Paloalto-2020年云原生安全报告(英文)-2021.1-37页_10mb
报告摘要
Summary of the State of Cloud Native Security Report
Core Content
This report provides an in-depth analysis of cloud and cloud native security practices, challenges, and trends among organizations globally. It outlines the current state of cloud adoption, the evolution of cloud security strategies, and the measurement of security preparedness.
Main Findings
Cloud Adoption Trends
- High Adoption Rate: 46% of surveyed organizations currently run their workloads in the cloud, and this is expected to rise to 64% within the next 24 months.
- Multicloud is the Norm: 94% of organizations use more than one cloud platform, with 60% using between 2 and 5.
- AWS Dominates: Amazon Web Services is the most popular public cloud provider.
- Platform Distribution: Companies spread their workloads across four compute types: VMs (30%), containers (24%), CaaS (21%), and PaaS (22%). 86% of companies expect their usage of all four to increase or stay the same.
- Industry Variations: Technology, media, and telecom companies have the highest cloud adoption, while energy and resources companies lag behind with 42%.
- Geographic Trends: U.S. and German companies have slightly higher cloud adoption than others, with 48% and 47% respectively.
- Company Size: Companies with less than $1 billion in annual revenue are expected to increase cloud adoption from 47% to 64%, while those with more than $1 billion are projected to go from 45% to 66%.
- Public vs. Private Cloud: The use of public and private clouds is balanced, with 52% of workloads on public cloud and 48% on private cloud. However, high adopters tend to use private cloud more, and low adopters rely more on public cloud.
Cloud Security Challenges
- Top Three Challenges:
- Technical complexity (42%)
- Maintaining comprehensive security (39%)
- Ensuring compliance (32%)
- Internal Challenges:
- Lack of visibility of security vulnerabilities (15%)
- Employee training on security tools (14%)
- Employee training on safe practices (11%)
- Evaluating current security state (11%)
- Security Team Structure:
- 77% of companies have more than 20 people on their cloud security teams.
- 47% use a hybrid model, combining centralized security teams with embedded experts in delivery teams.
- Security Tools and Vendors:
- 71% of companies use third-party vendor tools.
- 65% use CSP-provided security tools.
- 62% use open source tools.
- Companies with high budgets are consolidating their toolset, with 53% using 5 or fewer cloud security tools.
Security Preparedness
- Measurement Framework: A new metric called "Cloud Security Preparedness" is introduced, based on 19 specific security practices across cloud workloads.
- Three Levels of Preparedness:
- High: Only 18% of companies fall into this category.
- Medium: A larger portion of companies.
- Low: 29% of companies fall into this category.
- Highly Prepared Companies:
- Embed security into DevOps processes (4.5%).
- Integrate security into at least four stages of the development lifecycle (4.1%).
- Tool Overload:
- 52% of highly prepared companies with 11 or more security tools said that having too many tools made it harder to prioritize risks.
- 71% of companies use multiple tools, leading to overlaps and inefficiencies.
Cloud Security Spend
- Investment Trends:
- 56% of surveyed companies spent less than $50 million on cloud platforms.
- Companies with higher annual revenue tend to spend more on cloud.
- Companies with over $100 million in annual cloud budget allocate 16% or more to cloud security.
- Cloud Security Spend by Revenue:
- Under $10M: 49% allocate more than 10% to security.
- $10M to $50M: 24% allocate 16% or more to security.
- Over $50M: 34% allocate 16% or more to security.
- Paradox of Investment: Higher cloud adoption does not always mean higher cloud investment. Only 17% of the highest cloud adopters invested more than $100 million in cloud in 2019, and these high spenders are 19% of the lowest adoption group.
Key Takeaways
- Cloud adoption is high and growing across all industries and company sizes.
- Multicloud usage is widespread, with AWS leading the public cloud adoption.
- Cloud security is a complex and evolving challenge, with many internal organizational issues.
- Security teams are transitioning to hybrid models, and the use of multiple security tools is causing inefficiencies.
- Security preparedness is low in many organizations, with only 18% being highly prepared.
- The use of a single, comprehensive security solution is seen as a way to improve cloud security posture.
- Cloud security spend is increasing, but not always in line with cloud adoption levels.
Conclusion
The report emphasizes the need for organizations to move beyond individual security measures and adopt a more integrated, comprehensive approach to cloud security. It also highlights the importance of employee training, the role of security in DevOps and application development, and the need for better understanding of shared responsibilities in cloud security. As cloud adoption continues to grow, so does the complexity of securing it, and the findings suggest a shift towards consolidation and integration of security practices.
试读结束,高清完整版pdf/doc/ppt,请点下载