VOOZH about

URL: https://thenewstack.io/the-top-4-threats-to-securing-your-cloud-infrastructure/

⇱ The Top 4 Threats to Securing Your Cloud Infrastructure - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2023-01-19 10:40:19
The Top 4 Threats to Securing Your Cloud Infrastructure
sponsor-crowdstrike,sponsored-post-contributed,
Cloud Native Ecosystem / Security

The Top 4 Threats to Securing Your Cloud Infrastructure

Jan 19th, 2023 10:40am by David Puzas
👁 Featued image for: The Top 4 Threats to Securing Your Cloud Infrastructure
CrowdStrike sponsored this post.

The growth of private, public and hybrid cloud use among enterprises has done more than spur digital transformation; it has broadened the infrastructure businesses need to secure. To safely embrace the cloud and reap the benefits, organizations need visibility into a larger and more complex landscape than ever before.

There are four broad categories of security issues when it comes to securing cloud infrastructure: human error, runtime threats, shadow IT and poor strategic planning.

Understanding these issues and their potential impact will be critical if organizations are to achieve the business outcomes they expect. Here are four threats you need a game plan for.

1. Human Errors

Of all four categories, human error is the one most often blamed for cloud breaches. According to Gartner, 99% of all cloud security failures through 2025 will be the customer’s fault.

These errors often take the form of misconfigured Amazon S3 buckets, open ports and the use of unsecure accounts or APIs. If left undetected, they can open the door for attackers looking to compromise cloud environments.

A key challenge to addressing human error is visibility. It is difficult for security to keep pace with the need to support the constantly changing and elastic reality of the cloud. In addition, using multiple point solutions to manage security across different cloud services as well as their on-premises environment has left many organizations struggling to maintain consistent security policies and enforcement. Without the ability to identify and remediate insecure APIs and misconfigurations, cloud workloads can go from being IT assets to IT threats.

CrowdStrike has redefined modern cybersecurity with advanced cloud-native platforms for protecting endpoints and cloud workloads, identity and data. CrowdStrike’s adversary-focused approach to CNAPP provides agent-based and agentless solutions delivered from the CrowdStrike Falcon® platform.
Learn More
The latest from CrowdStrike

2. Runtime Threats

That statement is also true as it relates to workloads that are targeted using zero-day exploits.

In public clouds, much of the underlying infrastructure is protected by the cloud service provider (CSP). However, organizations that fail to understand the shared responsibility model — which delineates the responsibilities of the CSP and the customer — sometimes create security holes for threat actors to exploit. This situation can enable attackers to target the operating system and application to obtain access. From there, they can potentially gain persistence through the use of malware or other techniques and move laterally throughout the organization’s environment.

In addition to attempting to gain a larger foothold in the environment, adversaries may also target intellectual property and confidential information stored in the cloud. The CrowdStrike Threat Research team has noted this trend this year across numerous breach investigations. Even if a cloud workload is properly configured, it may still be susceptible to unpatched vulnerabilities and zero days, making runtime threats a critical concern for today’s enterprises.

3. Shadow IT

Visibility issues are exacerbated by shadow IT, which by its nature circumvents the normal IT approval and management process. Usually, shadow IT is not created for malicious reasons. Its creation is typically the result of employees adopting cloud services in order to do their jobs. The ease with which cloud resources can be spun up and down makes controlling its growth difficult.

These unauthorized assets can threaten the environment because they are often not properly secured and are accessible via default passwords and misconfigurations. With cloud and DevOps teams looking to maintain high velocity, obtaining the visibility and management levels that security teams require is challenging.

DevOps teams want a frictionless way to ensure that they deploy secure applications and that their security solutions directly integrate with their continuous integration/continuous delivery (CI/CD) pipeline. There needs to be a unified approach for security teams to get the information they need without slowing down DevOps, and both security and IT teams will need to adapt and collaborate to meet each other’s needs.

4. Lack of Cloud Security Strategy and Skills

The final critical security issue facing the cloud is the skills shortage and the lack of a cloud security strategy inside many organizations. As a result, many administrators attempt to secure cloud workloads the same way they secure their on-premises data centers. Unfortunately, traditional data center security models do not apply to cloud computing, and poor planning can open up new risks and vulnerabilities.

A key part of any strategy for cloud adoption is education — educating teams on security best practices such as how to store secrets, how to rotate keys and how to practice good IT hygiene during software development is critical. However, this piece of the puzzle is often overlooked. DevOps may be happening, but DevSecOps often is not, which is hampering the industry’s ability to make the cloud secure.

Winning Means Planning and Execution

New tech and cloud adoption can be a double-edged sword. Organizations need it to innovate and improve business value, however, it is not without risk. CSOs are instrumental in the planning and execution of an effective cloud security program. With good planning and execution readiness they are in a prime position to influence growth and mitigate disruption by ensuring that business, technology and DevOps intersect effectively.

Learn more about CrowdStrike Cloud Security. 

CrowdStrike has redefined modern cybersecurity with advanced cloud-native platforms for protecting endpoints and cloud workloads, identity and data. CrowdStrike’s adversary-focused approach to CNAPP provides agent-based and agentless solutions delivered from the CrowdStrike Falcon® platform.
Learn More
The latest from CrowdStrike
TRENDING STORIES
David Puzas is senior director of product marketing, Cloud Security at CrowdStrike.
Read more from David Puzas
CrowdStrike sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.