Sécurité du cloud computing 101 : quels sont les risques ?
Once seen as an addition to the on-premises data storage solutions, the cloud as a technology has changed a lot since 2002 introduction of Amazon Web Services. It’s estimated that the global spend on cloud services will reach $474 in 2022 with cloud revenue to surpass estimate non-cloud revenue for enterprise IT markets in the next few years and 85% of organisations adopting the cloud-first principle by 2025.
This unprecedented usage growth for the cloud technology comes at a price, though. Ability to share and access data from anywhere in the world has enabled global businesses to operate and thrive – especially during the Covid-19 pandemic – but it also brought a swarm of cybersecurity risks and issues with 74% of large US companies experiencing a data breach in the last 12 months.
Quelles en sont les principales raisons et comment les entreprises peuvent-elles se montrer plus résilientes face aux défaillances de la sécurité cloud ?
Vérifions le niveau de sécurité de la technologie cloud fournie par les prestataires.
Le cloud est-il sécurisé ?
En bref : c'est très sécurisé.
Similarly to other cloud providers, Amazon Web Services now offers full compliance and certification aligned with sector-specific standards such PCI-DSS, GDPR, HIPAA, SOC 2, and many others. The cloud providers have also been continuously implementing solutions and tools that avert or mitigate security threats. They also conduct and are subjected to regular and comprehensive maintenance and security audits as they are – unsurprisingly – interested in the longevity and the reliability of the services. Cloud providers such as AWS (Amazon Web Services) and Azure build secure tools and it is now up to us – their regular users – to use them safely.
In this article, I’m exploring the topic of the cloud computing security risks. I will also feature actionable advice on how to address these risks from two of our cloud experts: Tomasz Wojciechowski, a newly appointed Head of Cybersecurity at Spyrosoft and our Responsable de l'ingénierie cloud, Lukasz Marcinek.
Quels sont les risques du cloud computing ?
Comme vous pouvez le supposer d'après l'introduction, le niveau de risque plus élevé pour les entreprises cherchant à utiliser ou à maintenir leurs solutions cloud réside dans ce que l'on appelle le « facteur humain » plutôt que dans un manque de fiabilité des fournisseurs – les données montrent que 95 % des défaillances de la sécurité cloud sont dues à ce facteur.
Défaillances de la sécurité des données
Si vous examinez cette question, la question la plus importante est de savoir qui a accès aux données de votre entreprise et dans quelle mesure. Les pirates recherchent les vulnérabilités les plus faciles à exploiter et l'aspect de la gestion des accès est négligé dans la plupart des entreprises.
With multiple users and several cloud environments to manage, making sure that there are no gaps can be difficult, especially for large organisations that use on-demand services with their own systems and tools. To put it simply: if your data is unciphered, shared with many users at once across multiple cloud platforms and not monitored, it is not safe.
Problèmes de conformité
As stated above, most of cloud providers are compliant and offer certificates for industry-wide data management norms. The services themselves may be secure but it does not mean that you should not worry about internal standard compliance. Make sure that you see compliance as an organisation-wide issue and conduct regular checkups or even use third-party bodies to assess the level of compliance for all your resources, be it internal and external.
Absence de stratégie de gestion multicloud
Managing multiple cloud solutions at once is not an easy task. If you work at a large global organisation that combines Amazon Web Services with Google Cloud and Microsoft Azure in its projects, developing a procedure on how you will approach the use of such a complex combination is necessary. In this Rapport Gartner sur la migration vers le cloud, 81 % des entreprises ont déclaré travailler déjà avec deux fournisseurs cloud ou plus.
Accès API non authentifié
While using Application Programming Interfaces (APIs) for both external suppliers and your employees will help keep data in sync and automate their processes, this can also mean that your business will be more vulnerable to cyber attacks. Implementing a web application security system, adequate authorisation as well as authorisation protocols will ensure that your data is and stays secure.
