Cloud adoption is on the rise and businesses are continuing to diversify the way they use cloud solutions. Globally, 57% of respondents reported they make use of two or more cloud infrastructure providers, whilst 24% of organisations flagged that most of their workloads and data now reside in the cloud.
Figure 1: Percentage of sensitive data in cloud that is encrypted by industry sector
A McKinsey study says companies globally have accelerated their cloud adoption by three years compared to pre-pandemic adoption rates. This marks a significant shift in the use of cloud-based solutions, from being purely data storage solutions to environments in which data is used transactionally and supports day-to-day business operations.
What’s wrong with this picture?
The 2021 Thales Global Cloud Security Study reports that 40% of organisations have experienced a cloud-based data breach in the past 12 months. But despite the increased attacks, 83% of businesses do not encrypt at least half of the sensitive data they store in the cloud, raising even greater concerns as to the impact cybercriminals can have.
According to the 451 Research study commissioned by Thales, 21% of businesses host most of their sensitive data in the cloud, while 40% reported a breach in the last year.
To secure their cloud infrastructure 33% use multi-factor authentication (MFA) as the core of their cybersecurity strategy. However, only 17% of those surveyed have encrypted more than half of the data they store in the cloud. This figure drops to 15% where organisations have adopted a multi-cloud approach.
Even where businesses protect their data with encryption, 34% of organisations leave the control of keys to service providers rather than retaining control themselves. Where large numbers of organisations fail to protect their data sufficiently with encryption, limiting potential access points becomes even more critical.
However, 48% of business leaders globally admitted their organisation does not have a Zero Trust strategy, and 25% aren’t even considering one.
Complexity as a concern
Businesses share common concerns about the increasing complexity of cloud services. Almost half (46%) of global respondents claimed managing privacy and data protection in the cloud is more complex than on-premises solutions.
Hybrid models are common with many organisations not moving entirely to the cloud. 55% of businesses have indicated a preference for a ‘lift & shift’ approach to cloud adoption over re-architecting, as the cloud becomes a more integrated part of the business infrastructure.
Sebastien Cano, senior vice president for cloud protection and licensing activities at Thales comments: “Organisations across the world are struggling to navigate the increased complexity that comes with greater adoption of cloud-based solutions. A robust security strategy is essential to ensuring data and business operations remain secure.”
He added that with nearly every business reliant on the cloud to some extent, it is vital that security teams can discover, protect, and maintain control of their data.
Fernando Montenegro, a principal research analyst, information security at 451 Research, acknowledges that protecting customer data is always the priority, and organisations should strongly consider reviewing their strategies and approaches to proactively protect data in the cloud.
He added that this includes understanding the role of specific technologies including encryption and key management, as well as the shared responsibilities between providers and their customers.
“As data privacy and sovereignty regulations grow, it will be paramount that organisations have a clear understanding of how they remain responsible for data security and make clear decisions about who is in control and who can access their sensitive data,” he concluded.