Nearly all firms have suffered cloud security threats this year

Image of someone clicking a cloud icon.

(Image credit: Shutterstock)

The vast majority of organizations have suffered at least one cloud-related cybersecurity incident in the last 12 months, a new report from Venafi has claimed. 

It found that rising complexity, and the lack of clarity over whose responsibility cloud security really is, are two major contributors to these incidents.

According to Venafi, 81% of firms experienced at least one such incident in the last year. Almost half (45%) suffered as many as four incidents. 

Security and operational risks

Most of the time, they experience security incidents during runtime (34%), unauthorized access (33%), misconfigurations (32%), major vulnerabilities that haven’t been patched (24%), or failed audits (19%). 

At the same time, only unauthorized access made it to the top five list of the biggest operational and security concerns security decision-makers are having. There are also account, services, and traffic hacks (35%), malware and ransomware (31%), privacy issues (31%), and nation-state attacks (26%).

“Attackers are now on board with business’ shift to cloud computing,” says Kevin Bocek, vice president of security strategy and threat intelligence at Venafi. “The ripest target of attack in the cloud is identity management, especially machine identities. Each of these cloud services, containers, Kubernetes clusters and microservices needs an authenticated machine identity – such as a TLS certificate – to communicate securely. If any of these identities is compromised or misconfigured, it dramatically increases security and operational risks.”

The study has also shown how businesses don’t really know whose responsibility cloud security really is. Enterprise security teams (25%) are the most likely ones to manage app security in the cloud, right before operations teams (23%). For almost a quarter (22%) it should be a collaborative effort shared between multiple teams, while 16% think it should be the responsibility of developers writing cloud applications. 

Venafi seems to hint that shared responsibility models shouldn’t be adopted, as “security teams and development teams have very different goals and objectives”. While developers need to move fast, it creates visibility issues for security teams. “Without this visibility, security teams cannot evaluate how those controls stack up against security and governance policies,” the report states.

Organizations studied for the report currently host (opens in new tab) 41% of their applications in the cloud and expect the number to rise to 57% in the next year and a half.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Making a comeback, LeTV mobile phone S1 was released, and the selling point was actually "Made in China" thumbnail

Making a comeback, LeTV mobile phone S1 was released, and the selling point was actually “Made in China”

樂視闊別手機市場多年,在9月30人捲土重來,發布了新品——樂視手機S1,並正式開賣。作為樂視手機回歸的第一款產品,沒有選擇走性價比提升銷量或者高端旗艦,而是另闢蹊徑走「全(中)國產」道路。性能方面,樂視手機S1 採用了 6.53吋 LCD 水滴屏,解析度為 1600X720。搭載紫光展銳唐古拉T740(虎賁T7510)處理器,該處理器採用八核 CPU 架構,能效比≥2.5TOPS/W,配備 8GB RAM+256GB ROM。手機支援 SA/NSA 雙模組網,覆蓋中國主流5G頻段。此外,手機內置了4900mAh容量大電池,續航表現相信也會很不錯。拍攝方面,樂視手機S1 採用4800萬超清 Samsung CMOS 主鏡+微距鏡頭+景深鏡頭的後置三鏡配置。據樂視的介紹,樂視手機S1 手機的處理器、RAM、屏幕等均為中國供應商提供,中國本產佔比很高。除了大量採用國產硬件外,樂視手機S1 出乎意料的內置了華為賬號體系、華為 HMS Core、華為音樂、閱讀等多款華為應用。樂視智能生態執行副總裁李曉偉稱「樂視對於生態抱有開放的態度,不希望用戶選擇一個手機就被限定在某一生態,所以選擇與華為合作,用戶購買樂視手機之後,可以與華為產品互聯,也可以與樂視生態互聯。」在當下晶片等原材料供應短缺的市場下,樂視此時回歸手機市場遇到的困難是空前絕後的。樂視對此情景感慨道「能回來,比什麼都好,也希望市場能給我們一些時間,我們在努力中。」售價方面,樂視手機S1 售價1599元人民幣,購機還可獲贈 Ears Pro 無線藍牙耳機一對,不過價格絕對毫無性價比可言,應該想購買的人並不多。
Read More
Google's latest Pixel feature drop is here thumbnail

Google’s latest Pixel feature drop is here

Here we go again. See if this sounds familiar: a new update is rolling out to Google's Pixels, but the latest ones, namely the Pixel 6 and 6 Pro, have to wait and aren't getting the new software as soon as all the others. Well, it's happening this month too. Google has today unveiled its…
Read More
A Long Game thumbnail

A Long Game

“Every season since the Gold Rush, California has blossomed with new money — first in gold, then in land, cattle, railroads, agriculture, film images, shipbuilding, aerospace, electronics, television and commercial religions. The ease with which the happy few become suddenly rich lends credence to the belief in magical transformation.” — Lewis Lapham, 1979, “Lost Horizon” “When do you think…
Read More
Förhandsversion av nya Microsoft Defender ute nu thumbnail

Förhandsversion av nya Microsoft Defender ute nu

Senast i januari rapporterade vi om nya rykten om att Microsoft ska bredda konsumentversionen av Defender från en renodlad Windows-funktion till alla de stora plattformarna. Företagsversionen har funnits för Mac, Android och Linux sedan ett par år tillbaka.Nu har företaget släppt en förhandsversion av det nya programmet som kallas Microsoft Defender Preview och till att…
Read More
Index Of News