The finding from the Tenable 2024 Cloud Security Outlook study is a clear sign of the need for proactive and robust cloud security. Read on to learn more about the study’s findings, including the main challenges cloud security teams face, their strategies for better protecting their cloud infrastructure and the tools they use to measure success.
Tenable has just published its "2024 Cloud Security Outlook" report, our annual assessment of organizations’ perceptions and experiences in securing their public cloud environments. The report, which polled 600 cloud security professionals in North America and Europe, explores the issues plaguing the respondents, the priorities they’ve set to address these challenges and the tools they’re using to measure success. We hope the report helps you understand how your peers are tackling cloud-environment complexity so you can set a strategic, effective path for securing yours.
Check out key highlights from the report below.
Each year, the study probes how many respondents are affected by cloud-related breaches. We’re always optimistic. One might think that the huge growth in cloud-security awareness and tooling options would have by now triggered a downward trend in – or at least some immunity to – breaches. Alas, we found that a discomforting 95% of the 600 organizations polled had experienced cloud-related breaches in the previous 18 months. Among those, somewhat predictably, 92% reported exposure of sensitive data, and a majority acknowledged being harmed by the data exposure.
Given that in the cloud world breaches seem unavoidable, it makes sense that cloud security platforms seek to not just flag vulnerable points of entry but also minimize a hacker’s ability to do harm once in. We were therefore curious about what cloud security professionals perceive as their greatest source of risk – workload vulnerabilities, ransomware attacks, third party access? Here, perception aligned with the most recent industry understanding: Respondents cited insecure cloud identities and misconfigurations as their leading security risks – and 99% of organizations that experienced cloud-related breaches placed the blame on insecure identities as the leading cause.
We drilled down into identities and access to see if organizations are not only aware of insecure identity and access management (IAM) as public enemy #1 for cloud security, but if they are doing something about it. Here respondents scored top marks, with many prioritizing efforts to minimize permissions through zero trust, access governance and just-in-time (JIT) initiatives.
The report focused on three angles in securing cloud infrastructure and, in particular, governing access to resources:
Other important findings included:
The findings revealed several regional disparities, including which region was more inclined to report experiencing no cloud-related breaches (spoiler: North America). We also saw regional differences in breaches’ causes. EU organizations were much more likely to pin their cloud breaches on excessive permissions and difficulty in detecting toxic combinations than their North American counterparts.
Regional differences also surfaced regarding the influence of DevOps teams on respondents’ ability to implement new cloud security capabilities. Significantly more respondents in North America than in Europe cited as a barrier the fear of DevOps teams that security efforts would disrupt their workflow.
Hopefully this blog has whetted your appetite for cloud security insights and best practices. We invite you to download the report, which will offer you:
Diane Benjuya is a senior product marketing manager in cloud security with 20+ years in the field, more recently in the focus areas of cloud infrastructure and identity. When at leisure she enjoys a decent run and soul-lifting jam session. Diane holds a masters degree in linguistics.
Enter your email and never miss timely alerts and security guidance from the experts at Tenable.
Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.
Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.
Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.
100 assets
Choose Your Subscription Option:
Thank you for your interest in Tenable Vulnerability Management. A representative will be in touch soon.
Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.
Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.
Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.
100 assets
Choose Your Subscription Option:
Thank you for your interest in Tenable.io. A representative will be in touch soon.
Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.
Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.
Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.
100 assets
Choose Your Subscription Option:
Thank you for your interest in Tenable Vulnerability Management. A representative will be in touch soon.
Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.
Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.
Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.
Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.
Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.
Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.
Thank you for your interest in Tenable Lumin. A representative will be in touch soon.
Please fill out this form with your contact information.
A sales representative will contact you shortly to schedule a demo.
* Field is required
Get the Operational Technology Security You Need.
Reduce the Risk You Don’t.
Continuously detect and respond to Active Directory attacks. No agents. No privileges.
On-prem and in the cloud.
Exceptional unified cloud security awaits you!
We’ll show you exactly how Tenable Cloud Security helps you deliver multi-cloud asset discovery, prioritized risk assessments and automated compliance/audit reports.
Exposure management for the modern attack surface.
Know the exposure of every asset on any platform.
Thank you for your interest in Tenable Attack Surface Management. A representative will be in touch soon.
FREE FOR 7 DAYS
Tenable Nessus is the most comprehensive vulnerability scanner on the market today.
Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.
Fill out the form below to continue with a Nessus Pro Trial.
Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.
Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.
FREE FOR 7 DAYS
Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.
Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.
Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.
Tenable solutions help fulfill all SLCGP requirements. Connect with a Tenable representative to learn more.