May 3, 2016 By Rick M Robinson 2 min read

Cloud Risks Are Real

The cloud wars are over, and of course the cloud won. We don’t just deal with the cloud; when it comes to IT, we pretty much live in the cloud. The most obvious result is enormous power at our fingertips — even when our fingers are on the go.

The power of the cloud also means that cloud risks are all around us. Since the cloud is everywhere, we may not even think of those risks as cloud-related — but they are, which means basic cloud security education is essential.

BYOCA: Bring-Your-Own-Cloud-App and Other Blunders

Remember when bring-your-own-device (BYOD) first became a big security concern? It still is, by the way, and it’s easy to forget that those mobile devices are used almost entirely for mobile access to — wait for it — the cloud.

It’s not just mobile, either. As Dennis McCafferty pointed out at CIO Insight, laptops are the primary way business users access the cloud.

The basic fact of cloud risks and cloud security is that it is a shared responsibility. According to Yotam Gutman at Infosec Island, the vendor, be it the cloud provider or a cloud resource provider, is typically responsible for offering a secured service. The client — you or your employee — is responsible for using it securely.

Cloud services vendors can and do slip up, but the real challenge is on the client end. Mistakes are legion. Infosec Island reported that one-third of business users surveyed have downloaded work-related apps without telling IT. Most probably never thought twice about it, especially if they were using a company-provided device.

The cloud also supports creative new versions of old-fashioned security blunders. One-quarter of respondents in the “(Still) Careless Users in the Cloud” survey stored passwords in documents that weren’t password-protected. When left in an unprotected document, that password is conveniently available to the cybercriminal working from anywhere around the world. Additionally, anyone could walk into an office and see the 20 percent of passwords written on a sticky note, according to the report. These poor practices could ultimately result in damaging breaches for an organization.

Security Education Should Not Be a Teachable Moment

More often than not, basic cloud security mistakes are made by people who have no idea that they are doing something risky. No warning sign comes up; employees only see the cloud as another resource that comes up on their monitor — not the massive risk it actually is. The time to discover the need for basic cloud security education is not when a breach occurs and company data spills all over the Internet.

Yes, a growing range of security solutions are available for protecting against specific cloud risks. But the most critical line of protection remains the human user. Organizations need to protect themselves and their people from the hazards of the cloud by educating them in security awareness for the cloud era.

Learn more about Cloud Security

More from Cloud Security

The compelling need for cloud-native data protection

4 min read - Cloud environments were frequent targets for cyber attackers in 2023. Eighty-two percent of breaches that involved data stored in the cloud were in public, private or multi-cloud environments. Attackers gained the most access to multi-cloud environments, with 39% of breaches spanning multi-cloud environments because of the more complicated security issues. The cost of these cloud breaches totaled $4.75 million, higher than the average cost of $4.45 million for all data breaches.The reason for this high cost is not only the…

Accelerating security outcomes with a cloud-native SIEM

5 min read - As organizations modernize their IT infrastructure and increase adoption of cloud services, security teams face new challenges in terms of staffing, budgets and technologies. To keep pace, security programs must evolve to secure modern IT environments against fast-evolving threats with constrained resources. This will require rethinking traditional security strategies and focusing investments on capabilities like cloud security, AI-powered defense and skills development. The path forward calls on security teams to be agile, innovative and strategic amidst the changes in technology…

Best practices for cloud configuration security

5 min read - Cloud computing has become an integral part of IT infrastructure for businesses of all sizes, providing on-demand access to a wide range of services and resources. The evolution of cloud computing has been driven by the need for more efficient, scalable and cost-effective ways to deliver computing resources.Cloud computing enables on-demand access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications and services) over the internet. Instead of owning and maintaining physical hardware and infrastructure, users…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today