De protección perimetral a ciber-resiliencia: nuevo paradigma de seguridad en nube híbrida

Autores/as

DOI:

https://doi.org/10.56880/experior52.1

Palabras clave:

ciber-resiliencia, nube híbrida, seguridad informática, Inteligencia Artificial, soberanía de datos

Resumen

La adopción generalizada de la nube híbrida ha disuelto las fronteras físicas de la infraestructura empresarial, dejando obsoletos los modelos de seguridad basados en el perímetro estático.  Este estudio analiza el cambio de paradigma desde la protección tradicional hacia la ciber-resiliencia, con el objetivo general de proponer un modelo estratégico que integre la automatización, la Inteligencia Artificial y los principios de Zero Trust como pilares fundamentales. Utilizando una metodología cualitativa, descriptiva y analítica, la investigación se basó en una revisión bibliográfica estructurada orientada al análisis crítico de contenido y la triangulación de estándares globales (NIST, ISO) con informes de la industria. Los resultados confirman la hipótesis de trabajo: la seguridad efectiva en entornos distribuidos depende de una transformación cultural hacia la resiliencia sistémica y no solo de la capacidad tecnológica. Se evidencia que, si bien la arquitectura de Confianza Cero resuelve el control de acceso, la integración de orquestación SOAR e IA es crítica para mitigar la brecha de talento humano del 54% y garantizar la soberanía de los datos. Se concluye que el futuro de la seguridad híbrida reside en la defensa autónoma, capaz de aprender y reconfigurarse en tiempo real para asegurar la continuidad operativa.

Descargas

Los datos de descarga aún no están disponibles.

Referencias

Amazon Web Services. (2024). Shared Responsibility Model. AWS Cloud Security. https://aws.amazon.com/compliance/shared-responsibility-model/

Arafah, M., Al-Banna, A., & Aladawi, A. (2025). Cybersecurity in the Age of Digital Transformation: Protecting Assets, Infrastructure, and Innovation. En A. Aldweesh (Ed.), Complexities and Challenges for Securing Digital Assets and Infrastructure (pp. 265-290). IGI Global Scientific Publishing. https://doi.org/10.4018/979-8-3373-1370-2.ch013

Buck, C., Olenberger, C., Schweizer, A., Völter, F., & Eymann, T. (2021). Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust network architecture. Computers & Security, 110, 102436. https://doi.org/10.1016/j.cose.2021.102436

Check Point Research. (2024). 2024 Security Report. Check Point Software Technologies. https://www.checkpoint.com/security-report/?flz-category=items&flz-item=report--cyber-security-report-2024&fw=f28ef

Christian, J., Paulino, L., & Sá, A. (2022). A Low-Cost and Cloud Native Solution for Security Orchestration, Automation, and Response. Lecture Notes in Computer Science, 13608, 102-115. Springer. https://doi.org/10.1007/978-3-031-21280-2_7

Dua, S., & Du, X. (2016). Data Mining and Machine Learning in Cybersecurity. CRC Press. https://doi.org/10.1201/b10867

Flexera. (2025). 2025 State of the Cloud Report. Flexera. https://www.flexera.com/stateofthecloud

Fortinet. (2025). 2025 Global Threat Landscape Report. FortiGuard Labs. https://www.fortiguard.com/threat-landscape-report

IBM. (2025). Cost of a Data Breach Report 2025. IBM Security. https://www.ibm.com/reports/data-breach

IDC. (2023). IDC FutureScape: Latin America IT Industry 2024 Predictions. International Data Corporation. https://www.idclatin.com/2023/Events/13_Dec_LA/FutureScapeLA2024.pdf

ISACA. (2018). COBIT 2019 Framework: Governance and Management Objectives. https://www.isaca.org/resources/cobit

ISC2. (2023). ISC2 Cybersecurity Workforce Study 2023: How the Economy, Skills Gap and Artificial Intelligence are Challenging the Global Cybersecurity Workforce. ISC2. https://www.isc2.org/Research

Joint Task Force. (2020). Security and Privacy Controls for Information Systems and Organizations (NIST Special Publication 800-53, Revision 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5

Kaspersky. (2023). Redefining the Human Factor in Cybersecurity. Kaspersky. https://www.kaspersky.com/blog/human-factor-360-report-2023/

Lumu Technologies. (2023). 2023 Ransomware Flashcard Report. Lumu. https://lumu.io/resources/2023-ransomware-flashcard-report/

ManpowerGroup. (2024). Global Talent Shortage 2024. ManpowerGroup. https://go.manpowergroup.com/talent-shortage-2024

Microsoft. (2024a). Información sobre la clasificación automatizada de datos. https://learn.microsoft.com/es-es/purview/apply-sensitivity-label-automatically

Microsoft. (2024b). Microsoft Digital Defense Report 2024. Microsoft Security. https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf

National Security Agency. (2021). Embracing a Zero Trust security model (Cybersecurity Information Sheet). https://media.defense.gov/2021/Feb/25/2002588479/-1/-1/0/CSI_EMBRACING_ZT_SECURITY_MODEL_UOO115131-21.PDF

NIST. (2021). NIST SP 800-160 Vol. 2 Rev. 1: Developing Cyber-Resilient Systems: A Systems Security Engineering Approach. National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v2r1.pdf

Organización Internacional de Normalización. (2022). Sistemas de gestión de la seguridad de la información — Requisitos (ISO/IEC 27001:2022). https://www.iso.org/standard/27001

Rajendran, R. K., Mohana Priya, T., Goundar, S., Madhavi, K. R., Avanija, J., & Avula, B. R. (2025). Zero Trust Architecture in Cloud Security. En Convergence of Cybersecurity and Cloud Computing (pp. 515-530). IGI Global. https://www.researchgate.net/profile/Basi-Reddy-Avula/publication/387897412_Zero_Trust_Architecture_in_Cloud_Security/links/699d233542f94d1212ae271f/Zero-Trust-Architecture-in-Cloud-Security.pdf

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207

Upadhyaya, S. K., & Vivek, S. (2022, August). Revisiting a Privacy-Preserving Location-based Service Protocol using Edge Computing. In Proceedings of the 17th International Conference on Availability, Reliability and Security (pp. 1-5). https://doi.org/10.1145/3538969.3544432

Varghese, B., & Buyya, R. (2018). Next generation cloud computing: New trends and research directions. Future Generation Computer Systems, 79(3), 849-861. https://doi.org/10.1016/j.future.2017.09.020

World Economic Forum. (2024). Global Cybersecurity Outlook 2024. https://www.weforum.org/publications/global-cybersecurity-outlook-2024/

Zhukabayeva, T., Zholshiyeva, L., Karabayev, N., Khan, S., & Alnazzawi, N. (2025). Cybersecurity Solutions for Industrial Internet of Things–Edge Computing Integration: Challenges, Threats, and Future Directions. Sensors, 25(1), 213. https://doi.org/10.3390/s25010213

Zissis, D., & Lekkas, D. (2012). Addressing cloud computing security issues. Future Generation Computer Systems, 28(3), 583–592. https://doi.org/10.1016/j.future.2010.12.006

Descargas

Publicado

2026-07-15

Cómo citar

Castillo Serracín, J. R., Carmona , K., & Aranda , O. (2026). De protección perimetral a ciber-resiliencia: nuevo paradigma de seguridad en nube híbrida. Experior, 5(2), 105-118. https://doi.org/10.56880/experior52.1