Have you heard of cybersecurity mesh? Some are calling it one of the more notable trends for cloud security and today’s other cyber concerns. So, what is it, and how does it work?

The technology stack is breaking down as more people use architectures based on microservices. They’re also using blockchain and other trust models to embrace an information-centric security model that works with distributed services (key to cloud security).

These changes, among others, mean more groups will consider adopting a new overall approach to security. Niel Harper, a chief information security officer and ISACA board director, is well aware.

“The increase in remote access to on-premises data centers and cloud resources is driving the need for a flexible, composable architecture that integrates widely distributed and disparate security services,” he explained. “The goal would be to move perimeters encapsulating data centers to also creating perimeters around identities and objects that are not on-premises or on the same network — specifically, users accessing objects from anywhere, anytime and with a variety of device form factors. It also enables organizations to bring cloud services into their zero trust architecture and employ adaptive access control with more granular analyses of both subjects and objects.”

So, what does that mean in simpler terms? It comes down to the ‘mesh’ approach to cloud security.

What Does Cybersecurity Mesh Mean for Cloud Security?

According to Gartner, cybersecurity mesh is “a flexible, composable architecture that integrates widely distributed and disparate security services”. The tech research and consulting company named this as the second-highest strategic trend for 2022, coming behind data fabric. It’s about strengthening digital security while bringing tools closer to the assets they’re designed to defend.

To be honest, there’s a lot in Gartner’s definition to analyze. Some of it isn’t conclusive.

“My understanding is that ‘security mesh’ is still very much a conceptual strategy rather than a defined architecture or standardized technical approach,” Harper clarified. “It suggests that organizations need to adopt a cybersecurity architecture to integrate security tools into a cooperative ecosystem to reduce the risk impact of individual security incidents. A mesh will use analytics and intelligence coupled with ‘meshed’ controls around identity, policy, posture and information/event visibility.”

That means more chances to drive cloud security and general cyber defense programs forward using mesh. This is even more pertinent for zero trust. Businesses can use cybersecurity mesh to ensure that all their data, systems and equipment receive equal treatment and attention regardless of where they are located. It can therefore help teams to protect against emerging threats and navigate evolving tech needs in real-time. That extends to microservices, too.

How to Implement Cybersecurity Mesh

The future of cybersecurity mesh looks bright. In October 2021, for instance, Gartner predicted that this architecture will help to reduce the financial impact of security incidents by 90% on average within the next few years. Gartner also predicted it will support more than half of all identity and access requests by 2025.

So, mesh can make a difference. How can you take advantage of it? One way is to create a roadmap to bring cloud security and other solutions together. This unified, integrated system can uphold zero trust and other key defensive measures. Doing so will make the task of creating and enforcing policies easier. That will make it easier for security teams to monitor their assets, too.

Teams can then further augment this work by ensuring that basic protections are in place. Harper recommended multi-factor authentication, data loss prevention, identity governance and administration, SIEM and more.

More from Cloud Security

New cybersecurity sheets from CISA and NSA: An overview

4 min read - The Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) have recently released new CSI (Cybersecurity Information) sheets aimed at providing information and guidelines to organizations on how to effectively secure their cloud environments.This new release includes a total of five CSI sheets, covering various aspects of cloud security such as threat mitigation, identity and access management, network security and more. Here's our overview of the new CSI sheets, what they address and the key takeaways from each.Implementing…

Why security orchestration, automation and response (SOAR) is fundamental to a security platform

3 min read - Security teams today are facing increased challenges due to the remote and hybrid workforce expansion in the wake of COVID-19. Teams that were already struggling with too many tools and too much data are finding it even more difficult to collaborate and communicate as employees have moved to a virtual security operations center (SOC) model while addressing an increasing number of threats.  Disconnected teams accelerate the need for an open and connected platform approach to security . Adopting this type of…

Cloud security uncertainty: Do you know where your data is?

3 min read - How well are security leaders sleeping at night? According to a recent Gigamon report, it appears that many cyber professionals are restless and worried.In the report, 50% of IT and security leaders surveyed lack confidence in knowing where their most sensitive data is stored and how it’s secured. Meanwhile, another 56% of respondents say undiscovered blind spots being exploited is the leading concern making them restless.The report reveals the ongoing need for improved cloud and hybrid cloud security. Solutions to…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today