Cyber Security Risks Of Cloud Computing

The global cloud market is expected to grow to $190+ billions by 2020. Cloud computing has brought the advantage of lower cost of ownership of IT applications, super-fast time to market, and unmatched surges in employee productivity.

From storage to data analytics, applications of all scales and sizes are operating on the cloud. Employees are bringing their own cloud based apps to work, furthering a culture of Bring Your Own Cloud (BYOC).

It’s fair to say, right from SMEs to large enterprises, all organisations are using dozens of cloud computing based tools, and will continue to do so.

However, does this increased cloud adoption not call for better understanding and mitigation of common cloud cyber security threats? This guide helps you understand the most common of these cyber security issues that threaten cloud computing applications.

Loss of Intellectual Property

An analysis done by Skyhigh revealed that more than 20% of the data kept on cloud by enterprises contains sensitive information, including but not limited to intellectual property. Now, most enterprises use multi-tenancy cloud services, wherein their data is kept in servers that are also used to deliver similar services, to other organisations.

Also, there are several entry level cloud based storage solution providers out there who are behind the security game, and lacking the state of the art data protection and security means. Any security breach faced by the cloud service provider compromises your sensitive data. Also, there are cloud storage vendors who misuse circuitous terms and conditions to establish ownership of the uploaded data!

Violations of Compliance and Regulatory Norms

There are several regulatory and compliance requirements facing enterprises in all kinds of markets and geographies. For instance, there’s HIPAA guidelines for private health information, and FERPA for student information. This means that enterprises need to ensure that their cloud storage and application service providers take care of these regulatory norms.

Also, for enterprises that promote the Bring Your Own Device and Bring Your Own Cloud concepts, ensuring compliance to these norms becomes a lot more challenging. Any security breaches and data leakages can lead to severe penalties and loss of brand equity.

Compromised Credentials and Authentication Breaches

Poor certificate and key management, weak passwords, and lax authentication are causes of frequent data breaches in cloud hosted applications.

• Enterprises struggle with identity management issues as they map permissions and privileges with user roles.
• Another huge problem area is when enterprises don’t remove or change user access when he/she quits or changes role.
• Lack of multifactor authentication is attributed as the reason behind the compromising of 80 million customer records in the Anthem breach, and several cloud applications still continue to lack this authentication.

Furthermore, developers are often guilty of leaving crypto-graphic keys and credentials within open source codes, which makes them free to grab at portals like GitHub.

Enterprises looking to federate identify management with a cloud provider need to be aware of all these issues, and how the vendor ensures protection.

Threats to APIs

Most cloud solution providers offer their APIs to enterprise IT teams to help them with cloud provisioning, orchestration, management, and monitoring. This makes the security and availability of cloud solutions dependent on the API security. Re Weak API interfaces expose cloud applications to risks of accountability, confidentiality, integrity, and availability.

For most enterprises, such APIs continue to be the most vulnerable layers because they’re fairly easily accessible via the open Internet. Rigorous penetration testing and security focused code reviews are key enablers of sustainable protection of these APIs from cyber-attacks.

Hijacking of Accounts

Surprising as it sounds, software exploits, fraud, and phishing are still prevalent everywhere you see. Cloud services are also vulnerable to these disruptive cyber-attacks, because cyber criminals have more means to monitor the activities of users on shared clouds.

The two most effective preventive means for a business to protect its cloud data and applications are:

• ensure there is no sharing of passwords and account details among users;
• ensure there are multifactor authentication schemes in place, wherever possible.

Prevention of account details loss is the first step to keeping cloud applications safe from phishing and other violations.

Abuse of Cloud Services

Cloud services can be misused to commit nefarious cyber-crimes, right from usage of cloud resources to access encryption keys, to launching DDoS attacks on an enterprise’s servers. Use of an enterprise’s cloud resources for such cyber-crimes has the following impacts:

• low availability of the cloud systems
• exposure to legal liabilities in form of lawsuits from impacted parties
• severe loss of reputation

Ensure your cloud service provider offers a mechanism of reporting abuse quickly to help avoid and control such issues.

Adotas.com

You Might Also Read:

Cloud Portability Is Still Science Fiction:

Cloud Security Analysed For Management (£)

 

« HBO Offers Hackers $250,000 'bug bounty'
You Might Need To Hire AI Expertise Sooner Than You Think »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

2|SEC Consulting (2-SEC)

2|SEC Consulting (2-SEC)

At 2|SEC Consulting, we deliver an end-to-end service of cyber and information security solutions which are tailored to each client’s exact security needs.

SK-CERT

SK-CERT

SK-CERT National Computer Computer Emergency Response Team of Slovakia.

SBS CyberSecurity

SBS CyberSecurity

SBS CyberSecurity is a premier cybersecurity consulting and audit firm.

CorkBIC International Security Accelerator

CorkBIC International Security Accelerator

CorkBIC International Security Accelerator invests in early stage disruptive companies in the security industry including, Cybersecurity, Internet of Things (IOT), Blockchain and AI.

FortifyData

FortifyData

FortifyData is the next generation of cyber risk management–a comprehensive platform that continuously evaluates your third-party, internal and people risks.

SOC Experts

SOC Experts

SOC Experts is a pioneer (we started SOC training well before people realized how big the domain was going to be) and the only institution to provide end-to-end training on Security Operations Centers

Moviri

Moviri

Moviri combines security technology engineering, intelligence expertise and our data science DNA to help companies manage digital risk end-to-end.

Cyber Security Cooperative Research Centre (CSCRC)

Cyber Security Cooperative Research Centre (CSCRC)

The CSCRC provides frank and fearless research and in-depth analysis of cyber security systems, the cyber ecosystem and cyber threats.

GovernmentCIO

GovernmentCIO

GovernmentCIO was founded with a single purpose: to transform government IT. We are thought leaders in data analytics, machine learning, cybersecurity and IT transformation.

Cyral

Cyral

Easily observe, control, and protect your data endpoints in a cloud and DevOps-first world. Discover Data Mesh Security with Cyral.

Singtel Innov8

Singtel Innov8

Singtel Innov8, the venture capital arm of the Singtel Group, invests in and partners with innovative technology start-ups globally.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

CAT Labs

CAT Labs

CAT Labs is building digital asset recovery and cybersecurity tools to enable governments to fight crypto crime and to protect investors from hacks, fraud and scams.

FTI Consulting

FTI Consulting

FTI Consulting is a global business advisory firm dedicated to helping organizations manage change, mitigate risk and resolve disputes.

HIFENCE

HIFENCE

HIFENCE delivers cybersecurity and networking services that make your company safer and more secure. That’s all we do, so you can concentrate on all the things that you do best.

Panoptic Cyber

Panoptic Cyber

Panoptic Cyber are a team of elite Armed Forces Veterans who hold a wealth of experience in Information Security, Cyber Security, Data Protection and Risk Management.