Data breaches that resulted from cloud misconfigurations cost businesses nearly $3.18 trillion in 2019, according to DivvyCloud heres what to know to protect your business
The Covid-19 pandemic is having huge effects on the economy, our social lives, and the ways in which we work. With many staff around the world now being required to work from home, the crisis has focused attention on cloud security and the resilience of its infrastructure to stand up to cloud security threats.
The cybersecurity vulnerabilities inherent to cloud storage are nothing new. Many companies were still in the process of improving their cloud security when the pandemic hit, but have now been forced to accelerate their plans.
This move includes a renewed push to encrypt cloud storage using AES and an increased consciousness of the risk of phishing attacks in cloud environments. Experts also reckon that improved cloud security can save businesses up to $1.4 million per cyber-attack.
In this article, well look at the top 5 cloud security threats and will show you how to mitigate the cloud vulnerabilities that are associated with them.
Lets hash it out.
The cloud is here to stay. Flexeras 2020 State of the Cloud Report (formerly the Rightscale State of the Cloud Report) shows that, for the first time since the first edition of its report was published, every survey respondent indicated that they had cloud strategy plans or already used cloud in one form or another. In fact, 93% of their respondents indicated that their organizations have multi-cloud strategies.
The widespread use of cloud by organizations of all sizes serves to further underscore the importance of mitigating cloud security threats by eliminating existing cloud vulnerabilities.
Here are the five most common cloud security threats and what your organization can do to mitigate them:
One of the primary threats to cloud storage systems is not a feature of these systems themselves, but rather a result of the way that companies use them. The growing number of cloud providers with large free service plans drives down costs and encourages even small companies to move all of their data to the cloud. In many cases, this is done without carefully thinking through access policies.
Access management includes two fundamental elements. One is a rigorous access policy, and the other is a set of authentication and identity verification tools.
Lets look at access policies first. There is a simple principle when it comes to designing access policies for cloud storage: If an employee doesnt need access to particular files or systems in order to do their job, then they shouldnt have it. You should conduct regular audits of the level of access your employees have to your cloud systems and remove any unnecessary privileges.
This is particularly true when employees leave your company. A number of high-profile recent data breaches have been caused by disgruntled employees who have found that they still have access to their corporate accounts even long after leaving the company. IT administrators, therefore, need to liaise closely with HR departments to ensure that theres a process for removing privileges for departing employees as soon as possible.
Alongside this policy, you should deploy the most secure authentication and identity verification tools that are feasible for your cloud environment. Many cloud vendors now offer multi-factor authentication (MFA) systems as part of their standard packages. In these systems, users must have access to a second device typically a smartphone in order to log in to your systems. This makes access to your cloud storage dramatically more secure.
If youre looking to improve your cloud security still further, you can implement a separation of duties (SoD) model. This model separates the tasks that can be performed within your cloud environment so that no one user is able to totally control it. This means that tasks that might be damaging to your company such as deleting certain files require more than one person to execute.
SoD models afford you with a greater level of security because they mean that even if an administrative account is hacked, the attacker will not gain a level of access to your cloud environment that will allow them to cause significant levels of damage.
Data breaches and leaks are more of a threat in cloud systems than in those managed in-house. This is simply due to the large amounts of data flowing between employees and cloud systems, which can be intercepted by hackers looking for weaknesses in your systems. This is what happened to Equifax in 2017 when the personal data of more than 148 million Americans was stolen and published by hackers.
In the Equifax breach, the attackers were able to take advantage of an expired digital certificate. This is what helped the breach to remain undetected for more than a month and a half a total of 76 days..
Dont Get Breached
91% of cyber attacks start with an email, which can leave your business open to devastating data breaches. Not securing your email is like leaving the front door open for hackers.
One of the best ways to mitigate this threat is to secure your data using in-transit and at-rest data security. This would include the use of encryption both for your email server and for the messages themselves.This would include the use of digital certificates such as SSL/TLS website certificates and S/MIME (secure/multipurpose internet mail extension) certificates.
