Securing Your Data in the Cloud: Insights from Cyber Security Expert Jordan Stevens

Jordan Stevens headshot

Jordan Stevens headshot

As more and more businesses and individuals shift their data to the cloud, the importance of robust cloud security has never been greater. With over a decade of experience helping organizations protect their most sensitive information, cyber security expert Jordan Stevens has a wealth of knowledge to share on this critical topic.

The Making of a Cloud Security Leader

Jordan‘s journey in the field began with a degree in Computer Science from MIT, where he developed a keen interest in cryptography and network security. His talent was quickly recognized, and he was recruited out of college by tech giant IBM to join their elite cybersecurity research team.

Over the next several years, Jordan honed his skills working on cutting-edge projects for IBM, as well as stints at security firms Symantec and McAfee. He earned multiple certifications, including CISSP, CISM, and CCSP, and became a sought-after speaker at industry conferences.

In 2010, Jordan decided to strike out on his own, founding Cloud Armor Solutions with a mission to help businesses navigate the complex challenges of cloud data protection. Since then, he and his team have assisted over 500 clients in designing secure and compliant cloud environments, ranging from small startups to Fortune 500 enterprises.

Under Jordan‘s leadership, Cloud Armor has been recognized as one of the top managed security services providers by Gartner for five years running. The company has also developed several patented technologies, including a machine learning-based threat detection system called Stratus.

The State of Cloud Security

The adoption of cloud computing has skyrocketed in recent years. According to research firm Gartner, worldwide spend on public cloud services is forecast to grow 18.4% in 2021 to a total of $304.9 billion, up from $257.5 billion in 2020.

"The cloud has revolutionized the way we store and access data, enabling incredible agility and innovation," Jordan explains. "But it‘s also expanded the attack surface and introduced new risks that organizations must address."

Cloud adoption statistics
Source: Gartner

Some of the most pressing cloud security threats Jordan and his team encounter include:

  1. Misconfiguration – According to Gartner, nearly all successful attacks on cloud services are the result of customer misconfiguration, mismanagement and mistakes. Common issues include over-privileged accounts, exposed storage buckets, and unpatched vulnerabilities.

  2. Credential compromise – Stolen or compromised user credentials are a major risk, allowing attackers to access sensitive cloud data and systems. Techniques like phishing, keystroke logging, and password spray attacks are frequently used to obtain login details.

  3. Insecure APIs – Cloud services often expose APIs for customers and partners to integrate with. However, these interfaces can become a vector for attack if improperly secured. OWASP has identified broken authentication, lack of rate limiting, and code injection as common API risks.

  4. Compliance violations – Organizations in highly-regulated industries face the added challenge of ensuring their cloud usage complies with standards like HIPAA, PCI-DSS, and GDPR. Failure to implement proper controls and documentation can result in costly fines and reputational damage.

  5. Advanced threats – Sophisticated attackers are increasingly targeting the cloud with advanced persistent threats (APTs) designed to infiltrate networks and stealthily exfiltrate data over a long period. These multi-stage attacks can be extremely difficult to detect and contain.

"One of the fundamental issues is the shared responsibility model," Jordan notes. "Securing the cloud is a joint effort between the provider and the customer, but many organizations assume the provider will take care of everything. In reality, the customer is responsible for securing their data, applications, and access within the cloud environment they‘ve provisioned."

Best Practices for Cloud Data Protection

To effectively mitigate cloud risks, Jordan recommends employing a defense-in-depth strategy layering multiple controls:

  • Secure configuration – This starts with carefully vetting cloud service providers and their security posture. Once selected, ensuring all configurations are hardened in accordance with best practices and internal policies. This includes proper network segmentation, access control, logging, and more.

  • Encryption – Data should be encrypted both at rest and in transit using strong, industry-standard algorithms (like AES-256). Proper key management is critical to ensure data remains protected. Many cloud providers now offer native encryption options that simplify this process.

  • Strong authentication – Multifactor authentication (MFA) should be enforced for all user accounts to prevent unauthorized access even if a password is compromised. Single sign-on (SSO) solutions can help streamline authentication across cloud and on-premises applications.

