As misconfiguration, account compromises and exploited vulnerabilities continue to allow attacks on public cloud-based networks to surge, the majority of organizations are struggling to manage multiple cloud security solutions. Check Point Software Technologies' 2023 Cloud Security Report found most organizations prefer a single-platform approach.
The security vendor surveyed more than 1,000 security professionals worldwide and found 76% of respondents stated they are extremely or very concerned about cloud security and 24% of their organizations experienced a public cloud-related security incident in the past year.
Over half (59%) of the surveyed professionals selected misconfiguration of the cloud platform or wrong setup as the top cloud security threat, followed by exfiltration of sensitive data (51%), insecure interfaces or APIs (51%) and unauthorized access (49%).
“Our survey found that cloud misconfigurations are the foremost concern for today’s CISOs. However, what sets successful cloud security organizations apart is not only the ability to identify misconfigurations, but also to grasp their contextual relevance and prioritize their resolution,” TJ Gonen, VP of cloud security at Check Point, said in a statement.
“Understanding which misconfigurations truly pose a risk to business operations is paramount. As is the capability to swiftly and effectively address those vulnerabilities to maintain a strong security posture. It is imperative for enterprises to select a comprehensive solution that goes beyond surface-level detection,” he added.
Multicloud security management challengesCheck Point’s report also showed 58% of the respondents plan to store more than half of their workload in the cloud within the next 12–18 months, with 39% already doing so.
To manage this complex cloud environment and threat landscape, organizations have turned to a number of cloud security technologies and services, resulting in 72% of respondents struggling to manage access to multiple security solutions.
Additionally, 26% of the surveyed have more than 20 security policies in place to secure access to and protect data in private and public cloud applications and the web, which could lead to alert fatigue and hinder response teams’ ability to effectively counter high-risk incidents, Check Point researchers noted. On the other hand, around 30% have less than five policies in place, which may “leave their cloud environments vulnerable to security breaches and data leakage.”
Currently, surveyed organizations use various tools to manage their cloud infrastructure configurations: 62% of them use cloud-native tools, 29% dedicated cloud security posture management (CSPM) solutions, 24% manual processes and 16% leverage open-source tools.
Check Point: Cloud security management best practicesTo address management challenges, 90% of respondents expressed they consider the use of a single cloud security platform with one dashboard to be moderately to extremely helpful.
Check Point researchers also encourage organizations to embrace this single-platform approach, noting in the report that embracing an integrated cloud security platform can help ensure consistency, visibility and control across multicloud environments.
They also recommend following other best practices, including:
- Prioritizing automation to scale security operations, streamline processes and reduce manual work.
- Adopting DevSecOps principles by integrating security into the development and operations life cycle.
- Implementing a zero-trust model to enforce strict access controls and verification for users, devices and applications
- Using a cloud identity and entitlement management (CIEM) solution to manage access roles and entitlements.
- Developing a system that provides the necessary context to identify, detect and prioritize threats.
Comments