Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

Cloud presents biggest vulnerability to ransomware

ransomware freepik
September 22, 2021

Veritas Technologies surveyed more than 2,000 global IT leaders whose organizations have undertaken pandemic-led digital transformation and found the majority are severely vulnerable to ransomware attacks because they’ve been unable to keep pace with the accelerated digitization.


In fact, organizations would need to spend an average of $2.47 million to close the gaps in their technology strategy within the next 12 months. Additionally, the average organization experienced nearly three ransomware attacks that led to downtime in the past 12 months, and 10% were hit with ransomware more than five times.


Joseph Carson, chief security scientist and Advisory CISO at ThycoticCentrify, notes, “Ransomware is one of the top threats all organizations are facing today and a threat that can quickly bring an organization to a complete stop. It’s important to not only have an incident response plan in place but also be incident-ready. This means that you must practice and test your response plan.”


Carson adds, “Over the past year, many organizations accelerated their digital migration to cloud services in an attempt to stay productive while employees converted to working remotely. This major migration meant many organizations have simply moved the same security controls used on-premise and adapted them to their cloud environment. As a result, this has seriously increased risks and exposure for those organizations.”


Additional findings revealed:

  • The cloud presents the biggest vulnerabilities to ransomware, as only 61% believe that their organizations’ security measures have fully kept pace with their digital transformation initiatives—the largest gaps being cloud technology (56%) and security (51%).
  • The vulnerability lag has consequences, as organizations with at least one gap in their technology strategy have, on average, experienced around five times more ransomware attacks leading to downtime in the last year than those with no gaps.
  • Digitization is outpacing security, as only just over six in ten (61%) respondents believe that their organization’s security measures have fully kept up since the implementation of COVID-led digital transformation initiatives, with 39% experiencing some form of security deficit.
  • No organization is immune, with nine out of ten—88%—of organizations reporting that they experienced downtime in the past 12 months.


“When moving to cloud services, organizations must adapt security controls that enhance cloud security. Over the past few years, we have been discussing how the cloud can be secure by design. However, we must move beyond this term and move to secure by default, which means security must be on and used,” Carson says.


“Unfortunately for many organizations, they have migrated to cloud services. But, as security is not enabled by default, this has resulted in attackers taking advantage of these misconfigurations targeting organization’s cloud assets. This can easily become a nightmare for organizations as cybercriminals are increasing ransomware campaigns, and it is almost a daily occurrence of new victims having to decide on the best way to recover the business.”


As organizations migrate to cloud services, Carson says that leaders must prioritize a new security strategy that takes advantage of cloud assets. “This means identity is becoming the new security perimeter, and privileged access is the new security control along with a strong zero trust mindset that continuously verifies authentication and authorization requests. In cybersecurity, our job is to force the attackers to take more risks. As a result, this creates more noise in your infrastructure to give you a better chance to detect the attackers before they deploy nasty ransomware.”


Douglas Murray, CEO at Valtix, says, “The results of this survey aren’t surprising. Unfortunately, most organizations are dealing with a ticking time bomb of security concerns and technical debt built up over years of fragmented cloud efforts. Multi-cloud makes matters worse. This has left many organizations trying to play catchup while also dealing with the complexity of mastering cloud security – which is fundamentally different from on-premise security. 


“The good news is that it inevitably always comes back to the best practices of defense in depth and ensuring that the right security controls and policy are deployed against every cloud workload. Various technologies can help reduce ransomware risk in the cloud, including network-based intrusion prevention, antivirus, and the segmentation of workloads. By taking a cloud-first approach to these problems, security leaders can set the stage for the future through a cloud-native, multi-cloud security architecture.”

KEYWORDS: cloud security cyber security information security ransomware risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Trophy and soccer ball

Security Experts Discuss Threats to FIFA World Cup 2026

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Neighborhood

Residential AI Data Centers: Security, Privacy, and Governance Concerns

Hand reaching up out of the ocean

What I Learned About Burnout the Hard Way (and How to Actually Fix it)

Colorful laptop

Organizations Think They Know Who’s Visiting Their Sites. They Don’t.

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • ransomware

    Four steps to deliver a deadly counterpunch to ransomware attacks

    See More
  • ransomware-attack freepik

    6 common mistakes that lead to ransomware infections

    See More
  • data-leak-freepik2067.jpg

    Gigabyte victim to ransomware again

    See More

Related Products

See More Products
  • into to sec.jpg

    Introduction to Security, 10th Edition

  • The Complete Guide to Physical Security

  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing