![]() |
You’ve just launched your new Modern Marketing Platform in the cloud. However, there are several potential problems that marketing teams may not consider when creating a new digital infrastructure in the cloud. I’m not referring to the websites set up for online banking or strictly for transactions, I’m talking about the web platforms that are built by the rest of us. First, cybersecurity is not the chief priority when we (marketing) put our new digital marketing infrastructure together, which means we may be exposed in ways that we haven’t even begun to imagine. So while we are thinking about data use policies, opt-ins, and progressive profiling – we weren’t thinking about the possibility of this whole thing being potentially breached. If it hasn’t been pressure tested after all the services and apps have been bolted together, as far as we know, it could be a security hot mess. Second, no one really has our backs. Let me digress and provide a crash course in cybersecurity for non-technical marketing people, so this point can sink in.
Cut back to marketing. So here we are, merrily skipping through the tulips, to launch a new global campaign. We are so focused on the thing in front of us, we unknowingly just created an entire marketing system that has all the same vulnerabilities as the company’s core systems, but we have done it in a silo, outside of what our IT security teams are protecting (shadow IT). Our hearts were in the right place but it doesn’t make us awesome. Furthermore, even for a company with a dedicated security operations team, the biggest security blind spot is typically monitoring web, mobile, and social applications beyond core systems and outside the traditional perimeter. Yep, all the stuff you use. Don’t take my word for it, get a meeting with your CSO or head of IT Security and ask them about the access protection and management strategies they use, or what the limitations of their security incident & event management systems are…not only will you sound really smart, their answers will fascinate you. This is the problem. Your IT security team is probably not monitoring a good portion of your modern marketing infrastructure and if they are, they most likely don’t have the tools in place to best look after it end-to-end, or to fully consider the way you are using it and the way hackers would be cracking it. Enterprises have spent millions of dollars on security technology, yet, 80% still reported breaches in the last year, based on a new report that came out from KPMG, as reported by Dark Reading. While the individual big cloud applications might have gone through a security audit individually, (let’s assume the Marketing Cloud, CRM system, marketing automation system or web CMS came back solid in an audit), vulnerabilities still exist in the interfaces (APIs) that connect these tools with all the other add-ons tools you bought from other vendors who may be in various stages of cloud or security maturity. So now, you have tools that have not been vetted, connected with trusted tools that may be connected to sensitive information. Essentially, this is a hacker’s dream scenario and your security organization’s biggest nightmare. Leaving your security team or IT counterparts out of the loop on how you are setting up your infrastructure in the interest of going fast is tempting, but not worth it. And if you get hacked, maybe, it’s nobody else’s fault, so don’t do it. Looking for details about managing communications about data breaches? Visit the blog post, Planning for a Breach Crisis, for more information. The post Is Your Modern Marketing Cloud Infrastructure Vulnerable to Cyber Attacks? appeared first on Speaking of Security - The RSA Blog. |
