1 of 17

Enhancing the Security Posture of Existing Cloud Deployments

2025 Cloud Forum @ NYU

John Bailey

Asst. Director, Cloud Systems, WashU IT

jwbailey@wustl.edu

2 of 17

The Challenge

  • WashU provides a “cloud enablement” service that allows customers to deploy their own cloud infrastructure with few restrictions.
  • This approach means that we have many cloud accounts and a broad spectrum of cloud resources.

Gain visibility into our cloud workloads

3 of 17

Example Questions

  • “How many EC2 instances do we have with public IP addresses?”
  • “How many cloud endpoints are impacted by the vulnerability I just read about?”
  • “Do we have any protected data accidentally accessible to the public?”
  • We are concerned about a particular cloud resource – who owns it?”

We want to be able to readily answer for our executives

4 of 17

Goals

  • Have an always up-to-date inventory of all cloud resources and their attributes.
  • Identify and rank security risks.
    • Misconfigurations.
    • Vulnerabilities.
    • Public exposures of data.
    • Combinations of the above.
  • Reduce the risk of a security incident involving our cloud infrastructure.

We will succeed when we…

5 of 17

Selection Process

  • Start with existing partners who work in this space:
    • Microsoft.
    • Palo Alto.
    • Cisco.
    • CrowdStrike.
  • Identify additional candidates based on research, peer recommendations, etc.:
    • Wiz.
    • Orca.
    • Others.

Identify candidate companies

6 of 17

Selection Process

  • Once the project team gathered requirements from senior leadership, those were developed into a series of questions we would ask vendors to respond to.
  • 10 sections, 5-10 questions each.
  • Weighted some sections more heavily than others to reflect their importance.

Gather requirements, translate into questions and scoring criteria

7 of 17

Selection Process

  • This was a terribly boring, tedious process.
  • 8 reviewers across multiple teams (Infrastructure, Security, etc.)
  • Leveraged our WorkDay RFP tool to combine scores and produce an initial rank.

Send out RFP, review responses

8 of 17

Selection Process

  • Held live demos with top 3 candidate companies / tools.
  • Wiz, CrowdStrike, Orca.

Live Demos

9 of 17

Selection Process

  • Full proof-of-concept effort.
  • 1 project, 2 candidates: Wiz, Orca.
  • Connected both to production cloud environment simultaneously.
  • 30-day POC window, access to dashboards removed during vendor negotiations.

Proof of Concepts

10 of 17

Deployment

  • Selected winning vendor (Orca.)
  • Ran de-provisioning scripts to remove all resources and IAM access for Wiz tools.
  • Re-enabled our POC Orca tenant and it became our production tenant.
  • Built-out SSO, onboarded additional teams.

Lightning fast

11 of 17

Rollout

  • Audit mode only – no enforcement (for now.)
  • Passive scanning – one of the key reasons we selected Orca:
    • No agent deployment to endpoints.
    • API-based scanning of resources.
    • Data classification done by scanning temporary snapshots of block and object storage resources.
    • No additional load placed on existing resources.

Without breaking your customer’s cloud workloads

12 of 17

Key capabilities

  • Search by:
    • IP address.
    • Vulnerability name.
    • Cloud account.
    • Network name.
    • CVE.
    • Anything else.

Global search

13 of 17

Key capabilities

  • Allows us to focus limited resources on the riskiest cloud misconfigurations / vulnerabilities.
  • Risk score considers multiple factors:
    • Public facing.
    • Sensitive / protected data.
    • Known vulnerability.
    • IAM misconfiguration.
    • Many more.

“Alert” ranking

14 of 17

Key capabilities

  • Understand blast radius of a compromise
  • Understand attack paths.

Map dependencies

15 of 17

What’s Next?

  • Rolled out weekly email communication process with Office of Information Security to notify cloud account owners of critical risks.
  • Proactively identifying cloud hosted VMs not in compliance with security standards.

Process maturation

16 of 17

What’s Next?

  • Starting with new accounts, then carefully moving onto existing accounts:
    • Disable access to non-HIPAA approved services for accounts that will store and process PHI.
    • Block public-access to object storage if protected data is detected (will include exception process for false positives.)

Policy enforcement

17 of 17

Questions & Discussion