Cloud security flaws put data at risk - cloud security
Cloud security flaws put data at risk

Last year, 43% of UK businesses said they’d sustained a cyber breach or attack, according to the government’s Cyber Security Breaches Survey. That’s about 612,000 firms. Company size changed the picture fast: 65% of medium businesses were hit, along with 69% of large ones.

Once a business starts adding staff, suppliers, and cloud accounts, the original security plan can quickly become insufficient. Businesses usually start in the right place, scanning for exposed systems, outdated software, unsafe settings, and excessive permissions.

However, these tools mainly tell you where an attacker could get in, not whether somebody is already moving through the system. Wiz is one platform addressing that problem, mapping cloud assets, vulnerabilities, identities, and routes to sensitive data.

Wiz Sensor extends that foundation into production workloads, watching live activity and connecting what it sees back to the identity, exposure, and data context Wiz already holds in its Security Graph. That combination matters because a list of what could go wrong is different from knowing what’s happening right now.

A stolen login can cause plenty of damage before the morning scan arrives. It’s essential to know how the system spots unusual file access, strange connections, and movement between workloads. The concept of “continuous monitoring” needs a proper explanation, as some vendors mean regular checks for bad settings, while others may offer live visibility into processes, connections, file changes, and user behavior.

There are three key signs that your cloud security setup may not be sufficient to stop a live attack. First, the business has never tested what happens during a real attack. Plenty of businesses can produce a vulnerability report, but far fewer can explain what happens five minutes after somebody uses one of those weaknesses – or can see when that’s actually happening.

Second, the security only runs on a schedule, not all the time. It’s worth being suspicious when a provider says “continuous monitoring” and leaves it there. Continuous in what sense? A tool can keep refreshing its list of missing patches and dangerous settings without watching a single process running inside the workload.

Related: Historic watermill to be restored by new owners

Third, they’ve added systems or staff since the last review. Growth challenges old security assumptions rather quickly. A company hires developers, opens another cloud account, connects a cloud account, and gives a partner vendor temporary access. Six months later, nobody can say with confidence whether every new system appears in the security console.

Orca is a useful benchmark for coverage, discovering workloads across connected cloud accounts without installing an agent on each one. Its SideScanning technology and eBPF-based sensor provide process-level runtime monitoring across Linux, Windows, and Kubernetes.

When reviewing cloud security, it’s essential to ask the right questions: Have they tested the response? Are important workloads watched while they run? Can they prove every new asset is covered? Finding the weak spot is useful, but catching someone using it is where the real test starts.

The difference between spotting a risk and stopping an attack is significant. A scanner tells you where trouble could start, such as an exposed database or an overpowered account. Runtime protection watches what happens after someone gets in, cutting a connection, killing a process, or isolating the affected workload before the damage spreads.

For growing businesses, it’s recommended to review cloud security at least once a year, but ideally sooner after a cloud migration, acquisition, large hiring push, new AI project, or major application launch. Any change that adds users, data, suppliers, or infrastructure can leave the old coverage map badly out of date.

Runtime scans should be running on an ongoing basis, and it’s essential to ask vendors about real-time protection, including what the platform can see while a workload is running and what it blocks without human approval. Asking who deals with alerts overnight is also vital.

Cloud security should automatically cover new systems, but sometimes an asset might appear unexpectedly without live protection. Agentless tools can discover new workloads quickly, while sensors, logging, and response rules may need separate setup. It’s vital to ask providers to show which assets are visible and which ones are actually being watched.