毕马威-2020年云威胁报告(英文)-2020.8-54页_12mb
报告摘要
Oracle and KPMG Cloud Threat Report 2020 Summary
Core Content
The Oracle and KPMG Cloud Threat Report 2020 provides an in-depth analysis of the current state of cloud adoption, the evolving threat landscape, and the challenges organizations face in securing their cloud environments. It highlights the growing reliance on cloud services as part of digital transformation (DX) and cloud-first strategies, while also addressing the significant cloud security readiness gap that has emerged.
Main Findings
Cloud Adoption Trends
- Cloud adoption continues to expand: Digital transformation and confidence in public cloud security are driving increased cloud usage.
- 88% of organizations use public cloud infrastructure services.
- 92% of organizations admit to having a cloud security readiness gap between current and planned cloud usage and the maturity of their security programs.
- 44% of organizations report a wide gap in cloud security readiness.
Security Challenges
- Misconfigured cloud services are the top cloud security priority: Over 30% of respondents identified misconfigured services as a critical issue.
- Cyber fraud is a growing concern: Phishing attacks targeting privileged cloud credentials are on the rise, with 59% of respondents reporting such incidents.
- Configuration management challenges: A lack of visibility into cloud configurations leads to significant security risks.
- Lack of understanding of shared responsibility model: 67% of respondents find the shared responsibility model for SaaS the most confusing, with only 8% fully understanding it.
Security Practices and Tools
- Organizations are using over 100 discrete cybersecurity controls: This highlights the complexity of securing hybrid and multi-cloud environments.
- DevSecOps is gaining traction: It is seen as a means to automate security integration and shift the culture toward "security first."
- Cloud security architects are becoming more common: They are helping organizations retool their security stacks and address the readiness gap.
Cybersecurity Leadership
- Business information security officers (BISOs) are emerging as a new leadership role, especially in larger organizations.
- Only 18% of organizations currently have a BISO, but 50% plan to adopt one in the future.
Security Priorities
- Least privilege access is a fundamental security principle, yet many organizations are not implementing it effectively.
- Over-privileged accounts (37%) are the leading misconfigured cloud service.
- Exposed web servers (35%), insecure object store data (34%), lack of MFA (33%), and disabled logging (31%) are also top concerns.
Key Insights
- Public clouds are perceived as more secure than on-premises environments: 40% of respondents believe public clouds are much more secure than their own data centers.
- IT professionals are more worried about corporate security than personal safety: 3X as many are concerned about company security than their own home safety.
- SaaS adoption is increasing: Nearly 90% of companies are using SaaS, with a planned 9% increase in the next 24 months for business-critical applications.
- IaaS and PaaS usage is growing: Organizations are using these services for production workloads, reflecting a shift toward cloud-native applications.
Emerging Trends
- Hybrid and multi-cloud environments are the norm: 55% of organizations expect 41% of their server workloads to be in the public cloud within 24 months.
- Containerization is increasing: 46% of respondents plan to deploy container-based applications across both public cloud and private data centers.
- Cybersecurity tools are becoming more integrated: 80% of organizations are considering consolidating their cybersecurity tools into a single vendor platform.
Strategic Recommendations
- Unify security strategies across business units: Security must be a shared responsibility and a strategic priority.
- Improve cloud security visibility: Organizations need better tools and processes to monitor and manage cloud configurations.
- Adopt DevSecOps: This approach helps automate security integration and fosters a culture of proactive security.
- Enhance understanding of the shared responsibility model: Clear communication and training are essential for aligning security practices with cloud usage.
Conclusion
The report underscores that while cloud adoption is accelerating and public clouds are viewed as more secure, the rapid pace of change has created significant challenges in securing these environments. The need for a unified strategy, cultural shift toward security, and improved visibility and understanding of cloud security practices is critical for closing the readiness gap.
试读结束,高清完整版pdf/doc/ppt,请点下载