Deploy Bravely — Secure your AI transformation with Prisma AIRS
  • Sign In
    • Customer
    • Partner
    • Employee
    • Login to download
    • Join us to become a member
  • EN
  • magnifying glass search icon to open search field
  • Contact Us
  • What's New
  • Get Support
  • Under Attack?
Palo Alto Networks logo
  • Products
  • Solutions
  • Services
  • Partners
  • Company
  • More
  • Sign In
    Sign In
    • Customer
    • Partner
    • Employee
    • Login to download
    • Join us to become a member
  • EN
    Language
  • Contact Us
  • What's New
  • Get support
  • Under Attack?
  • Demos and Trials

asset thumbnail
Research Reports
Feb 07, 2024

The State of Cloud Data Security in 2023

The State of Cloud Data Security in 2023

English
  • Select the language
  • English
  • Japanese
  • Korean
  • Simplified Chinese
  • Traditional Chinese
Preview PDF Download
Preview PDF Download

The State of Cloud Data Security Report

The State of Cloud Data Security 2023 report analyzed more than 13 billion files stored in public cloud environments and found sensitive data in more than 30% of cloud assets. Download your copy now to gain insights on the best ways to engage with sensitive data in today's cloud environments.

This 3-part report covers:

Part 1: Where Is Your Sensitive Data?

The cloud empowers organizations through data democratization, but it also increases data sprawl. Data is constantly being shared, copied, transformed, and forgotten, often leading to security and compliance breaches. 44% of sensitive data is PII containing employee and customer data. Key takeaways from this section include:

  • Most companies don’t know where their data resides and what types of sensitive information it contains, leaving them exposed.

  • Attackers will use the weakest link in the chain to get into development environments.

  • Despite expert risk assessments, it's likely some sensitive data is still vulnerable to threats, including publicly accessible, unlogged, or non-encrypted data.

  • By knowing where sensitive data is stored, risk management can be simplified and data security can be improved.

 

Part 2: Who Has Access to Your Sensitive Data?

Overly permissive access granted across various roles can lead to data exposure and significant risk in sharing sensitive information between cloud accounts. Researchers found that 95% of principals were granted excessive privileges. Key takeaways from this section include:

  • The separation of duties concept is neglected and not enforced in the cloud. It’s recommended to remove consumer access from administrative roles.

  • While the majority of access is granted through excessive permissions, it’s recommended to grant explicit permissions to each asset.

  • Sensitive data shared between accounts weakens control and increases the risk of data exposure. Reduce the exposure of sensitive data to multiple accounts.

  • Permissions and role-based access control (RBAC) are insufficient protections in the cloud. Another security layer is needed to manage the sensitive information and all paths leading to it. See the Summary for more.

 

Part 3: Where Does Your Sensitive Data Flow?

When a security incident happens, it’s important to ask the right questions. What was taken? When was it taken? Who took it? Where was it taken from? How was it taken? The answers to those questions form the basis of the most important question of all—who is accessing the sensitive data? Key takeaways from this section include:

  • Sensitive data is accessed by many principals regularly. Minimize excessive permissions and continuously monitor principals' access to sensitive data, which will help reduce sensitive data exposure.

  • Turn on logging for sensitive data assets to enable monitoring.

  • Data flows represent duplication that increases exposure risk. Reduce flows to the minimum required and make sure the destination is secured.

  • Ensure that your data flows do not violate your internal governance and external compliance mandates.

 

Download the State of Cloud Data Security 2023 report now to see the research and gain insights on the best ways to engage with sensitive data in today's cloud environments.

Share page on facebook Share page on linkedin Share page by an email
Create an account Sign In

Already have an account? Sign in to continue reading.

Sign in here if you are a customer, partner or an employee.

Sign in with SSO
OR
Continue with Google Continue with LinkedIn
OR
Sign In

For unlimited access to ebooks and other resources, create an account today.

Join us to become a Member

Continue with Google Continue with LinkedIn
OR

Please complete reCAPTCHA to enable form submission.

I'd like to speak with a specialist
Email me exclusive invites, research, offers, and news

By clicking on "Join us to become a member", you agree to our Terms of Use and acknowledge our Privacy Statement.

Almost Done!

I'd like to speak with a specialist
Email me exclusive invites, research, offers, and news

By clicking on "Create Account", you agree to our Terms of Use and acknowledge our Privacy Statement.

Thank you for registering!

We have sent a confirmation email to {0}. Please check your email and click on the link to activate your account.

Get the latest news, invites to events, and threat alerts

By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement.

Products and Services

  • AI-Powered Network Security Platform
  • Secure AI by Design
  • Prisma AIRS
  • AI Access Security
  • Cloud Delivered Security Services
  • Advanced Threat Prevention
  • Advanced URL Filtering
  • Advanced WildFire
  • Advanced DNS Security
  • Enterprise Data Loss Prevention
  • Enterprise IoT Security
  • Medical IoT Security
  • Industrial OT Security
  • SaaS Security
  • Next-Generation Firewalls
  • Hardware Firewalls
  • Software Firewalls
  • Strata Cloud Manager
  • SD-WAN for NGFW
  • PAN-OS
  • Panorama
  • Secure Access Service Edge
  • Prisma SASE
  • Application Acceleration
  • Autonomous Digital Experience Management
  • Enterprise DLP
  • Prisma Access
  • Prisma Browser
  • Prisma SD-WAN
  • Remote Browser Isolation
  • SaaS Security
  • AI-Driven Security Operations Platform
  • Cloud Security
  • Cortex Cloud
  • Application Security
  • Cloud Posture Security
  • Cloud Runtime Security
  • Prisma Cloud
  • AI-Driven SOC
  • Cortex XSIAM
  • Cortex XDR
  • Cortex XSOAR
  • Cortex Xpanse
  • Unit 42 Managed Detection & Response
  • Managed XSIAM
  • Threat Intel and Incident Response Services
  • Proactive Assessments
  • Incident Response
  • Transform Your Security Strategy
  • Discover Threat Intelligence

Company

  • About Us
  • Careers
  • Contact Us
  • Corporate Responsibility
  • Customers
  • Investor Relations
  • Location
  • Newsroom

Popular Links

  • Blog
  • Communities
  • Content Library
  • Cyberpedia
  • Event Center
  • Manage Email Preferences
  • Products A-Z
  • Product Certifications
  • Report a Vulnerability
  • Sitemap
  • Tech Docs
  • Unit 42
  • Do Not Sell or Share My Personal Information
PAN logo
  • Privacy
  • Trust Center
  • Terms of Use
  • Documents

Copyright © 2025 Palo Alto Networks. All Rights Reserved

  • Youtube
  • Podcast
  • Facebook
  • LinkedIn
  • Twitter
  • Select your language