Technology Today

Cloud providers including Microsoft, Google, and others, have recently acknowledged that they are struggling to deal with a spike in remote tools usage.As organisations hastily adapt for remote working, they might fail to ensure adequate data security.
In particular, cloud usage increases the risk of insider threats as 53% of organisations believe detecting insider attacks is significantly harder in the cloud than on-premises, according toa recent report.
Therefore, it has never been as important as it is today for organisations to implement proper measures to mitigate the insider threat to protect data in the cloud.Why do remote workers pose a threat to cloud security?Firstly, remote employees use cloud applications to exchange data, including sensitive data, and could misplace it in insecure locations which could lead to a compliance violation.
For example, sharing sensitive data via Microsoft Teams an increasingly popular application for telecommunication will result in data spreading across SharePoint Online storage with a high risk of unauthorised access.
In fact, 39% of the UK respondents to our recent survey are sure that employees in their organisations share sensitive data via cloud applications outside of ITs control.Secondly, remote employees often work from their personal devices which are not controlled by the corporate IT team, and as such are more prone to data breaches than their corporate PCs.
Such devices are often unpatched and, therefore, vulnerable to cyber threats.
Once an attacker has a foothold in the employee's device, they have "remote control" and can observe and leverage any outgoing connections from this.
Essentially, they can gain access to all corporate cloud services the user connects to or even to the corporate network on-premises as soon as the user establishes their VPN connection or remote desktop (RDP) session to any internal servers.In addition, an employee might lose his/her device, or let other family members use it, which will result in unauthorised access.
In some rare cases, employees copy sensitive data to their personal devices from corporate cloud storage with malicious intent, which also is a serious security risk.Step 1: Develop security policies for remote employeesIn normal circumstances, before asking employees to work from home, an organisation should ideally develop proper security policies with a specific focus on cloud security.
First and foremost, it is critical to ensure that all user permissions to storages with sensitive data are granted on a 'need-to-access basis to prevent insiders from accessing the information they do not need to do their job.In addition, it is important to establish effective access controls as well as efficient identity verification methods such as multi-factor authentication, which will also protect organisations sensitive data in the cloud from unauthorised access.And last but not least, it is critical that the IT department trains employees on cloud dos and donts, starting from the principles of dealing with sensitive data and ending with instructions for patching and securing their personal devices.
All such measures should be implemented on an ongoing basis, with the IT team being ready to support employees with any issue when they work from home, whether its an operational problem or security issue.Step 2: Obtain visibility into sensitive dataIf an organisation does not know where its sensitive data resides in the cloud, it cannot ensure that remote employees are following security policies.
This is particularly challenging as modern organisations use multiple clouds.In fact, McAfee has calculated that an average enterprise uses around 1,427 distinct cloud services, while an average employee actively uses 36 cloud services at work.
The more cloud services remote employees use, the more challenging it is for an organisation's IT team to track how they handle data.
It means an increased risk of misplacing sensitive data and the bad PR and compliance findings that come with that.
To reduce data overexposure, it is critical to have technologies in place to automatically discover sensitive data across multiple cloud storages and classify it according to its sensitivity on a continuous basis.Step 3: Monitor user activity around sensitive dataAs the cloud is prone to a broad range of threat vectors for data exfiltration by insiders, it is critically important for an organisation to detect such cases in a timely manner.
Is it malware trying to break into the corporate network, or an insider aiming to steal customer database? All these cloud security risks, and many others, are accompanied by anomalies in user activity.
Therefore, if an organisation uses cloud computing and cloud storage, it is important to have user behaviour analysis (UBA) technologies in place that can detect deviations from normal user behavior and alert an IT team about potential cloud threats.Examples of the most common anomalies that indicate a threat include abnormal logon activities (such as attempts to log on from multiple endpoints, multiple subsequent logons in a short period of time, and an unusually high number of logon failures); or data access patterns differing from the user's past behaviour or that of their peers.
It is important to note the shift from office work to remote access will probably cause initial changes in users' access patterns.
Businesses can expect a higher than normal number of false positives from Machine Learning-based behaviour anomaly detection solutions in the first couple of weeks after users move away from their central offices.Such measures will help organisations minimise insider threats in the cloud not only during the worlds largest work-from-home experiment, asTime has dubbed the COVID-19 outbreak, but also when it comes to an end.
With the subsequent economic recession that is likely to follow, cloud computing will remain a cost-effective way to run a business.
A sustainable approach to cloud security will enable organisations to avoid unwanted data breaches and hefty compliance fines in the long run.Matt Middleton-Leal is EMEA - APAC General Manager at Netwrix





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Sky confirms exact date broadband prices will rise as 'exclusive' deals to end


Five typical home items that 'cause major WiFi' disruption


WiFi alert for UK homes with Sky, Virgin and BT broadband - check your router today


EE slashes ₤ 150 off the cost of the latest Samsung tablet, however you'll need to move fast


Sky sends important message to TV users and urges homes to follow simple advice


Argos is dishing out inexpensive iPads in extremely uncommon discount, and they are 'offering quick'


Samsung's best tablet drops to a less expensive rate and it comes with a £& pound; 339 giveaway For a


All Freeview television users given two-day warning and told to follow this new suggestions


All UK Gmail and Yahoo users placed on 'alert' and told to 'follow advice'


'Rare Apple Watch sale convinced me to upgrade my old SE device to one that's £& pound; 100 off'The Apple Watch Series 10 has been cut by £& pound; 100 at Argos, Currys, and Very, it's persuaded me to ditch my slow SE design for it.The Apple W


Tesco app down: Supermarket suffers huge outage as customers left unable to log in


Turn off your Sky TV box now - urgent alert issued to users across the UK


Top Tech: Save £400 on a Samsung Galaxy tablet with shopping expert's deal stack method


Everyone using Chrome needs to inspect their web internet browser now - don't ignore immediate alert


Sky Television down: Thousands not able to see television as service suffers big failure


Google confirms 'biggest' free Android upgrade in years and here's your first look


Sky announces surprise price alert and the exact date when it may affect you


Sky beats Samsung by handing out a £220 freebie with new S25 Edge phones


Amazon vacuum cleaner falls to record-low and branded 'exceptional for the price'


Apple fans can get an iPad for ₤ 10.50 a month as Sky releases brand-new offer


Lesser-known sale cutting cash off Ninja and Shark - however it ends this evening


Everyone with a Gmail account placed on red alert and warned to 'remain vigilant'


Top Tech: Samsung sale cuts Galaxy S25 to record low price as new Edge model drops


Samsung Galaxy S25 Edge pre-orders with official prices and double storage giveaway


'This 30% off power bank has a genius feature that makes it my everyday pick'


Your iPhone just got an important free upgrade from Apple - check your settings now


Your Galaxy S25 just got beaten by a radically new smartphone from Samsung


Gtech cordless vacuum that leaves floors 'pristine' has £100 off


Sky TV and broadband deal is cheapest yet - but it ends in days


All WhatsApp users placed on red alert - delete 'dangerous' new message now


Watch out Sky - brand-new UK rival includes more TV functions and is totally free to enjoy


You may be sorry for buying Samsung's Galaxy S25 after seeing what's coming this week


'Modelling is a human endeavour': Models push back rising of AI in style


Virgin Media issues crucial Wi-Fi recommendations - 5 things you 'need to do' today


'I got an AirTag for the cheapest ever price by stacking a deal most don't know about'