Orca:2021年公共云安全报告_20页_1mb
报告摘要
The Orca Security 2021 State of Public Cloud Security Report - Financial Services Edition Summary
Core Content
The Orca Security 2021 State of Public Cloud Security Report - Financial Services Edition highlights the critical security challenges faced by financial institutions in managing their public cloud environments. It emphasizes that cloud security is a shared responsibility between cloud providers and their customers, with the latter being primarily accountable for securing their workloads, data, and processes. The report reveals that despite the increasing adoption of cloud computing, many organizations are still struggling with fundamental security practices.
Main Findings
1. Neglected Workloads
- 80.7% of organizations have at least one neglected, internet-facing workload.
- 57.9% of these neglected workloads run on an unsupported operating system, reaching "end-of-life" and no longer receiving security updates.
- 49.1% of organizations have at least one unpatched web server within their cloud estate.
- 1.9% of neglected, internet-facing workloads contain sensitive customer data.
- 43.9% of organizations have internet-facing workloads containing secrets and credentials, such as clear-text passwords, API keys, and hashed passwords.
- 5.6% of internet-facing assets contain SSH keys that can be used to access adjacent systems.
2. Authentication Issues
- 23.5% of organizations have at least one cloud account without multi-factor authentication (MFA) for the root or super admin user.
- 19.3% of organizations have internet-facing workloads accessible via non-corporate credentials.
- 5.3% of organizations have workloads accessible using weak or leaked passwords, which are simple derivatives of existing credentials or found in Orca's database of breached passwords.
- 8.8% of organizations have Microsoft Windows OS with RDP port (3389) exposed to the internet, a highly vulnerable protocol that is frequently targeted by attackers.
3. Storage Misconfigurations
- 5.3% of organizations have at least one publicly writable storage bucket.
- 75.4% of organizations have storage buckets mistakenly open to the internet, which can lead to the exposure of sensitive data.
4. Internal Workload Vulnerabilities
- 77.2% of organizations have more than 10% of their internal workloads in a neglected security state, meaning they are running unpatched or unsupported operating systems and are vulnerable to hundreds of known security issues.
Key Recommendations
- Ensure Full Coverage: Cover 100% of cloud assets to prevent attackers from exploiting the weakest links.
- Focus on IT Hygiene: Address simple security issues such as unpatched services and lack of MFA before moving to advanced capabilities.
- Mitigate Lateral Movement Risk: Assume that internet-facing workloads may be breached and ensure that internal systems are not less secure.
- Implement Rapid Response Tools: Embrace the inevitability of human error and use tools that enable quick reaction to misconfigurations and breaches.
About Orca Security
Orca Security is a cloud security innovation leader that provides cloud-wide, workload-deep security and compliance for AWS, Azure, and GCP. Its SideScanning™ technology is designed to detect vulnerabilities, malware, misconfigurations, lateral movement risk, weak and leaked passwords, and unsecured PII, all without the need for security agents. It offers SaaS-based deployment, with no code running in the cloud environment, ensuring no performance impact and no overlooked assets. Orca Security also eliminates alert fatigue by prioritizing risks based on severity and environmental context, providing only the critical alerts that matter.
Conclusion
The report underscores that financial services organizations are particularly vulnerable to cloud security threats due to the presence of neglected workloads, authentication weaknesses, and misconfigured storage systems. These issues often serve as the entry point for attackers, who then move laterally to exploit internal systems. Orca Security recommends a proactive, comprehensive approach to cloud security, focusing on coverage, hygiene, risk prioritization, and rapid response.
试读结束,高清完整版pdf/doc/ppt,请点下载