Skip to content
  • Accueil
  • Explorer les pages
  • Stratégie de cyber-résilience pour les environnements hybrides

Stratégie de cyber-résilience pour les environnements hybrides

Why hybrid infrastructure poses heightened risk – and how to build a cyber resilience framework to protect yours.

Vue d’ensemble

Assurer la continuité des activités et une Recovery rapide

In a dangerous and unpredictable world, a cyber resilience strategy is your organization’s digital survival kit. Designed to for rapid recovery and business continuity following a cyberattack – and to prevent such incidents in the first place – the right cyber resilience framework can turn potential catastrophes into momentary inconveniences. But first, you have to address the unique cyber resilience challenges that hybrid environments pose.

We’ll explain how to build and implement an effective cyber resilience framework to keep your hybrid environments up and running for your business.

definition

Comprendre les environnements hybrides

To understand what makes cyber resilience difficult to achieve in hybrid infrastructure, let’s first take a closer look at those environments. In a hybrid IT strategy, the organization uses a mix of on-premises and cloud-based solutions to develop and deploy applications, run workloads, store data, and deliver services. In one common version, legacy applications remain in the datacenter while DevOps teams build new applications in the cloud. In other cases, IT may decide to migrate some or all existing on-premises applications to a cloud provider’s infrastructure, or even rebuild them entirely as cloud-native versions. Companies can also choose to leverage cloud providers’ services for IT and security functions traditionally handled locally, such as software-defined networking, detection and response, and serverless computing.

A hybrid IT strategy offers considerable advantages – especially around flexibility and agility. Organizations can répartir stratégiquement leur infrastructure informatique entre différents environnementsen fonction des besoins spécifiques de chaque charge de travail ; par exemple, en hébergeant sur site les applications critiques ou les données soumises à une réglementation stricte, tout en tirant parti du cloud pour d’autres charges de travail.

L’évolutivité peut être quasi instantanée sans qu’il soit nécessaire de provisionner du matériel supplémentaire, et les ressources peuvent être facilement transférées d’un site à l’autre pour optimiser les performances et la disponibilité. Le coût est également un facteur clé, car les organisations passent d’investissements en capital onéreux, d’une maintenance sur site et de cycles de renouvellement sans fin à des ressources entièrement gérées à la demande.

However, the cloud presents a number of drawbacks as well. Foremost is complexity, as IT teams work to manage and integrate disparate systems across on-premises and cloud platforms. An expanded attack surface – much of it inaccessible within the cloud provider’s own infrastructure – increases the potential for security incidents. That’s especially true given the gaps in security controls that can come with a decentralized infrastructure. Depending on your industry, cloud resources can introduce major regulatory headaches, and simply won’t be an option for some types of data and applications.

You’ll notice that several of these drawbacks are related to security and risk. That brings us to cyber resilience.

Gestion des risques

Utiliser les cadres de cyber-résilience pour réduire les risques

Whatever type of infrastructure a business uses – on-premises, all-cloud, or hybrid – building cyber resilience takes more than throwing together an assortment of security measures. To enable coherent protection and preparation across every part of the environment, mature organizations adopt a cyber resilience framework spelling out a comprehensive approach to managing cyber risk. The best practices detailed in these frameworks can help you minimize disruptions, protect your reputation, align with regulatory requirements, and stay agile in the face of evolving threats.

Parmi les cadres bien établis destinés à guider les organisations dans le renforcement de leur cyber-résilience, on peut citer :

• NIST Cybersecurity Framework – A set of requirements organized around five core functions: identify, protect, detect, respond, and recover.

• MITRE Cyber Resilience Engineering Framework (CREF) – Specific resilience techniques like adaptive response, deception, and dynamic positioning.

• UK Cyber Assessment Framework (CAF) – 14 principles supporting four primary objectives: managing security risk, protecting against cyberattacks, detecting cybersecurity events, and minimizing incident impact.

De tels cadres constituent un point de départ essentiel pour élaborer votre propre stratégie de cyber-résilience. Cependant, leur mise en œuvre dans un environnement hybride présente un certain degré de difficulté.

Défis

Les défis liés à la cybersécurité dans un environnement hybride

L’approche de la cyber-résilience peut s’avérer plus simple dans un environnement informatique entièrement virtualisé ou sur site. Mais dans un environnement hybride, la cyber-résilience devient particulièrement difficile en raison de la diversité des technologies sur site et dans le cloud utilisées. Les équipes de sécurité doivent désormais tenir compte :

• Increasing complexity – With resources spread across multiple environments, there are more potential entry points for attackers. Cloud services and on-premises systems may call for different security measures, making it harder to take a holistic approach to protection.

• Data movement and access – In hybrid environments, data flows constantly between systems and cloud platforms, often over public networks. Secure data transfer and consistent access management are mission-critical.

• Visibility and monitoring – Gaining a complete, unified view of systems and data across on-premises and cloud-based resources is anything but simple. To identify anomalies and potential threats, SecOps teams have to correlate data from multiple sources, environments, and tools.

