8 results ·
● Live web index
S
sentinelone.com
article
https://www.sentinelone.com/cybersecurity-101/cloud-security/security-risks-o…
3. More Risk for Data Breach: Data breaches present significant security risks in cloud computing. Misconfigurations in cloud settings, including poorly secured storage buckets and weak IAM policies, may expose sensitive data to unauthorized users. Such open vulnerabilities could be abused by attackers to steal sensitive data, causing major financial and reputational damage. Proper configuration of cloud resources and continuous monitoring for potential threats can only prevent data breaches. [...] ## FAQs
Major security risks in cloud computing include data breaches, hijacking of accounts, insecure APIs, inside threats, and misconfigurations in the cloud. Such vulnerabilities can expose business-sensitive information and affect business operations. [...] 12. Lack of Encryption: Encryption is a part of protection for sensitive data that is stored in cloud environments or data in transit. Information that does not have strong encryption becomes easy prey for interception or access by those not authorized. Businesses that fail to encrypt sensitive information expose it to breach risks and non-compliance with privacy regulations.
T
tierpoint.com
article
https://www.tierpoint.com/blog/cybersecurity/cloud-storage-security
Cloud storage security includes technologies and practices businesses use to protect their data in cloud storage solutions. This can consist of safeguards against theft, deletion, unauthorized access, or file corruption.
## Why is it So Important? [...] Cloud storage data deletion can also be completely accidental. Team members may press the wrong button or think data should be deleted without realizing its importance. Without a backup in place, this can severely impact business performance or reduce trust in the company’s security. Accidental data loss happens with about the same frequency as malicious insiders, costing businesses $4.46 million on average.
### Poor Security Patching [...] Boosting your cloud storage security posture starts with a solid plan incorporating solutions with advanced security features, such as ransomware protection with immutability or Dedicated Storage as a Service powered by Pure Storage. Need help creating a plan? TierPoint’s IT security consulting services can help you create a strategy and execute it to protect your data both in the cloud and in transit. Contact us to learn more.
Matt Pacheco
D
darktrace.com
article
https://www.darktrace.com/cyber-ai-glossary/the-most-common-cloud-security-th…
Misconfigurations in cloud environments are among the most common and critical security risks. These occur when cloud resources, such as storage buckets, databases, or virtual machines, are set up with weak security controls or improper access permissions. Examples include leaving storage buckets open to the public, not enabling encryption, or failing to configure identity and access management (IAM) settings correctly. These misconfigurations can expose sensitive data and cloud infrastructure [...] When data is improperly stored or transmitted without proper security protocols, attackers can exploit these vulnerabilities to access confidential information. This can result in significant financial losses, regulatory penalties, and reputational damage, especially as cloud services often store vast amounts of critical customer and business data across global locations.
### 2. Account hijacking [...] Compliance violations in cloud environments occur when organizations fail to meet the stringent regulatory standards governing data protection and privacy, such as GDPR, HIPAA, or PCI-DSS. These regulations require specific security measures to safeguard sensitive data, especially in cloud environments where data is often stored, processed, and transmitted across multiple locations and jurisdictions. Failure to implement adequate security controls in the cloud exposes sensitive data to
C
coursera.org
article
https://www.coursera.org/articles/cloud-data-security
Read more: 4 Cloud Computing Career Paths to Know
## How secure is your data in the cloud? Dangers of cloud data storage
Although there are many benefits to cloud data storage, there are also many potential dangers to their security that both organizations and individuals should consider. Some of the most common threats include:
### 1. Data breaches and misconfigurations [...] Hackers and other bad actors are a major threat to the cybersecurity of both on-premise and cloud-based data storage. In fact, according to IBM’s Cost of a Data Breach Report 2025, the average cost of a data breach reached a whopping $4.4 million in 2025 . While many attacks simply rely on run-of-the-mill phishing schemes or stolen credentials, a significant amount of these attacks exploit all-too-common cloud misconfigurations within an organization.
### 2. Insecure APIs [...] Accessibility is one of the great benefits of cloud data storage, but it could also be one of its major problems if not managed properly. Organizations that don’t limit privileged access to some data may inadvertently compromise it. Furthermore, employees who aren’t properly trained accidentally reveal and share sensitive information without realizing it.
