Samantha Cheh · · 6 min read

The future of work brings new security risks to tackle

In partnership withFastly

Thanks to the pandemic, remote work has very quickly become the norm.

This has led to immense growth in the demand for cloud computing software from companies transitioning their on-premise operations to the digital space. Edge cloud computing in particular saw demand rise as operations enabled by the internet of things became increasingly common.

However, this rapid migration – “three years [of change] in three weeks,” according to Sean Leach, chief product architect at edge cloud platform Fastly – means that some important details don’t get the attention they need. A chief example: data security.

Sean Leach, chief product architect at Fastly / Photo credit: Fastly

“Everybody is in such a hurry that they have not been able to go through the vetting process and the discovery process of figuring out what their security risks are,” Leach says. “That’s one of the most common mistakes we see: not knowing your risks, not knowing your data and assets, and not prioritizing them.”

Shifting the security mindset

In recent years, there has been a shift in the way people think about enterprise security.

That said, most organizations still think that the networks and tools they use at work are gatekeepers – anyone able to access these tools should in theory have clearance to do so. This system relies on what’s known as “perimeter security,” where a company’s data and assets are locked within a closed, internal network that is mainly protected by firewalls.

This works well as long as employees remain in physical offices. Perimeter security isn’t as effective, though, when staff try to access data and assets through off-the-shelf networking tools and vulnerable home Wi-Fi connections. And once the perimeter firewalls are breached, hackers face little to no resistance and can wander around a company’s intranet easily.

Photo credit: Aleksei Gorodenkov

Leach says that in a cloud-first future, enterprises need to adopt a “Zero Trust” approach to the security of their data. This philosophy, pioneered by Google’s BeyondCorp model, assumes that all networks – internal and external – are inherently untrustworthy.

“We’ve seen many attacks and compromises that have happened because of that network-level trust,” he says. That’s why companies need to cultivate an environment where every action is verified and secured with tools like two-factor authentication and passwords, Leach adds.

This is especially important in the case of edge computing cloud platforms, which capture, store, process, and analyze data nearer to where it is generated, instead of in a centralized server. This means it operates on a completely different threat level from standard cloud services because “regionally focused” edge infrastructure may create more vulnerabilities for users, especially those working across multiple cloud systems. However, Leach says those dangers can be offset by cloud providers’ built-in security systems.

For example, one of Fastly’s clients, a major payments provider, wanted to run a centralized security solution across its operations that could be managed through a single control panel.

Through its recent acquisition of web application and API security company Signal Sciences, Fastly was able to combine the company’s web application and API security solutions with its own edge cloud platform and existing security offerings. This allowed Fastly to create a suite of tools that could operate across a client’s various platforms and combine the collected data on a single user interface.

Cloud security

Change is in the air within the security industry itself too. Teams are beginning to leave behind the traditional approach – which relied on building huge databases to track attacker traffic with specific characteristics – in favor of an intent-based model. This approach looks at what goals attackers are trying to achieve instead.

The problem with the old model is that an attacker’s signature can change with alarming speed and frequency, leaving security teams constantly scrambling to keep up. In comparison, intent-based models like Fastly’s focus on monitoring unusual user behavior against historical data in order to highlight what seems out of the ordinary or physically impossible.

“When we take all of those things into account, you can start to find the intent,” Leach says.

The dashboard of Fastly’s platform / Photo credit: Fastly

The model was first established by big names in cybersecurity, such as FireEye, for specific operating systems. Fastly is doing the same thing: providing accessible solutions for web-based applications and APIs.

“We focus on use cases where customers need high-scale latency solutions,” the executive says. “We focus on making those faster, more available, and more secure.”

Planning your protection

For Fastly, the most common mistake it sees among companies trying to digitalize is having too little insight into their risk exposure, says Leach.

“[Companies] spend all this time planning for the most sophisticated hacker group in the world coming after them, and they don’t do the simple stuff,” he notes. “It comes down to knowing what your risk is and, once that’s locked down, then organizations can adequately plan for specific attack types.”

Widespread use of third-party tools like browser extensions, he says, is a major security risk. These can contain malicious code that makes a computer vulnerable to malware or even collect users’ personal information. While extensions can create user-friendly experiences, they must also be consistently audited for security vulnerabilities.

Most companies also tend to put their security functions into silos, treating them and their goals as separate from the rest of the product development cycle. This model – in which developers would only call in security to audit their products after they were done – made teams think that security wasn’t as important as design.

Balancing security with usability

Moving forward, it’s vital that companies are able to engage deeply with the available security technologies. Supply chain attacks like 2020’s SolarWinds virus – where hackers opened backdoors into companies’ internal systems by exploiting a compromised third-party application – will likely become more common as hackers learn from each other and exploit vulnerable enterprise systems.

Luckily, many solutions to new and existing threats already exist. These cloud-based solutions, with built-in security features and edge computing capabilities, make it easy for companies to scale up or down depending on their needs while also cutting out the costs of running a security team.

“What you’re doing is only giving them a small view into your stack,” he says. “It’s much easier to keep this secure, compared to [giving them a larger view].”

If companies are worried about transitioning to cloud infrastructures, however, Leach says Fastly has helped companies do just that without any problems. For one digital radio-streaming company, for instance, using Fastly helped it to migrate its data and applications from a data center to a cloud platform seamlessly, while also providing security detection services during and after the transition.

“By putting us in front of its applications, end-users only ever saw the Fastly infrastructure,” he says. “Behind the scenes, that streaming provider moved its application to the cloud, using us to load-balance the traffic.”

Though Fastly aims to support companies who want to scale fast and efficiently, it’s important to ensure that these goals are balanced against the need for robust security solutions that are sustainable in the long term.

“Everyone always talks about how the tool doesn’t have to be that easy to use as long as it protects, but how do you know it’s working if you’re not showing people what it’s protecting?” Leach posits. “It’s the endless game of protecting but also being user friendly.”


Fastly is a global edge cloud platform that enables companies to create great digital experiences quickly, securely, and reliably. It was recently named a Gartner Peer Insights Customers’ Choice for web application firewalls.

Learn more about how it has revolutionized security solutions in the cloud computing age for some of the biggest internet brands on its website.


This content was produced by Tech in Asia Studios, which connects brands with Asia’s tech community. Learn more about partnering with Tech in Asia Studios.

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

How would you feel if you could no longer use Tech in Asia?

Editing by Winston Zhang, Nathaniel Fetalvero, and Jaclyn Tiu

(And yes, we’re serious about ethics and transparency. More information here.)

Community Writer

Samantha Cheh

Hey there. My name is Samantha and I’m currently living in Kuala Lumpur. My skills include, but are not limited to: Copywriting & Editing, Writing, and Technical Writing.