• Incident response and recovery – Incident response plans have to account for both on-premises and cloud-based components. Enabling consistent and rapid data recovery across diverse environments takes careful planning and specialized tools.

• Compliance and governance – On-premises and cloud data can fall under different regulations, adding to the compliance burden. In many industries and regions, data security and data sovereignty requirements place strict rules on where data may be stored and processed.

• Flexibility and scalability – Shifting workloads between on-premises and cloud environments can alter security requirements. Your cyber resilience strategy has to be able to keep pace.

Entreprise hybride

Élaborer une stratégie de cyber-résilience pour une entreprise hybride

With these factors in mind, we can break down the key elements of a cyber resilience strategy – including special considerations for hybrid environments.

• Risk Assessment
Risk assessment focuses on identifying and evaluating potential threats and vulnerabilities. By analyzing their likelihood and impact, you can prioritize resources and effort where they’re most urgently needed. In a hybrid environment, this begins with taking a comprehensive inventory of all assets, both on-premises and in the cloud, including physical hardware, machines virtuelles, cloud services, and data repositories. You’ll also need to evaluate the risks associated with data movement between environments, including the potential for inconsistent security controls across platforms and any differences in compliance between local and cloud-hosted data.

Les tests de sécurité constituent un élément clé de l’évaluation des risques ; ils vous aident à comprendre dans quelle mesure vos données sont protégées contre divers types de menaces. Les tests d’intrusion peuvent aider à identifier les vulnérabilités des systèmes, des réseaux et des applications avant qu’elles ne puissent être exploitées par des attaquants. L’IA peut vous aider à automatiser certains aspects des tests de sécurité, tels que l’analyse des vulnérabilités, et à analyser les résultats des tests d’intrusion afin d’identifier des schémas et des tendances.

• Prevention
Prevention takes the form of proactive measures and defensive technologies to stop potential attacks across your diverse environments. This includes deploying robust security controls such as firewalls, intrusion prevention systems, and encryption for both on-premises and cloud-based assets. A unified identity and access management (IAM) system that works seamlessly across platforms can support zero trust by enforcing the principle of least privilege across all your resources wherever they reside. Network segmentation, another element of zero trust, is more complex in a hybrid environment – but no less critical.

Pour combler rapidement les failles de sécurité, les équipes informatiques doivent veiller à coordonner l’application des correctifs et des mises à jour sur l’ensemble des systèmes, même lorsque cela implique des processus différents pour les infrastructures sur site et dans le cloud. Une gestion sécurisée des configurations sur l’ensemble des composants de votre environnement hybride peut aider à vérifier que les niveaux de sécurité de base sont maintenus de manière cohérente.

• Detection
Detection in a hybrid environment calls for a unified approach to monitoring and threat intelligence across on-premises and cloud infrastructures. You’ll need an advanced security information and event management (SIEM) system capable of collecting and correlating data from diverse sources, including on-premises servers and network devices as well as cloud services.

Les algorithmes de détection des anomalies qui sous-tendent vos contrôles de sécurité devront être suffisamment sophistiqués pour comprendre les modèles de comportement normaux sur l’ensemble de votre infrastructure hybride, y compris les changements soudains tels que le comportement d’auto-scaling dans le cloud. La surveillance continue doit mettre l’accent sur les mouvements de données ou les modèles d’accès inhabituels entre les environnements sur site et cloud. Une infrastructure hybride nécessite également des outils de détection et de réponse au niveau du réseau et des terminaux (NDR/EDR) capables de fonctionner efficacement dans ces deux types d’environnements.

• Response
Response strategies in a hybrid environment need to be agile and coordinated across all infrastructure components. To prevent organizational silos from impeding resilience, incident response plans should clearly define roles and responsibilities for team members dealing with both on-premises and cloud-based incidents. These plans must account for the potential complexity of containing threats that may move between different environments.

À mesure que vous développez et renforcez vos capacités de réponse, assurez-vous que vos outils fonctionneront de manière transparente d’un environnement à l’autre. Par exemple, les fonctionnalités de réponse automatisée peuvent accélérer la remédiation, mais surveillez de près la manière dont elles interagissent avec les différentes parties de l’infrastructure hybride. Les outils et procédures d’analyse forensic doivent être adaptés pour collecter et analyser les preuves provenant à la fois des environnements physiques et virtuels.

• Recovery
Recovery – restoring operations and data following an incident – can be an especially delicate matter in a hybrid environment. You’ll need the ability to back up and restore data quickly and securely regardless of its original location, which may involve cross-platform data migration tools. Recovery plans should prioritize critical business functions and consider dependencies between on-premises and cloud services. Testing recovery procedures regularly is crucial, simulating scenarios that affect different parts of the hybrid infrastructure.

Le cloud offre en effet certains avantages facilitant la Recovery, tels que la possibilité de basculer vers des services cloud si les systèmes sur site sont compromis, ou inversement.

