Todays organizations desire the accessibility and flexibility of the cloud, yet these benefits ultimately mean little if youre not operating securely. One misconfigured server and your company may be looking at financial or reputational damage that takes years to overcome.
Fortunately, theres no reason why cloud computing cant be done securely. You need to recognize the most critical cloud security challenges and develop a strategy for minimizing these risks. By doing so, you can get ahead of problems before they start, and help ensure that your security posture is strong enough to keep your core assets safe in any environment.
With that in mind, lets dive into the five most pressing cloud security challenges faced by modern organizations.
According to Gartner, the shift to cloud computing will generate roughly $1.3 trillion in IT spending by 2022. The vast majority of enterprise workloads are now run on public, private or hybrid cloud environments.
Yet if organizations heedlessly race to migrate without making security a primary consideration, critical assets can be left unprotected and exposed to potential compromise. To ensure that migration does not create unnecessary risks, its important to:
Effectively managing and defining the roles, privileges and responsibilities of various network users is a critical objective for maintaining robust security. This means giving the right users the right access to the right assets in the appropriate context.
As workers come and go and roles change, this mandate can be quite a challenge, especially in the context of the cloud, where data can be accessed from anywhere. Fortunately, technology has improved our ability to track activities, adjust roles and enforce policies in a way that minimizes risk.
Todays organizations have no shortage of end-to-end solutions for identity governance and management. Yet its important to understand that these tools alone are not the answer. No governance or management product can provide perfect protection as organizations are eternally at the mercy of human error. To help support smart identity and access management, its critical to have a layered and active approach to managing and mitigating security vulnerabilities that will inevitably arise.
Taking steps like practicing the principle of least privilege by permitting only the minimal amount of access necessary to perform tasks will greatly enhance your security posture.
The explosive growth of cloud computing has highlighted new and deeper relationships between businesses and vendors, as organizations seek to maximize efficiencies through outsourcing and vendors assume more important roles in business operations. Effectively managing vendor relations within the context of the cloud is a core challenge for businesses moving forward.
Why? Because integrating third-party vendors often substantially raises cybersecurity risk. A Ponemon institute study in 2018 noted that nearly 60% of companies surveyed had encountered a breach due to a third-party. APT groups have adopted a strategy of targeting large enterprises via such smaller partners, where security is often weaker. Adversaries know youre only as strong as your weakest link and take the least path of resistance to compromise assets. Due to this, it is incumbent upon todays organizations to vigorously and securely manage third-party vendor relations in the cloud. This means developing appropriate guidance for SaaS operations (including sourcing and procurement solutions) and undertaking periodic vendor security evaluations.
APIs are the key to successful cloud integration and interoperability. Yet insecure APIs are also one of the most significant threats to cloud security. Adversaries can exploit an open line of communication and steal valuable private data by compromising APIs. How often does this really occur? Consider this: By 2022, Gartner predicts insecure APIs will be the vector most commonly used to target enterprise application data.
With APIs growing ever more critical, attackers will continue to use tactics such as exploiting inadequate authentications or planting vulnerabilities within open source code, creating the possibility of devastating supply chain attacks. To minimize the odds of this occurring, developers should design APIs with proper authentication and access control in mind and seek to maintain as much visibility as possible into the enterprise security environment. This will allow for the quick identification and remediation of such API risks.
Weve mentioned visibility on multiple occasions in this article and for good reason. It is one of the keys to operating securely in the cloud. The ability to tell friend from foe (or authorized user from unauthorized user) is a prerequisite for protecting the cloud. Unfortunately, thats a challenging task as cloud environments grow larger, busier and more complex.
Controlling shadow IT and maintaining better user visibility via behavior analytics and other tools should be a top priority for organizations. Given the lack of visibility across many contexts within cloud environments, its a smart play to develop a security posture that is dedicated to continuous improvement and supported by continuous testing and monitoring.
Cloud security is achievable as long as you understand, anticipate and address the most significant challenges posed by migration and operation. By following the ideas outlined above, your organization will be in a much stronger position to prevent and defeat even the most determined adversaries.
