State of Cloud Security 2021.pdf

CLOUD SECURITY 2021

A report on the risks, costs, and challenges organizations and cloud teams are experiencing in 2021.

Introduction

The cloud and digital transformation have radically changed the IT landscape and introduced new kinds of threats and security requirements. The Shared Security Model of Cloud has relieved organizations from the burdens of securing physical IT infrastructure, which is now the responsibility of the Cloud Service Providers (CSPs) such as Amazon Web Services, Microsoft Azure, and Google Cloud.

But cloud customers are responsible for the secure use of virtual cloud resources, which requires different approaches and tooling to accomplish than it did in the data center. Attackers operate differently in the cloud than in data centers as well, and how organizations go about keeping data safe needs to be different. According to Gartner, through 2023, at least 99% of cloud security failures will be the customer’s fault, mainly in the form of cloud resource misconfiguration.

Cloud and DevOps engineers are focused on the configuration of cloud resources, including security-sensitive resources such as networks, security groups, and access policies for databases and object storage. Organizations need to ensure that the configuration of their cloud resources is correct and secure on day one—and stay that way.

Industry analysts call this Cloud Security Posture Management (CSPM), which involves ensuring secure cloud resource configuration at every stage of the software development lifecycle (SDLC) from infrastructure as code to running cloud environments. Misconfiguration is what cloud customers tend to get wrong, sometimes with devastating consequences. Many data breaches that make the headlines are the result of the exploitation of cloud misconfiguration mistakes.

For the State of Cloud Security Report 2021, we surveyed 300 cloud professionals, including cloud engineers, cloud security engineers, DevOps, and cloud architects, to better understand the risks, costs, and challenges they are experiencing managing cloud security at scale.

The Nature and Scale of Cloud Misconfiguration Risk

Misconfiguration: The #1 Cause of Cloud Breaches

36% suffered a serious cloud security leak or breach in the past year

Misconfigurations represent the number one risk for every organization using the cloud. 36% of cloud professionals say their organization has experienced a serious cloud data leak or a breach in the past 12 months. More than 8 out of 10 are worried that they are vulnerable to a major data breach related to cloud misconfiguration.

83% concerned their organization is at risk
36% experienced a serious cloud data leak or breach in the past 12 months

Cloud Misconfiguration: By The Numbers

The rate of drift and misconfiguration remains extremely high
Deployment mistakes and compliance violations in infrastructure as code files constitute a significant contribution to cloud misconfiguration risk. Cloud infrastructure environments are highly dynamic and subject to unapproved post-deployment configuration changes called drift, which require constant monitoring for configuration errors.

Cloud Misconfiguration Incidents(per day) 2021
1-10 24%
10-50 21%
50-100 19%
100-250 13%
250-500 6%
500-1,000 8%
More than 1,000 3%

Misconfiguration Mistakes: The Ultimate Insider Threat

Cloud misconfiguration is a problem born of many causes—all attributed to human error. Enterprise cloud environments are vast and complex, and the dynamism of these environments creates many opportunities for critical mistakes. The number one cause of cloud misconfiguration cited in our survey is the number of APIs and interfaces that require governance. A lack of adequate controls and oversight (31%), and lack of awareness of policies (27%) were also cited.

With 45% reporting that they are using more than one cloud provider, the problem can compound if teams choose a cloud service provider’s native security tooling, which doesn’t work in multi-cloud environments.

The Most Prevalent Cloud Misconfigurations

One of the many aspects of the cloud that differentiate it from the data center is the sheer number of unique cloud services available, each with its risks and security best practices.

Preventing Cloud Misconfiguration

Cloud Security: Whose Job Is It?

Cloud security is largely a responsibility shared across functions, including cloud engineering, security teams, compliance analysts, and outside consultants. The application developers and cloud engineers that develop, deploy, and maintain their cloud environments generally own the security of those environments.

Different teams are generally concerned with different phases of the cloud SDLC:

Cloud Policy: Approaches to Implementation and Enforcement

Every organization operating in the cloud has a set of policies intended to govern usage, from internal rules to compliance standards. The advent of policy as code (PaC) has revolutionized how IT policy is implemented. The adoption of PaC continues to grow, but there are a wide variety of tools and implementation patterns.

35% still rely on manual checklists for cloud security, which is time-consuming and introduces the risk of human error.

Securing Infrastructure as Code Pre-Deployment

A key component of the Cloud Development Lifecycle (CDLC) is the early development phase involving infrastructure as code (IaC), which is used to define and provision the initial cloud resources and configurations in code files. The use of IaC is now mainstream, with more than 90% of respondents citing at least some IaC usage.

Detecting and Remediating Cloud Misconfigurations

Managing cloud vulnerabilities is a race between attacker and defender, as attackers use automation tools to scan the internet to find cloud misconfigurations within minutes of their deployment. 47% of teams analyze cloud provider logs to identify dangerous drift events and misconfigurations, and 35% rely on manual audits of their environment.

Measuring the Success of Cloud Security

Mean Time to Remediation (MTTR) is the key security metric for measuring cloud infrastructure risk.

Ideal MTTR Real MTTR
Fewer than 15 minutes 14% 10%
15 minutes to 1 hour 36% 39%
1 hour to 1 day 30% 33%
1 day to 1 week 13% 12%
1 week to 1 month 5% 5%

Auditing Cloud Environments for Compliance

Cloud environment audits are routine, and failing a cloud audit is also quite routine, with 45% citing a cloud audit failure. Only 26% continuously audit their environment (i.e., “daily”).

Managing Cloud Security and Compliance Issues: Level of Effort

The costs of cloud security and compliance are predictably high. Teams need to manually review alerts and tickets, identify critical misconfigurations that need remediation, and manually fix them.

Hours per week Fewer than 10
Hours per week 10-50
Hours per week 50-100
Hours per week More than 500

Cloud Security: Team Challenges and Organizational Consequences

While cloud misconfiguration vulnerabilities are preventable with proactive approaches, an over-reliance on manual processes stresses teams already under pressure.

Conclusions: Where Cloud Security is Going

The scale and complexity of cloud risk is growing. The nature of cloud threats has also evolved, and attacks have become more sophisticated. The result: a vast majority of respondents (83%) are concerned their organization is at risk of a cloud-based data breach.

Recommendations