# The Future of Finance: How to defend against the top threats to cloud security
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-10-14
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Mitigating Risks: Financial Sector Cloud Vulnerabilities
Meta Description: Discover how vulnerabilities in chosen cloud services and reliance on single vendors can jeopardise the security of UK financial organisations.
URL: https://financedigest.com/the-future-of-finance-how-to-defend-against-the-top-threats-to-cloud-securityhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/future-1736815025718-compressed.jpg)

![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/milad-aslaner-450x337-1736815025667-compressed.jpg)

_By_ **_Milad Aslaner,_** _Head of Technology Advisory Group,_ [_SentinelOne_](https://www.sentinelone.com/)

Despite their ethereal appearance, when it comes to computing, clouds are the bedrock of most organisations’ daily business activities. In fact, 89 percent of organisations report having a multi-cloud strategy, per the [2022 State of the Cloud Report](https://www.flexera.com/blog/cloud/cloud-computing-trends-2022-state-of-the-cloud-report/).

And although there are [hundreds](https://www.gartner.com/en/newsroom/press-releases/2019-02-27-gartner-says-nearly-50-percent-of-paas-offerings-are-) of cloud platform services, in the finance sector, there is a marked concentration on a small number of cloud vendors. In fact, over 65 percent of UK banking and insurance firms used the same four cloud providers in 2020, according to [HM Treasury’s](https://www.gov.uk/government/publications/critical-third-parties-to-the-finance-sector-policy-statement/critical-third-parties-to-the-finance-sector-policy-statement) policy paper. This comes with inherent risks, which left unmitigated, could pose a serious threat to the UK’s financial services sector.

What are the actual risks posed to the [financial by cloud-based services](https://www.financedigest.com/what-can-we-learn-from-financial-services-security.html "What can we Learn from Financial Services Security?") and what can businesses do to protect against them?

**Vulnerabilities in the cloud**

At first glance, there isn’t much downside to UK [firms increasingly turning](https://www.financedigest.com/turning-a-blind-eye-wont-work-for-financial-firms-as-the-fca-tightens-its-grip.html "TURNING A BLIND EYE WON’T WORK FOR FINANCIAL FIRMS AS THE FCA TIGHTENS ITS GRIP") to the cloud, as it simplifies digital transformation, and consolidation of tech portfolios arguably makes the job of monitoring threats easier. However, the lack of diversity when making that choice of vendor exposes [financial organisations to the vulnerabilities intrinsic to their chosen cloud service](https://www.financedigest.com/4-ways-high-performance-analytics-powers-financial-services.html "4 ways high-performance analytics powers financial services").

When it comes to threat actors’ targets, Microsoft is in the firing line. For instance, security [researchers](https://www.proofpoint.com/us/blog/cloud-security/proofpoint-discovers-potentially-dangerous-microsoft-office-365-functionality) discovered Microsoft Office 365 has inherent flaws which would enable hackers to encrypt files created and stored on SharePoint and OneDrive, aiding in the proliferation of so-called double-extortion ransomware attacks. Vulnerabilities like this could ravage a [financial organisation, compromising the integrity of the UK financial sector](https://www.financedigest.com/overcoming-information-overload-in-the-financial-sector.html "OVERCOMING INFORMATION OVERLOAD IN THE FINANCIAL SECTOR") as a whole.

Likewise, SentinelLabs disclosed a [privilege escalation vulnerability](https://www.sentinelone.com/labs/cve-2021-24092-12-years-in-hiding-a-privilege-escalation-vulnerability-in-windows-defender/) in Windows Defender in 2021 that was undiscovered for 12 years. This was a severe vulnerability as it allowed attackers to maliciously escalate privileges from a non-administrator user. Windows Defender is deeply integrated into the Windows operating system and is installed by default on every Windows machine (more than one billion devices), so any vulnerabilities will have far reaching consequences.

As well, all Microsoft services are dependent on Azure [Active Directory for Identity and Access Management](https://www.financedigest.com/with-the-right-active-manager-you-really-do-get-what-you-pay-for.html "With the Right Active Manager, You Really Do Get What You Pay For") (IAM). When a threat actor can compromise a user identity with elevated privileges, like the security administrator role, they can evade all of Microsoft’s defence measures and security tools. Consequently, being overly de pendent on a single vendor can expose organisations to significant risks.

**Cloud Misconfiguration**

Another significant [threat to cloud security](https://www.financedigest.com/5-ways-to-protect-your-company-from-cyber-security-threats.html "5 Ways to Protect Your Company From Cyber Security Threats") comes from cloud misconfiguration. In fact, 27 percent of organisations experienced a security incident in their public cloud infrastructure, per the [2022 Cloud Security Report](https://pages.checkpoint.com/2022-cloud-security-report.html), and nearly one in four of those were caused by cloud misconfigurations.

Many organisations mistakenly assume that Cloud [Service Providers will secure](https://www.financedigest.com/how-financial-services-are-overhauling-security-to-defend-against-spoofing-scams.html "How financial services are overhauling security to defend against spoofing scams") the cloud, but it’s still the cloud user’s responsibility to apply updates to their applications and software. Missing updates and patches can lead to enterprise breaches.

