Multicloud and security: The risks of poor access management

More than 75% of organizations operate in the cloud. Access management in multicloud environments has become a critical challenge for enterprise security.

More than 75% of organizations operate in the cloud. Access management in multicloud environments has become a critical challenge for enterprise security.

 

By: Mateo Díaz, Sales Manager at BeyondTrust for Latin America.

Cybersecurity is no longer an option,

nor merely a technical issue confined to the IT department: it is now a strategic imperative. In this context, credential and access management has emerged as one of the most critical aspects for organizations—especially in an environment where multicloud architectures are increasingly prevalent.

The days when cloud migration costs dictated technology decisions are long gone. Today, companies are not choosing between clouds—they are choosing all of them.

According to PwC’s 2024 Cloud and AI Business Survey, 78% of business leaders report having adopted cloud across most or all areas of their organizations.

This growth has fueled remote work and digital transformation, but it has also introduced new security challenges.

Challenges of the Multicloud Environment

Mateo Díaz, Sales Manager at BeyondTrust for Latin America.
Mateo Díaz, Sales Manager at BeyondTrust for Latin America.

One of the major challenges presented by the multicloud and hybrid environment is fragmentation: identities stored across different services, native tools that are useful but incomplete, and unclear shared responsibility models among providers.

To this, we must add the fact that most organizations are not 100% cloud-based; many continue to operate on-premises infrastructures, often relying on legacy technologies. The result is fertile ground for malicious actors.

Today, many security breaches share a common element: inadequate control over privileged access. Whether due to compromised passwords, misconfigurations, or excessive permissions, poorly managed privileged access poses a persistent risk in both cloud and on-premise environments.

Strategies for Managing Privileges

To address this reality, organizations must move away from isolated tools and adopt a unified approach that enables comprehensive and efficient privilege management. Here are some key recommendations:

  1. Put identity management in order:
    Applying the principle of least privilege (PoLP) starts with knowing who needs access and why. This involves auditing users, superusers, applications, and APIs across both cloud and on-premise environments.
  2. Control administrators:
    Attackers seek persistence by creating privileged accounts. Identifying and reducing unnecessary privileges is essential to minimizing risk.
  3. Implement temporary access:
    Just-in-time (JIT) access limits exposure. Enforcing time-bound access windows helps reduce the attack surface.
  4. Modernize password management:
    Password reuse remains a serious issue. Solutions such as MFA, OTP, and secrets management are key to protecting critical credentials.
  5. Unify privileges across clouds:
    Native tools are helpful but insufficient in multicloud environments. A cross-platform identity management solution is required.
  6. Measure and demonstrate:
    Risk reduction must be demonstrable. Ongoing audits, access monitoring, and unified reporting are essential to showcase the effectiveness of the security program.

The Future of Cybersecurity

The multicloud environment offers tremendous benefits, but also raises the level of complexity and exposure. Organizations that fail to take control of their credentials and access are leaving the door open to attackers. Cloud security cannot be reactive; it must be proactive, cross-functional, and strategic. Because in the new digital paradigm, whoever controls access, controls the future.

Share:
Hosting Web
Most Read