• Testing
When an incident occurs – not if – you don’t want your security and IT teams to be overwhelmed by the complexity of incident response in a hybrid environment. Regular testing of your security controls, including penetration tests, will mettre au jour d’éventuelles vulnérabilités et contribueront à améliorer votre Readiness. Des exercices sur table et des simulations d’attaques permettront d’identifier les lacunes de votre plan de réponse aux incidents et de vérifier que tous les membres de l’équipe comprennent bien leurs rôles. Le plan doit également inclure des procédures d’analyse post-incident afin de tirer les leçons de chaque événement et d’améliorer les réponses futures.

• Adaptation
Cyber resilience is an ongoing process, not a moment in time. You’ll need to continuously assess and evolve your strategy and security measures to address new threats and changes to your infrastructure, applications, and data storage strategy. This can include adopting new cloud security tools, updating on-premises security measures, or implementing new integration strategies between the two.

Les renseignements sur les menaces peuvent vous aider à ajuster vos défenses de manière proactive en comprenant comment de nouveaux vecteurs d’attaque pourraient exploiter les caractéristiques propres à votre environnement hybride. Vous devez également favoriser une culture d’amélioration continue, en encourageant les retours d’expérience des équipes de sécurité et en intégrant les leçons tirées des incidents afin de renforcer la résilience globale.

• Employee Training
A key but often overlooked element of any security strategy, employee training in a hybrid environment is critical to maintain cyber resilience across diverse platforms. Your programs should cover security best practices for both on-premises and cloud-based systems, including how to securely access and handle data across different environments by using VPNs, multi-factor authentication, and secure file sharing methods.

In a zero-trust environment, employees need to understand why they may be required to repeatedly authenticate themselves. Phishing awareness training should include scenarios specific to hybrid environments, such as recognizing attempts to steal cloud credentials. Regular simulations and exercises should be conducted to test employees’ ability to identify and respond to threats in both on-premises and cloud settings. IT and security staff should receive specialized training on managing and securing hybrid environments.

Mise en œuvre

Capacités clés pour la mise en œuvre de votre plan de cyber-résilience hybride

Si la cyber-résilience repose sur des contrôles de sécurité complets, certaines capacités clés revêtent une importance particulière dans les environnements hybrides.

• On-demand Cleanrooms
Isolated, malware-free environments will allow you to test recovery processes, conduct forensic analysis, and perform actual recoveries as part of a cyber resilience strategy. Delivered on-demand, these cleanrooms offer un accès rapide à des espaces contrôlés sans nécessiter d’infrastructure dédiée coûteuse. Cette fonctionnalité est particulièrement précieuse pour les configurations hybrides, car elle fournit un espace sûr et évolutif, distinct des environnements de production sur site et dans le cloud.

• Continual Recovery Testing
The dynamic and complex nature of hybrid environments makes continual, automated testing essential. By validating your ability to recover critical systems and data across both on-premises and cloud infrastructures, you can identify gaps in recovery processes, maintain the integrity of backed-up data, and build confidence in your ability to respond to cyber incidents.

• Unified Monitoring and Threat Detection
Silos and proliferating screens can slow response and impair understanding. Analysts need a comprehensive monitoring solution that incorporates advanced SIEM, anomaly detection, and threat intelligence across on-premises and cloud environments. With effective visibility across your entire hybrid infrastructure, security teams can quickly identify potential security incidents, correlate events from different sources, and respond to threats more effectively.

• Automated Response and Orchestration
Automated incident response capabilities that work across hybrid environments can significantly reduce response times and minimize the impact of cyberattacks, regardless of where an incident originates. This includes automated containment measures, orchestrated recovery processes, and integration with both on-premises and cloud-based security tools.

• Secure data Backup and Recovery
Robust backup and recovery solutions designed for hybrid environments are essential. These should include features like air gapping, l’immuabilitéet le chiffrement afin de protéger les sauvegardes contre toute altération ou corruption. La capacité à restaurer rapidement les données et les systèmes, que ce soit dans des environnements sur site ou dans le cloud, offre une flexibilité dans les options de Recovery et contribue à maintenir la continuité des activités.

Building cyber resilience in a hybrid environment can seem daunting, and for good reason. But by focusing on the core principles of cyber resilience, and understanding how they apply in a more complex, dynamic, and diverse hybrid infrastructure, security and risk management leaders can develop and implement the right strategy to enable continuous business. It takes work – but for the organization, it can mean the difference between life and death.

Ressources connexes

Découvrez les ressources associées

Solution Brief

Pourquoi opter pour la cyber-résilience dans le cloud hybride ?

Commvault has several options for backup storage to help customers meet their RPO and RTO objectives.
En savoir plusabout Pourquoi opter pour la cyber-résilience dans le cloud hybride ?
Solution Brief

Cyber Recovery for Any Cloud, Any Workload, Anywhere Guide

Navigating the challenges of hybrid cloud.
En savoir plusabout Cyber Recovery for Any Cloud, Any Workload, Anywhere Guide