Exposed Cloud Data is $28 Mn Cyber Risk for Average Company

“The Great SaaS Data Exposure” report from Varonis analyzes SaaS risk at hundreds of companies, shedding light on the tension between productivity and security

0
269

India— The average company with data in the cloud faces $28 million in data-breach risk, according to a new report from Varonis. The Great SaaS Data Exposure examines the challenges CISOs face in protecting data across a growing portfolio of SaaS apps and services such as Microsoft 365, Box, and Okta. 

The study highlights how hard-to-control collaboration, complex SaaS permissions, and risky misconfigurations — such as admin accounts without multi-factor authentication (MFA) — have left a dangerous amount of cloud data exposed to insider threats and cyberattacks.

For the report, researchers at Varonis analyzed nearly 10 billion cloud objects (more than 15 petabytes of data) across a random sample of data risk assessments performed at more than 700 companies worldwide. 

Key findings from the Varonis report include:

  • Most companies are sitting on exposed data in the cloud. A whopping 81 percent of organizations had sensitive SaaS data exposed.
  • Companies face dangerous cloud data risks. In the average company, 157,000 sensitive records are exposed to everyone on the internet by SaaS sharing features, representing $28 million in data-breach risk.
  • Broad internal data exposure is a real problem One out of every 10 records in the cloud is exposed to all employees — creating an impossibly large internal blast radius, which maximizes damage during a ransomware attack.  
  • Missing MFA makes attackers’ jobs easier. The average company has 4,468 user accounts without MFA enabled, making it easier for attackers to compromise internally exposed data. 
  • Sitting-duck admin accounts leave companies vulnerable. Out of 33 super admin accounts in the average organization, more than half did not have MFA enabled. This makes it easier for attackers to compromise these powerful accounts, steal more data, and create backdoors.
  • Untenable permission structures pose a big challenge. Companies have more than 40 million unique permissions across SaaS applications, creating a nightmare for IT and security teams responsible for managing and reducing cloud data risk.

Get the Report: The Great SaaS Data Exposure

“Cloud security shouldn’t be taken for granted. When security teams lack critical visibility to manage and protect SaaS and IaaS apps and services, it’s nearly impossible to ensure your data isn’t walking out the door,” says Brian Vecci, Field CTO, Varonis. “This report is a true-to-life picture of over 700 real-world risk assessments of production SaaS environments. The results underscore the urgent need for CISOs to uncover and remediate their cloud risk as quickly as possible.”

“Organizations throughout India have been investing heavily in cloud adoption,” said Maheswaran Shamugasundaram, Country Manager for India, Varonis. “While the cloud has facilitated new ways to collaborate and made remote work possible, SaaS applications and services make protecting sensitive data more complex. The new report highlights how the cloud widens an organization’s blast radius and quantifies how exposed data is at risk. To stay ahead of insider threats and cyberattacks, it is imperative to take a data-first approach to security, which starts with understanding that permissions and security in SaaS are extremely complex.”

Additional Resources

  • For more information on Varonis’ solution portfolio, please visit www.varonis.com.