Home Blog Page 202

86% of Security Pros Says Common Attacks Rose During COVID-19

remote working, cyberattacks on remote workforce

A new survey from Bitdefender revealed that 50% of infosec professionals did not have a contingency plan to face a situation like the COVID-19 pandemic. The survey “The Indelible Impact of COVID-19 on Cybersecurity” stated that lack of forward planning from organizations resulted in a surge of cyberthreats, with 86% of infosec professionals admitting that attacks in the most common attack vectors were on the rise during the pandemic.

“Cyberwarfare and IoT as an attack vector were reported to be up by 38%, and APTs and cyber espionage IP theft and social media threats/chatbots by 37% — all of which could be an indication of a bumper year for breaches,” the report said.

According to the report, 81% of security professionals believed that COVID-19 will change the regular business operations. The survey found that phishing attacks (26%), ransomware (22%), social media threats/chatbots (21%), cyberwarfare (20%), Trojans (20%), and supply chain attacks (19%), rose during the pandemic. 1 in 3 (34%) of respondents said that they fear that employees are feeling more relaxed about security issues because of their surroundings. Nearly, 33% of respondents reported that employees not sticking to protocol, especially in terms of identifying and flagging suspicious activities.

While 33% of respondents are concerned about their colleagues may fall prey to attacks, 31% cited that the heightened risk of a data breach was caused by unsuspecting employees. 25% of respondents were worried about bad actors targeting remote workforce with malware and ransomware attacks.

Industries Under Attacks

According to the report, the financial services (43%), health care (including tele medicine) 34%, and the public sector (29%) are the hardest hit industries during COVID-19 outbreak, followed by retail (22%), energy (20%), and education (18%). Around 77% of infosec professionals believed that health care was not effectively prepared due to budget constraints.

Liviu Arsene, Global Cybersecurity Researcher at Bitdefender, said, “At least half of organizations admitted they were not prepared for a scenario such as this, whereas the attackers are seizing the opportunity. But within the current situation there is a great opportunity for positive change in cybersecurity. In cybersecurity with high stakes around monetary and reputational loss the ability to change, and change rapidly, without increasing risk is critical. With COVID-19 changing the business landscape for the foreseeable future security strategy has to change. The good news is that the majority of infosec professionals have recognized this need for rapid change, although forced by current by circumstances, and have started taking action.”

 

Dropbox Drops a Box of Security Surprises for its Premium Customers

dropbox

With the lines between work and home blurring due to the ongoing forced remote work, Dropbox has now decided to introduce additional security measures and other features for its premium customers who are stuck at their home desks. The beta version of this update is already released; however, the final version will be rolled out soon in the coming weeks.

Dropbox is traditionally a data and file storage, sharing and collaboration platform which offers solutions for both home and work users. It follows a subscription-based model called the Dropbox Plus, which charges a mere premium of $9.99 per month for 2TB worth storage space.

Based on the type of user, Dropbox Plus has two product offerings – Home and Work – with different features and capabilities. Here are the new security features for the two modules:

For Home Users

  • Dropbox Passwords: We are quite familiar with the “Remember Password?” option that pops-up on the screen while logging into any website or web applications. If you click “Yes,” it simply remembers it and fills it in the next time you visit the same website. Dropbox Passwords does the same thing. It allows a seamless login process for websites and apps by storing their passwords and syncing them across the user’s various devices with zero-knowledge encryption (Single Sign-On).
  • Dropbox Vault: It allows the user to secure and organize documents and permits exclusive emergency access rights only to select friends or family members. Additionally, the Vault has a secure 6-digit PIN over and above the existing security features.
  • Backup: Now, Dropbox also automatically backs up users’ Mac or PC folders to Dropbox for enabling them secure access on-the-go. This feature is also helpful in data restoration in case of data loss due to hardware or OS failure.

For Office Users

  • HelloSign eSignature: Dropbox acquired HelloSign last year and this feature is proof of their collaborative work. This eSignature has been introduced as an embedded feature and has been set by default for Dropbox. It enables Dropbox users to securely send, sign, and store their confidential documents without leaving Dropbox. This functionality will be available to private beta users shortly and will become available to all users in the next month.
  • Dropbox App Center: For Dropbox users, connecting to Zoom, Slack, and Google is now just a few clicks away. The App Center is a centralized repository that is currently available to a subset of users in beta with 40+ integrated partners.

