Poor security practices put cloud-driven business growth and cost savings at risk

47 per cent of businesses face data loss at the hands of 3rd party cloud providers.

  • Thursday, 14th December 2017 Posted 6 years ago in by Phil Alsop
Swift adoption of cloud-based services and a lack of well-defined security strategies is leaving organisations struggling to keep control of their data, across a sprawling number of services and applications. According to new research from Kaspersky Lab, 35 per cent of businesses admit that they are unsure if certain pieces of corporate information are stored on company servers or on those of their cloud providers. This makes the safeguarding and accountability of data extremely hard to achieve, putting its integrity at risk and paving the way for potentially severe security and cost implications.
With cloud services enabling companies to take advantage of key technologies to support day-to-day operations and growth plans – without worrying about maintenance or the hefty price tag -  it’s no surprise that 78 per cent of businesses are already using at least one Software-as-a-Service (SaaS) based platform. The same number (75 per cent) are also planning to move more applications to the cloud in the future. When it comes to IaaS, nearly half (49 per cent) of enterprises and 45 per cent of SMBs are looking to outsource IT infrastructure and processes to third parties.
However, for many organisations, the speed of adoption and lure of cost and operational savings has been to the detriment of security, with many using cloud services with no strategy in place for the security of their information. Uncertainty around who is responsible for the security of data in the cloud can often be the basis for this approach. Indeed, our research found that 7 out of 10 (70 per cent) businesses using SaaS and cloud service providers have no clear plan in place to deal with security incidents which could affect their partners. A quarter admit to not even checking the compliance credentials of their service provider, suggesting an assumption that they will pick up the pieces if something goes wrong.
However, with 42 per cent of businesses not feeling adequately protected from incidents affecting their cloud service provider and a quarter (24 per cent) of businesses having experienced a security incident affecting the IT infrastructure hosted by a 3rd party, over the last 12 months – a reliance on cloud providers alone to provide complete protection could be a risky strategy.
This lack of planning and accountability by cloud adopters for the security of their information, could have serious consequences for companies, with enterprises suffering an average financial impact ?900k as the result of a cloud-related security incident, compared to ?75k for SMBs. Where data has been compromised as the result of a 3rd party incident, the top three types of data to be affected were: highly sensitive customer information (experienced by 49 per cent of SMBs and 40 per cent of enterprises); basic employee information (35 per cent for SMBs, 36 per cent for enterprises); and emails and internal communication (31 per cent for SMBs, 35 per cent for enterprises).

Therefore, businesses have to find ways to get the cloud zoo under control. Every package of data needs to be protected wherever it happens to be at any one time. To do so, companies need to be able to spot anomalies within their cloud infrastructures, and that can only be achieved through a combination of techniques including machine learning and behavioral analytics. This ability to identify and defend against unknown threats is absolutely fundamental to cloud infrastructure security. Besides that, enabling visibility of the cloud ecosystem and its cybersecurity layer will give businesses a clear view on where data resides and if its current protection status meets corporate security policies. Only in this way businesses will be able to tame the cloud zoo and have complete control - no matter how much and where data is stored.
“Kaspersky Lab has proven experience in protecting cloud infrastructures. Our cybersecurity portfolio is ‘cloud-ready’ and is already supporting our existing customers in their transition from on premise datacentres to private and public clouds and hybrid infrastructures with multiple solutions and applications, all centrally managed.” said Alessio Aceti, Head of Enterprise Business, Kaspersky Lab. “Today’s rapid pace of digital transformation is bringing more efficiency and flexibility to business operations, but it is also presenting new security challenges that put business agendas in danger. To address these cloud security shortcomings, we will continue to expand our offering, taking the protection of cloud infrastructure to an entirely new level. Our customers will benefit from agile security for their cloud infrastructures of any size and shape. This includes the protection of Amazon Web Services and Microsoft Azure-based workloads, as well as Microsoft Office 365 cloud applications, while also ensuring security orchestration and visibility across the entire hybrid cloud.