Did you know that the volume of attacks on cloud services more than doubled in 2019? According to the 2020 Trustwave Global Security Report, cloud environments are now the third most targeted environment for cyber attacks. While these incidents are on the rise, migrating to the cloud is no longer optional for many organizations, due to the widespread shift to remote work. In today’s ever-evolving, dynamic security landscape, mitigating risk effectively requires thorough cloud security monitoring and continued visibility into your expanding attack surface.
Understanding the unique security challenges and requirements
According to Gartner, up to 60% of organizations will use an external service provider’s cloud managed service offering by 2022 — doubling the percentage from 2018. Given this trend, it’s more important than ever that organizations understand the shared responsibility model.
The cloud shared responsibility model essentially outlines that the cloud provider is in charge of securing the cloud architecture itself, while the customer is responsible for securing the data and apps stored in that cloud instance. Unfortunately, this model makes it difficult for many organizations to understand what portion of risk they own and manage versus their cloud providers. In a recent survey conducted by Oracle and KPMG, only 10% of CISOs reported that they fully understood the shared responsibility model, while 82% claimed to have experienced security events due to confusion in the model.
It’s clear that mitigating third-party cyber risk effectively requires you to understand how this model operates with each of your cloud vendors — and ensure each instance is configured securely. According to the Oracle and KPMG Cloud Threat Report 2020, organizations who discovered misconfigured cloud services experienced 10 or more data loss incidents in the last year.
Cloud security monitoring: Discover and mitigate risk effectively
When it comes to effective cloud security posture management, one of the biggest challenges is gaining an ecosystem-wide view into all of your digital assets. After all, you can’t secure what you can’t see.