As cloud services increase in popularity, a worrying cybersecurity trend has emerged. According to the 2020 Trustwave Global Security Report, the volume of attacks on cloud services more than doubled in 2019 and accounted for 20% of investigated incidents. Although corporate and internal networks remain the most targeted domains, representing 54% of incidents, cloud environments are now the third most targeted environment for cyber attacks.
As digital transformation drives cloud adoption, these alarming statistics underscore that a different approach is needed to reduce the new and evolving set of risks associated with the cloud.
Cloud services complicate security performance management
The cloud substantially grows the corporate digital footprint far beyond its usual digital perimeter. As such, organizations often lack visibility into the inventory of critical assets in their cloud ecosystems, as well as the risk associated with those assets.
This challenge is compounded by the cloud shared security model. Organizations must understand the model for every cloud vendor they work with and configure each cloud instance securely. If they don’t, they open themselves to cyber risk. Furthermore, traditional cybersecurity assessments used for on-premise environments can be difficult to scale. This makes it hard for security teams to discover and determine how well they are securing their cloud-hosted assets — and what portion of the risk they own and manage versus their cloud providers.
As the Trustwave report shows, it’s more important than ever that organizations achieve broad and continuous visibility into all assets across their digital ecosystems. They need insight into unknown malware infections, outdated security certificates, exposed ports (such as those exposed by the BlueKeep exploit in 2019), SSL misconfigurations, bad web application headers, and so on.
In an on-premise environment, this really comes down to basic security hygiene — but in the cloud it’s far more complex. Bitsight Attack Surface Analytics can help security teams overcome the challenges of managing cyber risk across their expanding digital ecosystems.
Monitor risk hidden in cloud environments
Bitsight Attack Surface Analytics gives security teams continuous, broad visibility and context into their attack surface in the cloud. Security managers can understand the risk profiles of all cloud-hosted assets, even across subsidiaries and acquired companies.
A centralized dashboard outlines the location of all assets — broken down by their cloud providers — and shows the corresponding cyber risk associated with each individual asset based on the number of material/severe findings. These findings can reveal areas of weaknesses in an organization’s security programs and failed security controls that expose them to risk.