Skip to Content

Study reveals companies expose databases and storage services when migrating to the cloud.

January 9, 2019 by
Study reveals companies expose databases and storage services when migrating to the cloud.
Kleber Leal by Zamak Portal
Security company Palo Alto Networks has released a study showing trends and analyzing the behavior of companies that are migrating their infrastructure to the cloud – that is, outsourcing part of their infrastructure to providers like Amazon and Google. According to the survey, many companies make various mistakes in this process, which can expose databases, make the process more expensive, or make adopting the service less advantageous. Cloud computing is often associated with online storage services, but it is much more than that for businesses. Among other benefits, it is more flexible and reduces costs with scale, as it tends to be "elastic": it expands during peak access times, without requiring the company to maintain an idle processing center during low-usage hours. However, when placing its infrastructure in a fully online system, the company must adopt appropriate measures. As companies store employee and customer information, negligence can ultimately harm consumers through data leaks. The benefits for companies moving to the cloud are clear: greater flexibility, agility, scalability, and cost reduction. However, adopting public cloud infrastructure can also increase security risks and compliance challenges. The study data points to problems in various areas. The research reveals that 28% of databases receive connections from the internet — typically, databases are for the exclusive use of the company's application and do not need this external connection. Furthermore, 49% of databases are not encrypted and 32% of companies have some cloud storage service exposed. These oversights, while not synonymous with data leaks in themselves, lower the barriers that could be present for an attacker. Inadequate access controls were also targeted by the study. It states that 29% of companies suffer from possible account compromises, that is, when someone without authorization obtains system access credentials. Even with the risk of losing an account, 27% of companies adopt root access — accounts with full control, without restrictions, and which, therefore, should be avoided, especially when there is a risk of unauthorized access. These and other missteps can contribute to an unnecessarily painful migration to the cloud. For Palo Alto Networks experts, it is easier and cheaper to design projects with security from the beginning than to pay the bill when problems occur, as the company can suffer from lost sales, image problems, and even fines due to legislation. The study highlighted that the cloud is a trend for companies and that it is even more secure than traditional infrastructure, but that there is still sometimes a lack of information, especially in the use of newer technologies, such as containers. It also highlights that the cloud operates on a shared responsibility model: the provider handles basic issues, but the customer is responsible for everything else. Thus, the provider supplies the security of the base structure, such as routers, datacenters, etc., however, the customer is responsible for the rest. One cannot assume that by moving to the public cloud, security is fully guaranteed. It is necessary to use the cloud correctly, with governance, compliance, etc., as is done in private infrastructure. And mainly with a migration process well planned and adjusted to the needs of each company. Source: G1 Technology

Frequently asked questions

What is the shared responsibility model in cloud security?

It is the principle that the cloud provider secures the base infrastructure, such as routers and data centers, while the client company is responsible for protecting everything built on top of it, including databases, access controls, and configurations. A Palo Alto Networks study found that assuming migration to the public cloud automatically guarantees security is a mistake: it still requires governance and compliance, just like private infrastructure.

What configuration mistakes most often leave cloud databases exposed?

The Palo Alto Networks study found that 28% of the databases analyzed accept direct connections from the internet, when they should be reserved exclusively for the company's own application, and that 49% are not encrypted. On top of that, 32% of companies had some cloud storage service exposed; these are oversights that don't guarantee a breach on their own, but they lower the barriers for an attacker.

How does poor access control raise the risk of a cloud breach?

According to the study, 29% of companies experience possible account compromise, meaning someone without authorization obtains system access credentials. Despite that risk, 27% of companies still use root access accounts with full, unrestricted control, which should be avoided precisely because of the potential for unauthorized access.

Study reveals companies expose databases and storage services when migrating to the cloud.
Kleber Leal by Zamak Portal January 9, 2019
Share this post
Tags
Archive