Laminar study reveals companies are turning to cloud-native security solutions to combat shadow data and rising breaches.
Over the past two years, companies’ adoption of public cloud services has surged. However, fast-paced change and weaker security controls have led to an increase in data breaches, finds the State of Public Cloud Data Security Report 2022, released by Laminar.
In the survey, 50% of security professionals said their cloud environments had been breached in 2020 or 2021. As companies go digital-first, data security professionals are managing an increasingly complex multi-cloud environment, while struggling with a lack of visibility, inadequate controls, and rising shadow data problem. Among those who were breached, 58% said that their cloud data had been knowingly exfiltrated.
It’s no surprise, then, that shadow data is cited by 82% of respondents as a top concern. Shadow, or unknown, unmanaged data, is growing as both IT and business users can self-provision cloud services and stand up instances for application development and testing. Examples of shadow data now include database copies in test environments, unmanaged backups, toxic application logs and caches, analytics pipelines, stale unmaintained databases, and unlisted embedded databases. All of this data is at risk for exposure, causing revenue and reputational harm to corporations at a time when regulatory censure and fines are increasing. For security professionals anxiety comes from knowing that these unknown “shadow” datastores are causing undue risk to the organizaiton.
The good news is that the high number of public cloud data breaches has increased executive buy-in for cybersecurity at 50% of companies surveyed. In fact, 81% of teams have increased their security budget >40% since January 2020. As a result, these companies will be able to focus resources on hiring and upskilling teams and investing in new solutions.
Given worsening cyber risks, security gaps, and breaches, data protection professionals believe it’s time to try another approach. Some 65% of respondents believe that cloud environments are different enough from on-premises infrastructures to warrant unique solutions.
Survey respondents believe that cloud-native security solutions can help them oversee their fast-expanding, heterogeneous cloud environments and data stores:
Not all cloud-native security tools are created equally, however. The majority are focused on SaaS apps or infrastructure, but a true defense in depth strategy also requires direct protection for the crown jewels, the data itself. A cloud-native security solution should be able to autonomously discover and classify sensitive data across all cloud accounts. In addition, it must be able to enforce data policies and best practices to secure and control data. Finally, it should provide asynchronous monitoring of data egress channels, detecting unsanctioned or risky activity without interrupting valid data flow.
Laminar surveyed 500 data security professionals in February 2022. To read the full report, visit https://laminarsecurity.com/resources/state-of-public-cloud-data-security-report-2022/.
For more insight into securing data across public clouds, the risks of ‘shadow data,’ and the future of cloud data security, register for ISMG’s Cloud Data Security Summit sponsored by Laminar and featuring CISOs, analysts and industry leaders here.
Patti Jo Rosenthal chats about her role as Manager of K-12 STEM Education Programs at ASME where she drives nationally scaled STEM education initiatives, building pathways that foster equitable access to engineering education assets and fosters curiosity vital to “thinking like an engineer.”