Can you hack-proof the cloud?

CCTV Handbook 2021 Infrastructure

For someone not working in cybersecurity, the most high-profile case of cloud hacking is, arguably, ‘celebgate’, or the 2014 breach of several device-storage accounts that saw hundreds of personal photos of celebrities stolen and published online. For cybersecurity professionals, though, this represents a minute ingress compared to, say, the infamous 2013 breach compromising as many as one billion user accounts, or the 2019 ‘cloud hopper’ case which saw cyber attackers (allegedly involving state actors) access reams of data including intellectual property from some of the world’s largest companies.

The cost and impact of cybercrime is climbing by around 15% every year, according to a 2020 report in Cybercrime Magazine and is expected to cost $10,5 trillion globally by 2025. This makes cybercrime, they argue, more profitable than the global illegal drug trade.

The real costs are far greater though, both broadly and to individual companies, as these funds represent lost investment and innovation and companies increasingly face stringent fines for personal data losses under regulations such as the General Data Protection Regulation (EU GDPR) and Protection of Personal Information Act (PoPIA).

The human layer

All it takes is a chink in the armour and this can be through human error, misconfiguration, permissions-based or sheer brute force attacks. This is why I liken solid data security strategy to a South African staple – the humble braaied onion.

The outer edge gets the most heat through the tinfoil when you’re cooking it. At the centre is the soft part – valuable data – and you have to have multiple layers of protection around that ‘sweet data’. Hacked or – worse – lost, our data is incredibly valuable. This is why you need prevention tactics and training on human error and how this can be exploited.

User education – training on cyber threats and the kinds of tactics used by bad actors – is a key protection layer and one that is particularly valuable because people are inherently fallible. The users of your systems are vulnerable to phishing, spear-phishing and social-engineering attacks. Even if your security professionals are ‘jaded and grumpy’, the outgoing nature of your sales staff (as just one example), their keenness to establish relationships, to be helpful, has been exploited since time immemorial.

And what about a systems administrator who is having a bad day, who makes a simple error in a moment of distraction? These kinds of lapses are so relatable, but they also render the ‘human layer’ susceptible to breaches.

This is why cloud should be seen as an extension of the systems we have always used. In definitional terms, it is scalable and highly agile, accessible by Internet technologies. There are standards that apply, such as usage per hour, availability and so on. This is why cloud can be a boon to business. But, using cloud shouldn’t make you feel more comfortable than using your own server and network.

Strategies, tactics and responsibility

Another important thing to realise is that ‘shifting to the cloud’ doesn’t absolve you of responsibility for your part in the cybersecurity conversation. Most cloud providers, in fact, work on a shared responsibility model, with customers retaining responsibility – for example – for defining who has access to their cloud environments, delineating roles and, ultimately, ensuring that their data is secure.

Password standards are important, of course, but a password is part of the human layer or interface. So, we must also verify that users are who they appear to be, that they aren’t a stolen identity or the result of shoulder surfing. Role-based access would definitely be a preventative measure, as is two-factor or multi-factor authentication (2FA and MFA). Still, it is important to ensure these avenues of control do not become prohibitively convoluted. They must be relatively intuitive so that users don’t push back or see them as a barrier to getting their work done.

Then, whether it is inside your HQ, or out in the cloud, data is always in one of three states: in use, at rest and in motion. With each of these, there are vulnerabilities that need to be addressed. Here again, taking a layered approach to security is required.

In order to both enable your workforce and protect the organisation, you need to ensure that the right data is given to the right people at the right time – that is data in use. This is where a security framework like ‘zero trust’ can be appropriate as this requires all users, devices, applications and services – internal and external – to be authenticated, authorised and constantly verified.

Other tactics in this layered approach, used in combination or in discrete instances, include perimeter security, intrusion detection and prevention systems (IDS/IPS) that can identify anomalies and sandboxing that enables the identification of threats being seen for the very first time. The key in all of this is having real-time threat intelligence being continually fed into your security infrastructure so that it’s always up-to-date with the latest malware, attack techniques and attacker profiles. An ever-evolving threat landscape can only be addressed with an ever-evolving cyber defence.

Standards in place, and beyond standards

Data at rest includes ‘backup in the cloud’ or storage. Firstly, a backup needs to be a backup, meaning that best practice requires keeping data in multiple places and not just ‘cutting and pasting’ off a machine. Secondly, that cloud storage is only as safe as the policies, protocols and standards that are applied. Correctly configuring access is key. Equally critical is encrypting data at rest.

