According to research by Check Point, over 98% of organisations have incorporated some kind of cloud-based infrastructure into their operation. It’s no surprise then, that some of the biggest cloud security challenges affect a huge number of businesses.
A large portion of this adoption came about as a result of the pandemic, with companies needing to provide critical services and support to off-site workers during the shift to remote working.
More than three-quarters (76%) of companies now use multiple cloud providers across a litany of services – with these cloud environments playing host to critical data and business applications.
Naturally, this reliance on cloud services has posed some security risks. And with that in mind, here are five of the biggest cloud security challenges facing companies, according to Check Point Research.
Cloud Security Challenges
Multi-cloud Challenges
Most companies now leverage multi-cloud deployment within their business infrastructure. Naturally, this increases potential attack surfaces and the statistics reflect this.
More than half (57%) of organisations find it difficult to wholly adhere to corporate policy and regulation when it comes to properly protecting multi-cloud environments. A large part of this problem can be attributed to a lack of skills in this space, with 56% of organisations struggling to gain the necessary skills to manage consistent security across multi-cloud environments.
Another pitfall of using more than one cloud service is that different vendors have different security functionality and compatibility, meaning that integration between security solutions can be challenging with 50% of organisations struggling with this issue.
This reliance on frameworks provided by vendors also creates issues with visibility and control – as 46% of organisations attest to.
Automation & Orchestration
Dealing with complex, multi-cloud deployments means that automation is essential. With Check Point’s breakdown in how companies address this, it’s clear that there’s no umbrella solution, but a neccessity to spread the task across multiple means.
48% use templated Infrastructure as Code (IaC) and Security as Code (Terraform or AWS CloudFormation). Serverless Technologies (Lamba or Azure functions) are a similarly popular solution with 44% of companies using this route.
Roughly split is also the use of continuous integration and delivery (CI/CD) plugins (Jenkins or TeamCity) – 44%, security orchestration, automation, and response (SOAR) tools at 41% and finally, another 41% of companies use configuration orchestration tools (Chef or Ansible).
Least popular is web application firewalls, with only 4% of organisations using these.
DevOps Cycle
Shifting security into earlier stages of the software development lifecycle can dramatically reduce the costs and impacts of vulnerabilities or code that violates regulatory requirements.
Organisations implement DevOps security and compliance testing into various stages of the SDLC, including system testing and production (52%); feature development and unit testing (42%); staging (42%); no testing (10%) and finally, other (27%).
Recommended
- The 11 most expensive NFTs ever sold
- Atlassian customers face lengthy disruption after cloud outage
- What can augmented business intelligence do for your organisation?
Operational Security
This accounts for some of the biggest challenges in securing complex cloud environments – especially when there’s more than one involved.
Broken down, the main issues are a lack of qualified staff (45%), regulation compliance (35%), lack of security visibility inherent to the tech, currently (35%), difficulty in identifying misconfigurations (33%).
Unfortunately, the issues don’t end there, with 28%-32% of companies also citing an inability to set consistent security policies, cloud security automation and automated security enforcement also being consistent problems.
Cloud Compliance
Compliance with various data protection regulations and industry standards is a must for most organisations. However, designing and implementing compliance policies for cloud environments is very different from on-premise systems.
Some of the biggest cloud security challenges in this space include how daunting it is to create effective risk management and compliance audits, with 43% of companies struggling with this.
Also, manually maintaining and reporting compliance with multiple regulations across multi-cloud environments is complex and unscalable. 27% of organizations claim that scaling and automating compliance is one of their biggest cloud compliance challenges.
Cloud First Summit 2022 | Join the Conversation
​The 2nd annual Cloud First Summit will take place live and in-person on Thursday 16th June 2022 at Dynamic Earth in Edinburgh.
The Summit will contextualise the transition to Cloud-based services, looking at key trends, advancements, and use-cases, and discussing how to optimise the business impact of Cloud technology.
For more information, visit:Â www.cloudfirstsummit.com





