Nearly all firms have some kind of cloud misconfiguration issue

A person at a laptop with a secure lock symbol floating above it.
(Image credit: Shutterstock / laymanzoom)

New research by Zscaler Threatlabz has found many businesses haven’t set up their cloud technologies correctly, potentially exposing themselves to some serious vulnerabilities and risk of cyberattacks.

The research analyzed more than 260 billion daily transactions globally across Zscaler’s platform, which uncovered some pretty disconcerting results.

Among the key findings were misconfigurations that had put almost all businesses at risk, as well as the lack of adoption of some pretty basic technology that goes a long way to protect users.

Data exposure on the cloud

The number of organizations that have “concerning” misconfigurations that cause “critical” risks to data and infrastructure sits at an alarming 98.6%. However, Zscaler stresses that these are merely misconfigurations and not vulnerabilities, meaning that with the correct care and attention, the risk could be minimized drastically.

It also found that 68% of companies had given external users admin permissions, which increases the risk of data exfiltration and exploits. While this isn’t a misconfiguration as such - as it’s likely intentional - businesses should carefully consider exactly who needs higher levels of permission.

The study also found that very few organizations employ basic protection in the form of multi-factor authentication (MFA) to privileged user accounts, which means that a leaked or otherwise exposed password could be all that a malicious user needs to gain access to sensitive company information.

Moving away from misconfigurations, Zscaler highlighted the number of companies who blatantly fail to apply basic ransomware controls for cloud storage (which sits at 59.4%), which could be a cost-saving effort that puts them at serious risk.

Overall, it’s clear that almost every business can take basic steps to protect its data before needing to fork out for expensive and more advanced tools.

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
API
Businesses are being plagued by API security risks - with nearly 99% affected
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Hacker Typing
Racing against time on a menacing caldera: survey finds majority of organizations take days to tackle critical vulnerabilities, each of them a potential open goal for cybercriminals
Digital clouds against a blue background.
Companies still want to do more with cloud, but security remains a key concern
Representational image of a hacker
The 10 worst software disasters of 2024: cyberattacks, malicious AI, and silent threats
Cyber-security
Many firms see cyberattacks as their top business concern this year
Latest in Pro
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Adobe Firefly
Adobe launches game-changing GenAI tools for video editing
Adobe AI agents
Adobe launches 10 new AI agents to automate key marketing workflows
Data leak
Top California sperm bank suffers embarrassing leak
Latest in News
Stability AI 3D Video
Stability AI’s new virtual camera turns any image into a cool 3D video and I’m blown away by how good it is
The Google Wallet app with a mode for kids shown on-screen.
Google Wallet’s new kid-friendly payment system is a win for parents
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years