Google has some recommendations for keeping your business safe

A blue color image of a person trying to log into a protected laptop.
(Image credit: Shutterstock/JARIRIYAWAT)

A new report has highlighted some of the biggest cybersecurity mistakes coming from businesses, but also offered some advice on how to deal with these threats.

Research from Mandiant for Google Cloud outlined how, during the first three months of 2023, having a weak password or even not having one accounted for more than half (54.8%) of all cloud compromise factors, followed by misconfiguration in second place accounting for 19% and API exposure at 11.9%.

Being that compromised credentials are of greatest concern (a further 7.1% of factors were made up of leaked passwords), Google Cloud shifts the emphasis onto the company to implement stronger identity management guardrails at org level.

Businesses continue to make cybersecurity mistakes

The company also made a note of malicious Android apps that are also targeting employees’ credentials. Without protective measures in place, those issued with business phones may download apps of their own accord.

Google pointed out a common tactic observed whereby threat actors create a seemingly legitimate app in order to gain Play Store approval before updating it to carry a malicious payload.

Companies can take simple action to prevent this by creating application allowlists across their fleet of smartphones and tablets. 

While smaller in number, domain and IP compromises were also prevalent in the first quarter of 2023, with remedies including adequate endpoint protection and regular scanning and examination.

Finally, a distinct threat to the telecommunications industry was recorded with breaches affecting T-Mobile, AT&T, and Dish all in the US alone during the first half of 2023. Other cyber, DDoS, and ransomware attacks were also observed, which Google Cloud puts down to threats both from nation-states and other cybercriminals.

As businesses continue their transition to cloud, it’s clear than an enhanced focus on cybersecurity is needed in an era of increased attacks in order to secure sensitive information.

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Holographic representation of cloud computing over open businessman's hand
AWS, Azure and Google Cloud credentials from old accounts are putting businesses at risk
API
Businesses are being plagued by API security risks - with nearly 99% affected
Flags of Iran, China, Russia and North Korea on a wall. China North Korea Iran Russia alliance
Cybercrime is helping fund rogue nations across the world - and it's only going to get worse, Google warns
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
Cyber-security
Many firms see cyberattacks as their top business concern this year
Security padlock in circuit board, digital encryption concept
Rising cost of breaches forces organizations to rethink cybersecurity
Latest in Pro
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Customer service 3D manager concept. AI assistance headphone call center
The era of Agentic AI
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
A hand reaching out to touch a futuristic rendering of an AI processor.
Balancing innovation and security in an era of intensifying global competition
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off