Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Technology
    3. >Why are so many companies in the cloud falling foul of security breaches?
    Technology

    Why Are so Many Companies in the Cloud Falling Foul of Security Breaches?

    Published by Jessica Weisman-Pitts

    Posted on June 14, 2022

    7 min read

    Last updated: February 6, 2026

    Add as preferred source on Google
    This image illustrates the concept of cloud security breaches, highlighting the importance of securing cloud infrastructures to prevent data loss. It relates to the article's discussion on the rising security threats faced by companies using cloud services.
    Data breach concept illustration depicting cloud security vulnerabilities - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Tags:securitycybersecurityClouddata breachesrisk management

    By James Hunnybourne, Cloud Solutions Director, Ultima

    You’ve been told time and again cloud is secure. And it is, but only if you treat it appropriately. Too many companies move their workloads to the cloud and think all the work is done. They often forget that their usual security measures don’t work in the cloud. The reality is that your cloud estate needs appropriate cloud security in place, then it needs constant monitoring and analysis to ensure it stays secure.

    We’ve all heard of the infamous breaches that Yahoo, Alibaba, LinkedIn, Sino Weibo and Facebook have experienced in the past few years. But you’d be wrong to think it’s just the big boys under attack.

    The 2021 Thales Global Cloud Security Study reported that 40% of organisations had experienced a cloud-based data breach in the past 12 months. Despite these incidents, the vast majority (83%) of businesses still fail to encrypt half of the sensitive data they store in the cloud. And in a recent study, Sysdig found 75% of companies running containers (in the cloud) have high or critical vulnerabilities which can be fixed with patches but aren’t.

    I’m not surprised by any of this, nor are my cyber security colleagues, but if companies – even small ones – don’t sit up and listen, there is a 50/50 chance they will be next. If your cloud estate isn’t configured correctly, constantly monitored, and updated, it will likely leave your business open to attack.

    So, how can you ensure your cloud estate is secure? Here are my top five tips.

    1. Build a secure cloud infrastructure

    If your IT infrastructure isn’t built and configured correctly, you leave yourself open to attack. But building a secure cloud infrastructure goes beyond the traditional IT infrastructure where it was all about a corporate network accessed in the office. Remote working and cloud technology mean every part of the network needs to be secure and protected – from the infrastructure, network, apps and data to endpoints.

    Everyone will be using your cloud services, so when building out your cloud infrastructure, it’s key to involve all departments and understand how they will use the cloud and what impact this is likely to have on security. IT teams are used to managing and updating their on-premise IT infrastructure with anti-virus software and implementing the latest patches, but cloud security is different, and IT departments need to recognise this. How staff access the network and use their apps are key considerations when ensuring your infrastructure is secure.

    I would recommend any company operating in the cloud or moving to it does an audit and assessment against industry best practice benchmarks to assess their cloud vulnerabilities. And working with a cloud consultant who understands all the possible security risks is a good way of informing this process.

    1. Update security to make it cloud appropriate

    A typical scenario is for a business to keep existing security solutions when they move to the cloud, layering it over the top as best as possible. This gives some form of protection, but visibility over the whole environment is reduced because the cloud works in a very different way to on-premise. For example, traditionally, the in-house IT team would do a true-up of that environment once a month or quarter. This works fine in an on-premise service, but when you are in the cloud scaling up and down quickly, you can end up creating a void if the true-ups only occur infrequently.

    Having the right security that manages and monitors your entire cloud estate 24/7 is the only way to help prevent security breaches. There are now software solutions like MDR (Managed Endpoint Detection & Response) that continually monitor your endpoint devices beyond the scope of anti-virus software. It will continuously monitor for anomalies or suspicious activity across your cloud estate. If an incident is detected, it can act upon it for you 24/7, down to machine isolation or automated playbooks.

    1. Test, monitor and analyse the estate continually

    Things will slip through the net if you aren’t testing, monitoring, and analysing your cloud estate 24/7. It’s worth employing consultants to assess and test your cloud estate to help provide actionable insights to improve your security. This will allow you to align with industry best practices and help you understand your vulnerabilities, and potentially reduce your operating expenditure.

    For example, one services company that did this found they could reduce costs by moving from four to two operational regions, orphaning services not in use, and downgrading their storage disks without loss of service quality. Their assessment has saved them £18,000 per year, representing a 30% saving against their annual cloud consumption. But most importantly, the review highlighted their VPN was in a ‘failed’ state, and their WordPress websites were not secure, so both needed immediate updating to prevent vulnerability to attack. The assessment led the business to implement more robust security policies and align better with ISO27001.

    Once your estate has been assessed and tested for vulnerabilities and any immediate remedial action taken, it’s then a case of monitoring and analysing activity 24/7. There are some excellent cloud management platforms that will do that for a business and don’t cost the earth. These automated security and monitoring solutions are automatically applied to existing and new workloads. They scan the collected data and include proactive monitoring around security events to let you know what’s happened in clear-to-understand alerts and where action should be taken if needed, covering critical areas such as anti-malware.