More:
Five critical cloud security challenges and how to overcome them - Help Net Security
- Roundup Of Cloud Computing Forecasts, 2017 - Forbes - May 3rd, 2017 [May 3rd, 2017]
- RCom arm in tie-up for cloud computing - Moneycontrol.com - May 3rd, 2017 [May 3rd, 2017]
- How Do You Define Cloud Computing? - Data Center Knowledge - May 3rd, 2017 [May 3rd, 2017]
- 5 Cloud Computing Stocks to Buy - TheStreet.com - May 3rd, 2017 [May 3rd, 2017]
- Cloud Computing Continues to Influence HPC - insideHPC - May 3rd, 2017 [May 3rd, 2017]
- Red Hat's New Products Centered Around Cloud Computing, Containers - Virtualization Review - May 3rd, 2017 [May 3rd, 2017]
- Adobe bets big on cloud computing for marketing, creative professionals - Livemint - May 3rd, 2017 [May 3rd, 2017]
- Verizon sells cloud services to IBM in 'unique cooperation between ... - Cloud Tech - May 3rd, 2017 [May 3rd, 2017]
- How Cloud Computing Is Turning the Tide on Heart Attacks - Fortune - May 3rd, 2017 [May 3rd, 2017]
- Hospital CIOs see benefits of healthcare cloud computing - TechTarget - May 3rd, 2017 [May 3rd, 2017]
- Trends In Cloud Computing - Business Solutions Magazine - June 6th, 2017 [June 6th, 2017]
- A deeper dive into cloud security as a service: Advantages and issues - Cloud Tech - June 6th, 2017 [June 6th, 2017]
- OpenText buys cloud computing firm for US$103 million - TheRecord.com - June 6th, 2017 [June 6th, 2017]
- Belfast IT firm celebrates cloud computing success in 57 countries ... - Belfast Telegraph - June 6th, 2017 [June 6th, 2017]
- Meet The Cloud Wars Top 10: The World's Most-Powerful Cloud-Computing Vendors - Forbes - June 6th, 2017 [June 6th, 2017]
- How to approach cloud computing and cyber security in 2017 - Information Age - June 6th, 2017 [June 6th, 2017]
- CFOs have discovered the big stick of cloud computing - InfoWorld - June 6th, 2017 [June 6th, 2017]
- Belmont Stakes Odds 2017: Latest Vegas Betting Lines Before Post Positions Draw - Bleacher Report - June 7th, 2017 [June 7th, 2017]
- Cloudistics Announces New Cloud Computing Program That Enables High Margin Reoccurring Revenue Models for ... - Marketwired (press release) - June 7th, 2017 [June 7th, 2017]
- CloudCheckr, cloud computing company expects rapid growth in Rochester - WXXI News - June 7th, 2017 [June 7th, 2017]
- IBM Losing Facebook's WhatsApp as Cloud Customer, says CNBC - Barron's - June 7th, 2017 [June 7th, 2017]
- What My Father Taught Me About Cloud Computing - Virtualization Review - June 7th, 2017 [June 7th, 2017]
- Workday Phenomenon Goes Global As Cloud Computing Goes Mainstream - Forbes - June 7th, 2017 [June 7th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - JD Supra (press release) - June 9th, 2017 [June 9th, 2017]
- 3 Things You Should Know About Cloud Computing Right Now - Fortune - June 9th, 2017 [June 9th, 2017]
- Learning in the Sky: Collaborative Robots Embrace Cloud Computing - Machine Design - June 9th, 2017 [June 9th, 2017]
- Best Practices To Manage Your Hybrid Cloud - Forbes - June 9th, 2017 [June 9th, 2017]
- Here's how venture capitalists are thinking about cloud computing companies and technologies - GeekWire - June 9th, 2017 [June 9th, 2017]
- Amazon is helping veterans find jobs in cloud computing - Marketplace - Marketplace.org - June 9th, 2017 [June 9th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - Lexology (registration) - June 9th, 2017 [June 9th, 2017]
- Growing Patent Claim Risks in Cloud Computing - Lexology (registration) - June 9th, 2017 [June 9th, 2017]
- The benefits of cloud computing, Rust 1.18, and intelligent tracking prevention in WebKit SD Times news digest ... - SDTimes.com - June 9th, 2017 [June 9th, 2017]
- Edge Computing Is New Cloud Computing Tech Investors Should Track - GuruFocus.com - June 9th, 2017 [June 9th, 2017]
- Real Estate Weekly: Digital Realty Becomes A Cloud Computing Giant - Seeking Alpha - June 9th, 2017 [June 9th, 2017]
- Virtualization admin? Pivot -- pivot now -- to a cloud computing career - TechTarget - June 10th, 2017 [June 10th, 2017]
- Why isn't Cloud Computing in the 2017 Belmont Stakes? - FanSided - June 11th, 2017 [June 11th, 2017]
- Cloud Computing Companies Move Into Medical Diagnosis (GOOG, IBM) - Investopedia - June 11th, 2017 [June 11th, 2017]
- China's cloud industry moving to new era with emergence of unicorns - TechNode (blog) - June 12th, 2017 [June 12th, 2017]
- Terry Crews Is On Crackdown 3 Trailer, No Cloud Computing For Single Player - EconoTimes - June 12th, 2017 [June 12th, 2017]
- The Risks and Perquisites of Cloud Computing - DATAQUEST - June 12th, 2017 [June 12th, 2017]