Foodora Data Breach Impacts 727,000 Customers Across 14 Countries

Foodora Data Breach

Food delivery firm Foodora is a victim of a data breach that exposed more than 727,000 customers’ details from 14 countries across Europe including France, Finland, Austria, Spain, and Italy. The exposed data included usernames, phone numbers, addresses, full names, locations, and hashed passwords of Foodora customers. However, payment information or credit card details are not breached in the incident, according to Databreachtoday report.

Delivery Hero, the parent company of Foodora, stated that unknown members posted the leaked customers’ data on various hacking forums. The data was dumped in a series of SQL files for each country, labelled as “CustomerAddress” and “Customers.” The affected customers are getting suspicious emails from unknown third parties, the company said.

Image Courtesy: Databreachtoday

“Unfortunately, we can confirm that a data breach has been identified concerning personal data dating back to 2016. The data originates from some countries across our current and previous markets. We started a thorough internal investigation and have informed all relevant authorities. We are working closely with our security and data protection teams, as well as local authorities, to identify what caused the breach and inform the affected parties,” Delivery Hero said in a statement.

In addition, Troy Hunt, data breach expert and the creator of Have I Been Pwned data breach notification service, tweeted, “Foodora had 583k unique customers exposed in 2016. Data included names, delivery addresses, phone numbers and passwords stored as either salted MD5 or bcrypt. 73% were already in @haveibeenpwned.”

Cyberattacks on Food Delivery Services

Multiple security incidents have been reported on food delivery service providers globally. In a recent incident, threat actors launched a distributed denial-of-service (DDoS) attack on Germany-based food delivery firm Takeaway.com (Liefrando.de). Attackers demanded two Bitcoins (around US$11,000) in ransom to stop the attack. Earlier, DoorDash, a San Francisco-based food-delivery service provider, faced a massive data breach that affected data of around 4.9 million people (its customers, delivery workers, and merchants), who were using its service platform. The company said that an unauthorized third-party accessed its user data on May 4, 2019. DoorDash clarified that users who joined its services platform on or before April 5, 2018, were affected in the incident.

 

Israel And Greece Sign an Agreement on Cybersecurity Info-Sharing

Israel And Greece Sign an Agreement on Cybersecurity Info-Sharing

Israel and Greece have signed a cooperation agreement on cybersecurity info-sharing. The cooperation agreement, between the Israel National Cyber Directorate (INCD) and the Ministry of Digital Governance of the Hellenic Republic, is aimed to strengthen regional cybersecurity in both the countries. The agreement was signed by Yigal Unna, Director General of the INCD, and Kyriakos Pierrakakis, Greek Minister of State and Digital Governance, in the presence of Israeli Prime Minister Benjamin Netanyahu during the visit of Greek Prime Minister Kyriakos Mitsotakis to Israel.

According to INCD, the joint statement is intended to promote cooperation in various areas, which include:

  • Engage in a mutual operational dialogue
  • Joint projects for enhancing national cyber platforms (i.e. CERT/SOC)
  • Cooperate on workforce training initiatives
  • Increasing cyber resilience, by sharing government cybersecurity know-how, best practices, legal and regulatory frameworks, methodologies, and strategic insights

“Cybersecurity is based on info-sharing. Both threats and solutions are international. Hence international cooperation is vital for the cybersecurity of every nation. Proper functioning and security of the digital environment is essential to national security, and to the continued prosperity of our economies and societies. The COVID-19 world crisis made this insight even more pronounced,” said the INCD.

Israel Combats Cyberthreats with Key Partnerships

Israel’s reputation as a cybersecurity force attracted considerable attention from different countries, which are looking for strong cybersecurity associates. The country entered into multiple key partnerships with other countries in an effort to make the cyber world a safe place. The latest of the partnerships is the news of Polish power grid operator, Polskie Sieci Elektroenergetyczne’s (PSE) with Israel Electric Corporation Limited to secure its energy sector. The deal resonates with the cybersecurity leader’s tie-up with Canada in 2017. The Israel Electric Corporation (IEC) had partnered with the Canadian Hydro-Quebec utility to boost the security of their grid infrastructure.

On his first visit to India in January 2018, Israeli Prime Minister Benjamin Netanyahu and Indian Prime Minister Narendra Modi shook hands on cybersecurity collaboration, which includes training, B2B assistance, and enablement of industrial summits to enhance skill development in the country.

