* [Topics](/en/topics "Topics")
* [Security](/en/topics/security "Security")
* What is edge security?
What is edge security?
======================
Updated  July 19, 2023•*3*-minute read
Copy URL
Jump to section
---------------
What is edge securityChallenges of securing the edgeSecuring the edgeWhy Red Hat
What is edge security?
----------------------
[Edge computing](/en/topics/edge-computing/what-is-edge-computing) moves data processing and applications out of a centralized on-premises datacenter or [public cloud](/en/topics/cloud-computing/what-is-public-cloud) to physical locations near users and data. By placing computing services closer to these locations, organizations can use latency sensitive applications and benefit from faster, more reliable services and data-driven decision making.
Edge security refers to the combination of tools and practices used to protect edge infrastructure and workloads in remote locations where on-site expertise may be limited. It includes protecting valuable data that is generated and processed farthest from an organization's on-premises data center or public cloud. Edge security is essential as the attack surface grows as the edge architecture scales out.
The key to security is recognizing the need for an ongoing, holistic security approach because security goes beyond just implementing perimeter walls. With security approaches like [zero trust](/en/topics/security/what-is-zero-trust), gaps in architecture can be closed, and IT environments and organizations will protect your IT environment and organization.
Zero-trust environments are at the core of how to secure at the edge, as edge devices often do not have the firewalls and other security infrastructure that exists in a data center. Those devices are often physically vulnerable in remote unsecured locations and are inherently more vulnerable to physical attacks and must be managed as an untrusted node.
What are the challenges of securing the edge?
---------------------------------------------
As the popularity of edge computing grows, organizations are challenged to secure their infrastructure and workloads in locations with limited to no-onsite expertise. Computing at the edge can often involve heterogeneous software and hardware that is hard to manage and maintain,  adding additional complexity to ensuring up to date security policies and processes are in place.
Organizations need to continuously analyze their edge environments to keep track of edge devices, predict security risks, and recommend actions. Key challenges to securing edge architectures include:
* **Limited or intermittent network access**: These limitations make it difficult to update edge devices and adds a lack of security visibility when offline.
* **Physical tampering and attacks**: Due to the remote nature of edge environments, physical protection isn’t always guaranteed, and there’s an increased risk of theft and supply chain attacks.
* **Preventing human error in edge security**: Many edge locations are not staffed with IT or networking specialists,  introducing numerous potential attack vectors.
* **Edge device management at scale**: With hundreds to hundreds of thousands of devices to manage, ensuring systems are up to date and include needed security patches, can challenge teams who need to ensure a strong security posture across the organization.
Because edge infrastructure and workloads are not in a protected data center with controlled physical access, they are more susceptible to physical tampering and cyberattacks vulnerabilities.
Recommended for you
Defense Nation
--------------
[Watch the webinar](https://www.redhat.com/en/events/webinar/defense-nation?percmp=RHCTG0250000455235)
Why is securing the edge important?
-----------------------------------
Workloads deployed at the edge are often tied to a company’s core business such as retail point of sale systems, sensors on manufacturing lines, and connected medical devices in healthcare as examples. Ensuring steady operations of these key workloads, while protecting the data that is being processed becomes essential.
The top three greatest risk security incidents within or from edge systems are:
1. Cyberattacks from malicious insiders
2. Cyberattacks from outside attackers
3. Vulnerabilities of not knowing the health of edge devices
When powering your business with edge, it’s important to secure hardware when it's outside of the physical environment of the data center. First, you want to address the physical access challenges by protecting deployments. Next, you want to protect the infrastructure by attacking surface growth as the architecture scales out. Lastly, you protect your workloads with a secure software supply chain. Edge security provides a way to protect against zero-day threats, malware, and other vulnerabilities at the point of access, especially as the attack surface grows.
Why choose Red Hat?
-------------------
Red Hat’s approach to edge and hybrid cloud security prioritizes the integration of security throughout the entire infrastructure and application stack and life cycle. Red Hat works to help you build security into applications, deploy applications onto a hardened platform, and manage, automate, and adapt your infrastructure and applications as security and compliance requirements change.
With the varied use cases for edge computing, Red Hat is focused on providing an extensive set of security capabilities across our portfolio which includes [Red Hat® Enterprise Linux®](/en/technologies/linux-platforms/enterprise-linux), [Red Hat Device Edge](/en/technologies/device-edge), [Red Hat OpenShift with Advanced Cluster Security for Kubernetes](/en/technologies/cloud-computing/openshift/advanced-cluster-security-kubernetes), and Red Hat Ansible Automation Platform.
