As companies turn up the dial on cloud migration, the need to continuously monitor and update security configurations and policies is taxing many resource-constrained organizations, and is seen as the top threat for cloud computing by the Cloud Security Alliance.

The good news: AWS and IBM are tackling the challenge with a novel generative AI-powered solution that automatically addresses misconfiguration and policy drift. This frees up much-needed resources and accelerates transformation.

Security and compliance have become critical business imperatives as the proliferation and sophistication of cyberattacks continue. The first half of 2024 saw some of the most widespread data breaches in recent history, capturing millions of customers’ personal information and troves of medical data. Estimates are that 1 billion records have been stolen due to cyberbreaches so far this year, and that number is rising rapidly, with no real end in sight.

The pace and scale of incidents has also sent costs soaring. According to the IBM Cost of a Data Breach Report 2024, the global average price tag associated with a data breach increased 10% over last year, rising to $4.88 million, the biggest jump since the pandemic. With 220 estimated regulatory changes happening on a daily basis, compliance-related operational costs are also climbing, expected to increase by 30% over the next two years.

The continuing cybersecurity skills shortage is making matters worse. More than half of breached organizations face high levels of security staffing shortages, according to the IBM report. Shortages are 26% more acute than 2023. Dealing with the situation has forced companies to add another $1.76 million, on average, to the already high cost of mitigating cybersecurity threats.

Security in the cloud is particularly onerous because monitoring, managing, and maintaining updates and configurations requires a battery of experts. The cloud’s shared responsibility security model exacerbates the issue, creating confusion over what specific measures are the domain of the customer or the hyperscaler. What’s more, measures vary among cloud providers.

“Things change so quickly in the cloud, and every time new systems are added, there are new configuration issues,” says Jayesh Kamat, program manager for product management in cybersecurity at IBM. “The amount of physical labor required to continuously address drifts and misconfigurations is not possible without an army of team members. Today, customers prioritize work based on some logic. Yet everything needs to be secured—otherwise, there are vulnerabilities or loopholes for a hacker to exploit.”

Generative AI is a game changer for cloud security automation

AI has been used to automate cloud security controls, but accessibility has been limited. There are also limits to setting the proper context to determine optimal controls based on risk levels, industry compliance regulations, or best practices. Automating updates or correcting cloud security misconfigurations on the fly is challenging due to the need for manual report review and action initiation.

Generative AI flips that model on its head, bringing security operations closer to full automation and proactive problem-solving. Through use of customer-specific requirements like security policies, resource tags, sensitive data flags, and unique compliance directives, generative AI automatically builds a security paradigm that drives controls, policies, and compliance requirements based on client context. By automatically adapting to evolving security needs, enterprises can avoid error-prone manual processes, ensuring better security outcomes.

Companies recognize the advantages of applying generative AI to ensure cloud security at scale. The IBM Cost of Data Breach Report 2024 found that two out of three organizations are deploying security AI and automation across the security operations center, a 10% jump over the prior year. In some cases, the technologies can lower breach costs by an average of $2.2 million.

IBM and AWS: Collaborating for autonomous and continuous security and compliance

IBM and AWS are working together to elevate cloud security with a solution to automate and streamline security and compliance, helping accelerate cloud adoption by addressing misconfiguration and policy drift.

The Autonomous Security for Cloud solution leverages generative AI to understand customers’ unique AWS environments and complex compliance and policy parameters, deploying security policies that protect AWS landing zones, workloads, and users. Autonomous Security for Cloud taps the power of generative AI to facilitate three primary use cases:

  • Autonomous resource deployment to tailor the AWS environment so it aligns with customer-specific internal security policies, ensuring all deployments are compliant from the start. This reduces the need for manual checks, making secure cloud adoption smoother and more reliable by deploying the right set of security controls.
  • Continuous compliance monitoring using an AI model that learns from customer data and evolving regulatory policies.
  • Autonomous remediation leverages generative AI for threat detection and response. This enables quicker response times by supporting both automatic and semi-automatic responses.

Based on past customer engagements, IBM estimates the tool will drive significant value for enterprises. Among the projected benefits:

  • Up to 30% reduction in manual compliance workloads
  • Up to 15% reduction in operational inconsistencies
  • Up to 25% improvement with real-time assurance
  • Up to 20% more efficient adaption to compliance changes

IBM’s offering encompasses an AI model, retrieval-augmented generation techniques to optimize large language model output, as well as a set of managed services. IBM also supports the solution with orchestrator apps used to automatically execute recommended changes. Initially, IBM will involve humans to ensure accurate configurations. As confidence grows, automated configuration changes will be allowed in lower-risk scenarios, Kamat says.

The following example illustrates how generative AI-enabled context helps Autonomous Security for Cloud address specific customer security challenges. Consider an industry regulation requiring eight-character security passwords, while a specific company in that sector mandates a 12-character password. IBM’s Autonomous Security for Cloud generative AI capabilities learn from policies and customer-specific data to generate a 12-character password on the fly.

“The solution learns customers’ context and adapts to it,” Kamat explains. “The Autonomous Security for Cloud solution deployed for customer A might make decisions differently than it would when deployed for customer B.”

The solution is optimized for AWS native environments and leverages AWS tools, including AWS Bedrock to run generative AI models. The system is built on IBM intellectual property culled from decades of innovating in cybersecurity, complex hybrid cloud environments, and generative AI. The Autonomous Security for Cloud will be offered to AWS customers as a next-generation security offering.

The bottom line

The complexity of cloud security makes it difficult for companies to stay abreast of an escalating threat landscape and keep operations safe. With the generative AI-empowered IBM Autonomous Security for Cloud solution, organizations can confidently make the leap to AWS cloud and accelerate modernization.

For more information, visit https://www.ibm.com/services/autonomous-security-cloud

Share
Share