You should also ensure that all of your staff can access your cloud securely from anywhere, while at the same time youre using a reputable virtual private network to encrypt data that is in transit between Wi-Fi access points and your companys network. What is considered reputable? You neednt invest in an enterprise VPN, which can cost hundreds of dollars per month per user. However, it is important to do your research to ensure that the VPN service youre investing in is genuinely secure.
This is particularly true if you are looking for cost-effective VPN services. As weve pointed out in our recent article on free VPNs, some of these services are not as secure as they claim to be. Some free or ostensibly free VPN services i.e., those that do not keep log files and are AES-encrypted are fine. Others will log all of your activity in order to sell on this information, or will use less secure encryption schemes. Both of these practices are a potential source of risk, and if youre investing in a security tool it really shouldnt expose you to more risk.
Data loss is another issue that plagues cloud systems. After moving your business processes to the cloud, the amount of data you store remotely can quickly grow to an unmanageable size, which makes backups both difficult and costly. Because of this, research has found that an average of 51% of organizations have publicly exposed at least one cloud storage service, and 84% of organizations have said that traditional security solutions dont work in cloud environments.
Not performing regular, thorough backups is a major threat because of the rise of ransomware attacks, in which a hacker will encrypt your cloud storage and demand payment for returning data to you.
If you wait until something goes wrong, its too late. Preventing this kind of attack means designing and implementing a rigorous and stable backup system now. Ideally, this should be a distributed system, in which data is backed up in multiple systems and locations, in order to avoid data loss from individual storage area network (SAN) systems crippling your business.
Application user interfaces (APIs) are the primary tools that enable interaction with cloud storage systems. Normally, APIs are used by (at least) two distinct sets of employees:
Unfortunately, many APIs still have security vulnerabilities, most often giving cloud storage providers undue levels of access to your data. It emerged a few months ago, for instance, that both Facebook and Google stored user passwords in plaintext, and that these could, therefore, be read by staff within those organizations.
Considering that the 2019 Online Security Survey by Google and Harris Poll shows that more than two-thirds of respondents reuse their passwords across multiple accounts, thats particularly worrisome.
Mitigating the threat presented by insecure APIs means choosing a cloud storage vendor carefully. A quality vendor will adhere to OWASP API security guidelines, and also be able to provide you with data on the number of attacks they have seen, and the number they have defeated.
DivvyCloud recently highlighted another common threat in cloud systems: misconfiguration, which can lead to data being left unsecured. Some companies dont change the default security settings on their cloud storage; others allow their data to be stored in large and confusing structures in which it is easy to leave particular files unprotected. A good example of the dangers of misconfigured cloud storage is the National Security Agencys (NSA) mishap, a mistake that made a number of top secret documents available to everyone via an external browser.
Such cloud vulnerabilities are exacerbated by the sheer number of systems that are now connected to cloud storage. Most companies will now use the cloud for all of their operational processes from certificate management and email outreach and marketing automation to small business phone and messaging systems. Managing data flowing to the cloud from multiple endpoints can be a challenge for even the most experienced admins.
For most companies, ensuring that your cloud storage is configured correctly will be a question of speaking to your cloud storage vendor, and seeking assurances (and potentially legal assurances) that these have been set up correctly. You should ensure that you have an understanding not only of your cloud storage system, but also of all the systems that you use alongside it that could compromise its security.
A quality cloud storage provider will take the time to assess how you use your cloud storage, and the other systems you use alongside it, and highlight any potential risks and cloud vulnerabilities that this gives rise to.
The present moment with the world battling a global pandemic might seem like a strange time to reassess your cloud security. But, in reality, this is a necessary step, and theres no better time than the present.
None of the cloud security threats above are new, but theyre more important than ever as employees are forced to work from home. As a result, encryption is essential to defend against as are regular audits of who has access to your cloud storage and choosing a high-quality cloud provider.