Red Hat’s edge computing solutions approach to edge security can help your business:
* Deploy at the edge with a stable foundation
* Manage complexity at the edge
* Monitor the edge 24x7
* Boost security for both traditional and containerized environments
Recommended for you
E-book
Red Hat technologies for edge computing innovation
--------------------------------------------------
Read how 5 organizations use Red Hat Edge to maintain remote operations, manage applications anywhere, and make intelligent decisions efficiently.
[Read the e-book](https://www.redhat.com/en/resources/scale-innovation-at-the-edge-ebook?percmp=RHCTG0250000455234)
All Red Hat product trials
--------------------------
Our no-cost product trials help you gain hands-on experience, prepare for a certification, or assess if a product is right for your organization.
[Keep reading](/en/products/trials "All Red Hat product trials")
Keep reading
------------
### What is security automation?
Security automation uses technology to perform tasks with reduced human assistance to integrate security processes, applications, and infrastructure.
[Read the article](/en/topics/automation/what-is-security-automation "article | what is security automation")
### What is SOAR?
SOAR refers to 3 key software capabilities that security teams use: case and workflow management, task automation, and a centralized means of accessing, querying, and sharing threat intelligence.
[Read the article](/en/topics/security/what-is-soar "article | what is soar")
### What's an insider threat?
An insider threat is leaked or misused data that—whether released accidentally or purposefully—could be used in malicious ways or viewed by individuals who shouldn’t have legitimate access.
[Read the article](/en/topics/security/what-are-insider-threats "article | What's an insider threat")
Security resources
------------------
### Related content
* Blog post
  [MCP security: Implementing robust authentication and authorization](/en/blog/mcp-security-implementing-robust-authentication-and-authorization)
* Case study
  [Powering O2’s next-generation 5G network with Red Hat OpenShift](/en/resources/o2-czech-republic-case-study)
* Blog post
  [AI trust through open collaboration: A new chapter for responsible innovation](/en/blog/ai-trust-through-open-collaboration-new-chapter-responsible-innovation)
* Blog post
  [The nervous system gets a soul: why sovereign cloud is telco’s real second act](/en/blog/nervous-system-gets-soul-why-sovereign-cloud-telcos-real-second-act)
### Related articles
* [What is security automation?](/en/topics/automation/what-is-security-automation)
* [What is AI security?](/en/topics/ai/what-is-ai-security)
* [What is edge AI?](/en/topics/edge-computing/what-is-edge-ai)
* [What is SOAR?](/en/topics/security/what-is-soar)
* [What's an insider threat?](/en/topics/security/what-are-insider-threats)
* [What is IoT Edge computing?](/en/topics/edge-computing/iot-edge-computing-need-to-work-together)
* [The evolution to a 5G core network](/en/topics/5g-networks/evolution-to-a-5g-core)
* [What is post-quantum cryptography?](/en/topics/security/post-quantum-cryptography)
* [What is lightweight directory access protocol (LDAP) authentication?](/en/topics/security/what-is-ldap-authentication)
* [What is software supply chain security?](/en/topics/security/what-is-software-supply-chain-security)
* [What is secrets management?](/en/topics/devops/what-is-secrets-management)
* [Edge computing with Red Hat OpenShift](/en/technologies/cloud-computing/openshift/edge-computing)
* [What is confidential computing?](/en/topics/security/what-is-confidential-computing)
* [What are SPIFFE and SPIRE?](/en/topics/security/spiffe-and-spire)
* [Red Hat Enterprise Linux security](/en/technologies/linux-platforms/enterprise-linux/security)
* [What is zero trust?](/en/topics/security/what-is-zero-trust)
* [Functional safety and continuous certification on Linux](/en/topics/open-source/functional-safety-and-continuous-certification-on-linux)
* [What is access control?](/en/topics/security/what-is-access-control)
* [What is a CVE?](/en/topics/security/what-is-cve)
* [Edge solutions for real-time decision making](/en/topics/edge-computing/edge-solutions-real-time-decision-making)
* [What is role-based access control (RBAC)?](/en/topics/security/what-is-role-based-access-control)
* [What is kubernetes security?](/en/topics/containers/kubernetes-security)
* [How to manage and automate applications at the edge](/en/topics/edge-computing/how-to-manage-automate-applications-edge)
