Data in the cloud may be more exposed than organizations think: report

Published: Friday, 02 November 2018 08:58

McAfee has released its Cloud Adoption and Risk Report, which analyzed billions of events in anonymised customers production cloud use to assess the current state of cloud deployments and to uncover risks. The report reveals that nearly a quarter of the data in the cloud can be categorised as sensitive, putting an organization at risk if stolen or leaked. Coupled with the fact that sharing sensitive data in the cloud has increased 53 percent year-on-year, those who do not adopt a cloud strategy that includes data loss protection, configuration audits and collaboration controls, will endanger the security of their data while exposing themselves to increased risk of noncompliance with internal and external regulations.

The study found that while organizations aggressively use the public cloud to create new digital experiences for their customers, the average enterprise experiences more than 2,200 misconfiguration incidents per month in their infrastructure-as-a-service (IaaS) and platform-as-a-service (PaaS) instances. Cloud service providers only cover the security of the cloud itself, not customer data or customer use of their infrastructure and platforms. Companies are always responsible for securing their data wherever it is, hence highlighting the need to deploy cloud security solutions that span the whole cloud spectrum, from SaaS (software-as-a-service) to IaaS and PaaS.

“Operating in the cloud has become the new normal for organizations, so much so that our employees do not think twice about storing and sharing sensitive data in the cloud,” said Rajiv Gupta, senior vice president of the Cloud Security Business, McAfee.  “Accidental sharing, collaboration errors in SaaS cloud services, configuration errors in IaaS/PaaS cloud services, and threats are all increasing.”

Cloud services bring a momentous opportunity to accelerate business through their ability to quickly scale, allowing businesses to be agile with their resources and provide new opportunities for collaboration. Cloud services like Box and productivity suites like Office 365 are used to increase the fluidity and effectiveness of collaboration. However, collaboration means sharing, and uncontrolled sharing can expose sensitive data. Findings demonstrate that:

To secure sensitive data in cloud storage, file-sharing and collaboration applications, organizations must first understand which cloud services are in use, hold their sensitive data, and how that data is being shared and with whom. Once organizations have gained this visibility, they can then enforce appropriate security policies to prohibit highly sensitive data from being stored in unapproved cloud services and provide guardrails that prevent noncompliant sharing of sensitive data from approved cloud services, such as when data is shared with personal email addresses or through an open, public link.

IaaS and the risks of misconfiguration

With SaaS, securing data, user identity and access to data is primarily the customer’s responsibility. With IaaS, customers take on a much larger share of security responsibility that includes data, identity, access, applications, network controls and host infrastructure. While this provides customers with an opportunity to have greater control over their cloud infrastructure, it also increases the organization’s surface area for security risks and their responsibility for the same. IaaS providers, like Amazon Web Services (AWS), provide several infrastructure and platform services, each having deep and complicated security settings. Magnifying the IaaS/PaaS security challenge is the fact that organizations use multiple IaaS/PaaS vendors running several instances of each vendor’s product.

McAfee’s research found that:

Compromised accounts and insider threats

Most of the threats to data in the cloud result from compromised accounts and insider threats. The average organization generates over 3.2 billion events per month in the cloud, of which 3,217 are anomalous behaviors and 31.3 are actual threat events. In addition:

Survey methodology

For the Cloud Adoption and Risk Report, McAfee analyzed aggregated, anonymised cloud usage data for over 30 million McAfee MVISION Cloud users worldwide at companies across all major industries including financial services, healthcare, public sector, education, retail, high tech, manufacturing, energy, utilities, legal, real estate, transportation and business services. Collectively, these users generate billions of unique transactions in the cloud each day. The McAfee cloud service registry tracks over 50 attributes of enterprise readiness, which provides the ability to track behavior using detailed data signatures for over 25,000 cloud services. Additional contextual data was sourced from a survey of 1,400 security professionals in 11 countries, all using public or private cloud services.

Read the report (registration required).