Cloud security could be the biggest risk your workplace faces

Cloud Security
(Image credit: laymanzoom / Shutterstock)

As cloud computing usage in the workplace grows, so do related cybersecurity threats, new research has warned.

A report from Secure Access Service Edge (SASE) provider Netskope claims malware delivered via cloud apps now accounts for more than two-thirds (68%) of all malware delivered to businesses.

Furthermore, malicious Office documents now make up almost half (43%) of all malware downloads. At the same time, cloud app usage is growing, rising by almost a quarter (22%) in the first half of 2021 alone, with the average company now using 805 distinct apps and cloud services.

However, of those apps, almost all - 97% - are shadow IT, which could be posing a significant security problem.

Another major issue is managing sanctioned cloud applications and IaaS. At the moment, more than a third (35%) of all workloads within AWS, Azure, and Google Cloud Platform are “unrestricted”, meaning they’re free for viewing, to anyone who knows where to look.

Using corporate Google credentials as a convenient shortcut to log into third-party apps, something 97% of businesses allegedly do - is also another major attack opportunity, the report further claims. This shortcut requires third-party app access to various permissions, and if users allow access to view and manage Google Drive files, that places all those files at risk.

Insider threats

Insiders also present a major threat to the cybersecurity posture of an organization, as many departing employees usually take significant amounts of data with them. According to the report, employees that are in their final 30 days with the company, upload three times more data to personal apps, with 15% of that data originating either from a corporate app, or directly violates corporate data policy.

These employees mostly pick up the files from Google Drive or Microsoft OneDrive.

For Ray Canzanese, Threat Research Director at Netskope, in order to mitigate these threats, enterprises should “rethink security” based on the reality of cloud application use. Businesses should opt for a security architecture that provides context for apps, cloud services and web user activity, and that applies zero-trust controls.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
A person in a wheelchair working at a computer.
Why betting on Mac security could put your organization at risk
Fraude en ligne phishing
Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks
Security
Protect your network with an AI-secure browser and SASE framework
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
Latest in Pro
A person holding out their hand with a digital AI symbol.
AI is booming — but are businesses seeing real impact?
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
A business woman looking at AI on a transparent screen
Most businesses are now fully embracing AI - but aren't always protected against the risks
Hands on a laptop with overlaid logos representing network security
Winning the war on ransomware with multi-layer security
Protection from AI hacker attacks
Maintaining SAP’s confidentiality, integrity, and availability triad
Latest in News
An image of the Nintendo Switch 2
Nintendo Switch 2 pre-orders will start on April 2 according to Best Buy Canada
Person printing
Microsoft’s latest Windows 11 update exorcises possessed printers that spewed out pages of random characters
Pro-Ject A1.2 in black, playing a vinyl record in a hi-fi listening room
Pro-Ject's new fully-automatic turntable could be the buy of Record Store Day 2025
Intergalactic: The Heretic Prophet
Intergalactic: The Heretic Prophet reportedly won't release until after 2026, as Neil Druckmann says that staff 'are playing it at the office' right now - but I don't think I can wait that long
Screenshot from action RPG soulslike Lies of P
Lies of P Overture won't elaborate on the game's eyebrow-raising post-credits twist, and I think that's good news
Nintendo Switch 2
The Switch 2 launching with a Mario Kart game 'is very unlike Nintendo' compared to the original Switch releasing with Breath of the Wild, says former marketing leads: 'That's what's gonna make you want to buy the new hardware'