- Alibaba Cloud announces launch of data centres in India and Indonesia - Cloud Tech - June 12th, 2017 [June 12th, 2017]
- Indonesia banks have yet to implement cloud computing - Jakarta Post - June 13th, 2017 [June 13th, 2017]
- 'Sweden is heaven for cloud computing': Amazon Nordic chief - The ... - The Local Sweden - June 14th, 2017 [June 14th, 2017]
- Amazon.com to open second government cloud-computing region ... - The Seattle Times - June 14th, 2017 [June 14th, 2017]
- Shadow raises $57 million for its cloud computing service for ... - TechCrunch - June 14th, 2017 [June 14th, 2017]
- Amazon Still Leads Cloud Rankings, But Competition Is Coming On Strong - Fortune - June 16th, 2017 [June 16th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 | Air ... - Air Cargo World (registration) - June 17th, 2017 [June 17th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 - Air Cargo World (registration) - June 17th, 2017 [June 17th, 2017]
- Pressing Tech Issue: Enterprise Software Vs. Cloud Computing? - Credit Union Times - June 17th, 2017 [June 17th, 2017]
- 7 Tips for Securely Moving Data to the Cloud - Government Technology (blog) - June 20th, 2017 [June 20th, 2017]
- Chinese tech giant Alibaba joins key open-source cloud computing foundation - GeekWire - June 20th, 2017 [June 20th, 2017]
- Microsoft Could Surpass Amazon in Cloud Computing This Year (AMZN, MSFT) - Investopedia - June 20th, 2017 [June 20th, 2017]
- GDS Holdings Limited (GDS) Announces Strategic Partnership with Tencent Cloud - StreetInsider.com - June 20th, 2017 [June 20th, 2017]
- Cloud first - Philippine Star - June 20th, 2017 [June 20th, 2017]
- Three Considerations for Reducing Risk in Cloud Computing - CIOReview - June 21st, 2017 [June 21st, 2017]
- Cloud Computing and Digital Divide 2.0 - CircleID - CircleID - June 21st, 2017 [June 21st, 2017]
- Microsoft will ride artificial intelligence, cloud computing to higher ... - CNBC - June 21st, 2017 [June 21st, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- Update - Fox Business - June 21st, 2017 [June 21st, 2017]
- Report affirms continued cloud spend for US businesses in 2017 - Cloud Tech - June 22nd, 2017 [June 22nd, 2017]
- Catching up with an interconnected federal cloud - GCN.com - June 22nd, 2017 [June 22nd, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- 2nd Update - Fox Business - June 22nd, 2017 [June 22nd, 2017]
- Cisco adapts to the rise of cloud computing - The Economist - June 22nd, 2017 [June 22nd, 2017]
- Amazon accuses Walmart of bullying in cloud computing clash - BBC News - June 22nd, 2017 [June 22nd, 2017]
- Companies plan to spend more on cloud computing services this year, higher prices among drivers: Clutch - Canadian Underwriter - June 23rd, 2017 [June 23rd, 2017]
- Survey: businesses ramp up spending on cloud computing DC ... - DC Velocity - June 24th, 2017 [June 24th, 2017]
- Morgan Stanley: Cloud computing is at 'an inflection point' but how big will it get? - GeekWire - June 26th, 2017 [June 26th, 2017]
- How the cloud has changed education and training - TNW - June 26th, 2017 [June 26th, 2017]
- Cloud computing key to 4th industrial revolution - News VietNamNet - VietNamNet Bridge - June 26th, 2017 [June 26th, 2017]
- Lady Eli, Cloud Computing Among Workers for Brown - BloodHorse.com (press release) (registration) (blog) - June 26th, 2017 [June 26th, 2017]
- Microsoft signs cloud-computing partnership with Box - The Seattle Times - June 27th, 2017 [June 27th, 2017]
- Microsoft Signs Cloud Computing Partnership with Box - CIO Today - June 30th, 2017 [June 30th, 2017]
- US action on Microsoft email case could devastate cloud computing - Irish Times - June 30th, 2017 [June 30th, 2017]
- Cloud computing challenges today: Planning, process and people - TechTarget - July 2nd, 2017 [July 2nd, 2017]
- Five podcasts to catch up on the latest trends in cloud computing - TechTarget - July 2nd, 2017 [July 2nd, 2017]
- Microsoft reportedly set to lay off thousands as part of massive sales reorganization - GeekWire - July 3rd, 2017 [July 3rd, 2017]
- VMware to surge more than 20 percent because the Amazon cloud ... - CNBC - August 25th, 2017 [August 25th, 2017]
- Google Unveils Custom Hardware Chip for Cloud - Investopedia - August 25th, 2017 [August 25th, 2017]
- Cloud Computing Confirmed for Travers | TDN | Thoroughbred Daily ... - Thoroughbred Daily News - August 25th, 2017 [August 25th, 2017]
- Why 2017 Is The Year To Understand Cloud Computing - Nasdaq - August 25th, 2017 [August 25th, 2017]
- Biz Cloud Computing - Four States Homepage - August 25th, 2017 [August 25th, 2017]