logo
Why Hybrid Cloud Security Is A Top CISO Priority For 2025

Why Hybrid Cloud Security Is A Top CISO Priority For 2025

Forbes22-07-2025
Jonathan Fischbein is the Chief Information Security Officer at Check Point Software Technologies.
Cloud infrastructure has become the backbone of modern IT frameworks, playing a critical role in supporting services ranging from email and data storage to application hosting and DevOps. As organizations continue to accelerate their adoption of cloud technology to streamline operations and drive business efficiency; they may also be exposing themselves to an expanding array of security risks and vulnerabilities.
The rise of hybrid cloud environments—where companies utilize a mix of private and public clouds—has only compounded these security risks. According to research by my company, Check Point, security risks from hybrid cloud deployments pose a unique set of challenges for cybersecurity professionals. From vulnerabilities related to administration and misconfigurations to challenges in threat detection and prevention, global CISOs must become more vigilant in their treatment of hybrid environments.
The Complexity Of Cloud Administration
As organizations expand their cloud footprint to take advantage of cost, performance and geographic efficiencies, they must now monitor for issues across a more diverse and disconnected cloud ecosystem. With each new cloud service provider comes a new potential threat surface and an opportunity for administrative oversight. Navigating this ever-expanding landscape is no easy task, especially when administrators are tasked with managing myriad configurations and settings to ensure the security of their environments.
One of the most challenging aspects of cloud security is the management of non-human identities (NHIs), such as service accounts, API keys and built-in user accounts. These entities are critical to the functionality of cloud systems but can often be misconfigured or inadequately secured, providing easy points of entry for attackers.
One example occurred in January 2024, when the advanced nation-state threat group Midnight Blizzard exploited a misconfigured OAuth application in Microsoft's Azure environment. This vulnerability allowed attackers to pivot from testing environments to production, accessing sensitive systems and even internal emails from top Microsoft executives.
In India, a misconfigured S3 bucket exposed over 500GB of sensitive personal and biometric data, including information from military personnel, while other major corporations also experienced breaches due to misconfigured cloud storage containers.
The Hazards Of Hybrid Environments
Many organizations use identity and access management (IAM) solutions to integrate and streamline user authentication across both cloud and on-premises systems. While this integration provides seamless user experiences, it also creates potential pathways for lateral movement by attackers.
Why is this so important? Once attackers compromise an on-premises network, they can pivot into cloud environments through various vectors, including hybrid user accounts and cloud connectors.
In 2024, an attack like this occurred when the financially motivated threat actor Storm-0501 launched a series of multi-stage attacks against hybrid cloud environments. These attacks allowed the actor to deploy backdoor accounts, spread ransomware and infiltrate sensitive systems across the network.
Securing Single Sign-On Accounts
Single sign-on (SSO) systems have become a popular method for managing authentication across cloud and on-premises applications. However, as organizations increasingly rely on third-party SSO providers, cybercriminals have shifted more focus to exploiting these services. Credential stuffing and brute-force attacks are common tactics used to compromise SSO accounts, making them prime targets for advanced persistent threat (APT) groups.
This highlights a critical concern: the reliance on third-party SSO providers for security can be risky, especially if their own security practices are not up to par. Without comprehensive visibility into log data and account activity, organizations may struggle to detect and respond to security incidents in a timely manner.
The Emergence Of AI-Driven Threats
As cloud providers integrate more advanced technologies into their offerings, one of the most significant emerging threats comes from generative AI. Cloud services now provide the infrastructure to build, train and deploy custom large language models (LLMs), enabling companies to create tailored AI solutions for their specific business needs. These models can integrate proprietary data, offering better control over sensitive information and ensuring privacy.
However, as AI becomes more accessible, threat actors are finding new ways to exploit these technologies. One of the newest threats is a form of cloud hijacking known as LLM-jacking. In this attack, malicious actors compromise cloud accounts to take control of existing hosted LLM models or deploy their own.
Once in control, attackers can resell access to these models or exploit them for malicious purposes. For example, one group used an LLM proxy to resell access to the model, while others leveraged jailbreaks to create and sell uncensored chatbot characters.
This trend isn't just hypothetical. Threat groups have been caught using ChatGPT to generate advanced tools and research vulnerabilities. There is also now growing evidence that threat actors may pivot to private LLM instances to gain better operational security, using cloud-based AI for more sophisticated, harder-to-detect attacks.
Hybrid Cloud Visibility And Protection Have Become Mission-Critical
The cloud's attack surface is growing exponentially as businesses continue to leverage its capabilities for operational efficiency. Protecting these environments requires staying ahead of evolving threats, securing both cloud and hybrid infrastructures, and continuously refining security practices. The key to mitigating cloud vulnerabilities lies in understanding the technology's evolving nature and taking proactive measures to safeguard sensitive data and systems.
Of course, in the AI era, a prevention-first security strategy means organizations must leverage AI solutions to drive real-time detection and response and consolidate security operations. Most importantly, security must be a primary business goal. Building modern cyber resilience requires a robust zero trust strategy, automated threat and misconfiguration management, agile and comprehensive data protection and more. Organizations must prioritize the investments and tactics that will help them build the cybersecurity foundation they need. By staying ahead of the curve, businesses can defend against the next generation of cloud-based cyberattacks.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Samsung Galaxy Z Flip 7 Deals: Grab This Pocket-Sized Foldable for Free
Samsung Galaxy Z Flip 7 Deals: Grab This Pocket-Sized Foldable for Free

CNET

time7 minutes ago

  • CNET

Samsung Galaxy Z Flip 7 Deals: Grab This Pocket-Sized Foldable for Free

When it comes to foldable phones, Samsung makes some of our absolute favorite models on the market. And its latest generation just hit shelves. The Galaxy Z Flip 7 and Z Flip 7 FE (as well as their large-screen counterpart, the Galaxy Z Fold 7) started shipping in July, and there are plenty of ways to get your hands on one for less right now. Retailers are offering discounts and free gift cards, and you can potentially pick one up for free with a trade-in or a new line at a carrier. To help you make the most of these bargains, we've rounded up all the best deals out there right now below. CNET reviewer Patrick Holland was impressed by the new Galaxy Z Flip 7 in almost every way, specifically citing the thinner design, smaller crease and stunning AMOLED display. It features a 4.1-inch cover screen and a 6.9-inch interior display, and is just 4.2mm thick when open (or 8.9mm when closed). It's also equipped with a Exynos 2500 processor, 12GB of RAM, a 4,300 mAh battery and a high-res 50MP rear camera. There are also 12MP front cameras on both the cover and interior screen, which makes it easy to take selfies from afar. There's also the more affordable Galaxy Z Flip 7 FE, which starts at $900 rather than $1,100. It has a slightly smaller display and thicker design, as well as a Exynos 2400 processor and 8GB of RAM rather than 12GB. Though it's still equipped with the same 50MP camera, and has many of the same features, including IP48 water resistance, 25W fast charging and onboard AI. Best Galaxy Z Flip 7 deals Samsung Samsung is the obvious choice if you're looking to grab an unlocked model of the new Galaxy Z Flip 7. It's automatically $50 off, and you'll get access to the exclusive mint color variant. Plus, you can save up to $600 with an eligible trade-in. You'll get the full discount when you exchange the latest Apple and Samsung phones, though devices from Google, Motorola and other brands are accepted as well. Details Save $50, up to $600 off with trade-in See at Samsung Close Amazon Order the new Galaxy Z Flip 7 from Amazon before August 10, and you'll also get a free $200 Amazon gift card with the purchase. Plus, the online retailer has its own trade-in program where you can save up to $725 in exchange for your old phone. Devices from Samsung, Apple, Google, Motorola and OnePlus are all accepted. Details Free $200 gift card, up to $725 off with trade-in See at Amazon Close Best Buy Like Amazon, Best Buy is including a free gift card with the purchase of a new Galaxy Z Flip 7, though only for $100. The tech retailer is also has a trade-in offer that could knock up to $600 off the usual price. Phones from Samsung, Apple, Google and tons of smaller brands are accepted, though only the latest Samsung devices will net you the full discount. You'll also get an extra $100 off if you opt to activate the phone through Verizon. Details Free $100 gift card, up to $600 off with trade-in See at Best Buy Close AT&T AT&T is offering chance to potentially grab this phone for free with an eligible trade-in. You'll get $1,100 off in exchange for any Samsung phones valued at $95 or more, and even older and damaged devices valued at just $35 or more will still net you $800 in credit. That means you can grab the 256GB model for free, or the 512GB model for around $3 per month. The discount will be applied as bill credits over 36 months. Details Free with trade-in See at AT&T Close Verizon Those adding a new line on Verizon's Unlimited Ultimate plan can trade in their old phone for up to $1,100 the Galaxy Z Flip 7, which scores you the basic 256GB model for free or the 512GB model for around $3 per month. You can also buy one and get a second for free without a trade-in or new line, as long as you're on an Unlimited Plus or Ultimate plan. Just note that these two offers can't be combined. Details Free with new line and trade-in See at Verizon Close T-Mobile T-Mobile is offering some significant savings on the new Galaxy Z Flip 7, but the discounts will depend on which plan you have. If you're trading in an old phone, you'll get up to $1,100 off if you're on a Go5G Plus or Experience More plan, scoring you the basic model for free. Those on a Go5G Next or Experience Beyond plan can save up to $1,000 and those on most other plans can save up to $500. Those adding a new line will can also get this phone for free if they opt for an Experience More or Experience Beyond plan. You'll save $800 if you opt for a a Go5G Plus plan or $600 for most other plans. You'll also get a free pair of Samsung Buds 3 Pro with the purchase. Details Free with new line or trade-in See at T-Mobile Close Boost Mobile Those on Boost Mobile's $65 per month Infinite Access for Galaxy plan will automatically save $1,100 on the new Z Flip 7, which means you can pick it up for free. You can also pay for the entire phone upfront, which scores you a free year of service. Just note that only the blue shadow color variant is available. Details Free with select plans See at Boost Mobile Close Best Galaxy Z Flip 7 FE deals Samsung Samsung has also knocked $50 off the starting price for the more affordable Galaxy Z Flip 7 FE, and you can save up to $500 with an eligible trade-in. The latest Apple and Samsung phones will get you the full discount, though devices from Google, Motorola and other brands are also accepted. Details Save $50, up to $500 with trade-in See at Samsung Close Amazon You'll get a free $100 gift card with the purchase if you order the new Galaxy Z Flip 7 FE through Amazon. The online retailer also has its own trade-in program where you can save up to $725 with an eligible trade-in. But unlike the standard Z Flip 7, these two offer can't be combined for the FE model. Details Free $100 gift card or up to $725 off with trade-in See at Amazon Close Best Buy The Galaxy Z Flip 7 FE also comes with a $100 gift card when you purchase the phone through Best Buy. Plus, you can save up to $550 when you also trade-in an old phone from Samsung, Apple, Google or other brand. Activating the phone through Verizon also knocks another $100 off the price. Details Free $100 gift card, up to $550 off with trade-in See at Best Buy Close Boost Mobile Like the standard Galaxy Z Flip 7, you can pick up the Z Flip 7 FE for free if you're on Boost Mobile's $65 per month Infinite Access for Galaxy plan. Though considering you can also get the more advanced model for free with this offer, there's really no reason not to upgrade. You can also pay for the entire phone upfront, which scores you a free year of service. Also note that only the black color variant is available. Details Free with select plans See at Boost Mobile Close How much does the Galaxy Z Flip 7 cost? The starting prices for all configurations of the Galaxy Z Flip 7 in the US, before any trade-ins or discounts, are as follows: Samsung Galaxy Z Flip 7 FE (128GB): $900 Samsung Galaxy Z Flip 7 FE (256GB): $960 Samsung Galaxy Z Flip 7 (256GB): $1,100 Samsung Galaxy Z Flip 7 (512GB): $1,220 What colors does the Galaxy Z Flip 7 come in? There are three basic colors for the Galaxy Z Flip 7, which include jet black, blue shadow and coral red. An exclusive mint green variant is also available, but only when you order online through Samsung. The Galaxy Z Flip 7 FE is only available in black or white, and there aren't any Samsung-exclusive variants.