 

4 Reasons Your Business Needs to Consider ISO/IEC 27701:2019 Implementation & Certification

ISO/IEC

Privacy is the new security: This is borne out by the increasing public awareness of privacy issues and violations. This, in turn, is reflected in our legislation. Businesses around the world are feeling the dual impact of customer privacy expectations and legislative enforcement. General Data Protection Regulation (GDPR) fines are perhaps a useful gauge as to the impact that privacy is having on organizations. Up to March 2020, there had been almost half a billion euros in fines issued under GDPR.

By Al Mahdi Mifdal, Global ISO Assurance Practice Principal at Coalfire Systems

Understanding how to ensure that personal data is maintained under privacy regulations can be complicated. Data, especially when used across disparate cloud apps, has a complex life cycle. Mapping these data to regulatory requirements is a challenge. That challenge can be met using a structured approach based on standards and frameworks. To this end, ISO/IEC 27701:2019 “Security techniques, Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management has entered the standards lexicon as an expansion of the better-known ISO/IEC 27001:2013 “Information Technology-Security Techniques- Information security management systems-Requirements” and ISO/IEC 27002:2013 “Information technology-Security techniques-Code of practice for information security controls”

Here, I look at what this new standard is about and how it can benefit your business.

What is the Scope of the ISO/IEC 27701:2019 Standard?

ISO/IEC 27701:2019 was published in August 2019 as an addition to ISO/IEC 27001:2013. This new standard acts as an expansion to an Information Security Management Systems (ISMS) to include guidelines on implementing a Privacy Information Management System (PIMS). In doing so, it adds a dimension of privacy to the existing security arrangements.

ISO/IEC 27701 defines the need for an information classification system that includes Personal Identifiable Information (PII). In addition, ISO/IEC 27701:2019 gives guidance for implementation of the standard by both PII controllers and PII processors, including when performing Privacy Impact Assessments (PIA), and using Privacy by Design. This maps the standard closely with the tenets of GDPR.

The standard came about as part of a general global movement towards ensuring that personal data meets privacy expectations. If an organization processes personal data or Personally Identifiable Information (PII), no matter what sector or size your business is, ISO/IEC 27701:2019 will be of benefit.

In terms of laws such as GDPR, the framework can be an invaluable asset. Following the guidelines within ISO/IEC 27701:2019 PIMS, your organization will be able to follow structured implementation and advisories on meeting the various data privacy requirements of GDPR. Having ISO/IEC 27701:2019 certification will certainly help in meeting GDPR, but it also offers a more general validation of your business commitment to privacy.

ISO/IEC 27701:2019 is an extension to ISO/IEC 27001:2013. This means that your organization will either have to already have or be in the process of meeting the ISO/IEC 27001:2013 standard to then work towards expanding to meet ISO/IEC 27701:2019.

4 Business Benefits of ISO/IEC 27701:2019

Acquiring certification, such as ISO/IEC 27701:2019 can be resource intensive for a business. To justify going through the process to achieve any standard, you need to have sound reasons to do so. Because data privacy is such a high-profile issue, the benefits of having ISO/IEC 27701:2019 can be distilled down to:

  • Business Benefit One: Having a Framework to Work To

Meeting privacy expectations of customers and of the legislature, such as GDPR, can be a challenge. Privacy can be nuanced and require multiple layers of control and protection applied to personal data. Having a set of well-thought-out guidelines in the form of a framework helps to condense the requirements of a data protection law. ISO/IEC 27701:2019 is an internationally recognized accreditation that helps meet compliance using a structured framework.

  • Business Benefit Two: Trust

Trust is a crucial remit of any online system or service that uses personal data. Privacy is a key part of building trust with a customer. If you demonstrate that your service is trustworthy, customers stay loyal. A survey by UK watchdog Ofcom, on attitudes towards online trust, found that 60% of respondents agreed with the statement “people who buy things online put their privacy at risk”. Improving this perception will encourage a more seamless interaction between customer and service. A Privacy Information Management System (PIMS) is designed to measure and map compliance with ISO/IEC 27701:2019, and in turn, help an organization meet the requirements of GDPR.

