Cloud Usage in Modern Business
We have reached the point where most companies are using the cloud for some part of their business. Some companies operate completely off the cloud without any on-premise server infrastructure. The wholesale cloud adoption by so many has reached the point where the long and laborious system installation and configurations of the past are mostly forgotten.
Unfortunately, the ease and speed of cloud adoption have also led to some complacency when it comes to SaaS security. It is far too common for companies to purchase and use a Software-as-a-Service solution with the assumption that it is ready to use “out of the box.” While these services may be fully functional, they are far from secure.
Your first thought might be to accuse cloud service providers of offering a substandard product, but this is not the case. It all comes down to expectations. Cloud ease of use has many thinking of it just like any other product. We buy a car and expect it to have passed safety tests, so a new car should be safe to drive. It is easy to forget, however, that most accidents occur not from faulty manufacturing but from faulty use. Similarly, SaaS solutions need a bit of configuration before they can meet your security needs. Let’s explore the five most common cybersecurity gaps in the sections below.
Table of Contents
- Insufficient Logging
- Standard Authentication Mechanisms
- Decentralized Identity Management
- Improper Privilege Assignment
- Lack of Compliance
- Final Thoughts on SaaS Security
1. Insufficient Logging
Logs provide a record of what has occurred on a computing system—for example, logging into your email to retrieve new messages, downloading a file, or updating a document. These events, as well as system actions, can all be tracked in log files.
SaaS solutions often have many options for what is logged and how long such data is retained. This may seem unimportant until a system is compromised and log files are needed to identify the scope of impact, root cause, and remediation steps. The default settings on many services do not capture enough information for a thorough investigation. This can put your company in an uncomfortable position where you cannot determine if data was exposed, how much data was exposed, or how the system was compromised.


