The report has found that human error is the top cause of cloud data breaches, with 55% of respondents citing it. This was well ahead of the next most common reason, exploitation of vulnerabilities, at 21%.
Featuring 2,889 respondents from across the globe except for Africa, and with 260 respondents from the UK, the survey was aimed at professional security and OT management.
From the offset of the report, it is clear that much of the digital world has become cloud first, but this increased reliance on the cloud, and cloud supporting services, has left many enterprises with complex security issues and legal confusing surrounding data sovereignty.
It’s A Multicloud WorldÂ
Cloud’s proliferation in the digital landscape quickly made it the rule of data storage, not the exception, and it seems multicloud is well on its way to achieving this same status.
In fact, 79% of respondents to the survey Thales Group conducted have more than one cloud provider, with the average number of cloud infrastructure providers being 2.3.
Thales Group said there were many benefits to a multicloud portfolio – additional functionality, diversifying resilience, increasing service availability may all have contributed to the rise of the multicloud. Partnerships, mergers, and acquisitions seem to be contributing as well.
Coupled with this is the increased usage of Software as a Service (SaaS) applications, with 22% of respondents saying that their enterprises use between 51 to 100 SaaS applications.
This expansion, however, means there is more to manage and keep secured.
The Cloud Threat LandscapeÂ
When asked to rank targets by the likelihood of attack, 38% of respondents said that SaaS applications were the leading targets for attacks, followed by cloud-based storage (36%).
Overall, securing the cloud was seen as a top, increasingly complex, priority among enterprises.
And this is not unfounded – 46% of respondents say they experienced a data breach in their cloud environment, and the number experiencing a data breach in the last year is up by four per cent (from 35% to 39%).
The increase in SaaS providers makes security more complex, and could be contributing to the increase in cyber attacks. Organisations may have to dedicate specific teams to secure each application provider, or have a team well-versed in multiple platforms.
Either way, with human error being labelled as the leading cause of cloud data breaches – a stat that is being echoed across the cybersecurity industry – then strategies may need a major update.
Cloud DataÂ
Cloud has become a more common path for new applications, with those with 60% or more of their workloads and data in the cloud increasing from 23% to 27% in the last year.
The amount of sensitive data stored in the cloud is on the rise – in 2022, 52% of respondents said that 40% of their sensitive date was in the cloud. In 2023, this increased to 64%. This reflects the increase of core applications running in the cloud, brining their data with them.
Even with more sensitive data being stored in the cloud, there is stull much of it not encrypted.
Only 22% of respondents said that over 60% of sensitive data in the cloud is encrypted, with an average of 45% of data being encrypted.
Further, only 2% reported that 100% of their sensitive data stored in the cloud was encrypted.
Data SovereigntyÂ
Data or digital sovereignty is how states regulate the protection, privacy, and security of technology in use under their jurisdiction. Different governments provide different levels and guarantees surrounding digital sovereignty, and countries often have to work together to reach agreements for safe data transfers to protect the integrity of their nation’s data sovereignty.
Respondents appeared wary around data sovereignty – 83% said they were somewhat or very concerned about its impacts on cloud deployment.
This is for good reason – laws are continuously challenged and changed across the globe affecting data transfers, digital rights and privacy, which can massively effect the ability of companies to use, access, and share data.
The introduction of cloud services, especially multiple cloud providers, gives companies an extra layer to regulate when it comes to data soverignty, ensuring third parties are complaint through strict regulations and contractual bases.
To meet digital sovereignty requirements, 96% of respondents said that designating or changing the location or jurisdiction of full data encryption are acceptable measures to achieve data sovereignty. In contrast, four per cent are not concerned about the location of data with respect to data sovereignty.
Some organisations are taking the location-based approach, while others are opting for increased encryption to ensure that data is secure from disclosure not matter its jurisdiction.
Complexity in the Cloud
More than half (55%) of respondents have said it is more complex to manage data in the cloud than in on-premises environments.
To delve into what might be causing this complexity, Thales Group asked respondents more questions regarding the organisation of data in the cloud.
Recommended
- 6th Edition of Scots Fintech Festival Coming in September
- Eureka Solutions Announces New Partnership
- Major UK Banks Sign Up to Mastercard’s AI-powered Anti-fraud Tool
It revealed that only 14% of respondents could control all of their encryption keys in their cloud environments, meaning that the majority of organisations work with multiple cloud environments with different encryption keys across the environments.
Further, 62% said they have five or more key management systems in place across their infrastructure, and 27% say their cloud provider controls all of their keys.
With such complexity across cloud systems, or companies forfeiting key control to their cloud providers, it is unsurprising that 55% report human error as the leading cause of cloud data breaches.
Ways to Improve
Thales Group listed several ways companies are trying to improve their cloud security.
Adopting multi-factor authentication has increased to 65% across organisations, which is an improvement Thales Group says is simply not good enough.
Further, centralising encryption management could be key to keeping data more secure in a multicloud environment. This would reduce operational complexity and improve flexibility to secure new environments.
A zero trust environment could also be vital – only 41% of respondents said their organisation had zero-trust controls on cloud infrastructure, with only 38% using zero-trust in their cloud networks.