  • Business Benefit Three: Reputation

By showing that your organization has ISO/IEC 27701:2019 certification you demonstrate your commitment to building a trusted service that respects data privacy. Company reputation as a privacy-respectful business is a valuable asset. A Ponemon Institute study demonstrates this, describing how 31% of consumers will stop using a company if a data breach happens.

  • Business Benefit Four: Fines

As mentioned at the start of this article, GDPR fines are onerous. On analysis of the figures, CMS Law who runs ‘Enforcement Tracker’, found that most fines were issued because of “Insufficient technical and organizational measures to ensure information security”. By using the ISO/IEC 27701:2019 framework to implement the right privacy measures, you are acting to help reduce your organization’s risk of being issued a GDPR fine.

Conclusion

Since the GDPR came into effect in May 2018, companies have scrambled to get structures in place to meet the laws stringent requirements. This has been a serious challenge and has seen mistakes made and fines issued. ISO/IEC 27701:2019 can help companies to understand how to effectively put in place measures that help to meet GDPR. It is also possible that the PIMS implemented using ISO/IEC 27701:2019 may be used in GDPR certification going forward, so helping with audit during compliance. ISO/IEC 27701:2019 is useful not only for GDPR but for any organization that wants to demonstrate to its user and customer base that it respects their personal data privacy.

About the Author

Al Mahdi Mifdal Al Mahdi Mifdal currently serves as the Global ISO Assurance Practice Principal at Coalfire Systems and manages ISO assurance services and programs for clients worldwide. He is an information security subject matter expert with over 12 years of senior information security compliance and consulting expertise for fortune 500 companies, cloud service providers, Silicon Valley startups and international companies in healthcare, technology, and critical infrastructure sectors. Al Mahdi has extensive experience managing a wide range of consulting projects (Risk Management, Critical Infrastructure Protection, Security Operations Center Design etc.), compliance assessments (PCI, SOC, ISO 27001, HIPAA, etc.).

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

70% of Security Pros Say Government Cannot Protect Election Infrastructure from Cyberattacks

US Voters

A recent survey from machine identity protection provider Venafi revealed that 70% of cybersecurity professionals most likely believe their local governments cannot defend election infrastructure against cyberattacks from domestic and foreign threat actors. The survey, based on election infrastructure cybersecurity, also disclosed that 75% of security experts consider that the spread of malicious information is the biggest cyber risk to election integrity.

The majority of cyberattacks targeting election campaigns come from automated machines that inevitably spread information and direct attacks on the vote counting systems. Industry experts opine that the ongoing pandemic brings additional security hurdles to the election season. It is suspected that cybercriminals might take advantage of the crisis to spread false information and initiate cyberattacks, making security experts concerned about election data protection.

The research findings are based on the responses and opinions of 485 IT security professionals attending the RSA Conference 2020.

Kevin Bocek, Vice President of security strategy and threat intelligence at Venafi, said, “Security professionals are rightly concerned about cyberthreats impacting the democratic process. Organizations may have difficulty curbing deceptive or inaccurate information from people; however, they can keep their machines from spreading malicious disinformation. The election season is already in process and COVID-19 adds a new layer of security complications. Cyberattackers may take advantage of this period of uncertainty to undermine further public confidence by spreading disinformation. As a result, it’s not surprising security professionals are concerned that governments won’t be able to safeguard election data.”

Cyberattacks on U.S. Voters

Multiple security incidents have been reported earlier on misusing voters’ information and a lot of meddling happened in previous election campaigns. In October 2018, voter databases of around 35 million U.S. citizens were being peddled on a hacking forum. According to a report, cybercriminals obtained unauthorized access to the U.S. voter registration databases and kept them for sale in dark web forums, priced between $150 and $12,500. The database leaked personal information like names, phone numbers, address details, and voting history. The report stated the data disclosure affected 19 states, including Georgia, Idaho, and Iowa.

 

 

Magecart Payment Card Skimmers Infect Intersport and Claire’s Online Store

Ask Yourself These 4 Questions Before Shopping Online

Online shops of retail giants Intersport and Claire’s have been found to be infected with Magecart’s payment card skimmers. These web skimmers are ideally designed to exfiltrate customers’ payment card data. The modus operandi of a Magecart attack is simple. First, the cybercriminals gain access into a company’s online store website by compromising and hiding malicious code in it and then collect the payment card information from users using this malicious code while they make online purchases on the infected website.

