Cloud security could be the biggest risk your workplace faces

Cloud Security
(Image credit: laymanzoom / Shutterstock)

As cloud computing usage in the workplace grows, so do related cybersecurity threats, new research has warned.

A report from Secure Access Service Edge (SASE) provider Netskope claims malware delivered via cloud apps now accounts for more than two-thirds (68%) of all malware delivered to businesses.

Furthermore, malicious Office documents now make up almost half (43%) of all malware downloads. At the same time, cloud app usage is growing, rising by almost a quarter (22%) in the first half of 2021 alone, with the average company now using 805 distinct apps and cloud services.

However, of those apps, almost all - 97% - are shadow IT, which could be posing a significant security problem.

Another major issue is managing sanctioned cloud applications and IaaS. At the moment, more than a third (35%) of all workloads within AWS, Azure, and Google Cloud Platform are “unrestricted”, meaning they’re free for viewing, to anyone who knows where to look.

Using corporate Google credentials as a convenient shortcut to log into third-party apps, something 97% of businesses allegedly do - is also another major attack opportunity, the report further claims. This shortcut requires third-party app access to various permissions, and if users allow access to view and manage Google Drive files, that places all those files at risk.

Insider threats

Insiders also present a major threat to the cybersecurity posture of an organization, as many departing employees usually take significant amounts of data with them. According to the report, employees that are in their final 30 days with the company, upload three times more data to personal apps, with 15% of that data originating either from a corporate app, or directly violates corporate data policy.

These employees mostly pick up the files from Google Drive or Microsoft OneDrive.

For Ray Canzanese, Threat Research Director at Netskope, in order to mitigate these threats, enterprises should “rethink security” based on the reality of cloud application use. Businesses should opt for a security architecture that provides context for apps, cloud services and web user activity, and that applies zero-trust controls.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Fraude en ligne phishing
Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks
Holographic representation of cloud computing over open businessman's hand
AWS, Azure and Google Cloud credentials from old accounts are putting businesses at risk
Security
Protect your network with an AI-secure browser and SASE framework
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
A padlock resting on a keyboard.
AI-powered cyber threats demand enhanced security awareness for SMEs and supply chains
Latest in Pro
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Squarespace
Build a website for less with 10% off Squarespace subscriptions
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
UK Prime Minister Sir Kier Starmer
UK PM says AI should soon replace civil servants
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all