Posted inSecurity

Vectra AI uncovers cybersecurity blind spots in PaaS and IaaS environments

New report finds 100% of companies have experienced a security incident, but continue to expand their footprint as 64% report deploying new AWS services weekly

Rapid7 wants to democratise threat intelligence with IntSights acquisition
Rapid7 wants to democratise threat intelligence with IntSights acquisition

The rapid expansion and reliance on AWS services while simultaneously showcasing security blind spots within many organisations, according to the latest findings of Vectra AI’s PaaS & IaaS Security Survey report.

As digital transformation efforts continue, the survey found that AWS is becoming an even more critical component to organisations who are regularly deploying new workloads, leveraging deployments in multiple regions, and are relying on more than one AWS service. The survey found that 64% of DevOps respondents are deploying new workload services weekly or even more frequently. It also revealed that 78% of organisations are running AWS across multiple regions (40% in at least three) and 71% of respondents say that they are using more than four AWS services (such as S3, EC2, IAM, etc.).

The expansion of AWS services has naturally led to increased complexity and risk with 100% of companies surveyed having experienced at least one security incident in their public cloud environment. Gartner anticipated that over 99% of cloud breaches will have a root cause of customer misconfiguration.

The Vectra report uncovered several blind sports such as 30% of organisations surveyed have no formal sign-off before pushing to production. It also found that 40% of respondents say they do not have a DevSecOps workflow. Additionally, 71% of organisations say that 10 or more people can modify the entire infrastructure in their AWS environments, creating numerous attack vectors for hackers

Despite these blind spots, the survey showed that companies are taking security seriously. Over half of the companies reported having double-digit security operations centre (SOC) headcounts, showing a significant investment in keeping their organisations secure.  

“Securing the cloud with confidence is nearly impossible due to its ever-changing nature,” said Matt Pieklik, Senior Consulting Analyst at Vectra. “To address this, companies need to limit the number of attack vectors malicious actors are able to take. This means creating formal sign-off processes, creating DevSecOps workflows and limiting the number of people that have access to their entire infrastructure as much as possible. Ultimately, companies need to provide security holistically, across regions and automate as many activities as possible to enhance their effectiveness.”

Vectra has answered this industry need through the creation of Detect for AWS which reduces risk of cloud services being exploited, detects threats against AWS services, and automatically responds to attacks against applications running in AWS.