With the new hybrid-working model we see organizations increasingly moving more of their workload settings to the cloud. While this transformation offers great agility and scalability benefits, it comes with inherent and increased risks to security and compliance. A simple configuration error can result in your entire organization being exposed to threat actors who no longer need to break into your data center to access your critical data or conduct ransomware attacks.
Gartner predicts that by 2025, 99% of cloud security issues will be a result of human error when configuring assets and security in the cloud. At a time when organizations are becoming increasingly dependent on third-party cloud vendors such as AWS, Microsoft Azure, IBM and Google Cloud Platform to securely manage their data, concern around misconfigurations and other vulnerabilities in the cloud is likely to amplify quickly. What’s more, many of the organizations finding themselves at risk have had to accelerate their digital transformation initiatives at an uncomfortable pace over the past two years, resulting in knowledge and talent gaps that only add to their fears around cloud security.
Under the shared responsibility model – a security framework designed to ensure accountability for compromised data and other incidents – the cloud provider will offer basic cloud security, but it’s up to businesses themselves to secure their own data within the cloud. To put it another way, if cloud providers ensure the town gates are locked and the perimeter is well guarded, it’s still up to businesses to ensure their own doors are locked. That’s no mean feat, particularly when you consider that many large enterprises now rely on three or four cloud platforms as part of a multi-cloud strategy.
Attacks on cloud service providers are ramping up
As outlined in our 2022 Security Report, the previous year has seen a tidal wave of attacks that exploit flaws in the services of industry-leading cloud providers. For the cybercriminals involved, the end goal is to gain full control over an organization’s cloud infrastructure or, worse, an organization’s entire IT estate, including its proprietary code and customer records. Needless to say, this can have a devastating impact on the businesses affected and they’re quite right to be concerned.
The kinds of flaws we’re talking about here aren’t logic or permission-based flaws derived from an organization’s control policy that threat actors might use to gain unauthorized access and escalate privileges. This could at least be pinpointed and dealt with by the organization in question. Instead,
these flaws tend to be critical vulnerabilities within the cloud infrastructure itself that can be much more difficult to guard against.
Take the OMIGOD flaw, for example, which broke the floodgates when it came to attacking cloud services in 2021. In September, four critical vulnerabilities were discovered in the Microsoft Azure software agent that enabled users to manage configurations across remote and local environments. An estimated 65% of Azure’s customer base was made vulnerable by this exploit, putting thousands of organizations and millions of endpoint devices at risk. Through this OMIGOD flaw, threat actors were able to execute remote arbitrary code within an organization’s network and escalate root privileges,
effectively taking over the network. As part of its September 2021 update, Microsoft addressed the issue but the automatic fix that it released appeared ineffective for several days. Further flaws were exposed
in Microsoft Azure’s cloud services throughout the year, including the “ChaosDB” vulnerability which allowed cybercriminals to retrieve several internal keys used to obtain root privileges that would eventually enable them to manage the databases and accounts of targeted organizations. Businesses made vulnerable by this particular “open door” included Coca-Cola, Skype and even security specialist, Symantec.
It’s likely that there will be many more cloud provider vulnerabilities in 2022 but fortunately there are things within an organization’s control that can mitigate the risk.
Locking the doors and bolstering internal security
Tightening cloud security isn’t just about having the right products and services in place, it’s also about nurturing a security-first mentality within an organization as a whole. Regardless of what a service level agreement between an organization and cloud provider might say, the onus ultimately falls on the
organization to make sure its customers’ records and other important data are protected.
So, before moving mission-critical workloads into the cloud, organizations must ensure that the “doors” to their applications and data are firmly locked. That means getting identity and access management finely tuned, implementing the principle of “least privilege” so that data is only accessed by humans and applications on a strictly need-to-know basis. It also means better segmentation of networks and use of firewall technology to ensure that sensitive data can be appropriately siloed and guarded where necessary.
Cloud security is complex, and with multi cloud environments it gets even more complex. So, think about consolidating all your cloud security across all cloud vendors into one solution that monitors all malicious
activity and reduces the workload by automating common tasks like policy updates. In an ideal world this would mean a ‘single pane of glass’ approach to security management across all your cloud assets so that you can keep a closer eye on security incidents and focus your effort on those of greatest concern.
Any cloud security solution is only as good as the intelligence engine behind it so ask your vendor how they stay on top of emerging and Zero-day threats. At Check Point we have the ThreatCloud which monitors millions of network nodes across the world and uses over 30 AI technologies to identify threats in real time so that they can be blocked before they get onto your cloud, or indeed on-prem network or end user devices.
And finally introduce security at the earliest stage of application development. You do not want security checks to slow down your DevOps unduly and delay application rollout but equally you cannot afford to cut corners on security. A DevSecOps approach that allows you to scan code for misconfigurations or even malware as part of the DevOps process will ensure that you don’t ‘bake in’ vulnerabilities at the outset.
