Cloud technology is becoming increasingly important, not least for running AI services. But the number of security incidents is increasing and the needs linked to digital sovereignty are becoming increasingly clear. Two FOI researchers have evaluated incidents and measures in the cloud security area.
Cloud services allow organizations to access storage services, software, and computing capacity without having to build and maintain server facilities themselves. Cloud services have therefore created the conditions for many businesses to expand, especially in areas such as machine learning and AI that place high demands on computing power. Nowadays, cloud services are also used by public organizations, such as government agencies.
US-based hyper-scalable cloud solutions – so-called hyperscalers – which offer the ability to quickly scale up computing capacity and storage, have come to completely dominate the market.
– Amazon, Google and Microsoft are the major American players who have built up data capacity and large platforms with many different services for a long time, says Viktor Bergström, a research engineer at FOI department Cyber Defense and Management Technology.
Risky Relying on the US Cloud
More and more organizations are relying on cloud services, primarily for financial reasons.
– This means that we are in an interesting situation now, where we have a lack of sovereignty even in the cloud services area, says Viktor Bergstrom.
This creates risks if, for example, the US decides to shut down the IT infrastructure used, but also because the US government has access to data from US cloud service providers by law, even if it is managed in Europe.
– You can try to solve it technically, but there is a healthy hesitation about running your business on hardware that someone else owns, says Viktor Bergström.
As the use of cloud services increases, the number of security incidents also increases. On behalf of the Swedish Armed Forces, Viktor Bergstrom and research engineer colleague John Ziegenbein evaluated incidents and security measures related to cloud security, which they describe in the report A review of security incidents and actions regarding cloud services.
They have targeted the hyperscalers that dominate the market, and investigated what kinds of vulnerabilities that were behind 157 security incidents reported in the last ten years.
– We have looked at public data, and when it comes to security incidents, you have to keep in mind that there are always incidents that are not public. But we have tried to get a reasonable overview, says Viktor Bergström.
Simple misconfigurations behind incidents
Identity and access management deficiencies accounted for the largest share of cloud incidents, 58 percent. Other common causes of incidents were deficiencies in data protection and infrastructure management.
“We saw that many of these vulnerabilities are simple misconfigurations. Our hypothesis is that when systems become very complex, as cloud systems tend to become, it becomes easy to miss small, simple errors. You might create new subcomponents and remove others,” says Viktor Bergstrom.
In systems with deficiencies in identity and access management and infrastructure management, sensitive data was often easy to access for anyone who managed to get in.
– Overall, we observed that there was a lot of sensitive data publicly available on the internet. It is more time-consuming to work with encrypted stored data, and it is not always obvious to determine when data should be encrypted. But we believe that data leaked in multiple incidents in many cases should have been found to be encrypted at rest.
Viktor Bergström and John Ziegenbein also reviewed the security measures recommended by recognized institutions and authorities in cloud security. One conclusion is that the security frameworks with suggested security measures are large and complex, which can make them difficult to follow in practice.
– But there were a lot of things that were in common, so it feels like there is a certain consensus even among hyperscalers, says Viktor Bergström.
Time-consuming to build secure systems
Cloud security has gradually improved over the ten-year period studied by the research engineers. In the report, they propose measures that can prevent security incidents, for example, infrastructure as code (IaC), which means that IT resources are managed through code instead of through manual configuration.
– There are also more general tools, overview systems that look at the entire system and provide warnings for misconfigurations. There is a large number of security solutions that are relevant and effective, but where there is a risk that you will be locked into the supplier, given that a lot of supplier-specific expertise is required.
The development of cloud technology is happening at a rapid pace, and if European and Swedish people want to create their own platforms, a lot of knowledge and preparation is required, says Viktor Bergstrom.
– Cloud services could be very interesting from a defense perspective. But building systems with high security takes a very long time.








