4. Misconfigured software
Misconfigurations pose a significant cloud security risk, and there are many examples of how a simple mistake can snowball fast. In 2019, the Capital One breach – the result of a misconfigured AWS cloud instance – resulted in the compromise of more than 100 million customer accounts.
Because AWS’s shared responsibility model makes it clear that customers are responsible for configuring their own cloud assets, Capital One was held accountable. The company was fined $80 million for failing to identify and manage risks as it moved its operations to the cloud.
Best practices such as implementing access restrictions and permission controls can help limit who can make changes to your cloud environment. But these steps are only the beginning. Checking regularly for signs of misconfiguration should also be a priority. Which leads to our next point.
Why continuous monitoring is key to remediating cloud security risk
Cloud security risk can occur for any number of reasons. But one thing is clear: the cloud is creating visibility blind spots that must be addressed. Indeed, when asked, the Oracle/KPMG survey found that identifying software vulnerabilities and misconfigurations are the most important things that security teams feel they must do to improve security visibility in the cloud.
While many cloud service providers are proactive in providing cyber security auditing checklists to help their customers assess the security of cloud environments, they can take time to complete and only provide a snapshot of cyber risk.
A more efficient way to improve visibility is to get a handle on the risk hidden across digital assets stored in the cloud – on a continuous basis. With automated monitoring and discovery your enterprise can quickly and easily assess areas of high risk exposure, such as unpatched and misconfigured systems, and prioritize those assets for remediation. No waiting around for audit season.
Similarly, as digital transformation drives more applications and data to the cloud across your digital supply chain, you can further leverage continuous security monitoring technology to identify potentially risky service providers connected to your company’s vendor ecosystem.
Gain visibility where it's needed most
As the cloud continues to prove its value and companies become increasingly comfortable moving sensitive data off premises, security remains a problem. In this environment, having a dialog with your cloud service providers and becoming an expert on various shared responsibility models is important. But continuous monitoring of your digital assets in the cloud is key to gaining visibility into where hidden risk lies and mitigating that risk before the bad guys exploit it.