Also, configuration oversights can often [lead to customer](https://www.financedigest.com/customer-engagement-whos-leading-the-way.html "Customer engagement – who’s leading the way?") data being mistakenly left publicly accessible, or easily accessible, to attackers. Although this isn’t a risk solely limited to the cloud, it’s far more common now due to the complexity of cloud [services](https://www.financedigest.com/tomorrows-world-how-cloud-computing-will-impact-the-financial-services-sector-in-2016.html "TOMORROW’S WORLD: HOW CLOUD COMPUTING WILL IMPACT THE FINANCIAL SERVICES SECTOR IN 2016") configurations and because cloud services are so widely used.

**Insider threat: the risk from within**

When it comes to attacks that target Microsoft environments, on top of cloud vulnerabilities and misconfigurations, the insider threat is a key factor. The insider threat can be unintentional – people with access to the corporate system who make an innocent or careless mistake resulting in a cyber attack – or intentional, by malicious insiders with access who intentionally cause a breach.

Mimecast [research](https://www.mimecast.com/content/what-is-security-awareness-training/) shows that 90 percent of breaches occur because of human error. One of the most effective solutions to reduce the [risk of your own staff falling foul of a breach is to conduct an effective security](https://www.financedigest.com/tesla-to-warn-of-data-privacy-risk-from-car-security-cameras-in-germany.html "Tesla to warn of data privacy risk from car security cameras in Germany") awareness programme. Nobody is perfect and mistakes do happen, so fostering a culture of cyber-awareness is crucial.

**People, Process and Technology**

Given the threats posed by cloud misconfigurations, cloud vulnerabilities, and insider threats, how can organisations reduce the risk of a breach? This requires a multi-faceted approach, and understanding the requirements across people, processes, and technology.

_People_

When it comes to the incautious insider threat, it’s important to remember that no one is immune from making mistakes and from falling for a targeted [social engineering](https://www.financedigest.com/31972social-engineering-in-the-financial-services-people-are-the-weakest-link-in-the-security-chain.html "Social engineering in the Financial Services : People Are The  Weakest Link in the Security Chain") attack. Make sure that staff know precisely what their privilege levels are, how they can contribute to securing the organisation, and how to spot and report suspicious activity before it’s too late.

_Processes_

Consistent processes are vital and need to be reinforced. Having a device usage policy is one thing, but it needs to be clear about what employees can or cannot do, explicit about the relevant [security controls that need](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") to be in place and enforced to be effective. The same goes for [reporting possible security incidents](https://www.financedigest.com/uks-morgan-advanced-materials-reports-cyber-security-incident-on-its-network.html "UK’s Morgan Advanced Materials reports cyber security incident on its network"). In addition to defining reporting processes with clarity, it’s essential that they are getting tested to ensure the [security team can identify trouble areas](https://www.financedigest.com/2018-it-security-predictions-methods-for-attacks-investment-areas-cybersecurity-strategies.html "2018 IT Security Predictions-Methods For Attacks, Investment Areas & Cybersecurity Strategies").

_Technology_

The right [technology is vital to combatting cloud](https://www.financedigest.com/7-ways-cloud-technology-can-transform-business-finances.html "7 ways cloud technology can transform business finances") attacks. For many enterprises, the IT and security team support various operating systems, [cloud services](https://www.financedigest.com/cloud-migration-for-financial-services-organisations-whats-the-best-approach.html "Cloud Migration for Financial Services Organisations – What’s the best approach?"), and endpoint types. This often means a combination of [legacy and modern systems](https://www.financedigest.com/retailers-weighed-down-by-their-own-legacy-systems-survey-reveals.html "Retailers Weighed Down by their own Legacy Systems, survey reveals"), resulting in anywhere from 25 to 49 different tools from 10 or more vendors to detect, triage, investigate or hunt for threats.

[Finance firms should be looking for platforms](https://www.financedigest.com/make-way-for-the-rise-of-the-finance-super-apps-consolidation-of-financial-digitisation-tools-platforms.html "Make way for the rise of the Finance Super Apps – Consolidation of Financial Digitisation Tools & Platforms") that can help them holistically, rather than focusing on individual silos. Security platforms that can detect, protect and respond to threats across the entire estate – and integrate capabilities like extended detection and response (XDR) and identity [threat detection and response](https://www.financedigest.com/forescout-and-fireeye-expand-partnership-enabling-faster-response-to-cybersecurity-threats.html "FORESCOUT AND FIREEYE EXPAND PARTNERSHIP, ENABLING FASTER RESPONSE TO CYBERSECURITY THREATS") (ITDR) – are the ones that will ensure that organisations are best securing the cloud, and beyond.

**Conclusion**

[Cloud computing offers](https://www.financedigest.com/how-hybrid-cloud-computing-offers-the-best-of-all-worlds.html "How hybrid cloud computing offers the best of all worlds") finance firms a number of benefits, from unlimited storage and the ability to scale computing, to compliance and mobility.  But it is essential to understand the cyber threats inherent to the cloud, and that [securing cloud services isn’t](https://www.financedigest.com/the-challenge-of-keeping-data-secure-why-in-house-security-isnt-enough.html "The challenge of keeping data secure: why in-house security isn’t enough") the sole responsibility of the Cloud Service Provider. Finance firms need to look at the bigger picture and understand the risks across different surfaces – identity, email, endpoint, network – and identify ways to protect, detect, respond, and recover from cyber [threats across the entire digital](https://www.financedigest.com/3-top-digital-asset-threats-facing-your-brand-in-2017.html "3 top digital asset threats facing your brand in 2017") estate.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

