Cloud Security

Sysdig Announces Google Cloud Security Partnership

Sysdig, Inc. announced a partnership with Google Cloud to deliver cloud and container security solutions that help organizations address security and compliance needs. This collaboration establishes the Sysdig software-as-as-service (SaaS) offering on Google Cloud and introduces a new unified cloud and container security offering for Google Cloud customers. The Sysdig Secure DevOps Platform brings new continuous cloud security and compliance controls together with existing vulnerability scanning, compliance validation, and threat detection for containers.

Adopting secure DevOps to manage your security risk on Google Cloud

Enterprises are under pressure to accelerate the delivery of applications in the cloud. Modern cloud apps built using a DevOps approach, CI/CD, and containerized microservices require a shift in security processes. According to the State of DevOps 2021 study, “Teams who integrate security best practices throughout their development process are 1.6 times more likely to meet or exceed their organizational goals.” Without secure DevOps, misconfigurations and weak passwords in the cloud are common, evident by the many high-profile cloud breaches. Sysdig is solving these problems, together with Google Cloud, to help joint customers reduce security risk and confidently run containers, Kubernetes, and cloud.

New security and compliance capabilities for Google Cloud
With this announcement, Sysdig adds cloud capabilities to give enterprises a new way to meet key security and compliance requirements across their Google Cloud deployments.
  • Cloud Security Posture Management (CSPM) for Google Cloud: Secure public cloud accounts with automatic cloud asset discovery, cloud services posture assessment, and compliance validation based on the Cloud Custodian open-source project. Cloud security teams can automatically discover in-use Google Cloud services, flag misconfigurations, and alert on compliance violations.
  • Cloud configuration change and threat detection: Detect threats via Google Cloud Audit logs with out-of-the-box rules based on open source Falco to continuously monitor for suspicious activity or configuration changes across services and infrastructure in real-time.
  • Chronicle integration for advanced threat hunting: Forward Sysdig-detected security events directly to Google Cloud’s Chronicle security analytics platform. Sysdig cloud and container detection, built on Falco, gives Chronicle users unique insight to analyze and respond faster to cloud-native workload threats.
  • Sysdig SaaS on Google Cloud: The Sysdig SaaS platform is now available in the Google Cloud US-East region, making it even easier for cloud teams to get started with security, compliance, and monitoring for public, hybrid, and multi-cloud environments. Teams can get started in minutes leveraging Google Cloud’s trusted, world-scale infrastructure and grow without worrying about backend data management.
  • Availability on Google Cloud Marketplace: Purchase and deploy with a single click from the Google Cloud Marketplace. Consolidated billing allows customers to draw down on their Google Cloud spend commitment.
  • Free Tier for Cloud Security: Take advantage of continuous cloud security for free, forever, for a single account. Sysdig’s Free Tier includes a daily CIS benchmark check and threat detection to ensure cloud environments are secure and compliant. The Free Tier also includes image scanning for Google Cloud Registry (GCR) or Artifact Registry to automatically detect and block vulnerabilities for up to 250 images per month.

“With security top-of-mind for our customers, we expect the deep visibility and threat detection of Sysdig and the secure-by-default infrastructure of Google Cloud will encourage greater cloud adoption among today’s enterprises, we believe there is a lot of opportunity for us to accelerate innovation together with our partnership.”

said Vineet Bhan, Head of Security Partnerships, Google Cloud.

A SaaS-first approach to secure DevOps
The Sysdig Secure DevOps Platform provides organizations a SaaS-first platform to address the most critical security, compliance, and monitoring functions, allowing teams to ship cloud applications faster. The Sysdig platform delivers image scanning, Kubernetes and container monitoring, application and cloud service monitoring, runtime security, compliance, threat detection and prevention, incident response, and forensics at scale.

“We’re seeing an inflection point and cloud and container adoption is accelerating, yet we know security is the top barrier, we are excited to partner with Google Cloud to help customers adopt secure DevOps, so they can confidently run container and Kubernetes workloads.”

said Suresh Vasudevan, Chief Executive Officer, Sysdig.

The new capabilities announced today build on joint visibility, security, and compliance solutions previously available for Google Cloud services including GKE, Anthos, Security Command Center, Cloud Run, Cloud Build, Google Container Registry, and Artifact Registry.

About Sysdig:
Sysdig is driving the secure DevOps movement, empowering organizations to confidently secure containers, Kubernetes, and cloud. With Sysdig, teams secure the build, detect and respond to threats, continuously validate cloud configurations and compliance, and monitor performance. Sysdig is a SaaS platform, built on an open source stack that includes Falco and sysdig OSS, the open standards for runtime threat detection and response. Hundreds of companies rely on Sysdig for container and cloud security and visibility

Spotlight

Other News
Cloud Infrastructure Management

The Manufacturing Sector Experiences More Attacks in the Cloud than Any Other Industry

