Frequently asked questions
What is the shared responsibility model in cloud security?
It is the principle that the cloud provider secures the base infrastructure, such as routers and data centers, while the client company is responsible for protecting everything built on top of it, including databases, access controls, and configurations. A Palo Alto Networks study found that assuming migration to the public cloud automatically guarantees security is a mistake: it still requires governance and compliance, just like private infrastructure.
What configuration mistakes most often leave cloud databases exposed?
The Palo Alto Networks study found that 28% of the databases analyzed accept direct connections from the internet, when they should be reserved exclusively for the company's own application, and that 49% are not encrypted. On top of that, 32% of companies had some cloud storage service exposed; these are oversights that don't guarantee a breach on their own, but they lower the barriers for an attacker.
How does poor access control raise the risk of a cloud breach?
According to the study, 29% of companies experience possible account compromise, meaning someone without authorization obtains system access credentials. Despite that risk, 27% of companies still use root access accounts with full, unrestricted control, which should be avoided precisely because of the potential for unauthorized access.