THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Friday, June 17, 2022
Applications on the cloud have proven effective for facilitating remote work. However, cloud computing comes with its security vulnerabilities.
FREMONT, CA: Cloud computing services have become an indispensable resource for most enterprises. In recent years, cloud services like Zoom, Microsoft 365, Google Workspace, and many others have become remote teams' collaboration and productivity tools.
Although the cloud quickly became an indispensable tool, allowing businesses and employees to continue working remotely from home, it is becoming increasingly apparent that embracing the cloud can introduce extra cybersecurity threats.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Before now, most users connecting to the corporate network did so from their place of employment, allowing them to access their accounts, files, and company servers from within the office, secured by enterprise-grade firewalls and other security technologies. Thanks to the increased use of cloud applications, users could suddenly access corporate apps, documents, and services from any location. This has necessitated the development of new security tools.
Threats to cloud computing security
Remote working provides various benefits for employees, but it also creates an opportunity for cybercriminals, who have quickly taken advantage of the modification to attempt to breach the networks of organizations with inadequate cloud security configurations.
Corporate VPNs and cloud-based application suites are becoming hackers' primary targets. These can provide cybercriminals with simple access to corporate networks if they are not adequately guarded. The only requirement for an attacker to gain access is a username and password, which can be obtained via phishing emails or brute force assaults against easy passwords.
Because the intruder is using the genuine login credentials of someone already working remotely, it is more challenging to identify unauthorized access, especially given the increase in hybrid working, which has led to some employees working outside of core business hours.
As cybercriminals may remain on a network for weeks or months, attacks against cloud apps can be immensely devastating to victims. Sometimes they steal vast quantities of sensitive corporate data; other times, they may utilize cloud services as an initial entry point to set the groundwork for a ransomware attack, which can lead to data theft and ransomware deployment. Therefore, it is crucial for businesses utilizing cloud applications to have the proper tools and procedures in place to ensure that users can access cloud services securely and efficiently, regardless of their location.
Control user accounts with multi-factor authentication
Implementing robust security rules for how users log in to cloud services is an apparent preventative measure. Employees should require more than their username and password to use the services, whether it's a virtual private network (VPN), a remote desktop protocol (RDP) service, or an office application suite.
Multi-factor authentication (MFA) delivers a productive line of defense against unauthorized attempts to access accounts, whether software-based, requiring a user to touch an alert on their smartphone, or hardware-based, requiring the user to utilize a secure USB key on their computer. Microsoft claims that MFA prevents 99.9 percent of fraudulent login attempts.
Not only does it prevent unauthorized users from automatically accessing accounts, but the message issued by the service, which asks the user if they attempted to log in, can also serve as an alarm that someone is attempting to access the account. This can alert the business that it may be the target of malicious hackers.
More in News