Nearly all firms have suffered cloud security threats this year

Image of someone clicking a cloud icon.
Image Credit: Shutterstock (Image credit: Shutterstock)

The vast majority of organizations have suffered at least one cloud-related cybersecurity incident in the last 12 months, a new report from Venafi has claimed. 

It found that rising complexity, and the lack of clarity over whose responsibility cloud security really is, are two major contributors to these incidents.

According to Venafi, 81% of firms experienced at least one such incident in the last year. Almost half (45%) suffered as many as four incidents. 

Security and operational risks

Most of the time, they experience security incidents during runtime (34%), unauthorized access (33%), misconfigurations (32%), major vulnerabilities that haven’t been patched (24%), or failed audits (19%). 

At the same time, only unauthorized access made it to the top five list of the biggest operational and security concerns security decision-makers are having. There are also account, services, and traffic hacks (35%), malware and ransomware (31%), privacy issues (31%), and nation-state attacks (26%).

“Attackers are now on board with business’ shift to cloud computing,” says Kevin Bocek, vice president of security strategy and threat intelligence at Venafi. “The ripest target of attack in the cloud is identity management, especially machine identities. Each of these cloud services, containers, Kubernetes clusters and microservices needs an authenticated machine identity – such as a TLS certificate – to communicate securely. If any of these identities is compromised or misconfigured, it dramatically increases security and operational risks.”

The study has also shown how businesses don’t really know whose responsibility cloud security really is. Enterprise security teams (25%) are the most likely ones to manage app security in the cloud, right before operations teams (23%). For almost a quarter (22%) it should be a collaborative effort shared between multiple teams, while 16% think it should be the responsibility of developers writing cloud applications. 

Venafi seems to hint that shared responsibility models shouldn’t be adopted, as “security teams and development teams have very different goals and objectives”. While developers need to move fast, it creates visibility issues for security teams. “Without this visibility, security teams cannot evaluate how those controls stack up against security and governance policies,” the report states.

Organizations studied for the report currently host 41% of their applications in the cloud and expect the number to rise to 57% in the next year and a half.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
API
Businesses are being plagued by API security risks - with nearly 99% affected
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Hacker Typing
Racing against time on a menacing caldera: survey finds majority of organizations take days to tackle critical vulnerabilities, each of them a potential open goal for cybercriminals
Representational image of a hacker
The 10 worst software disasters of 2024: cyberattacks, malicious AI, and silent threats
Security padlock in circuit board, digital encryption concept
Rising cost of breaches forces organizations to rethink cybersecurity
Cyber-security
Many firms see cyberattacks as their top business concern this year
Latest in Pro
cybersecurity
What's the right type of web hosting for me?
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
construction
Building in the digital age: why construction’s future depends on scaling jobsite intelligence
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras