Join our Newsletter — 33% off our NHI Course

Cloud data security gaps: what 2022 survey results mean for teams

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: 80% of organisations store sensitive data in the cloud, 53% experienced a cloud infrastructure cyberattack in the prior 12 months, and 49% saw unplanned remediation costs after an attack, according to Netwrix’s 2022 survey of 720 IT professionals. The governance gap is not cloud adoption itself, but the fact that data, access, and detection controls are still maturing unevenly.

Editorial analysis by NHI Mgmt Group, based on content published by Netwrix: “2022 Cloud Data Security Report”.

By the numbers:

  • 80% of organizations store sensitive data in the cloud
  • 53% of respondents experienced a cyberattack on their cloud infrastructure within the last 12 months
  • 49% of IT pros said that an attack led to unplanned expenses to fix security gaps

Key questions

Q: How should security teams reduce cloud data exposure from misconfigured storage?

A: Start with continuous configuration monitoring on storage, snapshots, and backup locations, then block public access and unsafe sharing by default.

Q: Why do cloud incidents so often become expensive remediation events?

A: Cloud incidents spread cost because the same identity or misconfiguration can affect multiple services, regions, or accounts at once.

Q: What are the signs that security governance is failing in a cloud or platform organisation?

A: Common signs include executives giving inconsistent security numbers, production access with no action logging, outdated systems left unpatched, and unresolved questions about account ownership.

Practitioner guidance

  • Inventory where sensitive data actually resides Map the cloud services, storage locations, and applications that hold regulated or business-critical data so ownership is clear before the next control review.
  • Tighten entitlement scope around cloud data stores Review who can read, move, and administer data repositories, then remove standing access that is broader than current job need.
  • Correlate identity and data telemetry Connect cloud logs, access records, and storage events so incident responders can tell which data sets were touched and by which accounts.

Bottom line: Cloud adoption is still expanding, but security maturity is not keeping pace across access, visibility, and remediation.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Cloud adoption has outpaced cloud governance. The report shows that organisations are continuing to move sensitive data into cloud environments while the operational controls around access, visibility, and remediation remain uneven. That imbalance is the real security problem, because cloud adoption without matching governance increases the number of places where identity and data controls must hold at once. The practitioner implication is simple: security maturity has to scale with cloud usage, not follow it years later.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations prioritise access governance or authentication controls first in cloud programmes?

A: They need both, but the order depends on the failure mode. If users can log in but retain unjustified access, governance is the weaker layer. If access decisions are sound but entry controls are weak, authentication is the immediate gap. Cloud IGA becomes critical when the main problem is entitlement drift.

👉 Read our full editorial: Cloud data security remains weak as cloud adoption keeps expanding


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.