S&P 500's Banner Rally Faces Off With Worst Two Months of Year
S&P 500's Banner Rally Faces Off With Worst Two Months of Year

Bloomberg

time8 minutes ago

  • Bloomberg

S&P 500's Banner Rally Faces Off With Worst Two Months of Year

The S&P 500 Index, coming off its best streak of gains since 2020, is about to enter what has historically been its toughest stretch of the year. Over the past three decades, the benchmark has performed the worst in August and September, losing 0.7% on average in each month, compared with a 1.1% gain on average across other months, data compiled by Bloomberg show. Analysts attribute the pattern in part to money managers' tendency to reassess their portfolios around this time of year.

Global Stock Rally Faces Fed Reality Check After Trade Optimism
Global Stock Rally Faces Fed Reality Check After Trade Optimism

Bloomberg

time8 minutes ago

  • Bloomberg

Global Stock Rally Faces Fed Reality Check After Trade Optimism

For global stocks riding the wave of trade optimism, the Federal Reserve 's interest-rate announcement on Wednesday is likely to serve as a timely reminder that monetary policy still presents a risk to the rally. After recovering from the 'Liberation Day' selloff in early April, the MSCI All-Country World Index is tracking a fourth straight month of gains as signs of progress in US trade negotiations overshadowed slowing earnings growth and elevated valuations.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store