Site navigation

Google Cloud Platform Controls More Misconfigured Than Azure, AWS

Thom Carter

,

Google Cloud Platform Controls More Misconfigured Than Azure or AWS
Researchers found that Google Cloud Platform had the most misconfigured controls out of the big three CSP environments.

According to a new report from security solutions firm Qualys, controls within Google Cloud Platform (GCP) are the most misconfigured by users of the big three cloud service provider (CSP) environments, thereby increasing susceptibility to security risks.

This is just one of the many findings highlighted in the Qualys Threat Research Unit’s recently published TotalCloud Security Insights report. The research utilises anonymised data from global cloud scans.

“Configurations” refer to control settings applied to both software and hardware aspects within a cloud environment. While the platforms themselves aren’t intrinsically insecure, the misconfiguration of controls by users can magnify security risk.

Misconfiguration can be caused by myriad reasons: from the complexity of cloud environments to a lack of expertise with evolving technologies, human error leading to insecure settings and permissions, or rapid deployment that compromises the implementation of security measures.

When looking at cloud misconfiguration issues in the three major CSPs, the researchers found that Google Cloud Platform was in the lead with an average failure rate of 60% when measured against Centre for Internet Security (CIS) Benchmarks. The CIS Benchmarks are a set of configuration guidelines and recommendations provided to help protect systems against cyber threats.

However, Azure wasn’t far behind the GCP misconfiguration rates with an average failure rate of 57%. The last of the big three, AWS, had an average failure rate of 34%.

Further, the misconfiguration of controls in GCP services that most failed against CIS Benchmarks was DataProc, BigQuery, and Logging, according to the research.


Recommended


Encryption, identity and access management (IAM), and external-facing assets were highlighted as key misconfigurations across all clouds.

For instance, when it comes to encryption, 99% of the disks in Azure are either not encrypted or are not using a customer-managed key (CMK), despite the report noting that enabling encryption is usually as simple as selecting a checkbox within the configuration settings.

Meanwhile, regarding IAM in AWS, multi-factor authentication (MFA) is not enabled for 44% of IAM users with console passwords. Further, IAM Access Analyzer is not enabled in 96% of the accounts scanned by Qualys.

The report also underscored that a common misconfiguration by users of all three major cloud providers is inadvertently leaving data publicly accessible. For example, the research team found that 31% of S3 buckets are publicly accessible, which exposes them to a variety of potential cybersecurity vulnerabilities.

Thom Carter

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data