Organisations are racing to embrace cloud technologies for their myriad benefits. Be it private, public or a hybrid approach, cloud offers organisations scalability, flexibility and freedom for employees to work wherever, whenever. When you add that to the promise of cost savings combined with enhanced collaboration, cloud is a compelling proposition.
While the intention to expand cloud systems is evident among IT leaders, the alarming occurrence of breaches and the identified risks, such as third-party providers in supply chains, underscores the urgent need for organisations to prioritise cloud security.
In Tenable’s latest cloud security report, 2024 Cloud Security Outlook: Navigating Barriers and Setting Priorities, 33% of respondents stated that they believe one of the biggest risks to their cloud infrastructure now sits outside of the organisation in the form of third-party suppliers.
To gain control over cloud security gaps, organisations must be able to discern the most critical risks and set priorities.
The cloud challenge
It is widely recognised that cloud adoption increases an organisation’s attack surface. Even cloud-native organisations grapple with the difficulty of detecting and remediating risk in their cloud environments:
- Cloud is complex with moving parts – virtual machines, containers, Kubernetes, serverless, data, networks and identities – including people and machines, and all distributed across multiple providers. According to International Data Corp, having two cloud environments does not double the complexity, but in fact quadruples it.
- Organisations often struggle to monitor interactions or access events, which can be defined as any request by a human or a machine to access a file or a resource for a certain purpose.
- Identities, in particular, are a core threat given they are the keys to accessing cloud resources. If compromised, they allow attackers to gain access to everything, particularly sensitive data and systems. Ensuring credentials are kept private is paramount.
- Due to shorter build times and faster release cycles achieved through the use of DevOps tools, reorganising permissions across identities and entities every time new code is deployed is a challenge.
To gain control over cloud security gaps, organisations must be able to discern the most critical risks and set priorities. To do so at scale requires integrated, comprehensive risk analysis across all parts of the cloud infrastructure and automation of both the detection of risk and its remediation. Effectively securing the cloud requires looking across every aspect of potential exposure including vulnerabilities, configurations and identities.
Taking cloud control
True security, including in cloud environments, requires complete and holistic understanding of the risks that exist within the entire infrastructure. When threat actors evaluate a company’s attack surface, they’re probing for the right combination of vulnerabilities, misconfigurations and identity privileges.
In most instances, it’s a known vulnerability that allows threat actors an entry point to the organisation’s infrastructure. Having gained entry, threat actors will then look to exploit misconfigurations in Active Directory to gain privileges and further infiltrate the organisation to steal data, encrypt systems or cause other business-impacting outcomes.
Security teams should look to obtain an accurate picture of their attack surface, including visibility into unknown assets, cloud resources, code weaknesses and user entitlement systems. With this intelligence they must then audit the identity aspect, virtual machines, serverless functions, and Kubernetes clusters and containers, and so on. This intelligence empowers the security team to map the relationships between identities and systems they access. Understanding this context enables proper assessment of exposures and allows security teams to prioritise remediation based on actual risk.
How AI can help
Gaining this broad visibility can be difficult, challenging security teams to conduct analysis, interpret the findings and identify what steps to take to reduce risk as quickly as possible.
AI has the potential to address this. It can be used by cybersecurity professionals to search for patterns, explain what they’re finding in the simplest language possible, and decide what actions to take to reduce cyber risk.
AI is being harnessed by defenders to power preventative security solutions that cut through complexity to provide the concise guidance defenders need to stay ahead of attackers and prevent successful attacks. Harnessing the power of AI enables security teams to work faster, search faster, analyse faster and ultimately make decisions faster.
Knowing the adversary means organisations can anticipate cyberattacks, ensuring they are best positioned to defend against today’s emerging threats. Hackers looking for low-hanging fruit will target smaller organisations whose security practices may be less mature.
Organisations must bolster their cloud security strategies and invest in the necessary expertise to safeguard their digital assets effectively, especially as IT managers expand their infrastructure and move more assets into cloud environments. Raising the security bar should persuade threat actors to move on and find another target.
About Tenable
Tenable is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company’s AI-powered exposure management platform radically unifies security visibility, insight and action across the attack surface, equipping modern organisations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for more than 44 000 customers around the globe. Learn more at tenable.com, or connect on LinkedIn, X, YouTube, Instagram or Facebook.
- Read more articles by Tenable on TechCentral
- This promoted content was paid for by the party concerned