More Work Needed to Secure Data in the Cloud, Survey Finds
New survey results from the Cloud Security Alliance and BigID show gaps in protecting data in the cloud as well as a lack of confidence in controls being used by enterprises.

The Cloud Security Alliance (CSA) in coordination with data protection firm BigID released the results of a survey in which more than 1,500 IT and security professionals weighed in on the state of cloud data security in 2022. Among the survey’s fascinating results:
- Four percent of security and IT leaders think all of their cloud data is sufficiently secure
- Eighty two percent of organizations rate capturing dark data as a moderate to high priority in 2022
- Seventy six percent of organizations rate tracking data across SaaS platforms as moderately to highly difficult
- Eighty six percent of organizations utilize multiple cloud platforms to store their data across IaaS, PaaS and SaaS
- Eight percent of respondents believe that it’s very unlikely they will experience a data breach in the next 12 months
KEY FINDINGS
- Organizations are struggling with securing and tracking sensitive data in the cloud.
- Third parties and suppliers have similar access to sensitive data compared to employees.
- Dark data issues stem from staffing problems and interdepartmental conflict.
- The majority of security professionals believe their enterprise will experience a data breach in the next year.
The report, which I highly recommend downloading and reading, also contains numerous excellent charts and figures. Here are four that I am including (by permission), and there are also many more great metrics.
In your opinion, what percentage of your organization’s sensitive data in the cloud is sufficiently secured?

“Organizations utilize between four and five different components for their data protection strategy. Some of the most common components include data backup and recovery (33%), auditing and assessing data protection processes (32%), adhering to standards and regulatory compliance (31%), and establishing policies and procedures (31%).
What are the components of your data protection strategy?

“Organizations are struggling with tracking data in the cloud. Over a quarter of organizations aren’t tracking regulated data, nearly a third aren’t tracking confidential or internal data, and 45% aren’t tracking unclassified data. This suggests that organizations’ current methods of classifying data aren’t sufficient for their needs.

A DEEPER DIVE
FINAL THOUGHTS

See More Stories by Dan Lohrmann
*** This is a Security Bloggers Network syndicated blog from Lohrmann on Cybersecurity authored by Lohrmann on Cybersecurity. Read the original post at: https://www.govtech.com/blogs/lohrmann-on-cybersecurity/more-work-needed-to-secure-data-in-the-cloud-survey-finds