  • Continuous monitoring – Cloud environments are highly dynamic, requiring constant vigilance for issues like configuration drift, unusual user behavior, and network anomalies. Cloud native tools like AWS GuardDuty and Azure Security Center can help automate threat detection.

  • Employee training – With social engineering on the rise, employees are often the weakest link in cloud security. Regular security awareness training is essential to educate users on spotting phishing attempts, proper password hygiene, and secure remote work practices.

  • Incident response – Even with robust preventative measures in place, breaches can still occur. Having a well-defined incident response (IR) plan is critical for quickly containing incidents, mitigating damage, and restoring normal operations. This should include clear roles and communication channels.

"Securing the cloud is a continuous process, not a one-time project," Jordan stresses. "As new features and services are added, you must assess the potential risks and adjust your controls accordingly. Proactive management is really the name of the game."

Compliance in the Cloud

For organizations beholden to regulatory frameworks, the cloud introduces some unique compliance challenges. The shared responsibility model means customers must ensure their portion of the stack meets all relevant requirements. This is in addition to any industry-specific mandates.

"Compliance in the cloud is a huge focus area for our clients, especially those in healthcare, financial services, and government," says Jordan. "The key is really to bake compliance into your cloud strategy from the start, not treat it as an afterthought."

Some key compliance considerations include:

  • Verifying cloud provider has necessary certifications (e.g. FedRAMP, FIPS, HITRUST)
  • Contractual requirements around data ownership, sovereignty, and disposition
  • Implementing controls for user access, data protection, logging and monitoring
  • Ensuring audit reports and documentation are available

Failure to comply can be costly. For example, violating HIPAA can incur fines up to $50,000 per violation, with an annual maximum of $1.5 million. Under GDPR, fines can be as high as €20 million or 4% of a firm‘s global annual revenue, whichever is greater.

"We always advise clients to work closely with their legal and compliance teams to classify data and map out all requisite controls before migrating to the cloud," Jordan notes. "You must also have processes to continuously monitor adherence and adapt as regulations evolve."

The Future of Cloud Security

Looking ahead, Jordan sees several exciting technologies and trends reshaping cloud security:

  • AI and machine learning are becoming indispensable for analyzing vast volumes of security telemetry to swiftly identify and respond to threats. Capabilities like user and entity behavior analytics (UEBA) can model normal activity to flag risky deviations in real-time.

  • Zero trust security is displacing traditional perimeter-based models as organizations embrace more distributed, cloud-centric architectures. Zero trust assumes that no user, device, or network should be inherently trusted, requiring continuous verification of all access attempts.

  • Confidential computing enables processing of encrypted data in memory to protect against insider threats and malicious admins. Secure enclaves like Intel SGX create trusted execution environments, keeping sensitive data shielded even from the underlying infrastructure.

  • Quantum-resistant cryptography, while still an emerging field, will become crucial for protecting cloud data from threat actors with access to quantum computers. NIST is currently evaluating several quantum-safe algorithms that could become new standards.

"I‘m really excited about the convergence of cloud and edge computing," Jordan adds. "As 5G and IoT fuel the growth of intelligent edge devices, we‘ll see more demand for light-weight, scalable security solutions that can operate with minimal connectivity. Techniques like federated learning allow for decentralized AI that preserves data privacy."

Parting Advice

For organizations looking to elevate their cloud security posture, Jordan offers this guidance:

  1. Develop a comprehensive cloud security strategy aligned with business objectives
  2. Implement a cloud security posture management (CSPM) tool for unified visibility
  3. Use a secure access service edge (SASE) platform to enable zero trust access
  4. Leverage infrastructure as code (IaC) to automate secure cloud deployments
  5. Partner with a cloud managed security services provider (MSSP) for specialized expertise

"Cloud security is a journey, not a destination," Jordan reflects. "There‘s no such thing as 100% secure, but by continually assessing your risks and adjusting your controls, you can run a dynamic, resilient cloud program. It takes vigilance and collaboration from all stakeholders – security, IT, development, business leadership. But the benefits of the cloud are well worth the effort."

With evangelists like Jordan Stevens showing the way, organizations can confidently harness the power of the cloud while safeguarding their most valuable data assets. The future of cybersecurity is in the cloud, and it‘s never been brighter.

For more expert insights from Jordan, visit the Cloud Armor Solutions blog.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

Similar Posts