Thales: For Data Breaches, Cloud Assets are Biggest Cybersecurity Headache

Products You May Like

Thales cloud safety research exhibits that 79% of organizations have multiple cloud supplier and 75% of firms stated they retailer no less than 40% of their delicate information within the cloud.

The Thales logo on an office building.
Picture: Adobe Inventory/Florence Piot

Whereas Thales, in its 2023 Cloud Security Study, discovered that effectively over a 3rd (39%) of companies skilled an information breach of their cloud surroundings final 12 months versus 34% in 2021, organizations are more and more caching delicate information in a number of cloud environments.

Within the report, based mostly on a survey of three,000 IT and safety groups throughout 18 nations in EMEA, the Americas and Asia Pacific:

  • Seventy-five p.c of IT executives categorized as delicate greater than 40% of their information saved within the cloud, in comparison with 49% this time final 12 months.
  • Thirty-eight p.c of respondents stated software program as a service functions are the principle goal for hackers, adopted by cloud-based storage (36%).

Multicloud inflicting operational complexity

The research exhibits how extra firms are utilizing extra cloud service providers, monitoring with the 35% progress within the variety of reported suppliers out there. The research authors famous that the common variety of cloud infrastructure suppliers is now 2.3, and that greater than three-quarters (79%) of this 12 months’s respondents have multiple cloud supplier (Determine A).

Determine A

A growing number of organizations are using multiple cloud service providers.
A rising variety of organizations are utilizing a number of cloud service suppliers. Picture: Thales

“With a larger number of platforms to secure, the opportunity for operational errors grows, increasing the attack surface with each error. Organizations either have to dedicate separate teams to specialize in each platform or expect their security teams to become well-versed in multiple platforms at the same time,” in line with the research.

Extra delicate information being saved within the cloud

The research reported that organizations are lifting extra workloads and information into the cloud: The variety of organizations that reported that 60% or extra of their workloads are within the cloud elevated from 23% to 27% 12 months over 12 months.

SEE: Learn how IBM is boosting cloud data practice (TechRepublic)

The report polled respondents two methods about delicate information within the cloud to find out how they’re deploying their information and noticed will increase in each instructions. The survey requested about:

  • The proportion of a company’s whole delicate information that’s saved within the cloud.
  • The proportion of all the information a company shops within the cloud that’s delicate.

It discovered that:

  • In final 12 months’s research, 52% of respondents stated that greater than 40% of their delicate information was within the cloud. This 12 months, that quantity elevated to 64%.
  • The variety of respondents who stated that 40% or extra of their information saved within the cloud is delicate information, elevated from 49% in final 12 months’s research, to 75% this 12 months.

Encryption is rising, however slowly

On this 12 months’s research, 22% of respondents stated that over 60% of their delicate information within the cloud is encrypted and 40% stated over half of that cloud-based delicate information is encrypted. These numbers represent an enchancment from final 12 months’s research, which reported that solely 17% of respondents had stated over half of their delicate information within the cloud was encrypted. That stated, solely 2% stated 100% of their delicate information within the cloud is encrypted (Determine B).

Determine B

A percentage of organizations' sensitive data in the cloud is encrypted.
A share of organizations’ delicate information within the cloud is encrypted. Picture: Thales

Moreover, 62% of IT executives who responded to the survey stated they’ve 5 or extra key administration programs, which Thales stated constitutes elevated complexity for securing delicate information.

Software program-as-a-service creating safety challenges

Not solely do most firms report having a number of cloud service suppliers, the rise in the usage of SaaS apps is increasing the risk floor for information exfiltration:

  • Within the 2022 research, 16% of respondents reported their enterprises deployed 51-100 totally different SaaS functions.
  • On this 12 months’s research, that proportion grew to 22% of respondents, and 55% (versus 46% within the prior 12 months) famous that managing information within the cloud is extra advanced than in on-premise environments.
  • Moreover, 83% expressed issues over information sovereignty, with 55% of respondents asserting that information privateness and compliance within the cloud has develop into tougher.

The research included a rating query on which assault targets are most definitely to be attacked. SaaS was talked about first by 38% of respondents, adopted by cloud storage at 36% of these polled. Moreover, the research’s authors stated the variety of survey respondents reporting an information breach in the course of the research interval was up 4% from final 12 months’s report — 35% to 39%.

Data breaches and human error

Over half (55%) of respondents to the survey stated human error triggered cloud information breaches at their organizations, however solely 41% of organizations have carried out zero-trust controls of their cloud infrastructure — solely 38% use zero-trust protocols of their cloud networks. Nonetheless, extra firms are adopting authentication protocols for workers: 65% of respondents to Thales’ survey stated they now deploy multifactor authentication.

SEE: Palo Alto Networks on otherwise about cloud security (TechRepublic)

“Organizations are operating in a dynamic multi-cloud landscape, demanding seamless and efficient security measures,” stated Sebastien Cano, senior vp for cloud safety and licensing actions at Thales.

“To overcome challenges arising from human error and misconfiguration, it is imperative that data protections in the cloud are simplified and easily manageable.” He stated that the important thing to enhancing cloud safety lies in treating cloud environments as an extension of current infrastructure. “By adopting this approach, organizations can effectively bolster security and ensure comprehensive protection across the entire digital ecosystem.”

Cybersecurity

Products You May Like

Leave a Reply

Your email address will not be published. Required fields are marked *