Ultimately, by using this opportunity to improve your cloud security, you will also be protecting your data, staff, and customers in the long term. This will set you and your organization up for a successful future.
Recent Articles By Author
*** This is a Security Bloggers Network syndicated blog from Hashed Out by The SSL Store authored by Gary Stevens. Read the original post at: https://www.thesslstore.com/blog/cloud-security-5-serious-emerging-cloud-computing-threats-to-avoid/
Read the rest here:
Cloud Security: 5 Serious Emerging Cloud Computing Threats to Avoid - Security Boulevard
- Roundup Of Cloud Computing Forecasts, 2017 - Forbes [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- RCom arm in tie-up for cloud computing - Moneycontrol.com [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- How Do You Define Cloud Computing? - Data Center Knowledge [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- 5 Cloud Computing Stocks to Buy - TheStreet.com [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Cloud Computing Continues to Influence HPC - insideHPC [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Red Hat's New Products Centered Around Cloud Computing, Containers - Virtualization Review [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Adobe bets big on cloud computing for marketing, creative professionals - Livemint [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Verizon sells cloud services to IBM in 'unique cooperation between ... - Cloud Tech [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- How Cloud Computing Is Turning the Tide on Heart Attacks - Fortune [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Hospital CIOs see benefits of healthcare cloud computing - TechTarget [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Trends In Cloud Computing - Business Solutions Magazine [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- A deeper dive into cloud security as a service: Advantages and issues - Cloud Tech [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- OpenText buys cloud computing firm for US$103 million - TheRecord.com [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Belfast IT firm celebrates cloud computing success in 57 countries ... - Belfast Telegraph [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Meet The Cloud Wars Top 10: The World's Most-Powerful Cloud-Computing Vendors - Forbes [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- How to approach cloud computing and cyber security in 2017 - Information Age [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- CFOs have discovered the big stick of cloud computing - InfoWorld [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Belmont Stakes Odds 2017: Latest Vegas Betting Lines Before Post Positions Draw - Bleacher Report [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Cloudistics Announces New Cloud Computing Program That Enables High Margin Reoccurring Revenue Models for ... - Marketwired (press release) [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- CloudCheckr, cloud computing company expects rapid growth in Rochester - WXXI News [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- IBM Losing Facebook's WhatsApp as Cloud Customer, says CNBC - Barron's [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- What My Father Taught Me About Cloud Computing - Virtualization Review [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Workday Phenomenon Goes Global As Cloud Computing Goes Mainstream - Forbes [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - JD Supra (press release) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- 3 Things You Should Know About Cloud Computing Right Now - Fortune [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Learning in the Sky: Collaborative Robots Embrace Cloud Computing - Machine Design [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Best Practices To Manage Your Hybrid Cloud - Forbes [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Here's how venture capitalists are thinking about cloud computing companies and technologies - GeekWire [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Amazon is helping veterans find jobs in cloud computing - Marketplace - Marketplace.org [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - Lexology (registration) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Growing Patent Claim Risks in Cloud Computing - Lexology (registration) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- The benefits of cloud computing, Rust 1.18, and intelligent tracking prevention in WebKit SD Times news digest ... - SDTimes.com [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Edge Computing Is New Cloud Computing Tech Investors Should Track - GuruFocus.com [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Real Estate Weekly: Digital Realty Becomes A Cloud Computing Giant - Seeking Alpha [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Virtualization admin? Pivot -- pivot now -- to a cloud computing career - TechTarget [Last Updated On: June 10th, 2017] [Originally Added On: June 10th, 2017]
- Why isn't Cloud Computing in the 2017 Belmont Stakes? - FanSided [Last Updated On: June 11th, 2017] [Originally Added On: June 11th, 2017]
- Cloud Computing Companies Move Into Medical Diagnosis (GOOG, IBM) - Investopedia [Last Updated On: June 11th, 2017] [Originally Added On: June 11th, 2017]
