As enterprise applications and data become increasingly distributed across public clouds, data centers, edge locations, and on-premises environments, maintaining consistent security becomes more challenging. Each environment may have different workloads, connections, and access requirements, yet they all need to remain securely managed.
This is one of the defining characteristics of distributed cloud, where cloud services and infrastructure can be deployed across multiple locations while remaining centrally managed. For enterprises, this model provides the flexibility to place applications and workloads where they best fit business and operational requirements.
However, a more distributed infrastructure also means more areas to protect. There is no longer a single network perimeter that can serve as the primary security boundary. If an attacker manages to compromise one endpoint, they may look for ways to reach other workloads, applications, or data that remain accessible.
That makes distributed cloud security a broader challenge than simply securing the network. Enterprises need multiple layers of protection that can limit attacker movement, control access based on identity, secure applications and APIs, and keep critical data recoverable when an attack gets through.
Why Is Distributed Cloud Architecture Vulnerable to Ransomware and Lateral Movement?
In traditional security models, internal networks are often treated as more trusted once a user or device has passed through the network perimeter. Maintaining that model becomes increasingly difficult as applications and data span multiple environments.
An application running in a distributed cloud may communicate with databases, APIs, services, and other workloads located in different places. As connectivity grows, so does the number of paths that attackers could potentially exploit.
The risk becomes more serious when an endpoint or workload is compromised. Attackers may attempt to move from one resource to another in search of higher privileges or valuable data. This activity, known as lateral movement, is a common component of ransomware attacks.
Strengthening the perimeter alone cannot stop this type of movement. Organizations also need to control what users, devices, and workloads can access after they have gained entry.
This is where Zero Trust principles come into play, where every access request needs to be verified, and each resource should only be reachable when it is actually required.
Limiting Lateral Movement with AI-Powered Microsegmentation
One way to prevent ransomware lateral movement is to restrict communication between workloads through microsegmentation.
Think of an internal network as a collection of rooms with different access rules. An application server may only need to communicate with specific databases and services. There is no reason for unrelated workloads to have the same communication paths. Microsegmentation applies this principle digitally by creating more granular access controls between workloads.
Akamai Guardicore Segmentation helps security teams understand how applications and workloads interact through continuous discovery, application dependency mapping, and traffic visibility. This information helps identify which communications are necessary and which should be restricted.
The latest Guardicore capabilities also use AI to understand application behavior, help create and explain segmentation policies, and simulate their potential impact before enforcement. This can make it easier for security teams to implement Zero Trust microsegmentation without relying entirely on manual processes to understand complex application dependencies.
Protection also needs to cover more than traffic coming from outside. By controlling east-west traffic, organizations can restrict communication between servers, applications, and workloads, helping prevent a compromise in one area from becoming a pathway into another.
Explore Other Akamai Solutions.
Enhancing Your Security from Traditional VPN to ZTNA
What about users who need to access applications from outside the corporate network?
Traditional VPNs connect users to the network first. Once the connection is established, access to resources is then controlled through network-level configurations. In hybrid and multi-cloud environments with numerous applications and locations, this can result in broader network access than a user actually needs.
Zscaler Zero Trust Exchange takes a different approach. Users do not need access to the entire network simply to open one application. Instead, access can be granted specifically based on user identity, context, and applicable policies.
With identity-based access control, organizations can determine who can access a particular application, from which device, and under what conditions. Users can then connect directly to the resources they need without exposing the entire internal network.
This makes Zero Trust Exchange a potential VPN alternative for enterprise, particularly for organizations whose users, applications, and workloads are distributed across multiple environments.
Protecting Web Applications and APIs Across Multi-Cloud Environments
Even when network and user access are protected, internet-facing applications require their own layer of defense.
Web applications and APIs are attractive targets because they provide access to business services and data. The challenge becomes greater when applications run across AWS, Azure, Google Cloud, data centers, and edge environments.
Managing security policies separately across each environment can also increase operational complexity. Differences in configuration between clouds may create gaps that are difficult for security teams to identify.
F5 Distributed Cloud WAAP is designed to protect web applications and APIs across cloud, on-premises, and edge environments. Its capabilities bring together WAF, DDoS mitigation, bot defense, and API security within a unified platform.
The protection covers threats such as OWASP Top 10 risks, Layer 7 DDoS, malicious bots, and automated attacks. F5 also uses behavioral protection and AI-powered risk scoring to help security teams distinguish malicious activity from legitimate traffic.
For organizations with a distributed application footprint, this helps maintain more consistent security policies and visibility without having to build an entirely different protection strategy for every environment.
The Last Line of Data Defense: Immutable Storage for Data Resilience
Not every attack can be stopped before it reaches the production environment. When that happens, organizations need reliable data that can still be trusted and recovered.
Immutable storage plays an important role here. Using WORM (write once, read many) capabilities and retention policies, data can be locked so it cannot be modified or deleted during a defined protection period.
Hitachi Content Platform (HCP) provides object storage capabilities with retention and immutability features to help preserve data integrity. If a production environment or certain backups are compromised, protected data copies can provide a more secure recovery source because they are significantly harder for attackers to alter.
This is why data resilience needs to be part of an enterprise security strategy. The goal is not only to prevent an attack, but also to ensure that the business has trustworthy data available to support recovery when an incident occurs.
Immutable storage can also support data governance and retention requirements. For compliance purposes, however, implementation still needs to be aligned with applicable regulations and organizational policies, including requirements related to data protection under Indonesia's Personal Data Protection Law (UU PDP).
Explore Other Hitachi Vantara Solutions.
Build a Distributed Cloud Security Architecture with CDT
Distributed cloud gives enterprises greater freedom to place applications and workloads where they best fit their needs. At the same time, security can no longer depend on a single perimeter or security solution.
Each layer serves a different purpose. Akamai Guardicore Segmentation helps limit lateral movement through microsegmentation. Zscaler Zero Trust Exchange manages user access based on identity and policy. F5 Distributed Cloud WAAP protects web applications and APIs across different environments, while Hitachi Content Platform helps maintain data resilience through immutable storage.
Together, these capabilities create a defense-in-depth strategy that covers multiple points of risk, from user access and east-west traffic to application protection and data recovery.
As part of CTI Group, Central Data Technology (CDT) can help enterprises integrate these solutions into a distributed cloud architecture that aligns with their infrastructure and security requirements.
If your organization is expanding its hybrid or multi-cloud environment, security should be considered from the architecture stage, not added after the infrastructure is already in place. With the right security foundation, distributed cloud infrastructure can deliver not only flexibility and scalability, but also stronger resilience against evolving cyber threats.
Contact the CDT team to discuss a distributed cloud security strategy tailored to your environment, business requirements, and enterprise security priorities.
Author: Wilsa Azmalia Putri
Content Writer CTI Group