May 3, 2016 By Rick M Robinson 2 min read

Cloud Risks Are Real

The cloud wars are over, and of course the cloud won. We don’t just deal with the cloud; when it comes to IT, we pretty much live in the cloud. The most obvious result is enormous power at our fingertips — even when our fingers are on the go.

The power of the cloud also means that cloud risks are all around us. Since the cloud is everywhere, we may not even think of those risks as cloud-related — but they are, which means basic cloud security education is essential.

BYOCA: Bring-Your-Own-Cloud-App and Other Blunders

Remember when bring-your-own-device (BYOD) first became a big security concern? It still is, by the way, and it’s easy to forget that those mobile devices are used almost entirely for mobile access to — wait for it — the cloud.

It’s not just mobile, either. As Dennis McCafferty pointed out at CIO Insight, laptops are the primary way business users access the cloud.

The basic fact of cloud risks and cloud security is that it is a shared responsibility. According to Yotam Gutman at Infosec Island, the vendor, be it the cloud provider or a cloud resource provider, is typically responsible for offering a secured service. The client — you or your employee — is responsible for using it securely.

Cloud services vendors can and do slip up, but the real challenge is on the client end. Mistakes are legion. Infosec Island reported that one-third of business users surveyed have downloaded work-related apps without telling IT. Most probably never thought twice about it, especially if they were using a company-provided device.

The cloud also supports creative new versions of old-fashioned security blunders. One-quarter of respondents in the “(Still) Careless Users in the Cloud” survey stored passwords in documents that weren’t password-protected. When left in an unprotected document, that password is conveniently available to the cybercriminal working from anywhere around the world. Additionally, anyone could walk into an office and see the 20 percent of passwords written on a sticky note, according to the report. These poor practices could ultimately result in damaging breaches for an organization.

Security Education Should Not Be a Teachable Moment

More often than not, basic cloud security mistakes are made by people who have no idea that they are doing something risky. No warning sign comes up; employees only see the cloud as another resource that comes up on their monitor — not the massive risk it actually is. The time to discover the need for basic cloud security education is not when a breach occurs and company data spills all over the Internet.

Yes, a growing range of security solutions are available for protecting against specific cloud risks. But the most critical line of protection remains the human user. Organizations need to protect themselves and their people from the hazards of the cloud by educating them in security awareness for the cloud era.

Learn more about Cloud Security

More from Cloud Security

2024 Cloud Threat Landscape Report: How does cloud security fail?

4 min read - Organizations often set up security rules to help reduce cybersecurity vulnerabilities and risks. The 2024 Cost of a Data Breach Report discovered that 40% of all data breaches involved data distributed across multiple environments, meaning that these best-laid plans often fail in the cloud environment.Not surprisingly, many organizations find keeping a robust security posture in the cloud to be exceptionally challenging, especially with the need to enforce security policies consistently across dynamic and expansive cloud infrastructures. The recently released X-Force…

Cloud threat report: Why have SaaS platforms on dark web marketplaces decreased?

3 min read - IBM’s X-Force team recently released the latest edition of the Cloud Threat Landscape Report for 2024, providing a comprehensive outlook on the rise of cloud infrastructure adoption and its associated risks.One of the key takeaways of this year’s report was focused on the gradual decrease in Software-as-a-Service (SaaS) platforms being mentioned across dark web marketplaces. While this trend potentially points to more cloud platforms increasing their defensive posture and limiting the number of exploits or compromised credentials that are surfacing,…

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today