Application Security //

Database Security

6/9/2016
02:45 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Cloud Apps Just As Secure As On-Premise Apps, Say InfoSec Pros

Unfortunately, 75% of cloud apps will still fall afoul of the new EU General Data Protection Regulation, according to new studies.

Once studiously avoided by enterprises because of security and compliance concerns, cloud applications have now gained the trust of most infosec professionals, according to a new survey by Bitglass. However, cloud apps' security and compliance concerns are far from over -- the lion's share of them are unprepared for new legislation coming out of Europe, according to a new study by Netskope. 

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada July 30 through Aug. 4, 2016. Click for information on the conference schedule and to register.

Fifty-two percent of respondents to the Bitglass survey of 2,200 information security professionals said they believe cloud apps are at least as secure as on-premise apps (17% say more secure; 35% as secure). Enterprise confidence in cloud apps has increased so much that 61% of respondents have existing or planned Office 365 deployments and 26% have existing or planned Google Apps deployments.

But research from Netskope shows the number of enterprises that found malware in their sanctioned cloud apps nearly tripled from Q4 to Q1 (from 4.1- to 11%), including "many" instances of ransomware; and 73.5% of the threats were considered "high" severity.

Further, three-quarters of cloud apps are not ready to comply with the European Union's new General Data Protection Directive, according to Netskope.  

Our early findings indicate that 75.4 percent of all cloud apps are not ready for the GDPR, meaning they lack proper geography, security, and privacy controls as well as industry certifications to be considered ready to comply with the requirements of GDPR. When assessing cloud apps, enterprises will increasingly have to do the due diligence on cloud apps in use by employees and compensate for the lack of native controls.

The GDPR, which will go into effect in 2018, places rigorous demands on cloud application providers and the organizations that use them. For example, the legislation requires that enterprises can organizations can guarantee that EU citizens' personally identifiable information is kept in datacenters that reside within EU borders. Plus, it requires that EU citizen data be subject to a variety of other security and privacy protections and policies.

Maybe respondents to the Bitglass survey had GDPR on the brain when they were answering questions, because when identifying their "most-desired capabilities" creating data boundaries and setting security policies across multiple cloud apps were top of the wishlist.

Unfortunately, many cloud apps are falling short on these native capabilities, which means that organizations will need to eschew cloud services or find add-on solutions.

One to three respondents to the Bitglass survey state that external sharing is the biggest threat to cloud apps security. Netskope found a sizeable portion -- 26% -- of sanctioned enterprise cloud apps were shared externally; some even publicly.  

Related Content:

 

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Are you sure this is how we get our data into the cloud?
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14633
PUBLISHED: 2018-09-25
A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The at...
CVE-2018-14647
PUBLISHED: 2018-09-25
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by contructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming larg...
CVE-2018-10502
PUBLISHED: 2018-09-24
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 4.2.18.2. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exist...
CVE-2018-11614
PUBLISHED: 2018-09-24
This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Samsung Members Fixed in version 2.4.25. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists wit...
CVE-2018-14318
PUBLISHED: 2018-09-24
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S8 G950FXXU1AQL5. User interaction is required to exploit this vulnerability in that the target must have their cellular radios enabled. The specific flaw exists within the handling of ...