    1. Educate users

    While you may have the best cloud infrastructure in place and all the right security and monitoring tools in place, with poorly educated users, that is irrelevant. Human error is still the leading cause of cyber security failures. Recently, researchers from Stanford University found that employee mistakes cause approximately 88 per cent of all data breaches.

    It’s critical to have the right security policies in place – for remote access, mobile phone and BYOD, password use, and data transfer and disposal. Then you must continually educate, educate and re-educate all employees from the CEO down. Everyone needs to understand and buy into the concept that cyber security for your business is about shared responsibility – not just of the IT department or HR, but of all departments and all staff.

    1. Have a disaster recovery plan in place

    You’ve got the best infrastructure and monitoring and analysis tools, and your employees are regularly trained. But that still isn’t enough to guarantee 100% safety from cyber security breaches. It’s just not possible. To ensure your business can still operate at a time of breach or attack, you need to have proper disaster recovery (DR) plans in place and test them regularly. A remote date backup system is a must for all organisations. 80% of businesses affected by a major incident either never re-open or close within 18 months, partly because they don’t have an effective DR plan in place.

    And yet, 41% of businesses haven’t tested their DR solution in the last six months or don’t know if it has ever been tested. But there are now autonomous DR solutions on the market that include security protection and non-disruptive testing of virtual machines. As this is built in the cloud, costs are significantly reduced compared to on-premises DR solutions as you pay for the services you use. If you haven’t got a good plan in place and it’s not tested regularly, make it an action today to find a company that can help you change this.

    It’s hard for small and medium-sized enterprises to keep up to speed with all the latest regulatory requirements and potential vulnerabilities in their cloud estates and focus on cost optimisation. Working with a good cloud and security managed service provider will give you access to deep expertise to improve your cloud estate management, optimise your cloud costs, and ‘test’ how secure your estate is. Please don’t leave it too late, though, or you might become a statistic yourself.

    About Author:

    James Hunnybourne is Cloud Solutions Director at Ultima. He is responsible for its cloud practice and demonstrating how Ultima’s technology, people and services can help improve business outcomes. Prior to this he was Head of Technology Services and Solutions at Softcat.

    Frequently Asked Questions about Why are so many companies in the cloud falling foul of security breaches?

    1What is cloud security?

    Cloud security refers to the set of policies, controls, and technologies that work together to protect cloud data, applications, and infrastructure from threats and vulnerabilities.

    2What is a data breach?

    A data breach is an incident where unauthorized individuals gain access to sensitive, protected, or confidential data, often resulting in data theft or exposure.

    3What is risk management?

    Risk management is the process of identifying, assessing, and controlling threats to an organization's capital and earnings, including financial, operational, and reputational risks.

    4What is a disaster recovery plan?

    A disaster recovery plan is a documented process or set of procedures to recover and protect a business IT infrastructure in the event of a disaster.

    5What is cybersecurity?

    Cybersecurity is the practice of protecting systems, networks, and programs from digital attacks, which can lead to data breaches or unauthorized access.

    More from Technology

    Explore more articles in the Technology category

    Image for Innovation Through Partnership: The Role of External Tech Teams
    Innovation Through Partnership: The Role of External Tech Teams
    Image for Nominations Open for Technology Awards 2026
    Nominations Open for Technology Awards 2026
    Image for Nominations Open for Innovation Awards 2026
    Nominations Open for Innovation Awards 2026
    Image for Archie earns industry recognition across G2, Capterra, and SoftwareReviews
    Archie Earns Industry Recognition Across G2, Capterra, and SoftwareReviews
    Image for The Bankaool Transformation: How a Regional Mexican Bank Became a Fintech Disruptor
    The Bankaool Transformation: How a Regional Mexican Bank Became a FinTech Disruptor
    Image for Submit Your Entry Today for Digital Banking Awards 2026
    Submit Your Entry Today for Digital Banking Awards 2026
    Image for Behavioral AI in Financial Services: Moving Beyond Automation Toward Human Understanding
    Behavioral AI in Financial Services: Moving Beyond Automation Toward Human Understanding
    Image for Submit Your Entry for Brand of the Year Awards Technology Bahrain 2026
    Submit Your Entry for Brand of the Year Awards Technology Bahrain 2026
    Image for Entries Now Open for Best Islamic Open Banking Burkina Faso APIs 2026
    Entries Now Open for Best Islamic Open Banking Burkina Faso APIs 2026
    Image for Entrepreneurial Discipline in the AI Economy: Insights from Dmytro Lavryniuk
    Entrepreneurial Discipline in the AI Economy: Insights From Dmytro Lavryniuk
    Image for Entries Now Open for Best New Digital Wallet Innovation Award 2026
    Entries Now Open for Best New Digital Wallet Innovation Award 2026
    Image for Call for Entries: Best Digital Wallet 2026
    Call for Entries: Best Digital Wallet 2026
    View All Technology Posts
    Previous Technology PostFive New Customer-Centric Technologies That Every Bank Must Adopt
    Next Technology PostMaking the Most of Telecommunications in the Education Sector