS re:Invent
2015—Amazon Inspector, AWS WAF, and AWS Config Rules,” Amazon Web Services, October 7, 2015 (https://aws.
amazon.com/blogs/security/new-security-services-launched-at-aws-reinvent-2015-amazon-inspector-aws-waf-and-
aws-config-rules/).
14
See the Forrester report “The Public Cloud Services Market Will Grow Rapidly To $236 Billion In 2020.”
15
Source: Rahul Singh, “How the financial services industry is slowly waking up to cloud computing,” Cloud Tech,
October 3, 2016 (https://www.cloudcomputing-news.net/news/2016/oct/03/how-financial-services-industry-slowly-
waking-cloud-computing/).
16
FedRAMP is the result of close collaboration with cybersecurity and cloud experts from GSA, NIST, DHS, DOD, NSA,
OMB, the Federal CIO Council and its working groups, as well as private industry. Source: “About FedRAMP,” U.S.
General Services Administration (https://www.gsa.gov/portal/category/102375).
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
18
17
Looking at the US government as an example, Forrester sees a continuing shift to the cloud. For more information, see
the Forrester report “US Government Sector Tech Spending Trends, 2017 To 2018.”
Source: Barb Darrow, “Why the U.S. Government Finally Loves Cloud Computing,” Fortune, September 2, 2016
(http://fortune.com/2016/09/02/us-government-embraces-cloud/).
18
Source: James Bourne, “Deloitte strengthens cloud options with acquisition, new jobs and studios,” Cloud Tech,
March 27, 2017 (https://www.cloudcomputing-news.net/news/2017/mar/27/deloitte-strengthens-cloud-options-
acquisition-new-jobs-and-studios/).
© 2018 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law.
[email protected] or +1 866-367-7378
We work with business and technology leaders to develop
customer-obsessed strategies that drive growth.
Products and Services
›› Core research and tools
›› Data and analytics
›› Peer collaboration
›› Analyst engagement
›› Consulting
›› Events
Client support
For information on hard-copy or electronic reprints, please contact Client Support at
+1 866-367-7378, +1 617-613-5730, or [email protected]. We offer quantity
discounts and special pricing for academic and nonprofit institutions.
Forrester Research (Nasdaq: FORR) is one of the most influential research and advisory firms in the world. We work with
business and technology leaders to develop customer-obsessed strategies that drive growth. Through proprietary
research, data, custom consulting, exclusive executive peer groups, and events, the Forrester experience is about a
singular and powerful purpose: to challenge the thinking of our clients to help them lead change in their organizations.
For more information, visit forrester.com. 137882
Tata Communications Limited (CIN no: L64200MH1986PLC039266) along with
its subsidiaries (Tata Communications) is a leading global provider of A New
World of Communications™. With a leadership position in emerging markets,
Tata Communications leverages its advanced solutions capabilities and domain
expertise across its global network to deliver managed solutions to multi-national
enterprises and communications service providers.
The Tata Communications global network includes one of the most advanced and
largest submarine cable networks and a Tier-1 IP network with connectivity to
more than 240 countries and territories across 400 PoPs, as well as nearly 1 million
square feet of data centre and colocation space worldwide.
www.tatacommunications.com