The shift to the cloud is only going to accelerate as organizations realize the benefits it brings in terms of competitive advantage, agility and resilience so now is the time to take a responsible approach to security and compliance and scale up your cloud security. It’s a challenging and complex task but the good news is that there are solutions to not only lock down your cloud network but also ways, using AI and automation, to reduce the workload of detecting and preventing threats, even the ones that have yet to be devised. Finally, this can be done at speed…. it’s all in the cloud!
107 comments
purchase atorvastatin without prescription order atorvastatin 40mg without prescription atorvastatin where to buy
ciplox brand – trimox 500mg price
buy erythromycin 500mg generic
ivermectin oral – sumycin usa purchase sumycin online
furosemide 40mg sale – furosemide brand buy captopril paypal
order glucophage 1000mg online – buy cipro 1000mg online cheap lincomycin 500mg tablet
order clozapine pills – generic glimepiride purchase pepcid sale
clomipramine price – how to buy tofranil doxepin 25mg tablet
order amoxiclav sale – ethambutol 600mg cheap ciprofloxacin 1000mg tablet
stromectol 3 mg – buy cefaclor 500mg pills order cefaclor online
how to get ventolin without a prescription – albuterol inhaler theo-24 Cr usa
order desloratadine 5mg generic – buy beclomethasone sale albuterol for sale online
order glyburide 2.5mg online cheap – micronase drug pill dapagliflozin 10mg
repaglinide 1mg cheap – where can i buy prandin generic empagliflozin
buy metformin 500mg generic – acarbose over the counter buy precose 25mg for sale
cost semaglutide 14mg – order generic glucovance purchase DDAVP without prescription
nizoral 200mg oral – cost butenafine buy generic sporanox over the counter
order famvir 250mg pills – order acyclovir for sale order valaciclovir 1000mg generic
buy digoxin pills – furosemide 100mg over the counter buy lasix 40mg for sale
order hydrochlorothiazide 25 mg for sale – bisoprolol cost bisoprolol pills
brand metoprolol 100mg – buy telmisartan 20mg for sale buy adalat online
buy nitroglycerin for sale – order generic indapamide 1.5mg valsartan for sale
rosuvastatin online leap – rosuvastatin online boil caduet buy amiable
acne treatment license – acne medication toast acne medication above
asthma treatment act – inhalers for asthma regard asthma treatment tomb
treatment for uti air – uti medication moan uti medication visible
prostatitis treatment flap – prostatitis medications wrought prostatitis medications ghoul
claritin issue – claritin pills ready claritin sensible
promethazine grumble – promethazine spare promethazine confuse
ascorbic acid everywhere – ascorbic acid beckon ascorbic acid lady
buy dulcolax 5mg for sale – order oxybutynin generic order liv52 20mg sale
order rabeprazole 20mg for sale – order maxolon sale purchase motilium pills
bactrim 960mg pills – tobrex 10mg uk oral tobramycin 5mg
buy eukroma generic – desogestrel 0.075mg tablet purchase duphaston generic
buy dapagliflozin no prescription – buy precose for sale buy acarbose generic
fulvicin 250mg for sale – order dipyridamole 100mg generic brand lopid 300 mg
enalapril 10mg pills – enalapril where to buy xalatan buy online
oral feldene 20 mg – exelon 3mg generic rivastigmine order
order monograph 600 mg sale – buy etodolac 600mg online cheap buy generic cilostazol 100 mg
buy piracetam pills – secnidazole 10mg tablet oral sinemet
order hydroxyurea generic – disulfiram price methocarbamol cost
aldactone 25mg uk – dilantin 100 mg cost order revia for sale
order cyclobenzaprine generic – buy olanzapine pill buy enalapril 5mg without prescription
buy zofran 8mg pills – buy procyclidine cheap ropinirole order
order ascorbic acid without prescription – purchase prochlorperazine for sale prochlorperazine oral
buy durex gel online – latanoprost price buy latanoprost paypal
cheap leflunomide – buy cartidin pills buy generic cartidin for sale
order atenolol 100mg pills – betapace 40mg price coreg 6.25mg over the counter
buy calan 240mg – order diltiazem for sale buy tenoretic tablets
atorvastatin pills – order bystolic 20mg online cheap bystolic 20mg for sale
brand gasex – ashwagandha for sale online purchase diabecon generic
buy lasuna generic – diarex online order buy himcolin without a prescription
speman sale – cost speman cheap fincar tablets
norfloxacin over the counter – purchase noroxin buy confido online cheap
how to buy finax – buy alfuzosin for sale alfuzosin 10mg for sale
order oxcarbazepine 600mg – purchase levoxyl sale buy levothyroxine tablets
cost lactulose – brahmi for sale buy betahistine tablets
where to buy imusporin without a prescription – generic methotrexate 10mg buy colchicine 0.5mg generic
cost calcort – brimonidine online buy purchase alphagan
cbd thc oil have been a game-changer fit me! They’re useful, mouth-watering, and a great direction to enjoy the benefits of CBD discreetly. I’ve set that they employees me unwind after a fancy lifetime and even improve my sleep quality. Extra, sagacious accurately how much CBD I’m getting in each gummy makes it simple to make it my dosage. If you’re kinky about taxing CBD, gummies are a pronounced starting point. Just be certain to determine a reputable sort with high-quality ingredients inasmuch as the best experience!
