Cloud Security Alliance Study Finds While CASB Demand Is High, Additional Education Is Needed to Clarify Cloud Security Goals
More training, clear goals are needed to ensure companies get full effectiveness of cloud security access broker products
The Cloud Security Alliance (CSA), the world’s leading organisation dedicated to defining standards, certifications and best practices to help ensure a secure cloud computing environment, announced today the release of its latest survey report, The Evolution of the CASB. The study, which queried more than 200 IT and security professionals from a variety of organisation sizes and locations, examined the expectations, technical implementations, and challenges of using cloud access security brokers (CASB). The results reveal unrealised gaps between the rate of implementation or operation and the effective use of the capabilities within the enterprise.
“CASB solutions have been underutilised on all the pillars but in particular on the compliance, data security, and threat protection capabilities within the service,” said Hillary Baron, lead author and research analyst, Cloud Security Alliance. “It’s clear that training and knowledge of how to use the products need to be made a priority if CASBs are to become effective as a service or solution.”
Commissioned by Proofpoint, Inc., a leading cybersecurity company and CASB solution provider, the paper found that while nearly 90% of the organisations surveyed are already using or researching the use of a CASB, half (50%) don’t have the staffing to fully utilise cloud security solutions, which could be remediated by working with top CASB vendors.
Further, more than 30% of respondents reported having to use multiple CASBs to meet their security needs and just over one-third (34%) find solution complexities an inhibitor in fully realising the potential of CASB solutions. Overall, CASBs perform well for visibility and detecting behaviour anomalies in the cloud but have yet to become practical as a tool for remediation or prevention.
“To overcome the gaps uncovered in this Cloud Security Alliance survey look for a solution that is part of a larger security portfolio and can effectively address the people-centric cloud security concerns on cloud account compromise, cloud data loss prevention, and cloud application compliance and visibility,” said Tim Choi, vice president of Product Marketing for Proofpoint. “It’s critical that the journey starts with clear goals in mind and prioritised objectives. In addition, identifying CASB solutions that provide a deployment model that can be operationalised in hours, not weeks leads to faster time to value.”
Additionally, the report found that when it comes to utilising CASBs, of those surveyed:
- 83% have security in the cloud as a top project for improvement
- 55% use their CASB to monitor user behaviours, while 53% use it to gain visibility into unauthorised access
- 38% of enterprises use their CASB for regulatory compliance while just 22% use it for internal compliance
- 55% of total respondents use multi-factor authentication that is provided by their identity provider as opposed to a standalone product in the cloud (20%)
For more information on Proofpoint’s CASB solution, please visit https://www.proofpoint.com/uk/products/cloud-security/cloud-app-security-broker.
About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading organisation dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.
About Proofpoint, Inc.
Proofpoint, Inc. (NASDAQ: PFPT) is a leading cybersecurity company that protects organisations’ greatest assets and biggest risks: their people. With an integrated suite of cloud-based solutions, Proofpoint helps companies around the world stop targeted threats, safeguard their data, and make their users more resilient against cyber attacks. Leading organisations of all sizes, including more than half of the Fortune 1000, rely on Proofpoint for people-centric security and compliance solutions that mitigate their most critical risks across email, the cloud, social media, and the web. More information is available at www.proofpoint.com.