This page was machine-translated and may differ from the original. View original
Cloud environment visibility is declining
85% of data leakage incidents are due to user company negligence
The higher the cloud security, the more response time doubles.
With the adoption and use of cloud services by companies surging due to the prolonged COVID-19 pandemic, IBM X-Force Security Lab released a report on the 15th titled "Cloud Threat Landscape," which introduces various forms of cloud security threats.
This report is based on cloud security incidents that IBM responded to in 2019.

IBM warned that if companies adopt the cloud without sufficient security preparations in advance, the responsibility for cloud security may become unclear and responding to risks may become difficult.
According to an IDC survey, in 2019 alone, more than one-third of companies adopted over 30 types of cloud services from 16 cloud providers. In such a distributed environment, existing security policies are ineffective, and it is difficult to secure visibility across the entire cloud environment.
According to a survey by the IBM Institute for Business Value, most companies rely on cloud providers for cloud security. However, more than 85% of data breaches were attributed to the user.
◇ Cloud Security: User Response Capability Is More Important Than Provider
The most common route used by cybercriminals to infiltrate the cloud is cloud-based applications, accounting for 45% of all incidents. Cybercriminals exploit not only configuration errors but also vulnerabilities within applications; however, these vulnerabilities often go undetected because employees arbitrarily install new cloud apps through unauthorized channels.
Ransomware is also one of the most threatening entities in cloud environments, being distributed more than three times as often as other malware. It was followed by cryptominers and botnet malware.
This survey confirmed that companies with high maturity in cloud and security were able to identify and prevent data breaches more quickly. When looking at response times for data breaches, the most experienced organizations (average 125 days) were found to be able to identify and respond to breaches twice as fast as the least experienced organizations (average 250 days).
◇ 6 Rules for Implementing a Cloud Security Environment
IBM advised that companies should focus on the following six rules to implement cybersecurity optimized for cloud environments.
First, a collaborative governance and culture must be established. Application developers, IT operations, and security teams must formulate an integrated strategy that links cloud operations with security operations. Additionally, clear policies and lines of responsibility must be defined for existing and newly adopted cloud resources.
Second, risk-based visibility must be secured. You must evaluate the workloads and data types intended for migration to the cloud and define appropriate security policies. To gain visibility into the enterprise environment, you must first conduct a risk-based assessment and establish a roadmap for phased cloud adoption.
Third, enhanced access management policies must be applied. By utilizing access management policies and tools, including multi-factor authentication, for cloud resource access, attackers must be prevented from infiltrating using leaked credentials. Damage resulting from account breaches should be minimized by restricting special privilege accounts and granting only the minimum essential permissions to all user groups.
Fourth, you must know how to utilize appropriate tools. You must ensure that security monitoring, visibility, and response tools can be effectively applied to all cloud and on-premises resources. Additionally, you should consider transitioning to open technologies and standards to enhance interoperability between tools.
Fifth, security processes must be automated. Rather than responding to various events individually, security automation features should be implemented in the system to upgrade detection and response capabilities.
Sixth, simulations must be utilized proactively. We must conduct simulated tests on various attack scenarios to identify any potential security blind spots and enhance our ability to respond to forensic issues that may arise during attack investigations.
Abhijit Chakravorty, Cloud Security Capability Leader at IBM’s Security Services, advised, “The cloud is a vast and distributed environment, making it difficult for enterprises to manage and protect. Companies must properly understand cloud security technologies and policies and identify external security threats targeting the cloud in advance.”
The latest IBM X-Force cloud security report can be found here .
85% of data leakage incidents are due to user company negligence
The higher the cloud security, the more response time doubles.
With the adoption and use of cloud services by companies surging due to the prolonged COVID-19 pandemic, IBM X-Force Security Lab released a report on the 15th titled "Cloud Threat Landscape," which introduces various forms of cloud security threats.
This report is based on cloud security incidents that IBM responded to in 2019.
Companies must understand cloud security before adopting the cloud.
IBM warned that if companies adopt the cloud without sufficient security preparations in advance, the responsibility for cloud security may become unclear and responding to risks may become difficult.
According to an IDC survey, in 2019 alone, more than one-third of companies adopted over 30 types of cloud services from 16 cloud providers. In such a distributed environment, existing security policies are ineffective, and it is difficult to secure visibility across the entire cloud environment.
According to a survey by the IBM Institute for Business Value, most companies rely on cloud providers for cloud security. However, more than 85% of data breaches were attributed to the user.
◇ Cloud Security: User Response Capability Is More Important Than Provider
The most common route used by cybercriminals to infiltrate the cloud is cloud-based applications, accounting for 45% of all incidents. Cybercriminals exploit not only configuration errors but also vulnerabilities within applications; however, these vulnerabilities often go undetected because employees arbitrarily install new cloud apps through unauthorized channels.
Ransomware is also one of the most threatening entities in cloud environments, being distributed more than three times as often as other malware. It was followed by cryptominers and botnet malware.
This survey confirmed that companies with high maturity in cloud and security were able to identify and prevent data breaches more quickly. When looking at response times for data breaches, the most experienced organizations (average 125 days) were found to be able to identify and respond to breaches twice as fast as the least experienced organizations (average 250 days).
◇ 6 Rules for Implementing a Cloud Security Environment
IBM advised that companies should focus on the following six rules to implement cybersecurity optimized for cloud environments.
First, a collaborative governance and culture must be established. Application developers, IT operations, and security teams must formulate an integrated strategy that links cloud operations with security operations. Additionally, clear policies and lines of responsibility must be defined for existing and newly adopted cloud resources.
Second, risk-based visibility must be secured. You must evaluate the workloads and data types intended for migration to the cloud and define appropriate security policies. To gain visibility into the enterprise environment, you must first conduct a risk-based assessment and establish a roadmap for phased cloud adoption.
Third, enhanced access management policies must be applied. By utilizing access management policies and tools, including multi-factor authentication, for cloud resource access, attackers must be prevented from infiltrating using leaked credentials. Damage resulting from account breaches should be minimized by restricting special privilege accounts and granting only the minimum essential permissions to all user groups.
Fourth, you must know how to utilize appropriate tools. You must ensure that security monitoring, visibility, and response tools can be effectively applied to all cloud and on-premises resources. Additionally, you should consider transitioning to open technologies and standards to enhance interoperability between tools.
Fifth, security processes must be automated. Rather than responding to various events individually, security automation features should be implemented in the system to upgrade detection and response capabilities.
Sixth, simulations must be utilized proactively. We must conduct simulated tests on various attack scenarios to identify any potential security blind spots and enhance our ability to respond to forensic issues that may arise during attack investigations.
Abhijit Chakravorty, Cloud Security Capability Leader at IBM’s Security Services, advised, “The cloud is a vast and distributed environment, making it difficult for enterprises to manage and protect. Companies must properly understand cloud security technologies and policies and identify external security threats targeting the cloud in advance.”
The latest IBM X-Force cloud security report can be found here .
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.













