Virtualization Technology News and Information
Article
RSS
CISOs now think cloud is safer than on-premise, but security fears remain
Today, Nominet announces its Cyber Security and the Cloud researchfinding that 61 percent of security professionals believe the risk of a security breach is the same or lower in cloud environments compared to on-premise. The research, surveying nearly 300 UK & US C-level security professionals, marks a major tipping point in the perception of security of the cloud. That said, the cloud's perceived superiority over on-premise does not mean that respondents considered cloud systems to be completely safe. 

Cyber security concerns with cloud adoption

In fact, the research found that 71 percent were either moderately, very or extremely concerned about malicious activity in cloud systems. As new regulations such as the GDPR have increased the potential penalties, over half (56 percent) of respondents cited fines for data leaks as their biggest concern, closely followed by the increasing sophistication of cyber criminals (54 percent). Interestingly, some security professionals are more concerned than others:

  • US respondents were more wary of the cloud than their UK counterparts, responding almost twice as likely to be extremely concerned (21 percent versus 13 percent)
  • Respondents from heavily regulated industries were more likely to be very or extremely concerned by the security risk posed by cloud: healthcare (55 percent), financial services (47 percent) and pharma (46 percent)
  • Finally, organizations that were breached in the past 12 months were more than twice as likely to say cloud is higher risk (52 percent versus 25 percent)

"Security has traditionally always been cited as a barrier to cloud adoption, so it is significant that the perceived risk gap between cloud and on-premise has disappeared," said Stuart Reed, VP of Cyber Security at Nominet. "It is evident that security concerns are no longer an insurmountable barrier to cloud deployments given the high adoption rate of cloud services. And, as we move into the ‘cloud era', arguably security teams need to channel their concern into finding solutions that work with the cloud, just as they have been doing in an on-premise environment. The shift in attitude between on-premise and cloud doesn't change the remit for security teams, it just puts us on a different type of playing field."

Single-cloud, multi-cloud or hybrid - what's safest?

The research also looked into the relative security of cloud storage strategies and found that a multi-cloud approach is seen to be more risky than hybrid and single-cloud approaches. Those adopting a multi-cloud approach were far more likely to have suffered a data breach over the past 12 months: 52 percent versus 24 percent of hybrid-cloud users and 24 percent of single-cloud users. Companies with a multi-cloud approach are also more likely to have suffered a larger number of breaches: 69 percent suffering between 11-30 breaches compared to 19 percent of those from single-cloud and 13 percent from hybrid-cloud businesses.

"When it comes to ensuring resilience and being able to source ‘best-in-class' services, using multiple vendors makes sense," explained Reed. "However, from a security perspective, the muti-cloud approach also increases exposure to risk as there are a greater number of parties handling an organization's sensitive data. This is exactly why an eye must be kept on integration and a concerted effort be made to gain the visibility needed to counter threats across all different types of environments."

Security through the cloud

While the cloud is sometimes viewed as a challenge for businesses, it is also seen by almost all companies as a security enabler. Adoption of different cloud solutions are mixed - SaaS (71 percent) and IaaS (60 percent), PaaS (48 percent), BPaaS (30 percent), FaaS (25 percent) - but adoption of cloud-based security solutions is near ubiquitous (92 percent). The most popular cloud security tools are firewalls (55 percent), email security (52 percent), antivirus/antimalware (48 percent) and data loss prevention (48 percent). The majority (57 percent) of respondents said that they expected their cloud security budget to increase in the next 12 months.

"It makes absolute sense that organizations trusting an increasing amount of their data to the cloud are also utilizing its benefits to improve their security," concluded Reed. "Security, more than any other enterprise IT function, requires speed - of deployment and implementation. The ability of the cloud to rapidly deliver new security services that integrate easily into organizations' existing systems is a key value driver and explains why cloud security tools have been adopted so broadly."
Published Tuesday, September 03, 2019 1:27 PM by David Marshall
Filed under: , ,
Comments
There are no comments for this post.
To post a comment, you must be a registered user. Registration is free and easy! Sign up now!
top25
Calendar
<September 2019>
SuMoTuWeThFrSa
25262728293031
1234567
891011121314
15161718192021
22232425262728
293012345