A checklist for your cloud security audit
For the first time, cloud security breaches and incidents are more commonplace than on-premises attacks. According to the 2021 Verizon Data Breach Investigations Report (DBIR), in 2020, 73% of cyberattacks involved cloud assets, compared to only 27% in the previous year. That statistic is punctuated in a separate study by Oracle and KPMG, which found that three-quarters of organizations have experienced data loss from a cloud service more than once.
As your business increases its dependency on digital infrastructures and introduces more cloud providers to its network, you must assess its cloud security posture – on a continuous basis. While you should customize any assessment to your industry or size of your organization, here are some standard best practices we recommend you include in your cloud security audit.
1. Assess your cloud providers' security postures
No one wants to enter a relationship with a partner whose security posture isn’t what it should be. The same holds true of your cloud vendors. In addition to reviewing their security policies and protocols, you need a way to independently ascertain risk based on data-driven insights – from onboarding through the life of the relationship.
This practice may sound overwhelming, but you can easily automate this process using a tool like security ratings.
Ratings work by continuously monitoring a vendor’s security posture based on factors such as vulnerabilities, compromised systems, adherence to industry best practices, and compliance with cybersecurity frameworks. Findings are presented as an easy-to-understand numerical score with a higher rating equating to better overall security performance. If a rating is low, you may choose not to enter into a cloud services agreement with a vendor. Alternatively, if you consider them business-critical, you can work with them to improve their rating.
You can also use security ratings to keep an eye on any changes that may impact a vendor’s security posture over time. This will stop risk creeping into the relationship.
2. Understand your extended attack surface
Cloud consumption can create visibility blind spots. In fact, the Oracle/KPMG study found the biggest cloud security challenges organizations must overcome are a lack of visibility into software vulnerabilities and misconfigured cloud services that expose servers to cyber risk. Unfortunately, traditional cyber security audits and cyber security assessments don’t always scale into the cloud (particularly multi-cloud environments), making it hard to discover how secure your cloud-hosted assets are.
Bad actors know this and frequently exploit weaknesses that can arise when cloud assets aren’t monitored continuously and effectively. Compromised systems, open ports, unpatched software, and other vulnerabilities present open doors for industrious hackers.
Instead, consider adding attack surface monitoring technology to your cyber security audit checklist. By continuously analyzing your cloud environment, you can quickly identify your organization’s cloud assets and any gaps in your security controls. You can also identify areas of concentrated risk, such as a misconfigured web application firewall, and prioritize that asset for remediation. The technology even reveals hidden security issues that may be lurking in shadow IT.
With visibility into the risk profile of all your cloud assets, your organization will also solve the challenge of the shared responsibility model. After all, you can’t secure what you can’t see.
This form of monitoring also solves the challenge of the shared responsibility model by giving visibility into the risk profile of the cloud assets you are responsible for on a continuous basis.