Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

1/3/2020
10:30 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

Organizations May 'Uncloud' Over Security, Budgetary Concerns

While most cloud vendors forecast continued adoption and growth, some customers are taking a harder look at the cloud services they're using

With Gartner forecasting cloud revenue to hit $370 billion by 2023, and Microsoft highlighting how cloud has become a core element in enterprise IT, cloud's momentum looks unstoppable.  But cloud customers are bumping up against some harder realities; according to our most recent cloud data security report, 48% of organizations that store sensitive data in the cloud would consider moving that data back on premises. It's a costly and time-consuming proposition, yet organizations are thinking about it. Why?

In most cases, organizations uncloud because they face unexpected issues. Initially the plurality of organizations migrated to the cloud to cut costs (31%) and ensure availability for remote workers (26%). However, the survey results show that organizations are ready to uncloud due to their inability to ensure the desired level of protection (24%).

About one third of the organizations would uncloud because they didn’t achieve the initial goals of cloud migration. Among those who moved their data to the cloud to cut costs, 29% are ready to uncloud due to unexpected high costs. Among those who moved data to the cloud for security reasons, 27% would uncloud due to considerable security concerns.

Let's take a closer look at factors that affect the decision to uncloud, as well as possible best practices that could obviate the challenges. 

Unexpectedly high costs from storing too much data in the cloud
Prior to a migration, most companies (67%) don't discover and classify all the files which actually need migrated; in fact, 63% simply moved all their data to the cloud. This is likely the driver to the unanticipated high costs of storing data in the cloud.  Moreover, they neglect to take this opportunity to get rid of redundant, old, and trivial (ROT) files which complicates the lives of users and leads to unusually high cloud storage costs.

Best practice: Before moving data to the cloud, find and classify all your data. By doing this, you can be sure that you are migrating only the data required by the business. In addition to keeping a tight grip on your data (deleting or archiving ROT data), this will lower your overall costs associated with storing data in the cloud.

Inability to ensure the security of sensitive data in the cloud
About half of organizations looking to uncloud had at least one cloud security incident in 2018. This fact is disturbing, since organizations store extremely sensitive data in the cloud: 50% store personally identifying information of customers and clients, 24% store payment data, and 18% store intellectual property. What is even more frightening, 53% of organizations couldn’t determine who was to blame for the security incidents. This means that organizations lack visibility into their cloud environment and cannot investigate security incidents properly, which makes it hard for them to prevent similar incidents in the future and protect their data.

Best practice: To minimize risk of security incidents and investigate them more efficiently, you should audit your cloud environment to see who did what, when and where, and detect any suspicious activities around sensitive files. Also, don’t forget about data discovery and classification (DDC). "Data classification also allows organizations to focus their security and compliance efforts on sensitive information, to standardize and apply controls commensurate with risk, and to streamline those activities within business processes," Gartner claims in a 2018 report titled Hype Cycle for Data Security

The Netwrix study highlights the benefits of DDC and shows that organizations that classify their data have less chance of experiencing an incident. Only 14% of organizations that performed data classification had incidents in 2018 — a rate 3.5 times lower than for organizations that didn’t classify their data.

Lack of financial support and budgetary constraints
It’s hard to protect your data in the cloud if you lack financial support. About 61% of those who plan to uncloud said that their cloud security budgets didn’t increase in 2019, and 38% said that management doesn’t provide any financial support for cloud security initiatives. 

Best practice: You need to deliver the value of cloud security investments to your management. Specifically, you need to explain to management that a secure cloud is a great way to boost your business, while failure to protect sensitive data like customer PII can have negative financial impact, resulting in business downtime, costly data breaches, lawsuits, bad publicity and fines from regulatory bodies.

The best way to prevent disappointment with your cloud migration is to understand how much data you have, who has access to it and which data is most critical in your IT environment, so you can prioritize your security efforts and protect your data against compromise. Deep understanding of your data will also help you reduce cloud costs, as well as manage data more effectively by carefully choosing which data to migrate, which to leave on premises, and which to delete or destroy.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "5 Pieces of GDPR Advice for Teams Without Privacy Compliance Staff."

Matt Middleton-Leal is General Manager and Chief Security Strategist is at Netwrix, a software company that enables information security and governance professionals to reclaim control over sensitive, regulated and business-critical data, regardless of where it resides. Matt ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8144
PUBLISHED: 2020-04-01
The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It accepts a request with a URL to firmware u...
CVE-2020-8145
PUBLISHED: 2020-04-01
The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup� and “wizard� endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP ...
CVE-2020-8146
PUBLISHED: 2020-04-01
In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is running on Windows and adjusting the SafeDllSearchMode in the win...
CVE-2020-6009
PUBLISHED: 2020-04-01
LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
CVE-2020-6096
PUBLISHED: 2020-04-01
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker ...