Sysdig’s threat research team — who’ve worked for or presented to significant bodies such as the U.S. National Security Agency — explored cloud attacks against industry verticals for the company’s latest publication, the 2023 Global Cloud Threat Report.
Specifically, regarding the headline statistic that the current average time for a threat actor to launch a targeted cloud attack is ten minutes, five of those minutes are dwell time. The authors point to the weaponisation of automation as what’s hastening attack speed.
While it inevitably varies depending on motive and visibility, threat actors need only hours to find and determine a worthy target, the report indicated.
When it comes to more opportunistic attacks, meanwhile, it’s been found to take on average under two minutes to find a publicly exposed credential, and then 21 minutes from credential discovery to the initiation of an attack.
Because identity and access management (IAM) is a crucial cloud security control, attackers are focusing on evolving their techniques for credential access, privilege escalation, and lateral movement, the Sysdig threat security team warned.
Relatedly, earlier this week DIGIT reported on a separate piece of research from Qualys which highlighted that IAM controls had key misconfigurations by users of the big three cloud service provider (CSP) environments.
For instance, regarding IAM in Amazon Web Services (AWS), multi-factor authentication (MFA) was not enabled for 44% of IAM users with console passwords. Further, IAM Access Analyzer wasn’t enabled in 96% of the accounts scanned by Qualys.
Further, IBM’s Cost of a Data Breach report from 2021 found that cloud misconfigurations account for 15% of initial attack vectors in security breaches, making it the third most common initial attack vector.
Recommended
- Google Cloud Platform Controls More Misconfigured Than Azure, AWS
- The Cloud is Breaking ‘Traditional’ Security Approaches, Data Suggest
- The Future for Cloud Services in Scotland
But where are cloud attack efforts being directed, exactly? Sysdig’s threat research team underscored that the primary targets for cloud attacks, rather expectedly, were telecommunications and finance institutions: 65% of cloud attacks target these two areas.
Interestingly, the authors noted that they “did not expect the low levels of interest in defense and health care, considering the data that could be stolen from those organizations.” Statistically-speaking, 5% of cloud attacks target health care companies, while just 1% target organisations in the defence sector.
One potential theory for the lower attack rate for health care and defence is that “cloud hackers stick to what they know, like selling online banking info for $35 each or merchant payment accounts for $1,000+.”





