Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Leadership and ManagementAccess Management

Four cybersecurity best practices for keeping heads above the cloud

By Karl Fosaaen
luca-bravo-9l_326FISzk-unsplash.jpg

Image via Unsplash

September 6, 2024

Most organizations struggle to manage multiple cloud security solutions – yet, multi-cloud adoption is surging, with 79% of businesses using more than one cloud provider. As evident by last year’s zero-day vulnerability in the MOVEit file transfer being exploited by the Clop ransomware group, this was one of the first times we’ve seen an attack demonstrate a shift in targeting cloud storage providers on such a massive scale. 

With so much room for error when organizations rely heavily on their cloud providers’ security controls, IT leaders need a way to decrease the likelihood of a cloud-based breach impacting their business. 

There is no better time for leaders to reassess their cloud security strategies, given increased security mandates and the shock signals that major vulnerabilities have caused across the industry. To jumpstart these conversations and get leaders’ heads out of the cloud and back to reality, here are four tips for better managing the risk of cloud-based attacks.

Continually ask the question, “How are we evaluating our cloud security posture?”

Hopefully, the obvious answer to this question is to ensure that proper processes and tooling are in place to help automate the review of the cloud security controls. There’s an increased demand for cloud computing infrastructure, which means the attack surface constantly changes and expands as resources are added. A Cloud Security Posture Management (CSPM) tool can help close some of these attack surfaces by ensuring organizations can easily identify and remediate risks and protect their data and critical infrastructure.

However, many firms with CSPM tools still lack basic security hygiene and fail to conduct regular security assessments and audits. By consistently running configuration reviews and working with a third party to perform cloud penetration testing, organizations can be one step ahead of threat actors and get proactive in assessing the strengths and weaknesses of their overall cloud security posture.

2. Follow the principle of least privilege to ensure that all cloud services are restricted to internal, authenticated access if public access is not required

The National Institute of Standards and Technology (NIST) defines the principle of least privilege as the idea “that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.” While it can be standard practice, it’s best to avoid the use of overly permissive “basic” or “general” roles. This principle is particularly important when working in the cloud, as there are multiple layers of access controls that have to be considered. 

When an organization can restrict identity and access management (IAM) permissions to only those who truly need it – and regularly assess who has access to what – they can limit the blast radius in case of a breach. In the event of a breach, privilege restriction can also halt an attacker from having a suite of disruptive options once in an environment – blocking data access, lateral movement, or privilege escalation. Whenever possible, organizations must enforce and have additional security controls in place for those just-in-time occasions when identities need more advanced privileged access. 

3. Employ a layered security approach that uses both individual service configuration settings and organization-wide policies as an additional guardrail

A layered security approach confirms the complete protection of an organization’s valuable assets. The extra guardrail, implemented prior to a breach or vulnerability being identified or active, ensures all cloud services are restricted to internal, authenticated access – as inadvertent public or anonymous access can lead to the exposure of sensitive data. If a layered approach is not installed, resources can end up in a misconfigured and vulnerable state. Additionally, organizations can add guardrail products and policies to help automatically correct misconfigurations or drift configurations. All of these layers help organizations better identify cloud-based cyber threats by minimizing security gaps across networks before they cause massive damage.

4. Review the cloud provider's shared responsibility model to determine what is within the customer’s responsibility for security

It’s important never to assume a cloud provider's security practices are as comprehensive as they need to be in order to keep up with today’s evolving threat landscape. While many cloud providers conduct proactive security testing of their services, they haven’t received the same level of scrutiny or auditing that you’d expect to see from a financial institution or credit card processor. 

Last August, the DHS-led Cyber Safety Review Board started to dig into this issue in the hopes of setting clear expectations for cloud providers regarding security audit requirements and accountability. DHS stepping in should drive cloud providers to create more efficient remediation processes to help decrease their fix times – as there have been instances where cloud providers did not receive the immediate attention needed to help close major gaps. While there are complications with pushing fixes to global products, cloud providers should be evaluating their services and their ability to be agile when issues require fixes. Hopefully, this will be the push the cloud providers need to help proactively chase down and remediate these issues before someone else finds them.

While security leaders wait to see the repercussions of these investigations, they must acknowledge that additional steps are needed to ensure cloud provider resources are secure. A best practice for all teams is to review their cloud providers’ shared responsibility model to determine what responsibilities fall under the cloud provider versus the organization itself. Additionally, organizations should enable regular patch management practices to keep their software updated and upgrade all vulnerable and unsupported versions to supported versions that receive regular security updates.

Cloud providers need to step up their general security practices. But organizations need to as well if they have any hopes of avoiding the rise of cloud-based attacks. With 45% of breaches categorized as cloud-based and recent data indicating that 80% of organizations have undergone a cloud-based incident in the last year, now is the time to take these tips seriously and implement a proactive approach to security.

KEYWORDS: access management solutions cloud computing cloud security IAM systems

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Karl fosaaen headshot

Karl Fosaaen is a VP of Research at NetSPI. Image courtesy of Fosaaen 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Leadership and Management
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cyber Tactics Column
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    New Security Technology
    By: Charles Denyer
close

1 COMPLIMENTARY ARTICLE(S) LEFT

Loader

Already Registered? Sign in now.

Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Person holding large ball of twine

Preventing Burnout in The Security Industry

Harrods

Harrods’ Cyberattack: Cybersecurity Leaders Weigh In

Coding

AI Emerges as the Top Concern for Security Leaders

2025 Security Benchmark banner

Events

September 29, 2025

Global Security Exchange (GSX)

 

November 17, 2025

SECURITY 500 Conference

This event is designed to provide security executives, government officials and leaders of industry with vital information on how to elevate their programs while allowing attendees to share their strategies and solutions with other security industry executives.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Exclusives Feature Image

    Safety in the Cloud - Best Practices for Private and Public Models

    See More
  • multicolor pyramid on red orange background

    The threat landscape and best practices for securing the edge

    See More
  • cyber

    Industrial Network Cybersecurity: Debunking the Myths and Adopting Best Practices

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk-Analysis.gif

    Risk Analysis and the Security Survey, 4th Edition

See More Products

Events

View AllSubmit An Event
  • November 14, 2024

    Best Practices for Integrating AI Responsibly

    ON DEMAND: Discover how artificial intelligence is reshaping the business landscape. AI holds immense potential to revolutionize industries, but with it comes complex questions about its risks and rewards.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!