Summary
The threat landscape of the cloud differs from that of a traditional on-premises environment. An increasing reliance on the cloud brings new complexities and security challenges, and as a result, adversaries are increasingly targeting these environments. Customers often incorrectly assume that the cloud service provider (CSP) manages important aspects of safeguarding resources in the cloud that are not the CSP’s responsibility. CSPs provide highly automated, software-defined, and application programming interface (API)-driven platforms that “do what they’re told” by customers without any human oversight on the CSP side. Misconfiguration and lack of security controls are significant risks in cloud environments. Both the customer and the CSP are accountable for securing cloud environments.