Expel MDR for Kubernetes addresses three core layers of Kubernetes applications: configuration, control panel, and run-time security. Credit: shutterstock Security operations provider Expel has announced the general availability of Expel managed detection and response (MDR) for Kubernetes. The firm said the product enables customers to secure their business across their Kubernetes environment and adopt new technologies at scale without being hindered by security concerns. It has also been designed to align with the MITRE ATT&CK framework to help teams remediate threats and improve resilience, Expel added.Kubernetes is an open-source orchestration system that relies on containers to automate the deployment, scaling, and management of applications, usually in a cloud environment. Over time, it has become the de facto operating system of the cloud, but can also pose significant security risks and challenges for businesses.Expel MDR for Kubernetes addresses configuration, control panel, run-time securityExpel MDR for Kubernetes enables teams to quickly detect and respond to security risks in their Kubernetes environments without slowing down DevOps, enabling organizations to focus more on the priorities that matter most to the business, the company said in a press release. The offering provides insights across three core layers of Kubernetes applications: configuration, control panel, and run-time security. These include:Identification of cluster misconfigurations to help businesses stay ahead of pervasive misconfigurations, with reference to the Center for Information Security (CIS) Kubernetes benchmark for best practices to recommend configuration improvementsIntegration with Amazon Elastic Kubernetes Service (EKS) and Google Kubernetes Engine (GKE) infrastructure, analyzing Kubernetes audit logs, applying custom detection logic to malicious or interesting activity, and providing remediation recommendationsIntegration with a portfolio of run-time container security vendors to provide customers more value from the tech they already useExpel MDR for Kubernetes also aligns to the MITRE ATT&CK framework, providing Expel-written detections that learn and adapt based on activity in the environment, helping customers address Kubernetes threats and apply best-practices to track Kubernetes security posture over time, Expel said. Expel MDR for Kubernetes is available now. Organizations face significant Kubernetes security challengesRedhat’s 2022 State of Kubernetes security report highlighted the biggest Kubernetes security threats and challenges impacting businesses, based on survey results from more than 300 DevOps, engineering, and security professionals. It discovered that 93% of respondents experienced at least one security incident in their Kubernetes environments in the previous 12 months, sometimes leading to revenue or customer loss. A combination of likely contributing factors was cited, including a lack of security knowledge about containers and Kubernetes, inadequate or unfit security tooling, and central security teams unable to keep up with fast-moving application development teams.Detected misconfigurations was the top security incident cited (53%), followed by major vulnerabilities (38%), runtime incidents (30%), and audit fails (22%). The report also highlighted stark discrepancy over which operational roles primarily own Kubernetes security, with just 16% of respondents able to identify the central IT security team to hold responsibility for Kubernetes security. In 2021, the US National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint document entitled Kubernetes Hardening Guidance to help organizations deal with security in a containerized environment, which is more complex than traditional, monolithic software platforms. Related content news Multibillion-dollar cybersecurity training market fails to fix the supply-demand imbalance Despite money pouring into programs around the world, training organizations have not managed to ensure employment for professionals, while entry-level professionals are finding it hard to land a job By Samira Sarraf Oct 02, 2023 6 mins CSO and CISO CSO and CISO CSO and CISO news Royal family’s website suffers Russia-linked cyberattack Pro-Russian hacker group KillNet took responsibility for the attack days after King Charles condemned the invasion of Ukraine. By Michael Hill Oct 02, 2023 2 mins DDoS Cyberattacks feature 10 things you should know about navigating the dark web A lot can be found in the shadows of the internet from sensitive stolen data to attack tools for sale, the dark web is a trove of risks for enterprises. Here are a few things to know and navigate safely. By Rosalyn Page Oct 02, 2023 13 mins Cybercrime Security news ShadowSyndicate Cybercrime gang has used 7 ransomware families over the past year Researchers from Group-IB believe it's likely the group is an independent affiliate working for multiple ransomware-as-a-service operations By Lucian Constantin Oct 02, 2023 4 mins Hacker Groups Ransomware Cybercrime Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe