De protección perimetral a ciber-resiliencia: nuevo paradigma de seguridad en nube híbrida
DOI:
https://doi.org/10.56880/experior52.1Palabras clave:
ciber-resiliencia, nube híbrida, seguridad informática, Inteligencia Artificial, soberanía de datosResumen
La adopción generalizada de la nube híbrida ha disuelto las fronteras físicas de la infraestructura empresarial, dejando obsoletos los modelos de seguridad basados en el perímetro estático. Este estudio analiza el cambio de paradigma desde la protección tradicional hacia la ciber-resiliencia, con el objetivo general de proponer un modelo estratégico que integre la automatización, la Inteligencia Artificial y los principios de Zero Trust como pilares fundamentales. Utilizando una metodología cualitativa, descriptiva y analítica, la investigación se basó en una revisión bibliográfica estructurada orientada al análisis crítico de contenido y la triangulación de estándares globales (NIST, ISO) con informes de la industria. Los resultados confirman la hipótesis de trabajo: la seguridad efectiva en entornos distribuidos depende de una transformación cultural hacia la resiliencia sistémica y no solo de la capacidad tecnológica. Se evidencia que, si bien la arquitectura de Confianza Cero resuelve el control de acceso, la integración de orquestación SOAR e IA es crítica para mitigar la brecha de talento humano del 54% y garantizar la soberanía de los datos. Se concluye que el futuro de la seguridad híbrida reside en la defensa autónoma, capaz de aprender y reconfigurarse en tiempo real para asegurar la continuidad operativa.
Descargas
Referencias
Amazon Web Services. (2024). Shared Responsibility Model. AWS Cloud Security. https://aws.amazon.com/compliance/shared-responsibility-model/
Arafah, M., Al-Banna, A., & Aladawi, A. (2025). Cybersecurity in the Age of Digital Transformation: Protecting Assets, Infrastructure, and Innovation. En A. Aldweesh (Ed.), Complexities and Challenges for Securing Digital Assets and Infrastructure (pp. 265-290). IGI Global Scientific Publishing. https://doi.org/10.4018/979-8-3373-1370-2.ch013
Buck, C., Olenberger, C., Schweizer, A., Völter, F., & Eymann, T. (2021). Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust network architecture. Computers & Security, 110, 102436. https://doi.org/10.1016/j.cose.2021.102436
Check Point Research. (2024). 2024 Security Report. Check Point Software Technologies. https://www.checkpoint.com/security-report/?flz-category=items&flz-item=report--cyber-security-report-2024&fw=f28ef
Christian, J., Paulino, L., & Sá, A. (2022). A Low-Cost and Cloud Native Solution for Security Orchestration, Automation, and Response. Lecture Notes in Computer Science, 13608, 102-115. Springer. https://doi.org/10.1007/978-3-031-21280-2_7
Dua, S., & Du, X. (2016). Data Mining and Machine Learning in Cybersecurity. CRC Press. https://doi.org/10.1201/b10867
Flexera. (2025). 2025 State of the Cloud Report. Flexera. https://www.flexera.com/stateofthecloud
Fortinet. (2025). 2025 Global Threat Landscape Report. FortiGuard Labs. https://www.fortiguard.com/threat-landscape-report
IBM. (2025). Cost of a Data Breach Report 2025. IBM Security. https://www.ibm.com/reports/data-breach
IDC. (2023). IDC FutureScape: Latin America IT Industry 2024 Predictions. International Data Corporation. https://www.idclatin.com/2023/Events/13_Dec_LA/FutureScapeLA2024.pdf
ISACA. (2018). COBIT 2019 Framework: Governance and Management Objectives. https://www.isaca.org/resources/cobit
ISC2. (2023). ISC2 Cybersecurity Workforce Study 2023: How the Economy, Skills Gap and Artificial Intelligence are Challenging the Global Cybersecurity Workforce. ISC2. https://www.isc2.org/Research
Joint Task Force. (2020). Security and Privacy Controls for Information Systems and Organizations (NIST Special Publication 800-53, Revision 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5
Kaspersky. (2023). Redefining the Human Factor in Cybersecurity. Kaspersky. https://www.kaspersky.com/blog/human-factor-360-report-2023/
Lumu Technologies. (2023). 2023 Ransomware Flashcard Report. Lumu. https://lumu.io/resources/2023-ransomware-flashcard-report/
ManpowerGroup. (2024). Global Talent Shortage 2024. ManpowerGroup. https://go.manpowergroup.com/talent-shortage-2024
Microsoft. (2024a). Información sobre la clasificación automatizada de datos. https://learn.microsoft.com/es-es/purview/apply-sensitivity-label-automatically
Microsoft. (2024b). Microsoft Digital Defense Report 2024. Microsoft Security. https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf
National Security Agency. (2021). Embracing a Zero Trust security model (Cybersecurity Information Sheet). https://media.defense.gov/2021/Feb/25/2002588479/-1/-1/0/CSI_EMBRACING_ZT_SECURITY_MODEL_UOO115131-21.PDF
NIST. (2021). NIST SP 800-160 Vol. 2 Rev. 1: Developing Cyber-Resilient Systems: A Systems Security Engineering Approach. National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v2r1.pdf
Organización Internacional de Normalización. (2022). Sistemas de gestión de la seguridad de la información — Requisitos (ISO/IEC 27001:2022). https://www.iso.org/standard/27001
Rajendran, R. K., Mohana Priya, T., Goundar, S., Madhavi, K. R., Avanija, J., & Avula, B. R. (2025). Zero Trust Architecture in Cloud Security. En Convergence of Cybersecurity and Cloud Computing (pp. 515-530). IGI Global. https://www.researchgate.net/profile/Basi-Reddy-Avula/publication/387897412_Zero_Trust_Architecture_in_Cloud_Security/links/699d233542f94d1212ae271f/Zero-Trust-Architecture-in-Cloud-Security.pdf
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Upadhyaya, S. K., & Vivek, S. (2022, August). Revisiting a Privacy-Preserving Location-based Service Protocol using Edge Computing. In Proceedings of the 17th International Conference on Availability, Reliability and Security (pp. 1-5). https://doi.org/10.1145/3538969.3544432
Varghese, B., & Buyya, R. (2018). Next generation cloud computing: New trends and research directions. Future Generation Computer Systems, 79(3), 849-861. https://doi.org/10.1016/j.future.2017.09.020
World Economic Forum. (2024). Global Cybersecurity Outlook 2024. https://www.weforum.org/publications/global-cybersecurity-outlook-2024/
Zhukabayeva, T., Zholshiyeva, L., Karabayev, N., Khan, S., & Alnazzawi, N. (2025). Cybersecurity Solutions for Industrial Internet of Things–Edge Computing Integration: Challenges, Threats, and Future Directions. Sensors, 25(1), 213. https://doi.org/10.3390/s25010213
Zissis, D., & Lekkas, D. (2012). Addressing cloud computing security issues. Future Generation Computer Systems, 28(3), 583–592. https://doi.org/10.1016/j.future.2010.12.006
Descargas
Publicado
Número
Sección
Licencia

Esta obra está bajo una licencia internacional Creative Commons Atribución-NoComercial 4.0.