### 4. Inside actors
T
thundercattech.com
article
https://www.thundercattech.com/tcat_blog/security-risks-of-cloud-computing
Data stored in the cloud might be physically located in different countries, subject to varying data protection laws and regulations. To address this risk, organizations should clearly understand where their data is stored and processed, ensuring compliance with relevant legal requirements. Selecting CSPs that offer data residency options can also provide greater control over data jurisdiction.
#### 16. Third-party Integration Vulnerabilities [...] #### 18. Cloud Sprawl and Orphaned Resources
Cloud sprawl refers to the proliferation of cloud instances or resources beyond what is necessary. Orphaned resources, such as forgotten virtual machines or storage, pose security risks if left unattended and unpatched. Employing automated resource management tools, establishing clear resource ownership protocols, and regularly auditing cloud resources can mitigate the risks associated with cloud sprawl and orphaned resources. [...] #### 6. Data Loss
While cloud services provide high availability, technical failures and outages can lead to data loss. Businesses must have comprehensive disaster recovery plans, including regular data backups stored in geographically separate locations. Employing a multi-region or multi-cloud strategy can also enhance data resilience and reduce the impact of potential data loss incidents.
#### 7. Lack of Transparency
P
proofpoint.com
article
https://www.proofpoint.com/us/threat-reference/cloud-security
Cloud security encompasses the technologies, applications, controls, and policies that protect people, data, and infrastructure from cyber-attacks and compliance risks on cloud computing platforms. It involves a comprehensive set of security measures designed to address both external and internal security threats to organizations, including controlling security, compliance, and other usage risks of cloud computing and data storage. [...] Cloud computing—a broad term that describes the move to the cloud and a mobile workforce—has brought new security and compliance risks. Cloud account takeover, data oversharing, and usage of unapproved cloud applications present considerable challenges to security teams. That’s why gaining visibility into and control over IT-approved applications is critical to cloud security. Many organizations must secure Microsoft Office 365, Google G Suite, Box, Dropbox, Salesforce, Slack, AWS, ServiceNow, [...] With managed cloud security solutions, organizations can effectively prevent targeted cyber-attacks, address regulatory compliance, and mitigate usage risks associated with cloud computing and data storage. This critical investment fosters a more resilient cloud environment and a more productive organization.
### How Does Cloud Security Work?
C
cisa.gov
official
https://www.cisa.gov/resources-tools/training/get-most-out-cloud-storage-and-…
3. Potential for data to be intercepted: If your cloud service does not provide end-to-end encryption for data shared between your device and the cloud service, a threat actor could intercept it. Similarly, if the cloud provider does not encrypt your data while it is stored on their servers, threat actors that gain access to the cloud provider’s network could access your data. (Note: Reputable cloud providers encrypt your data while it is in motion and at rest.) [...] 4. Potential for data to be lost: If you only store your data in the cloud and don’t save a local copy, cyber incidents such as a denial-of-service attack could lead to temporary or even permanent loss of your data. [...] ## The Bottom Line
Cloud services, such as Microsoft OneDrive, iCloud, and Google Drive, enable real-time collaboration and allow you to back up your data. To reduce cybersecurity risks associated with cloud storage:
1. Ensure that your cloud provider encrypts your data and is headquartered in a country with privacy and security laws to help protect your data.
2. Protect your account with a strong password and multifactor authentication (MFA). Be wary of phishing attempts.
## The Problem
S
security.utexas.edu
research
https://security.utexas.edu/iso-policies/cloud-services/risks
### Security
Security is sometimes an afterthought. Some cloud services, especially storage services, have a history of poor security implementations and compromises. Security is not an important criteria for them; it gets in the way of their business model. Some of the more significant risks posed by cloud services in general are: [...] 4. The cloud service provider blatantly lying about the above or other security measures claimed
5. Loss of data or loss of access to data due to failure of the cloud service
6. Unintentional sharing of sensitive data through poor design decisions on the part of the cloud provider such as sharing items by file name or data deduplication practices (which also reveal that the vendor has access to the data)