Info Snapshot, sponsored by Fortinet
JANUARY 2024
Going Native: How European
Security Leaders Are Using
Cloud to Better Manage Risk
Dave Clemente
Research Director,
European Security
Cloud adoption is growing across Europe as organizations A rigorous approach is needed to securely harness the
of all sizes in all industries take advantage of the speed, full benefits of cloud, and security leaders are focusing on
agility, and disruptiveness it offers. three key principles to optimize cloud security operations,
In response, security leaders must adapt the way they improve service delivery, and support executives with
strengthen resilience, manage costs, find talent, maintain strategic business objectives. These principles are:
regulatory compliance, and thwart attackers. They must
consider how to achieve consistent security policies across
both their cloud and on-premises deployments, as hybrid 1. Dedicate Time to DevSecOps
cloud is a reality for many organizations.
Security leaders are investing in collaboration
The good news is that a majority of security leaders believe between development, security, and operations
security in the public cloud can be as effective as — or (also known as DevSecOps). IDC research
more effective than — on-prem security (see below).
shows this practice improves innovation;
Even better news is that organizations taking a platform
enhances collaboration between security, IT, and line of
approach can achieve effective security while reducing
operational complexity, no matter where their applications business; and increases revenue per customer through
may live across their hybrid cloud environments. faster time to market.
Cloud underpins the DevSecOps mantra of “continuous
Q: What best describes your organization’s stance
everything,” be that collaboration, integration, deployment,
on security in the public cloud (IaaS, PaaS, and SaaS)
testing, or monitoring. Cloud also allows DevSecOps
compared with security that can be delivered in on-
premises environments?1 teams to run the development process more efficiently. For
66% example, dissatisfaction with internal developer platforms
(IDP) has led to shadow app development at 50% of
organizations surveyed by IDC.2
This shadow development creates real security risks that
0% 20% 40% 60% 80% 100%
cloud-native solutions can help to mitigate. In a world with
Don’t know Less effective As effective “always on” customer expectations, organizations must
produce software and applications that are secure from
More effective
Day 1.
The first step is investing in security that is designed for
the cloud, or cloud-native. This offers greater levels of
1
Source: IDC’s European Security Technologies and Strategies Survey 2023
efficiency, scalability, and resilience and provides a solid (n = 700)
foundation for future digital business opportunities and 2
Source: DevSecFinOps — the New World of Collaboration: Key Insights from
market offerings. IDC’s European DevOps Summit (IDC #EUR151378723, December 2023)
© IDC 2024
Going Native: How European Security Leaders Are Using Cloud to Better Manage Risk
2. Prioritize People 3. Build on Platforms
Security technology often makes the headlines, Security leaders are focusing on reducing
but people remain the most valuable resource. complexity by eliminating overlapping products
However, talent is scarce and security leaders and investing in partners who offer integrated
regularly highlight the impact of skill shortages.3 and complementary solutions. This “platform
approach” is winning out over the earlier “best of breed”
approach, where buyers chose security solutions that were
Q: To what extent do challenges in lack of skills limit your
individually strong but not well-integrated with adjacent
organization’s cybersecurity capabilities?3
products. Platform solutions – whether cloud-hosted, cloud
native, or on-premises — offer security teams inherently
greater simplicity, flexibility, and agility for securing cloud
32% 18% environments.
Q: When selecting an IT security provider for your organization,
what are the primary vendor selection criteria?5
Best of platform
77%
Most cost effective
49%
25%
Fits with existing security environment
Low/No challenges Moderate challenges
23%
High challenges
Familiarity with vendor
18%
This shortage is particularly acute in cloud security, and in Best of breed
response, many organizations are pulling together internal 17%
expertise and creating a cloud center of excellence (CCoE)
to design and implement best practices, guidelines, and
governance policies. Expertise within a CCoE comes from
Go Further, Together
integrating technical specialists, financial analysts, legal European security leaders clearly want the efficiency and
and compliance, and HR – and, of course, security. simplicy of platform solutions, but they cannot do it alone.
Close partnerships are needed to reduce complexity,
Business leaders recognize the benefits of CCoEs. When
extend the reach of their security teams, and enable the
asked about their main reasons for establishing a CCoE,
business to move faster with confidence.
the top response was “ensuring security”.4 Security
leaders must take advantage of this broad support for 3
Source: IDC’s Europe CISO Survey 2023 (n = 400)
CCoEs to improve security maturity in other lines of 4
Source: IDC’s CloudOps Survey 2023 (n = 691)
business and nurture the development of future security 5
Source: IDC’s European Security Technologies and Strategies Survey 2023
talent across the organization. (n = 700)
Message from the Sponsor
Discover how Fortinet shapes its Cloud Vision to help organizations achieve
theirs with Fortinet CMO and EVP, John Maddison.
Watch the video
Over 705,000 organizations worldwide trust Fortinet for its AI-driven platform,
open ecosystem, innovation, and sustainability. Contact your local Fortinet team
to see how you can innovate to secure people, devices, and data everywhere.
Info Snapshot, sponsored by Fortinet
January 2024 | IDC #EUR251780224
@idc @idc [Link]
© 2024 IDC Research, Inc. IDC materials are licensed for external use, and in no way does the use or publication of
IDC research indicate IDC’s endorsement of the sponsor’s or licensee’s products or strategies. Privacy Policy | CCPA