- China's cloud industry moving to new era with emergence of unicorns - TechNode (blog) [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Terry Crews Is On Crackdown 3 Trailer, No Cloud Computing For Single Player - EconoTimes [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- The Risks and Perquisites of Cloud Computing - DATAQUEST [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Alibaba Cloud announces launch of data centres in India and Indonesia - Cloud Tech [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Indonesia banks have yet to implement cloud computing - Jakarta Post [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- 'Sweden is heaven for cloud computing': Amazon Nordic chief - The ... - The Local Sweden [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Amazon.com to open second government cloud-computing region ... - The Seattle Times [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Shadow raises $57 million for its cloud computing service for ... - TechCrunch [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Amazon Still Leads Cloud Rankings, But Competition Is Coming On Strong - Fortune [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 | Air ... - Air Cargo World (registration) [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 - Air Cargo World (registration) [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Pressing Tech Issue: Enterprise Software Vs. Cloud Computing? - Credit Union Times [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- 7 Tips for Securely Moving Data to the Cloud - Government Technology (blog) [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Chinese tech giant Alibaba joins key open-source cloud computing foundation - GeekWire [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Microsoft Could Surpass Amazon in Cloud Computing This Year (AMZN, MSFT) - Investopedia [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- GDS Holdings Limited (GDS) Announces Strategic Partnership with Tencent Cloud - StreetInsider.com [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Cloud first - Philippine Star [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Three Considerations for Reducing Risk in Cloud Computing - CIOReview [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Cloud Computing and Digital Divide 2.0 - CircleID - CircleID [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Microsoft will ride artificial intelligence, cloud computing to higher ... - CNBC [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- Update - Fox Business [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Report affirms continued cloud spend for US businesses in 2017 - Cloud Tech [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Catching up with an interconnected federal cloud - GCN.com [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- 2nd Update - Fox Business [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Cisco adapts to the rise of cloud computing - The Economist [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Amazon accuses Walmart of bullying in cloud computing clash - BBC News [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Companies plan to spend more on cloud computing services this year, higher prices among drivers: Clutch - Canadian Underwriter [Last Updated On: June 23rd, 2017] [Originally Added On: June 23rd, 2017]
- Survey: businesses ramp up spending on cloud computing DC ... - DC Velocity [Last Updated On: June 24th, 2017] [Originally Added On: June 24th, 2017]
- Morgan Stanley: Cloud computing is at 'an inflection point' but how big will it get? - GeekWire [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- How the cloud has changed education and training - TNW [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Cloud computing key to 4th industrial revolution - News VietNamNet - VietNamNet Bridge [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Lady Eli, Cloud Computing Among Workers for Brown - BloodHorse.com (press release) (registration) (blog) [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Microsoft signs cloud-computing partnership with Box - The Seattle Times [Last Updated On: June 27th, 2017] [Originally Added On: June 27th, 2017]
- Microsoft Signs Cloud Computing Partnership with Box - CIO Today [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- US action on Microsoft email case could devastate cloud computing - Irish Times [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Cloud computing challenges today: Planning, process and people - TechTarget [Last Updated On: July 2nd, 2017] [Originally Added On: July 2nd, 2017]
- Five podcasts to catch up on the latest trends in cloud computing - TechTarget [Last Updated On: July 2nd, 2017] [Originally Added On: July 2nd, 2017]
- Microsoft reportedly set to lay off thousands as part of massive sales reorganization - GeekWire [Last Updated On: July 3rd, 2017] [Originally Added On: July 3rd, 2017]
- VMware to surge more than 20 percent because the Amazon cloud ... - CNBC [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Google Unveils Custom Hardware Chip for Cloud - Investopedia [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Cloud Computing Confirmed for Travers | TDN | Thoroughbred Daily ... - Thoroughbred Daily News [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Why 2017 Is The Year To Understand Cloud Computing - Nasdaq [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Biz Cloud Computing - Four States Homepage [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]