Image: Maksym Yemelyanov/Adobe Stock
President Joe Bidens administration, as part of its recently released National Cybersecurity Strategy, said critical sectors such as telecommunications, energy and healthcare rely on the cybersecurity and resilience of cloud service providers.
Yet, recent reports suggest the administration has concerns that major cloud service providers constitute a massive threat surface one through which an attacker could disrupt public and private infrastructure and services.
That concern is hard to argue with given the monolithic nature of the sector. Research firm Gartner, in its most recent look at worldwide cloud infrastructure-as-a-service market share, put Amazon on top, leading with revenue of $35.4 billion in 2021, with the rest of the market share breakdown as follows:
The Synergy Group reported that together, Amazon, Microsoft and Google accounted for two-thirds of cloud infrastructure revenues in three months ending Sept. 30, 2022, with the eight largest providers controlling more than 80% of the market, translating to three-quarters of web revenue.
Jump to:
The administrations report noted that threat actors use the cloud, domain registrars, hosting and email providers, as well as other services to conduct exploits, coordinate operations and spy. Additionally, it advocated for regulations to drive the adoption of secure-by-design principles and that regulations will define minimum expected cybersecurity practices or outcomes.
Also, it will identify gaps in authorities to drive better cybersecurity practices in the cloud computing industry and for other essential third-party services and work with industry, congress and regulators to close them, according to the administration report.
If the administration is speaking to CSPs controlling traffic through vast swaths of the global web with an eye to regulating their security practices, it may be moot, as CSPs already have strong security protocols in place, noted Chris Winckless, senior director analyst at Gartner.
Cloud providers appear from all evidence to be highly secure in what they do, but the lack of transparency on how they do so is a concern, Winckless said.
See: Cloud security, hampered by proliferation of tools, has a forest for trees problem (TechRepublic)
However, Winckless also said there are limits to resilience, and the buck ultimately lands on the customers desk.
The use of the cloud is not secure, either from individual tenants, who dont configure well or dont design for resiliency, or from criminal/nation-state actors, who can take advantage of the dynamism and pay for flexibility model, he added.
Chris Doman, chief technology officer of cloud incident response firm Cado Security, said major cloud service providers are already the best at managing and securing cloud infrastructure.
To question their abilities and infer that the U.S. government would know better in terms of regulation and security guidance would be misleading, Doman said.
Imposing know-your-customer requirements on cloud providers may be well intentioned, but it risks pushing attackers to use services that are further from the reach of law enforcement, he said.
The biggest threat to cloud infrastructure is physical disaster, not technology failures, Doman said.
The financial services industry is a great example of how a sector diversifies activity across multiple cloud providers to avoid any points of failure, said Doman. Critical infrastructure entities modernizing towards the cloud need to think about disaster recovery plans. Most critical infrastructure entities are not in a position to go fully multicloud, limiting points of exposure.
While the Biden administration said it would work with cloud and internet infrastructure providers to identify malicious use of U.S. infrastructure, share reports of malicious use with the government and make it easier for victims to report abuse of these systems and more difficult for malicious actors to gain access to these resources in the first place, doing so could pose challenges.
Mike Beckley, founder and chief technology officer of process automation firm Appian, said that the government is rightly sounding the alarm over the vulnerability of government systems.
But, it has a bigger problem, and that is that most of its software isnt from us or Microsoft or Salesforce or Palantir, for that matter, said Beckley. Its written by a low-cost bidder in custom contracts and, therefore, sneaks by most rules and constraints we operate by as commercial providers.
Whatever the government thinks its buying is changing every day, based on least experience or least qualified, or even the most malicious contractor who has the rights and permissions to upload new libraries and codes. Every single one of those custom-code pipelines has to be built up for every project and is therefore only as good as the team that is doing it.
Seeking out malefactors is a big ask for CSPs like Amazon, Google and Microsoft, said Mike Britton, chief information security officer at Abnormal Security.
Ultimately, the cloud is just another fancy word for outside servers, and that digital space is now a commodity I can store petabytes for pennies on the dollar, said Britton. We now live in a world where everything is API- and internet-based, so there are no barriers as there were in the old days.
SEE: Top 10 open-source security and operational risks (TechRepublic)
There is a shared responsibility matrix, where the cloud provider handles issues like hardware operating system patches, but it is the customers responsibility to know what is public facing and opt in or out. I do think it would be good if there were the equivalent of a no failsafe asking something like Did you mean to do that? when it comes to actions like making storage buckets public.
Taking your 50 terabytes in an S3 storage bucket and accidentally making it publicly available is potentially shooting yourself in the foot. So, cloud security posture management solutions are useful. And consumers of cloud services need to have good processes in order.
Check Point Securitys 2022 Cloud Security report listed leading threats to cloud security.
A leading cause of cloud data breaches, organizations cloud security posture management strategies are inadequate for protecting their cloud-based infrastructure from misconfigurations.
Cloud-based deployments outside of the network perimeter and directly accessible from the public internet make unauthorized access easier.
