Source: Tenable Blog Author: Shai Morag URL: https://www.tenable.com/blog/whos-afraid-of-a-toxic-cloud-trilogy
ONE SENTENCE SUMMARY:
The Tenable Cloud Risk Report 2024 highlights critical vulnerabilities, excessive permissions, and public exposure in nearly 40% of organizations’ cloud workloads.
MAIN POINTS:
- 38% of organizations face critical vulnerabilities, excessive permissions, and public exposure in their cloud workloads.
- “Toxic cloud trilogy” combines critical vulnerabilities, excessive permissions, and public exposure, exacerbating security risks.
- The study analyzed telemetry from millions of cloud resources across multiple public cloud repositories.
- Organizational silos and different risk appetites hinder effective vulnerability remediation efforts.
- Critical vulnerabilities often remain unaddressed even a month after being published as CVEs.
- Excessive permissions in AWS lead to increased risks in identity-based attacks, especially for human identities.
- 96% of organizations possess public-facing cloud assets, with 29% having public-facing storage buckets.
- Comprehensive visibility requires unifying monitoring across multiple cloud environments for effective security posture.
- Organizations should prioritize rapid remediation of severe vulnerabilities to mitigate potential risks.
- Monitoring and managing public-facing assets is essential to prevent unnecessary exposure and potential breaches.
TAKEAWAYS:
- Assess your cloud workloads for the toxic cloud trilogy to enhance security.
- Promote collaboration between IAM and security teams to address excessive permissions.
- Ensure prompt remediation of vulnerabilities to minimize exploitation risks.
- Monitor public-facing assets and understand their configurations to avoid exposures.
- Implement a unified security approach across multi-cloud environments for better risk management.