Securing Cloud Technology in a Growing Threat Landscape

3 min read

Cloud technologies are becoming more and more popular. Many companies shifted their workloads and their IT infrastructures into the cloud. The advantages are clear: more flexibility and scalability, less admin overhead and often cost savings. But with those advantages also come many risks.

Recent studies have shown several threats cloud technologies face. As data transfers to the cloud, the risk of unwanted access to that data increases. Cloud service providers guarantee their clients that they protect the cloud infrastructure, while the client has to take care of the data and applications in the cloud. But many clients do not configure their environments properly, which makes their environments open to risks they didn’t face within their on-premises environments. 

The Cloud Security Alliance (CSA) recently published a white paper on the current top threats to cloud computing. The list shows that, in general, misconfigurations and a lack of proper identity and access management (IAM) are leading threats to cloud security. A lack of expertise and the rapid expansion of technology makes it difficult to keep security in mind while moving to the cloud.

CSA points out that, even if the cloud environments have proper security in place, attackers can still aim for the low-hanging fruit. They may attack misconfigured APIs or exploit overprivileged user accounts that don’t have the right policies in place. While it is always a challenge to put a secure architecture in place, implement a secure application development process and check third-party resources for vulnerabilities, the cloud adds new risks on top of those. In addition, serverless application developments and containers are a huge part of cloud computing, which completely change the way applications have to be secured.

When it comes to cloud security budgets, things don’t look any better. Companies can’t allocate their whole security budget to cloud security. However, ISC2 recently found that 57% of companies plan to increase their cloud security budget within a year. To better address the above-mentioned threats and improve training and education for their staff, the ISC2 report found that six out of 10 IT employees would feel more confident with cloud technologies if they had adequate training to improve their skills.

Some of the latest cloud breaches involve well-known companies from the tech industry. These cases underline that even for big tech companies, the cloud can be a challenge.

The LockBit ransomware breached IT consulting company Accenture last year. Attackers gained access to several cloud storage servers that were not configured correctly and encrypted them in order to demand a ransom. Almost 6TB of data, including 10,000 user accounts and passwords, resided on the servers.

In the same vein, attackers hit the tech giant Facebook in 2021. Millions of user records, such as account names, images and check-in data, were exposed in misconfigured publicly facing cloud storage buckets. This enabled attackers to simply download the data via the internet.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at securityintelligence.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.