* [Shift left vs. shift right](/en/topics/devops/shift-left-vs-shift-right)
* [What is OT orchestration in manufacturing?](/en/topics/edge-computing/what-is-ot-orchestration-manufacturing)
* [Red Hat Lightspeed data and application security](/en/topics/management/data-application-security)
* [What is MicroShift?](/en/topics/edge-computing/microshift)
* [Why choose Red Hat for edge computing?](/en/topics/edge-computing/why-choose-red-hat-edge-computing)
* [What is CI/CD security?](/en/topics/security/what-is-cicd-security)
* [How telcos can achieve their sustainability goals](/en/topics/telecommunications/telcos-achieve-sustainability-goals)
* [What is an intrusion detection and prevention system (IDPS)?](/en/topics/security/what-is-an-IDPS)
* [What is security information and event management (SIEM)?](/en/topics/security/what-is-SIEM)
* [Retail store transformation with edge](/en/topics/edge-computing/retail-store-transformation-with-edge)
* [The increasing importance of cybersecurity in banking](/en/topics/financial-services/increasing-importance-cybersecurity-banking)
* [What is private 5G?](/en/topics/5g-networks/what-is-private-5g)
* [Gain security with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/gain-security-with-red-hat-ansible-automation-platform)
* [What is the importance of operational resilience?](/en/topics/financial-services/what-is-operational-resilience)
* [What is vulnerability management?](/en/topics/security/what-is-vulnerability-management)
* [What is backup and recovery?](/en/topics/security/backup-and-recovery)
* [What is container security?](/en/topics/security/container-security)
* [What is DevSecOps?](/en/topics/devops/what-is-devsecops)
* [What is compliance management?](/en/topics/management/what-is-compliance-management)
* [Why choose Red Hat for DevSecOps](/en/topics/devops/why-choose-red-hat-for-devsecops)
* [What is cloud governance?](/en/topics/automation/what-is-cloud-governance)
* [What is a latency-sensitive application?](/en/topics/edge-computing/latency-sensitive-applications)
* [What is carrier-grade?](/en/topics/5g-networks/what-is-carrier-grade)
* [How edge helps solve connectivity issues](/en/topics/edge-computing/how-edge-solves-connectivity-issues)
* [Cloud vs. edge](/en/topics/cloud-computing/cloud-vs-edge)
* [What is edge architecture?](/en/topics/edge-computing/what-is-edge-architecture)
* [What is edge machine learning?](/en/topics/edge-computing/what-is-edge-machine-learning)
* [Security in the software development lifecycle](/en/topics/security/software-development-lifecycle-security)
* [What is operational technology (OT)?](/en/topics/edge-computing/what-ot)
* [Understanding edge computing for manufacturing](/en/topics/edge-computing/manufacturing)
* [What is multi-access edge computing?](/en/topics/edge-computing/what-is-multi-access-edge-computing)
* [Kubernetes security best practices](/en/topics/containers/kubernetes-security-best-practices)
* [Security for IoT devices](/en/topics/security/security-for-iot-devices)
* [What is MPLS?](/en/topics/edge-computing/what-is-mpls)
* [What is identity and access management (IAM)?](/en/topics/security/what-identity-and-access-management-iam)
* [What is SD-WAN?](/en/topics/edge-computing/what-is-sd-wan)
* [Advantages of Kubernetes-native security](/en/topics/containers/advantages-of-kubernetes-native-security)
* [Container and Kubernetes compliance considerations](/en/topics/containers/compliance)
* [Intro to Kubernetes security](/en/topics/containers/intro-kubernetes-security)
* [What is an autonomous vehicle?](/en/topics/edge-computing/what-is-an-autonomous-vehicle)
* [What is IIoT?](/en/topics/internet-of-things/what-is-iiot)
* [What is edge computing?](/en/topics/edge-computing/what-is-edge-computing)
* [What is 5G?](/en/topics/5g-networks/what-is-5g)
* [Understanding edge computing for telecommunications](/en/topics/edge-computing/telecommunications)
* [What is risk management?](/en/topics/management/what-is-risk-management)
* [What is SELinux?](/en/topics/linux/what-is-selinux)
* [Hybrid cloud security](/en/topics/security/what-is-hybrid-cloud-security)
* [What is API security?](/en/topics/security/api-security)
* [What is IoT?](/en/topics/internet-of-things/what-is-iot)
* [What is financial services security (and compliance)?](/en/topics/security/security-and-compliance-financial-services)
* [What is malware?](/en/topics/security/what-is-malware)
* [What is cloud security](/en/topics/security/cloud-security)
[More about this topic](/en/topics/security "More about this topic")