PR Newswire: | January 19, 2024

Netwrix, a cybersecurity vendor that makes data security easy, today revealed additional findings for the manufacturing sector from its survey of 1,610 IT and security professionals across more than 100 countries. According to the survey, 64% of companies in the manufacturing sector suffered a cyberattack during the preceding 12 months, which is similar to the finding among organizations overall (68%). However, it turned out that the manufacturing sector experiences more cloud infrastructure attacks than any other industry surveyed. Among manufacturing companies that detected an attack, 85% spotted phishing in the cloud compared to only 58% across all verticals; 43% faced user account compromise in the cloud as opposed to 27% among all industries; and 25% dealt with data theft by hackers in the cloud compared to 15% for organizations overall. "The manufacturing sector relies heavily on the cloud to work with their supply chain in real time. This makes their cloud infrastructure a lucrative target for attackers — infiltrating it enables them to move laterally and potentially compromise other linked organizations, as happened to one the world's top meat processing companies. Credential compromise or malware deployed via a phishing email is just the beginning of the attack," says Dirk Schrader, VP of Security Research at Netwrix. "The attack surface in the cloud is always expanding, so it's critical for manufacturing companies to adopt a defense-in-depth approach," adds Ilia Sotnikov, Security Strategist at Netwrix. "First, they must rigorously enforce the principle of least privilege to limit access to sensitive data, which ideally includes just-in-time access to eliminate unnecessary entry points for adversaries. They also need to gain deep visibility into when and how critical data in the cloud is being used so that IT teams can promptly spot potential threats. Finally, they need to be prepared to minimize the damage from incidents by having a comprehensive response strategy that is regularly exercised and updated." To learn more about security trends, check out the complete 2023 Hybrid Security Trends Report. About Netwrix Netwrix makes data security easy. Since 2006, Netwrix solutions have been simplifying the lives of security professionals by enabling them to identify and protect sensitive data to reduce the risk of a breach, and to detect, respond to and recover from attacks, limiting their impact. More than 13,500 organizations worldwide rely on Netwrix solutions to strengthen their security and compliance posture across all three primary attack vectors: data, identity and infrastructure.

Read More

Cloud Storage

TRG Screen Announces Acquisition of Xpansion for Reference Data Usage Management

PR Newswire: | January 25, 2024

TRG Screen, the leading provider of enterprise subscription spend and usage management software, today announced it has acquired Xpansion, the leading provider of cloud-based solutions for reference data usage monitoring in the financial services industry. The acquisition of Xpansion will further solidify TRG Screen's position as a global market leader in market data management solutions. Xpansion – established in 2013 – is focused on empowering data operations teams to proactively manage their usage, control costs and optimize data workflows. Xpansion's offerings include Xmon, Xprocess and Xplore, and provide real-time analytics, giving clients unprecedented transparency, visibility and control into their reference data usage. This deal consolidates TRG Screen's unique position as the only provider of enterprise subscription management capabilities spanning the whole spectrum of market data optimization, from spend and inventory tracking, through to usage and enquiry management, exchange reporting and compliance. "Xpansion and TRG Screen have been partners for many years. Bringing Xpansion into the TRG Screen family is a very logical next step for both companies, given our strong relationship and shared view that the industry demand for integrated usage management solutions is going to continue to grow," said TRG Screen CEO Leigh Walters. "Xpansion is an established firm with excellent customer satisfaction and retention, and highly experienced and industry respected leadership. We are very excited at the opportunities this acquisition brings." "We are thrilled to be joining TRG Screen," said Xpansion co-founder and CEO Amjad Zoghbi. "Reference data usage is one of the most complex aspects of market data management, and managing it correctly is essential to maintaining contractual compliance and ensuring clients are right-sizing their usage based on actual consumption and business need. I'm very pleased that Xpansion's customers, and team, will now be part of the best-of-breed solution with the industry's leading provider of market data management solutions." The acquisition demonstrates TRG Screen's ongoing commitment to servicing the needs of market data consumers, vendors and exchanges. Financial terms of the transaction were not disclosed. About TRG Screen TRG Screen is the leading provider of enterprise subscription management solutions. Founded in 1998, TRG Screen is uniquely differentiated by its ability to monitor both spend and usage of data and information services including market data, research, software licenses, consulting and other corporate expenses. TRG Screen's solutions provide its customers with full transparency into their vendor relationships and their subscription spend and usage, enabling them to optimize their enterprise subscriptions. TRG acquired Priory Solutions in 2016, Screen Group in 2018, Axon Financial Systems in 2019, Market Data Insights in 2020, and Jordan & Jordan's Market Data Reporting (MDR) business in 2021 and with these acquisitions is now positioned as the global market leader in the financial, legal, and professional services markets. TRG Screen's product portfolio includes subscription spend, usage, enquiry and compliance solutions. For more information visit trgscreen.com. Follow TRG Screen on LinkedIn, @TRG Screen, and on Twitter, @trgscreen. About Xpansion Xpansion delivers next-generation reference data solutions that empower financial institutions to streamline their reference data operations, reduce costs, enhance data quality, and improve data discovery. With a focus on customer satisfaction, continuous innovation and quick time to value, Xpansion is a trusted partner for financial institutions in the buy- and sell-side as well as solution providers in the industry.

Read More