Misconfigured Cloud Applications Are Putting Your Data At Risk

As more and more organisations continue to move their systems and applications to the cloud in 2023, cybercriminals everywhere hear the sound of opportunity knocking. They know that as they hunt for vulnerable systems, this increases their chances of coming across a cloud application that has been left exposed inadvertently due to misconfiguration.

The result: an open door to valuable company data including client and employee personal information, financial data, supplier agreements, et cetera. 

With cloud misconfiguration still being considered one of the biggest threats to cloud security, if not the biggest, organisations need to revisit their cloud adoption strategies and ensure their sensitive information is properly protected by prioritising cloud security.

Time To Ditch The Default

So, how do these misconfigurations occur in the first place?

There are all kinds of reasons. Some of these cloud applications are being rolled out to serve the needs of a specific department or team. Therefore, the priority is more on the business issue it is trying to resolve than the need to integrate and interact with internal systems and endpoints securely. So, to speed up the adoption and solve the issue for that department or team, the application is rolled-out with default settings which may seem sufficient at that time.

However, default settings tend to be too open and could be easily exploited by attackers. For instance, leaving a system account with a default password.

Another issue is the inconsistent approach to configuring cloud applications. Changes are made on an ad-hoc basis and not necessarily replicated across all applications and systems. This makes it more complicated when trying to fix configuration issues, and can expose data stored in these systems to breaches.

The lesson here? IT should be brought in early, even before any new cloud application is selected, to ensure the application is tested and meets the requirements of the configuration checklist defined by the organisation. A centralised approach is also necessary to ensure changes to configurations are carried out consistently across all cloud systems and properly documented.

Cloud Security Is A Shared Responsibility

The tendency to opt for default settings is closely intertwined with another important factor that can cause security gaps in cloud services: a lack of awareness that security is a responsibility shared by many parties - including the customer themselves. 

When it comes to cloud applications, there’s no such thing as “security that is 100% handled by the vendor.”

The service provider that provides the infrastructure - think here of Amazon Web Services (AWS), Microsoft Azure, or Google Cloud - is responsible for delivering a certain foundational level of security. On top of that service provider, the cloud vendor who delivers the specific application that the organisation is using, is responsible for another layer of security. But the final piece of the security puzzle is the customer.

Assuming that “it’s in the cloud, it must be protected”, it’s the wrong assumption. In fact, the customer needs to play a big part by determining which users get to access which data, what level of privileges should they have, and so on – the vendor can’t handle that aspect.

That’s why it’s critical for organisations to understand the Shared Responsibility Model, and for all key internal and external stakeholders to be clear about their roles and responsibilities.

Avoid The Gaps

Cloud adoption will only continue to gain momentum in the year ahead, which is all the more reason to ensure that cyber criminals aren’t provided with any low hanging fruit due to misconfigured cloud systems. Unfortunately, it is a matter of “when” and not “if” an organisation will be targeted by cyber criminals. So, preparation is key.

Auditing cloud applications and their configurations, as well as confirming that all parties are clear about their shared responsibilities can make a world of difference in ensuring that organisations are able to keep their sensitive data safe and out of the hands of bad actors.

Manuel Sanchez is an Information Security & Compliance Specialist at iManage

You Might Also Read: 

DMS Alerts Should Be Key To Organisations’ Security Orchestration:

 

« US Defense Contractors Don't Meet Basic Cyber Security Standards
Remote Work: Three Top Trends In 2023 »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

IP Performance

IP Performance

IP Performance Limited is a leading supplier of customised network infrastructure and security solutions.

Bayshore Networks

Bayshore Networks

Bayshore Networks was founded to safely and securely protect Industrial IoT (IIoT) networks, applications, machines and workers from cyber threats.

RiskLens

RiskLens

RiskLens is a software company that specializes in the quantification of cybersecurity risk.

Guardea

Guardea

Guardea Cyberdefense is an IT services company specializing in the management of security projects, with a pool of skills selected from a network of specialized partners.

PhishLabs

PhishLabs

PhishLabs provides 24/7 services that help organizations protect against the cyberattacks targeting their employees, their customers and their brands.

Wind River

Wind River

Wind River delivers the technology and expertise that enables the deployment of safe, secure, and reliable intelligent connected systems.

Bounga Informatics

Bounga Informatics

Bounga Informatics provides Digital Forensics, E-Discovery, and Endpoint Security software, hardware, and training in Singapore and other countries in Asia Pacific.

Cytelligence

Cytelligence

Cytelligence is a cyber security consulting company with deep expertise in Cyber Breach Response, Cyber Breach Investigations, and Digital Forensics.

Department of Justice - Office of Cybercrime (DOJ-OOC)

Department of Justice - Office of Cybercrime (DOJ-OOC)

The Office of Cybercrime within the Philippines Department of Justice is the Central Authority in all matters relating to international mutual assistance and extradition for cybercrime.

Cyber Threat Alliance

Cyber Threat Alliance

CTA is working to improve cybersecurity of our digital ecosystem by enabling near real-time cyber threat information sharing among companies and organizations in the cybersecurity field.

AlertFusion

AlertFusion

AlertFusion is a platform that makes security operations more effective. It complements existing tools and technologies, unifies operations, enhances process maturity and drives efficiencies.

Cloud Box Technologies

Cloud Box Technologies

Cloud Box Technologies is one of the premier IT Infrastructure Solution providers in the Middle East.

SkyePoint Decisions

SkyePoint Decisions

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider.

Debevoise & Plimpton

Debevoise & Plimpton

Debevoise & Plimpton LLP is a premier law firm with market-leading practices in areas including Data Strategy & Security.

National Coordinator for Security and Counterterrorism (NCTV) - Netherlands

National Coordinator for Security and Counterterrorism (NCTV) - Netherlands

The NCTV serves the Netherlands’ national security. We protect national interests, identify threats and strengthen resilience.

Flare Systems

Flare Systems

Flare proactively detects and remediates exposure across the clear & dark web, providing organizations with the equivalent of an automated cyber reconnaissance team.