HomeLatest NewsOpinionTop 10 things to consider while securing microservices

Top 10 things to consider while securing microservices

Preferred Source of Google

As enterprises look to become more agile and move towards a DevOps and continuous testing, the need for microservices has grown manifolds.

Businesses require a next-generation web application firewall (WAF) that enables secure delivery of applications. life cycle (SDLC), is as flexible as the dynamic environment and threat landscape and adapts to the needs of the business. Before considering any solution, make sure it meets the requirements of both development and operations (DevOps) and security teams.

SQL injections, cross-site scripting, access violations, remote file inclusion — running applications in a service mesh architecture don’t eliminate the risk from leakage or service disruptions. Emerging continuous integration and continuous delivery (CI/CD) technologies disrupt common practices and processes and create new blind spots.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Future-Ready Defence
Future-Ready Defence
A Leadership Dialogue on sovereign, trusted data infrastructure, AI readiness and mission resilience for Defence Forces.
Register Now →

Here are 10 characteristics to look for when considering protection to data and applications in a service mesh architecture.

Native Fit into CI/CD Pipeline

  • Kubernetes controlled elasticity — Easily orchestrated, grows and scales application security along with Kubernetes pods, including auto-learned policies and configuration settings.
  • Automation at the speed of development — Application programming interfaces (APIs) for integration with common tools for security provisioning of new services and applications, with a local management and reporting interface.
  • TLS termination — End-to-end encryption is necessary to secure data integrity and avoid eavesdropping and man-in-the-middle (MITM) attacks. A single TLS termination at the host also eliminates spreading multiple certificates across third parties.
  • Minimal footprint — Microservices are all about micro units; thus, the enforcement point in the data plane should be lightweight while the control plane (management, analytics and learning algorithms) is integrated into the environment independently.

Quality of Protection

Advertisement
  • Extensive security — Application protection today goes beyond the OWASP Top 10, so a good WAF needs to accurately detect malicious bot activity, secure APIs and mitigate denial-of-service attacks.
  • Effective security (zero-day protection) — Negative and positive security models are necessary to protect against known and unknown threats, thus maximizing security and minimizing false positives.
  • Adaptive security — Immediate detection of new and modified applications in the CI/CD pipeline isn’t enough and must be followed by automatic generation and optimization of security policies.
  • Data leakage prevention — Make sure data that is being shared externally is protected. Credit card and Social Security numbers must be masked, cookies must be encrypted, and scrapers should be misled with fake data.

Supplementary Requirements

Endorsed technology — Multiple firms evaluate technology solutions, including ICSA, NSS, and Gartner. Don’t take our word for it — check it for yourself.

Comprehensive reporting and analytics — Visibility to both development, security and operations (DevSecOps) and security teams via integration with common tools and platforms like elastic Kibana, Grafana, Prometheus, among others.

Advertisement

The author is Managing Director-India, SAARC & Middle East, . Views are personal.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Nikhil Taneja
Nikhil Taneja
Nikhil Taneja is managing director - India, SAARC & Middle East at Radware
Advertisement
- Advertisement -
- Advertisement -

Infosys Public Services head Lax Gopisetty missing after Nepal floods

Infosys Public Services head Lax Gopisetty is unreachable after flash floods struck the Nepal-Tibet border. The MEA says 320 Indians remain missing and 400 are stranded on the Chinese side.

RELATED ARTICLES