Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - 5 Essential Tips For Data Security On The Cloud
Articles Cloud Security Data Loss Prevention Data Protection Security Threat Intelligence Threats and Vulnerabilities

5 Essential Tips For Data Security On The Cloud

Dilki RathnayakeBy Dilki RathnayakeJuly 31, 2023Updated:August 24, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
data security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Moving to the cloud often means lower costs, 24/7 access, and higher security. But higher security doesn’t mean guaranteed. It takes two to make cloud security work: the cloud service provider, and you—the user. While a reputable cloud service provider keeps their systems patched and swiftly responds to threats on their infrastructure, it’s up to the cloud consumer to fill in the rest of the data security equation: your data and how you access it.

Challenges of the cloud

What makes securing data on the cloud different than data on your own machines? While the principles are the same, one of the main challenges as a subscribing enterprise is the lack of control and visibility. It’s a fine balance between outsourcing services and technologies while ensuring the implementation is up to par with your policies. Your employees could add new unsanctioned services on the fly, and the lack of standards in configuration and available options across vendors can make security a nontrivial task.

As an enterprise, you understand that there are risks you must take, but leaving security in the hands of a cloud provider is not enough. You have your own risk equation; how can you measure risk if you’re not sure what’s going on in the cloud? If you have hundreds of users and multiple vendors, what does a standard assessment look like? Read on to learn the must-dos for keeping data secure on the cloud and how to gain visibility to position yourself for the better.

Tip #1: Secure your accounts with MFA

Multi-factor authentication (MFA) should be a baseline, but the usage rates tell a different story. Less than 1/3 of Azure Active Directory administrators use MFA. Considering how common MFA is now in the consumer world—for banking, for email—you may have thought businesses have led the way.

The payoff of MFA is clear: Microsoft engineers stated that 99.9% of account compromises happened to those without MFA. Take the extra few minutes (at most) and opt-in for MFA. You can count on a SMS-based attack or theft of SIM card to be harder than cracking a password considering the speed of modern-day computing.

Tip #2: Configure your databases properly

In the past, an on-premise database may have been air-gapped and well-protected by access control or obscurity. Now, data can be exposed to the whole world with simple mistakes like forgetting to password-protect or leaving default settings in place. While mistakes happen, in some cases they come with costly ramifications in reputation and financial resources. Take it from Uber who paid $148 million to settle civil lawsuits after revealing private information of 57 million people.

Default settings often emphasize speed and convenience over security. For a database of public data like lottery powerball winning numbers, why not? For a database of credit card numbers and social security numbers, speed sounds great too—but not at the cost of security. Default settings must be reviewed and configured to protect against unauthorized access. Sometimes, a first solution is simply to use a password (vs. none) combined with MFA (see tip #1).

Tip #3: Encrypt your sensitive data

Having a strong authentication goes far, but for your most sensitive data, encryption will provide layers of extra protection. This protection is analogous to having a locked safe in your home; there’s a reason you aren’t leaving your birth certificate out on a shelf or kitchen table. Perhaps it’s a legal reason as well; encryption is commonly used to comply with the requirements of regulations such as the United States Health Insurance Portability and Accountability Act (HIPAA), which requires security for electronic health information.

Many reputable cloud service providers encrypt data at rest by default in the event an attacker lands on the machine without the correct credentials. When this isn’t enough, other options allow customers to manage the encryption on their own or use specialized hardware managed by the cloud service provider.

Tip #4: Enforce your policies with a broker

One of the main benefits of working on the cloud is the ability to outsource computing resources, applications, storage, and security to specialists. Like any decision in life, this choice comes with disadvantages. Hiring someone else to provide you a service means less visibility and less ability to enforce security policies of your own.

However, you do not have to settle for this gap. Providers known as cloud access security brokers (CASBs) fill this gap by sitting between cloud service providers and their users to enforce security policies such as authentication and encryption. CASBs accomplish this task through monitoring traffic between the cloud and user or by using the cloud provider’s API. Each has its own advantages and disadvantages, like speed or vendor lock-in. They all provide the advantage of visibility into your cloud activity and ensuring that the policies you’ve meticulously put in place are actually enforced.

Tip #5: Stay up to the date with the threat landscape

Five years (or less) from now, this advice may be moot if everyone is implementing MFA and configuring their databases correctly. Stay up to date by following cybersecurity news, domain experts, security research teams, and government authorities. While technology can help you stay updated with the latest patches to fix zero-day exploits, the trends over time will take more proactive work.

Training your staff, from the non-technical to technical also plays a part in disseminating best practices based on the current state-of-the-art. Anyone can implement MFA, and developers who handle sensitive information can understand the appropriate tier of encryption to implement. To up the game, live cybersecurity exercises can test how ready you truly are.

By following all of these tips, you can better protect your data on the cloud without having to settle for less.

Dilki Rathnayake
Dilki Rathnayake

Dilki Rathnayake is a cybersecurity content writer and the Managing Editor at Information Security Buzz, with a BSc in Cybersecurity and Digital Forensics. She is skilled in computer network security and Linux system administration. Dilki has also led awareness programs and volunteered for communities promoting best practices for online safety.

  • Dilki Rathnayake
    The new rules of war have no rules
  • Dilki Rathnayake
    AI Malware Arrives: Google Uncovers a New Wave of Adaptive Attacks
  • Dilki Rathnayake
    Out of Office, Not Out of Mind: Staying Cyber-Smart Over the Holidays
  • Dilki Rathnayake
    The Real Purpose of the UK’s Online Safety Act: An Expert Explains

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}