News

Study: Security Not Priority for Cloud Providers, Users

Security is not a top priority for cloud computing vendors and customers, according to a recent CA Technologies-sponsored survey by the Ponemon Institute.

The report, "Security of Cloud Computing Providers" (PDF), polled 127 cloud service providers from the United States and Europe. A whopping 73 percent of U.S. service providers and 75 percent of European service providers said their cloud services did not substantially protect and secure their customers' confidential or sensitive information.

Furthermore, two-thirds of U.S. providers and 61 percent of European providers were unsure whether their solutions meet customers' security requirements.

According to the polled vendors, the primary reasons customers purchased their solutions was cost reduction (91 percent), ease of deployment (79 percent) and improved customer service (37 percent). Vendors believe that improving security and complying with agreements and policies are low priorities for customers.

Another big reason for low security: The majority of cloud providers (69 percent) don't believe it's their responsibility. Even more worrisome, polled vendors said their systems and applications are not always evaluated for security threats prior to deployment to customers.

In addition, a majority admitted they do not have dedicated security personnel to oversee the security of their cloud applications, infrastructure or platforms. On average, providers allocate 10 percent or less of their operational resources to security.

Last year, Ponemon released a similar study on cloud users. Comparing results from the two studies, the firm concluded in the recent report that "neither the company that provides the services nor the company that uses cloud computing seem willing to assume responsibility for security in the cloud. In addition, cloud computing users admit they are not vigilant in conducting audits or assessments of cloud computing providers before deployment."

Featured

  • Microsoft Dismantles RedVDS Cybercrime Marketplace Linked to $40M in Phishing Fraud

    In a coordinated action spanning the United States and the United Kingdom, Microsoft’s Digital Crimes Unit (DCU) and international law enforcement collaborators have taken down RedVDS, a subscription based cybercrime platform tied to an estimated $40 million in fraud losses in the U.S. since March 2025.

  • Sound Wave Illustration

    CrowdStrike's Acquisition of SGNL Aims to Strengthen Identity Security

    CrowdStrike signs definitive agreement to purchase SGNL, an identity security specialist, in a deal valued at about $740 million.

  • Microsoft Acquires Osmos, Automating Data Engineering inside Fabric

    In a strategic move to reduce time-consuming manual data preparation, Microsoft has acquired Seattle-based startup Osmos, specializing in agentic AI for data engineering.

  • Linux Foundation Unites Major Tech Firms to Launch Agentic AI Foundation

    The Linux Foundation today announced the creation of a new collaborative initiative — the Agentic AI Foundation (AAIF) — bringing together major AI and cloud players such as Microsoft, OpenAI, Anthropic and other major tech companies.