Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Leadership and ManagementLogical Security

The biggest threats to enterprise cloud networks (and how to avert them)

By Shahzad Ali
cloud

Image from Pixabay

November 23, 2022

As more enterprises adopt multicloud architecture, hackers and other malicious actors are finding new ways to infiltrate corporate networks. Understanding the changing nature of the threat landscape for enterprise cloud and multicloud environments is crucial for thwarting malevolent actors intent on harming a company’s reputation and bottom line.

Cloud security presents a challenge to CISOs, who must identify the expanded attack surfaces that must be protected in the cloud, protect against the most common vulnerabilities, and learn how to think about security threats so cybersecurity teams can prevent them.

Understanding the expanded attack surfaces

With cloud, not to mention multicloud, security teams are dealing with vastly different attack surfaces than previously seen in the on-premises world or the branch or datacenter world.

When thinking about attack surfaces, it's helpful to start by considering the outer edges of your network and work your way in. At the edges of your cloud network, the application layer has become a massive threatscape made more complex with the advent of containerization. Every day brings new application services security leaders haven’t seen before, and we see a corresponding increase in the threat level in this area.

The next layer of the attack surface is the cloud networking layer, where organizations have all the different networking constructs, like hidden Virtual Private Clouds (VPCs)/Virtual Network (VNET) routers, hidden load balancers, etc. And now, every single VPC/VNET has an Internet Gateway (IGW) sitting next to the application, which provides direct access to and from malicious IPs and bad actors. IGW and other services widen the attack surface for applications and services deployed inside the cloud.

In the case of hybrid deployments, there may be uncontrolled areas of the network where the cloud is connected to the on-premises environment, which is yet another attack surface.

Across all these layers, CISOs need to be mindful of both external and internal threats.

In addition to protecting your network from unauthorized external access by hackers attempting to breach the company's defenses, you need to establish proper governance and audit models for secure user access by authorized personnel. In a typical enterprise, developers, contractors, partners and other individuals and groups will need access to various applications.

Internal personnel can also create potential threats. If cybersecurity leadership fails to apply appropriate identity and access management (IAM) policies and microsegmentation for internal personnel, they may inadvertently enable unauthorized access to various resources, including virtual machines or the code.

Multiple clouds = multiple attack surfaces

Up to this point, we've been discussing attack surfaces in a single cloud. But in a multicloud environment, the problem is even more significant.

In multicloud, you have multiple challenges with visibility, because constructs like VPC routers, IGWs, transit gateways and load balancers are black-box resources. They're behind the scenes, and oftentimes IT doesn't have access to them. These issues exist even in the single cloud, but they’re compounded with a multicloud deployment because each cloud operates differently.

Additionally, organizations are dealing with multiple cloud service providers (CSPs), each with unique architecture and without any unified control or data plane.

Let's assume the IT team is trained in AWS. They know how to protect AWS. They know the ins and outs of AWS networking. But what about GCP? What about Azure? What about OCI?

Each of these CSPs provide resources and security services specific to their cloud. So, with each additional cloud, you have entirely different services, which may or may not be compatible with the compliance posture your enterprise mandates. With no unification, IT teams are dealing with a completely discreet, fractured architecture. If the organization has a fractured architecture, your security will be fractured as well.

The three biggest cloud vulnerabilities

1. Human error

Perhaps unsurprisingly, human error is still the most common challenge. People make mistakes. The mistake could be as minuscule as a typo in the code, which allows a bad actor to launch SQL Injection type attacks, compromising enterprise application security.

2. Lack of familiarity with new technologies

When it comes to new technologies, deep expertise is naturally rather limited. For example, more and more cyberattacks are targeting containers, service mesh and Kubernetes. These are relatively new technologies, and many people using them may not be completely familiar with their security flaws, which makes them attractive targets for malicious actors.

The cloud itself is a new technology, and the cloud skills gap is a serious problem, especially when it comes to security. People are migrating applications into the cloud before putting the right architecture in place. They're not thinking about layered security or defense for an in-depth security model in the cloud.

3. Expecting your CSP to handle security for you

For a lot of organizations, the cloud represents an 'easy button.' However, it's a mistake to believe that a CSP provides an effective 'easy button' for cloud security. You may have heard that security is a "shared responsibility" between the CSP and the enterprise. The truth of the matter is that security is in no way, shape or form a shared responsibility — it’s your responsibility.

Say a bad actor attacks an enterprise application or workload. After an attack, it can become difficult for enterprises and CSPs to work together because in many cases, visibility is a challenge. You can’t see behind the curtain on their side, and they can’t see behind the curtain on yours. The reality is that it comes down to the enterprise architect or the CISO or the CIO to ensure a proper security posture is maintained.

Rethinking the CISO approach to cloud and multicloud security

Many architects take an add-on approach to cloud security. While it may seem expedient at the outset, this approach doesn’t scale. It’s much better to use a holistic approach to architecting layered security from the beginning. This is especially important as enterprises move to multicloud.

My advice to CISOs:

  • Embrace the security services CSPs offer. They’re available for a reason; use them.
  • Extend additional security where CSPs don’t provide it.
  • Leverage third-party services like firewalls.
  • Adopt and build networks where security is the priority.
  • Use microsegmentation with policies that can be enforced at different levels.

Enacting these strategies within organizational networks can result in a holistic, layered approach to security, as well as complete topological visibility that multicloud networks require.

KEYWORDS: Chief Information Security Officer (CISO) cloud cloud migration cloud security cyber attack

Share This Story

Shahzad Ali is well-known in the networking industry, considered a top technical resource and influencer by many. As a seasoned professional, he has over a decade of experience at Cisco Systems under his belt, and even played a key role on VMware’s NSX team. For the last three years, he’s been a part of Aviatrix, the pioneer of Intelligent Cloud Networking. He is an expert on networking and security and is equipped with deep knowledge in both private and public clouds. Ali often speaks at industry conferences and hosts his own YouTube Channel, called netJoints.

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

close

1 COMPLIMENTARY ARTICLE(S) LEFT

Loader

Already Registered? Sign in now.

Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Computer with binary code hovering nearby

Cyberattacks Targeting US Increased by 136%

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Person holding large ball of twine

Preventing Burnout in The Security Industry

Harrods

Harrods’ Cyberattack: Cybersecurity Leaders Weigh In

2025 Security Benchmark banner

Events

September 29, 2025

Global Security Exchange (GSX)

 

November 17, 2025

SECURITY 500 Conference

This event is designed to provide security executives, government officials and leaders of industry with vital information on how to elevate their programs while allowing attendees to share their strategies and solutions with other security industry executives.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!