besifloxacin uk – sildamax pill how to get sildamax without a prescription
benemid uk – carbamazepine 400mg us buy cheap carbamazepine
mebeverine 135 mg oral – buy colospa 135mg for sale cilostazol uk
diclofenac tablet – purchase diclofenac without prescription buy aspirin 75 mg generic
cost pyridostigmine 60mg – sumatriptan 50mg usa imuran 25mg brand
order voveran generic – buy generic diclofenac where can i buy nimodipine
buy generic lioresal over the counter – brand piroxicam 20mg feldene 20mg pills
mobic for sale online – meloxicam 15mg cost buy ketorolac pill
cyproheptadine 4 mg generic – cost cyproheptadine tizanidine for sale
cefdinir for sale online – cleocin over the counter
accutane online order – order deltasone 10mg generic buy deltasone 10mg generic
permethrin for sale – buy acticin purchase retin online cheap
betamethasone 20 gm cheap – monobenzone online order benoquin sale
flagyl 200mg pill – order metronidazole 400mg generic cenforce oral
buy cleocin sale – buy indomethacin no prescription indocin 50mg brand
hyzaar usa – hyzaar generic buy generic cephalexin
eurax order – crotamiton buy online aczone gel
modafinil pills – promethazine 25mg cheap cost melatonin 3mg
buy generic progesterone 100mg – how to buy progesterone buy clomiphene for sale
brand xeloda 500 mg – order danocrine 100 mg generic danocrine 100mg pills
how to buy norethindrone – lumigan drug purchase yasmin pills
alendronate ca – pilex brand oral medroxyprogesterone
order estradiol 2mg generic – femara 2.5 mg uk arimidex drug
г‚·гѓ«гѓ‡гѓЉгѓ•г‚Јгѓ« гЃ®иіје…Ґ – バイアグラ и–¬е±ЂгЃ§иІ·гЃ€г‚‹ г‚їгѓЂгѓ©гѓ•г‚Јгѓ«гЃ®иіје…Ґ
гѓ—гѓ¬гѓ‰гѓ‹гѓі – 5mg – гѓ—гѓ¬гѓ‰гѓ‹гѓігЃЇи–¬е±ЂгЃ§иІ·гЃ€г‚‹пјџ г‚ёг‚№гѓгѓћгѓѓг‚Ї гЃ©гЃ“гЃ§иІ·гЃ€г‚‹
гѓ—гѓ¬гѓ‰гѓ‹гѓігЃ®йЈІгЃїж–№гЃЁеЉ№жћњ – イソトレチノイン гЃЇйЂљиІ©гЃ§гЃ®иіј г‚ўг‚ュテイン処方
eriacta burden – eriacta flame forzest fury
buy generic indinavir – buy generic crixivan for sale where can i order emulgel
valif anyhow – buy generic sustiva 10mg buy sinemet 20mg pill
buy ivermectin for humans – ivermectin pills buy carbamazepine without a prescription
order phenergan online cheap – lincocin 500 mg cost lincomycin 500mg canada
deltasone online – nateglinide 120mg cost buy generic captopril 25 mg
isotretinoin canada – buy absorica for sale buy generic zyvox for sale
buy prednisolone 10mg online – brand prednisolone 40mg buy progesterone cheap
cheap gabapentin without prescription – buy anafranil 25mg pill itraconazole price
order furosemide 100mg online – order betamethasone 20gm sale3 buy betnovate without a prescription
vibra-tabs generic – albuterol inhaler order glipizide pill
rybelsus 14mg pill – rybelsus 14 mg price cyproheptadine order online
buy generic zanaflex for sale – brand microzide purchase hydrochlorothiazide sale
cenforce 100mg oral – chloroquine 250mg tablet order glucophage 500mg pills
medrol oral – medrol without prescription buy triamcinolone 10mg generic
buy clarinex 5mg without prescription – order claritin 10mg generic buy generic priligy 90mg
acyclovir 800mg us – purchase rosuvastatin sale buy rosuvastatin 10mg generic
motilium 10mg brand – order generic cyclobenzaprine 15mg buy generic cyclobenzaprine over the counter
buy domperidone generic – buy tetracycline 500mg generic buy generic flexeril
buy coumadin 5mg pill – coumadin for sale purchase losartan without prescription
esomeprazole pill – cost topiramate order imitrex 50mg generic
meloxicam oral – meloxicam without prescription flomax oral