Claire’s Story

Sanguine Security reports that the online store of Claire’s and its sister brand Icing were attacked by Magecart handlers between April 25 and June 13. A domain named claires-assets.com, was registered around March-end, which remained dormant for the next four weeks and became active only in the last week of April. The fake domain looked like a legitimate Claire’s website and was used to deliver the card skimmer.

The researchers said, “The injected code would intercept any customer information that was entered during checkout and send it to the claires-assets.com server. The malware was present until June 13th. The malware was added to the (otherwise legitimate) app.min.js file. This file is hosted on the store servers, so there is no “Supply Chain Attack” involved, and attackers have actually gained write access to the store code.”

The Card Skimmer Modus Operandi

  • The skimmer was placed on the submit button of the checkout form.
  • On clicking this button, the entire ‘Demandware Checkout Form’ was first given a serial number and then encoded by base64 encoding.
  • Further, a temporary image was added to the DOM with the __preloader identifier. This image is located on the server controlled by the cybercriminals.
  • Since, the submitted data is appended to the image address, the attacker receives the full payload.
  • On receipt, the image element is immediately removed to access and copy the payment card data.

The Intersport Story

Another similar type of attack was spotted by ESET researchers which targeted the Intersport website. This was a geotargeted web skimming attack as customers from Croatia, Serbia, Slovenia, Montenegro, and Bosnia and Herzegovina were specifically targeted.

According to reports, the Intersport online stores were compromised on April 30. As good Samaritans, the researchers contacted the company about the card skimmer hack on their respective websites. As per the latest update, the companies have now removed the malicious code and are functioning safely.

Qbot Malware: An Old Banking Trojan Back with New Capabilities

Android Trojan, Trojan, ReverseRat, Numando Banking Trojan

Security researchers at F5 Labs discovered an ongoing malware campaign using “Qbot malware” payloads to steal financial data from customers of the U.S. banks and financial institutions.

Qbot malware, also known as Qakbot and Pinkslipbot, is a banking Trojan active since 2008. According to F5 Labs researchers, attackers are still using the Qbot malware with updated worm features to steal users’ keystrokes, deploy backdoors, and spread malware payloads on compromised devices. The researchers stated that the latest version of Qbot has detection and research-evasion techniques that hide the malware codes and escape from scanners and anti-software tools.

“Attackers usually infect victims using phishing techniques to lure victims to websites that use exploits to inject Qbot via a dropper. It does this through a combination of techniques that subvert the victim’s web sessions, including keylogging, credential theft, cookie exfiltration, and process hooking,” the researchers said.

Qbot’s Targets

According to the research analysis, the Qbot campaign is mainly focused on banks and financial firms in the U.S., targeting around 36 U.S. financial institutions and two banks in Canada and the Netherlands.

qbot f5 labs
Image source: F5 Labs

“Several samples of the malware from this year showed that Qbot’s focus is on banks in the United States. This appears to be a dedicated campaign with a browser hijack, or redirection, as the main attack method when the machine is infected. As Qbot watches a victim’s web traffic, it looks for specific financial services from which to harvest credentials,” the researchers added.

Attack Process

The researchers listed how Qbot infection proceeds on a targeted device:

  • Qbot malware is loaded into the running explorer.exe memory from an executable file that is distributed via phishing mails or an open file share
  • The malware then installs itself into the application folder’s default location, as defined in the %APPDATA% registry key
  • Qbot creates a copy of itself in the specific registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run to run when the system reboots
  • Later it drops a .dat file with a log of the system information and the botnet name
  • The malware executes its copy from the %APPDATA% folder and replaces the originally infected file with a legitimate one
  • Finally, Qbot creates an instance of explorer.exe and injects itself into it. Hackers then use the always-running explorer.exe process to update Qbot from their external command-and-control server

F5 Labs recommended certain security measures like using updated antivirus software, fixing critical flaws in applications and devices, and providing necessary security awareness training to workforce to defend against evolving malware threats.

 

 

Poor Data Security Policies Affect Businesses During the Pandemic: Report

Cybersecurity-industry

A new research from secure payments provider PCI Pal revealed that most consumers may not trust organizations with poor cybersecurity practices or data breach history. The emerging sophisticated cyberattacks on organizations during the pandemic made data security a priority for consumers globally, the research said.