Too often, he cautions, clients are in a rush to get a system up and running and forget things like consultation with the group risk department who have standards for, for example, encryption. Cloud environments need to be proactively and continuously monitored to identify any data that is not encrypted or may be mistakenly publicly readable.

Finally, there’s data in motion. The encryption you use will be determined by what data is going to be transmitted. Data is very vulnerable when it is in motion. There are hundreds of millions of unencrypted emails flying about every day.

Stratified strategy

The bottom line is that none of the security or encryption tools are completely impenetrable, especially as the technology deployed against them becomes increasingly sophisticated – as we are seeing with the use of quantum computing in this context.

The final layer of the onion, so to speak, is monitoring and the capability of detecting when things aren’t going as expected and then – vitally – the means to automatically act on that info.

This is why artificial intelligence (AI) in security is coming to the fore. AI is being used in determining the behaviour of a bad actor versus a good actor while the data is in use. Our AI systems are diagnosing potential threats and proactively improving security. AI can quickly assess what a user’s previous access encompassed and determine that suddenly the user is asking for information that they have never had before. AI, along with automation, can then proactively work to limit access and tighten the controls in place.

As we increasingly rely on cloud environments and our world becomes ever more digital, all these defences are coming together to ensure that we are the ones left to enjoy the rewards of that sweet data core and not the bad actors.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Service robot technology for residential complexes
Suprema AI & Data Analytics Infrastructure Residential Estate (Industry)
Suprema has signed a three-party memorandum of understanding (MOU) with Hyundai Motor Group Robotics LAB and Hyundai Engineering & Construction (Hyundai E&C) to collaborate on advancing residential complexes through service robot technology.

Read more...
Genetec launches Cloudlink 2210
Genetec Infrastructure Surveillance
New cloud-managed appliance addresses the practical challenges when adopting a cloud-managed model at scale, including storage costs, support for devices that do not enable direct-to-cloud connectivity, and the need to maintain local operation during connectivity disruptions

Read more...
Proactive estate security in Cape Town
neaMetrics OneSpace Technologies Technews Publishing SMART Security Solutions Fang Fences & Guards ATG Digital Editor's Choice News & Events Integrated Solutions Infrastructure Residential Estate (Industry)
SMART Security Solutions started the year with our annual SMART Estate Security Conference in Cape Town on 26 February 2026. Held at Anna Beulah Farm, the conference saw a number of delegates enjoying the farm’s excellent cuisine, while listening to outstanding presenters.

Read more...
AI projects are failing at alarming rates
AI & Data Analytics Infrastructure
As organisations around the world accelerate their investments in artificial intelligence, digital transformation and data analytics, a growing number of industry experts are warning that many companies are still approaching these initiatives in fundamentally flawed ways.

Read more...
Understanding the Shared Responsibility Model
Infrastructure Security Services & Risk Management
While the cloud can certainly be a growth enabler in many ways, it can also introduce new security risks. Companies want to have a clear understanding of where their security duties end and where their cloud service provider’s begin.

Read more...
Cloud security in visitor management and access control
SA Technologies Access Control & Identity Management Infrastructure Residential Estate (Industry) Commercial (Industry)
Cloud has become the default platform for modern security operations, from visitor management portals and remote access control to incident logging, reporting, analytics, and integrations. But “in the cloud” does not mean “someone else is securing it for us”.

Read more...
New commercial and technical appointments at Veeam
News & Events Infrastructure
Veeam Software has announced two senior appointments in its South African business as it continues to invest in local market growth and partner and customer engagement.

Read more...
Access as a Service is inevitable
Technews Publishing SMART Security Solutions ATG Digital Access Control & Identity Management Infrastructure
When it comes to Access Control as a Service (ACaaS), most organisations (roughly 90% internationally) plan to move, or are in the process of moving to the cloud, but the majority of existing infrastructure (about 70%) remains on-premises for now.

Read more...
Privacy by design or by accident
Security Services & Risk Management Infrastructure
Africa’s data future depends on getting it right at the start. If privacy controls do not withstand real-world conditions, such as unstable power, fragile last-mile connectivity, shared devices, and decentralised branch environments, then privacy exists only on paper.

Read more...
Access trends for 2026
Technews Publishing SMART Security Solutions RR Electronic Security Solutions Enkulu Technologies IDEMIA neaMetrics Editor's Choice Access Control & Identity Management Infrastructure
The access control and identity management industry has been the cornerstone of organisations of all sizes for decades. SMART Security Solutions asked local integrators and distributors about the primary trends in the access and identity market for 2026.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.