Pas assez d'experts en cybersécurité
Si vous avez déjà essayé de recruter un spécialiste en cybersécurité, vous en êtes peut-être conscient, mais permettez-nous de le rappeler une fois de plus : il existe une pénurie mondiale de professionnels de la cybersécurité.
As L'ISC a découvert dans ses recherches, there are currently 3.12 million unfilled cybersecurity roles worldwide. The sector is poised to be the fastest growing tech sector with employment growth rate of 31% in US only according to the data collected by the US Bureau of Labor Statistics. If your organisation is already struggling with this global issue, invest in internal educational schemes and upskilling your employees to ensure that you have enough resources to protect your company data.
Problèmes de contrôle de la séparation des locataires
According to Tomasz Wojciechowski, the risk of such a breach is low and although it can happen that is not something that occurs very often. It is worth mentioning nevertheless as tenants’ separation control issues can pose a serious threat to medium-sized and large organisations when many users have access to the same cloud-based resource. Failure to maintain separation between multiple tenants can lead to a vulnerability that – in turn – can be easily spotted and exploited by hackers.
Comment atténuer ou éviter ces risques ?
Alors, quelles actions pouvez-vous entreprendre pour atténuer ou éviter ces risques liés au cloud computing ? Voici une liste de bonnes pratiques de nos experts, Lukasz Marcinek et Tomasz Wojciechowski.
Formez votre équipe
L'utilisation du partage de fichiers non chiffrés, de mots de passe faciles à craquer et de matériel personnel tel que des ordinateurs portables et des téléphones mobiles à des fins professionnelles, ainsi que les attaques de phishing, figurent parmi les erreurs les plus courantes commises par les employés des petites comme des grandes organisations.
To ensure that your teams will not fall into these traps, conduct regular training sessions and implement regular reminders for potentially hazardous tasks. Regular compliance audits and industry-specific safety standards training may also be necessary.
Utiliser des courtiers d'accès au cloud (CASB)
This reinstates the previous points mentioned above but it is something that is not highlighted enough in the enterprise world, according to our Head of Cybersecurity, Tomasz Wojciechowski. Cloud Access Security Brokers (CASBs) are security policy tools that are implemented to serve as a layer between cloud service users and cloud service providers. Encryption, tokenisation, malware detection, authentication and logging are all examples of such tools.
Surveillez et gérez vos données
Selon notre Head of Cloud Engineering, Lukasz Marcinek, si vous donnez accès à des ressources cloud à l'un de vos employés ou sous-traitants, utilisez Principe du moindre privilège. Le PoLP consiste à accorder à un utilisateur le niveau minimal d'accès ou de permissions nécessaire à l'accomplissement de ses tâches. Le soi-disant « privilege creep », où la plupart ou la totalité des utilisateurs obtiennent des permissions complètes et un accès illimité à toutes les ressources, constitue une mauvaise pratique.
Suivre le Cloud Adoption Framework
Chaque fournisseur de cloud dispose de son propre Cloud Adoption Framework – y compris Microsoft et AWS – and it will be helpful in planning your migration to cloud, your security strategy and even naming your resources. Start by developing your security end state and work from there by mapping to concept and frameworks, assigning roles – with ‘zero trust’ policy ingrained in the assignment roadmap – and drive the change on a business and organisational level.
Élaborer une stratégie de gestion des risques
I’m mentioning it last but developing a sustainable risk management strategy is no small feat, especially in highly regulated sectors such as Automotive and Healthcare. Depending on your business and organisational goals, you may need to employ a few different risk management tools and techniques, including évaluation de la qualité des données de risque et matrice de probabilité et d'impact, pour élaborer une stratégie qui permettra de soutenir votre entreprise sur le long terme.
À lire également : Notre approche de la gestion des risques chez Spyrosoft
À vous de jouer
Si vous êtes intéressé par nos services de cybersécurité ou si vous avez un projet que vous souhaitez discuter, n'hésitez pas à contacter notre équipe via notre Site web de cybersécurité ou directement surLinkedIn.