CSPs often provide a number of application programming interfaces and interfaces for their customers, according to Check Point, but security depends on whether a customer has secured the interfaces for their cloud-based infrastructures.
Not a surprise, password security is a weak link and often includes bad practices like password reuse and the use of poor passwords. This problem exacerbates the impact of phishing attacks and data breaches since it enables a single stolen password to be used on multiple different accounts.
An organizations cloud resources are located outside of the corporate network and run on infrastructure that the company does not own.
As a result, many traditional tools for achieving network visibility are not effective for cloud environments, Check Point noted. And some organizations lack cloud-focused security tools. This can limit an organizations ability to monitor their cloud-based resources and protect them against attack.
The cloud makes data sharing easy, whether through an email invitation to a collaborator, or through a shared link. That ease of data sharing poses a security risk.
Although paradoxical since insiders are inside the perimeter, someone with bad intent may have authorized access to an organizations network and some of the sensitive resources it contains.
On the cloud, detection of a malicious insider is even more difficult, said CheckPoints report. With cloud deployments, companies lack control over their underlying infrastructure, making many traditional security solutions less effective.
Cybercrime targets are mostly based on profitability. Cloud-based infrastructure that is accessible to the public from the internet can be improperly secured and can contain sensitive and valuable data.
The cloud is essential to many organizations ability to do business. They use the cloud to store business-critical data and to run important internal and customer-facing applications.
Its important for organizations to secure their own perimeters and conduct a regular cadence of tests on vulnerabilities internal and external.
If you want to hone your ethical hacking skills for web pen testing and more, check out this comprehensive TechRepublic Academy ethical hacking course bundle.
Read next: How to minimize security risks: Follow these best practices for success (TechRepublic)
Read the original post:
The Biden administration may eye CSPs to improve security, but the real caveat emptor? Secure thyself - TechRepublic
- Box for Android - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- eUKhost - eNlight Cloud Hosting! - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Cloud Computing -- Oracle is Ready to Take You There - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- What is Cloud Computing? - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Webinar - Cloud Computing: Why You Should Care - 2010-10-14 - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- What is Cloud Hosting? - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Cloud Computing Misconceptions and Benefits - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Cloud Hosting and How it is Set to Change Internet Commerce - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Awesome Cloud Computing Explained with Animation - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Rackspace Cloud Race - UK cloud hosting - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Improved Cloud Service Delivery And Hosting | IBM - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Cloud Computing Explained - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Software companies turn to Savvis for cloud hosting and other SaaS services - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Sky News Tech Report on Cloud Computing - Macquarie Telecom Interview - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- BitNami Cloud Hosting Demo - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Fully managed Cloud Computing solution using your current IT infrastructure (Closed Caption) - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- Cloud Hosting Server Provisioning - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- iomart Hosting Provides Cloud Storage and Backup for new Branding Network [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Harris plans to stop offering remote cloud hosting [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- iomart Hosting provides cloud storage and backup for new UK branding network [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- DynamicOps Debuts "Fastest Path to Cloud" Seminar and Webinar [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Harris Corporation to Discontinue Cyber Hosting Operation; Will Continue Providing Advanced Cyber Security and Cloud ... [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Tutorial! Amazon Cloud Minecraft Server Hosting! - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- MachPanel 4.3 - SaaS and Cloud Hosting Control Panel for Windows - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Webair Carrier Neutral Cloud: Open Network Access in the Cloud [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- iomart Hosting Takes UK Digital Media Agency Into the Cloud [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- FireHost Grows Executive Team on Heels of European Expansion; Appoints Jim Ciampaglio as Sr. Vice President of Global ... [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- INetU Managed Hosting is SOC 2 and SOC 3 Compliant [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- Web Host Webair Adds Carrier Neutral Cloud Services [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- FireHost Appoints Jim Ciampaglio as Sr. Vice President of Global Sales and Marketing [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- BitRock CEO on BitNami Cloud Hosting - Video [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- Harris kills remote hosting service as customers shun cloud storage [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- Understand Cloud computing in 60secs - Video [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- Systech Integrators® Forms Strategic Relationship With Rackspace Hosting® to Offer Cloud Hosting Services for SAP® ... [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- Dedicated & Cloud Hosting Provider Codero Names Industry Veteran Emil Sayegh, President & CEO [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- Cloud Computing and Technology Mobility - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- Cloud Hosting Providers - Video [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- Online Education Innovator Gives Virtual Internet Cloud Services an A+ [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- SingleHop Introduces the Hosting Industry's First Customer Bill of Rights [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Cloud Services Provider Intermedia Launches Integrated Partner Program [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Cloud Services Provider Intermedia Now Offering Microsoft Office 365 [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Inside IT Cloud Computing Security - Video [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Lansing Cloud Host Introduces Faster ‘Storm SSD’ [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Leading Industry Analyst Firm positions Hosting.com as a Challenger in Managed Hosting Magic Quadrant [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- Hosting.com Positioned as Challenger in Managed Hosting in Gartner's Magic Quadrant [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- ServInt Announces the First Finalist for Its Inaugural Sextant Award, Recognizing the Most Effective Use of the ... [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- Leading Analyst Firm Recognizes Savvis as a Leader in Two Cloud-Focused Magic Quadrants [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- UK Cloud Computing Company iomart Hosting Recruits Scotland Footballers to Kick off New Campaign [Last Updated On: March 9th, 2012] [Originally Added On: March 9th, 2012]
- Rackspace Hosting Positioned as a Leader in the Leaders Quadrant of the Magic Quadrant for Managed Hosting Providers [Last Updated On: March 9th, 2012] [Originally Added On: March 9th, 2012]
- 4t Networks Offers Red Hat Enterprise Linux 6 for Cloud Hosting [Last Updated On: March 9th, 2012] [Originally Added On: March 9th, 2012]
- elchemyv2.wmv - Video [Last Updated On: March 9th, 2012] [Originally Added On: March 9th, 2012]
- Steve VanRoekel Keynote, NIST Cloud Computing Forum and Workshop IV - Video [Last Updated On: March 11th, 2012] [Originally Added On: March 11th, 2012]
- Hosting.com Enhances Backup Capabilities to Deliver Leading-Edge Data Recovery Solution for Businesses Any Size ... [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Online Tech Hosts Webinar on Cloud Computing in EHR/RCM Systems [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Hosting.com Enhances Backup & Data Recovery [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- ServInt Introduces Its New Flex Line of High-Performance, Fully Managed Dedicated Servers [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- Telefonica targets LatAm with business cloud [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- TCWH Announces New InMotion Hosting Review 2012 [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- Lokahi Expands Cloud Offering to Include Managed Security Services Through Partnership With StillSecure [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Eco Cloud Hosting IPv6 Ready with Web Application Firewall and Load Balancer - Video [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Private SharePoint Cloud Beats Other Cloud Hosting Options for Enterprises on Price, Practicality [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Private SharePoint Cloud Beats Other Cloud Hosting Options for Enterprises, Says AISN [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- CaymanSecurity.com Introduces Secure Cloud Hosting Services [Last Updated On: March 19th, 2012] [Originally Added On: March 19th, 2012]
- Storm On Demand Introduces Windows Cloud Hosting [Last Updated On: March 20th, 2012] [Originally Added On: March 20th, 2012]
- Citrix Streamlines Delivery of Cloud-Hosted Apps and Desktops [Last Updated On: March 20th, 2012] [Originally Added On: March 20th, 2012]
- Cloud Computing Explained.mp4 - Video [Last Updated On: March 20th, 2012] [Originally Added On: March 20th, 2012]
- AMD Opteron 3200 Chips Target Cloud, Web Hosting [Last Updated On: March 20th, 2012] [Originally Added On: March 20th, 2012]
- Understanding the Cloud Computing Stack: SaaS, PaaS and IaaS | CloudU - Video [Last Updated On: March 21st, 2012] [Originally Added On: March 21st, 2012]
- Racemi Joins Rackspace Cloud Tools Program [Last Updated On: March 22nd, 2012] [Originally Added On: March 22nd, 2012]
- iNetRadio Adds User Music Cloud Hosting [Last Updated On: April 18th, 2012] [Originally Added On: April 18th, 2012]
- Managed Hosting Company, OneNeck IT Services, Selected by Southwest Home Builder for Cloud Services [Last Updated On: April 18th, 2012] [Originally Added On: April 18th, 2012]
- What is Cloud Hosting? - Australian Cloud Hosting Providers - Video [Last Updated On: April 18th, 2012] [Originally Added On: April 18th, 2012]
- Courion Leverages NaviSite's Enterprise Cloud to Deliver Identity and Access Management Software-as-a-Service [Last Updated On: April 24th, 2012] [Originally Added On: April 24th, 2012]
- TLD Solutions Launches Next Generation "4GH" Web Hosting [Last Updated On: May 4th, 2012] [Originally Added On: May 4th, 2012]
- ElasticHosts unveils simple cloud web hosting for SMEs [Last Updated On: May 4th, 2012] [Originally Added On: May 4th, 2012]
- Rackspace Hosting 1Q net income up on higher sales [Last Updated On: May 8th, 2012] [Originally Added On: May 8th, 2012]
- Infinitely Virtual Announces Support for Microsoft SQL Server 2012, Providing Cloud-Ready Hosting with Mission ... [Last Updated On: May 8th, 2012] [Originally Added On: May 8th, 2012]
- Kore Domains Launches Revolutionary New "4GH" Web Hosting Solution [Last Updated On: May 8th, 2012] [Originally Added On: May 8th, 2012]
- 4GH Web Hosting Europa Launches 4GH Cloud Web Hosting Solution in European Data Center [Last Updated On: May 10th, 2012] [Originally Added On: May 10th, 2012]
- Hughes Cloud Services & Hosting Showcases Its Comprehensive Enterprise IT Offering At ... [Last Updated On: May 12th, 2012] [Originally Added On: May 12th, 2012]