February 2, 2018 By Rick M Robinson 2 min read

Cloud risks have filled the news cycle of late, but the real cloud security landscape is nothing like the headlines would have you believe.

For example, serverside ransomware attacks, despite their high public profile, account for only about 2 percent of recorded incidents, according to Alert Logic’s “2017 Cloud Security Report.” In contrast, nearly three-quarters of security events involve attacks on web applications.

The study asserted that the public cloud is actually fairly secure. In fact, according to the report’s data, organizations using on-premises solutions experienced 51 percent more security incidents than firms that operate in the public cloud. Private and hybrid clouds, however, still have their fair share of security gaps.

Mapping the Cloud Security Landscape

The study examined more than 2.2 million security incidents recorded by more than 3,800 organizations over an 18-month period, CIO Insight reported. It found that web application attacks accounted for 75 percent of all incidents and that 85 percent of firms experience such attacks. Injection attacks, such as SQL injections, were the most common type of incident.

Unsurprisingly, the report found that threat actors are particularly drawn to e-commerce platforms and content management systems (CMS). This supports the notion that cybercriminals are increasingly eager to get their hands on intellectual property.

The survey also looked at comparative rates of attack against different types of application hosting environments. The public cloud fared best, with customers reporting an average of 405 security incidents over the 18-month window. Companies with on-premises storage, on the other hand, averaged 612 incidents over the same period.

Cybercriminals Aim for the Clouds

To be sure, these comparisons must be viewed in context. Private clouds and hybrid cloud environments are generally used by companies that handle a lot of highly sensitive data — the kind that draws attackers. Still, it is notable that public cloud users experience markedly fewer security incidents than on-premises firms.

It’s also worth pointing out that plain old brute-force attacks accounted for 12 percent of incidents, with 52 percent of them aimed at Windows platforms. This is noteworthy because the enterprise world is still largely a Windows environment.

The study recommended a few basic best practices to help organizations protect themselves in an evolving cloud security environment, such as whitelisting, consistent patching and careful handling of access privileges. Despite the widespread uncertainty and many misconceptions about the cloud, one thing is for sure: As long as security gaps exist, cybercriminals will continue to target sensitive data, no matter where it resides.

More from Cloud Security

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Cloud threat report: Possible trend in cloud credential “oversaturation”

3 min read - For years now, the dark web has built and maintained its own evolving economy, supported by the acquisition and sales of stolen data, user login credentials and business IP. But much like any market today, the dark web economy is subject to supply and demand.A recent X-Force Cloud Threat Landscape Report has shed light on this fact, revealing a new trend in the average prices for stolen cloud access credentials. Since 2022, there has been a steady decrease in market…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today