Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security //

Database Security

6/9/2016
02:45 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Cloud Apps Just As Secure As On-Premise Apps, Say InfoSec Pros

Unfortunately, 75% of cloud apps will still fall afoul of the new EU General Data Protection Regulation, according to new studies.

Once studiously avoided by enterprises because of security and compliance concerns, cloud applications have now gained the trust of most infosec professionals, according to a new survey by Bitglass. However, cloud apps' security and compliance concerns are far from over -- the lion's share of them are unprepared for new legislation coming out of Europe, according to a new study by Netskope. 

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada July 30 through Aug. 4, 2016. Click for information on the conference schedule and to register.

Fifty-two percent of respondents to the Bitglass survey of 2,200 information security professionals said they believe cloud apps are at least as secure as on-premise apps (17% say more secure; 35% as secure). Enterprise confidence in cloud apps has increased so much that 61% of respondents have existing or planned Office 365 deployments and 26% have existing or planned Google Apps deployments.

But research from Netskope shows the number of enterprises that found malware in their sanctioned cloud apps nearly tripled from Q4 to Q1 (from 4.1- to 11%), including "many" instances of ransomware; and 73.5% of the threats were considered "high" severity.

Further, three-quarters of cloud apps are not ready to comply with the European Union's new General Data Protection Directive, according to Netskope.  

Our early findings indicate that 75.4 percent of all cloud apps are not ready for the GDPR, meaning they lack proper geography, security, and privacy controls as well as industry certifications to be considered ready to comply with the requirements of GDPR. When assessing cloud apps, enterprises will increasingly have to do the due diligence on cloud apps in use by employees and compensate for the lack of native controls.

The GDPR, which will go into effect in 2018, places rigorous demands on cloud application providers and the organizations that use them. For example, the legislation requires that enterprises can organizations can guarantee that EU citizens' personally identifiable information is kept in datacenters that reside within EU borders. Plus, it requires that EU citizen data be subject to a variety of other security and privacy protections and policies.

Maybe respondents to the Bitglass survey had GDPR on the brain when they were answering questions, because when identifying their "most-desired capabilities" creating data boundaries and setting security policies across multiple cloud apps were top of the wishlist.

Unfortunately, many cloud apps are falling short on these native capabilities, which means that organizations will need to eschew cloud services or find add-on solutions.

One to three respondents to the Bitglass survey state that external sharing is the biggest threat to cloud apps security. Netskope found a sizeable portion -- 26% -- of sanctioned enterprise cloud apps were shared externally; some even publicly.  

Related Content:

 

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 4/7/2020
The Coronavirus & Cybersecurity: 3 Areas of Exploitation
Robert R. Ackerman Jr., Founder & Managing Director, Allegis Capital,  4/7/2020
'Unkillable' Android Malware App Continues to Infect Devices Worldwide
Jai Vijayan, Contributing Writer,  4/8/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11668
PUBLISHED: 2020-04-09
In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.
CVE-2020-8961
PUBLISHED: 2020-04-09
An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a write operation from an external process. Thus, code injection can be used to turn off this feature. After that, one can construct an event that will modify a file at a specific loc...
CVE-2020-7922
PUBLISHED: 2020-04-09
X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication, and those who do not use the Operator to generate their X.509 certificates are u...
CVE-2018-21034
PUBLISHED: 2020-04-09
In Argo versions prior to v1.5.0-rc1, it was possible for authenticated Argo users to submit API calls to retrieve secrets and other manifests which were stored within git.
CVE-2020-1895
PUBLISHED: 2020-04-09
A large heap overflow could occur in Instagram for Android when attempting to upload an image with specially crafted dimensions. This affects versions prior to 128.0.0.26.128.