Cloud has clearly redefined the IT landscape, on nearly every level in 2020 – serving as the perfect solution for increased remote collaboration while further enabling organizations to seamlessly scale and transform their business operations.
At the same time, as has been the case for years, the growing popularity of the cloud has also increased the threat of its arch-nemesis – data breaches, specifically those incidents related to improper cloud configuration. According to a recent report from Risk Based Security, the number of records exposed in Q1 2020 skyrocketed to 8.4 billion – a 273% increase compared to Q1 2019. Most of this can be attributed to one single breach – a ‘misconfigured’ ElasticSearch cluster that exposed 5.1 billion records.
Misconfigurations are undoubtedly the most significant security threat lingering in the cloud. Unrestricted access to non HTTP/HTTPS ports, lack of MFA, stale access credentials, overly permissive settings – any of these factors that result in a misconfigured cloud account represents a huge exposure for your organization. For its part, Gartner has predicted that 99% of cloud security failures over the next five years will be caused by user error – with much of the issue related to configuration issues. As a result, today’s security practitioners face a complex set of challenges while working to secure their business-critical workloads, applications, and data.
What leads to misconfigurations in the cloud?
Among the common contributors to cloud misconfiguration:
CipherCloud CSPM: An integrated solution for complex cloud security configuration challenges
CipherCloud’s integrated security platform approach offers a dedicated CSPM solution that offers critical administrative and configuration controls with tight security guardrails, – providing continuous insight into cloud risk posture through intuitive and drill-down dashboards.
Delivered both standalone and as an integrated complement to the CipherCloud CASB+ platform, CipherCloud Cloud Security Posture Management (CSPM) performs an automated assessment of your cloud landscape against well-defined security and compliance guidelines to prevent data loss due to misconfigurations.
Additionally, the solution offers built-in auto-remediation capabilities to reduce operational complexity in managing resources across multiple cloud applications and ensures alignment with the latest compliance guidelines – supporting GDPR, CCPA, HIPAA, and PCI for IaaS environments including Amazon AWS, Microsoft Azure, and Google Cloud Services.
As mentioned by Gartner in its latest Magic Quadrant Report for Cloud Access Security Brokers, “CipherCloud CSPM is well-developed, follows several common frameworks and can replace stand-alone tools” – making an even bigger case for addressing CSPM through an integrated CASB strategy.
Specific benefits offered by CipherCloud CSPM include:
To learn more about CipherCloud CSPM visit www.ciphercloud.com/cloud-security-posture-management.
The post The Cloud, The Breach, and the increased role of CSPM appeared first on CipherCloud.
*** This is a Security Bloggers Network syndicated blog from Blogs List with categories – CipherCloud authored by Matt Hines. Read the original post at: https://www.ciphercloud.com/the-cloud-the-breach-and-the-increased-role-of-cspm/
Many thanks to DEF CON and Conference Speakers for publishing their outstanding presentations; of which, originally appeared at the organization's…
via the respected information security capabilities of Robert M. Lee & the superlative illustration talents of Jeff Haas at Little…
Many thanks to DEF CON and Conference Speakers for publishing their outstanding presentations; of which, originally appeared at the organization's…
When the topic of 2021 security predictions came up at a recent meeting of top cyberindustry executives, several leaders starting…
Previous Sections As we continue the study guide for the Certified Kubernetes Security Specialist (CKS) program, be sure to check…
As we write this post, SlashNext Threat Labs is witnessing an active attack on Google’s App Engine service via Appspot.com…