According to the research, 33% of consumers in the U.K. will avoid a business for years if their personal information has been exposed due to the company’s poor data security practices during the ongoing crisis. While 30% of consumers reported that they would never return, whereas only 11% said security incidents would not impact their loyalty towards an organization. When asked about data sharing, 69% of consumers responded that they felt the same level of concern about how companies are going to handle their personal information post pandemic, while 28% said they felt more concerned.

Consumers in Spain (45%) stated that they are now more concerned about businesses handling their personal data, followed by 42% of consumers in Australia, 34% of respondents in Italy, 30% in Germany and 29% in France. The Spanish consumers (86%) said that since the pandemic, they are anxious about sharing their financial information to companies working remotely, compared to 83% in Canada, 76% in France, 80% in Australia, and 62% in Germany.

Geoff Forsyth, Chief Information Security Officer, PCI Pal said, “Cybercriminals are shamelessly opportunistic and are aiming to capitalize on the remote working situation. Hackers are working around the clock to steal data for profit and therefore consumers are rightfully holding businesses accountable for lax data security practices. This means that businesses must meet the highest compliance and security standards if they want to build and maintain customer loyalty during these unprecedented times.”

Forsyth added, “As organizations continue to adapt to the changing business and threat landscape, it is crucial to prioritize data security. This includes adjusting business models to meet the highest standards of security and compliance across all customer engagement channels.”

The findings are based on the responses of 3,501 consumers in the U.K., France, Italy, Spain, Australia, Germany, and Canada. PCI Pal said that consumers in different locations responded differently to the news of security incidents. It is found that Germans are most likely to never return to a company’s product/service that suffered a data breach.

54% of Organizations  Do Not Follow Data Security Practices

A report “2020 Data Risk & Security” from security firm Netwrix revealed how organizations treat sensitive and regulated data during each stage of its lifecycle. According to the report, 91% of respondents were certain their sensitive data is stored safely while  1 in 4 organizations admitting they had discovered such data outside of designated secure locations last year. The report also highlighted that 61% of organizations that are subject to the GDPR collect more customer data than the law permits. It’s found that 66% of CIOs don’t have cybersecurity and risk KPIs that are regularly reported to their executives. Nearly 54% of organizations said that they do not follow the security practices like reviewing user access rights to data on a regular basis.

 

76.36% Believe Cloud Service Provider is Responsible for Security: CISO MAG Market Trends Report

Cloud Security

Who do you think is responsible for the security of the cloud? This question evoked mixed responses in CISO MAG’s Cloud Security survey. More than two-thirds of respondents (76.36%) said the cloud service provider (CSP) is entirely responsible for the security of the cloud. This was a multiple-choice question and from this set, some also feel it is the responsibility of the business owner of the functionality being outsourced to a cloud service. And some (40%) said it is the responsibility of the cloud consumers. It is clear there is a disconnect with consumers on security responsibility in the cloud. The complete research report on Cloud Security trends is published in the June issue of CISO MAG here: https://staging-cisomag.com/magazine/

“There is a lack of clarity or understanding of the shared responsibility model related to security. As well as, a misconception about the potential security services available to organizations as they migrate to the cloud,” said AJ Yawn, a cloud security expert who is also on the Board of ISC2.

Cloud Security Survey, shared responsibility model

Understanding the shared responsibility model is a critical first step for companies as they move to the cloud, without this understanding they could be exposed to security risks and weaknesses.

AWS defined a Shared Responsibility model that says “Security of the Cloud” is the responsibility of the CSP, but “Security in the cloud” is the responsibility of the customer. This model is gradually being accepted in the industry.

In the IaaS model, end-user or business owners will own the security to their systems, but implement the controls made available by the provider. It depends on how the business owner configures all the services they use on the cloud.

Much depends on their security policies and access controls. Security issues are often the result of user carelessness and unawareness, and the CSP cannot be held accountable for that. On the other hand, the CSP or MSSP should take all steps to secure the infrastructure that it provides to its customers.

Cloud experts that CISO MAG editors consulted for this survey said customers should never assume that because they were hosted on a particular cloud service provider, they inherited the compliance certifications or achievements of the CSP. This false assumption will leave them unprepared when the time for compliance assessments comes.

CISO MAG conducts a Cloud Security survey annually, and the last such survey (and research report) was published in July 2019.