3 Insights about Enterprise Cloud Security in 2016

Mar 22, 2016 | Cloud, Security

Featured article by Sarah Patrick, Analyst at Clutch

The public’s perception of the Cloud seems to change constantly. In light of high-profile security breaches at Target (2013) and Home Depot (2014) and in the iCloud (2014), many users raised concerns about privacy and data security.

Even with recent technological advances, thoughts on cloud security remain mixed. In fact, while 64 percent of medium and large enterprises believe cloud infrastructure is more secure than legacy systems, 31 percent also deem security the most prominent challenge they encountered in 2015, according to a study on the state of cloud security in the enterprise market.

With more than 90 percent of businesses using cloud infrastructure, how do IT professionals combat lingering concerns about privacy, data safety, and security infractions?

Overall, enterprise impressions of cloud security are shaped by three factors.

1. Security is One of Many Benefits Cloud Infrastructure Offers Businesses

As cloud infrastructure plays an ever more prominent role in the enterprise market, IT professionals are charged with keeping the increasing amounts of data stored on the Cloud secure.

Cloud security systems’ robust monitoring and response systems aid this task, which explains why nearly 50 percent of enterprises believe security is a leading benefit of cloud computing.

Clutch_1

“Using the Cloud is like putting your money in the bank versus under your mattress. Even though your money, or data, is not on-premise, the bank will do a much better job of protecting it because it has vaults and security cameras — more than what a single enterprise company can do.” — David Linthicum, Senior Vice President, Cloud Technology Partners

Cloud infrastructure provides not only access to top-of-the-line data centers that are staffed by a team of expert IT professionals but also proactive monitoring and response mechanisms.

These include,

* Video surveillance

* Biometric scanning

* Patrol guards

* Equipment stored in locked cages

* 24/7 threat monitoring and intrusion detection systems

Overall, companies that migrate to the cloud become more secure.

“A cloud vendor will have good, if not better, security and support for security than any one company. Because of this, moving to the Cloud would increase the company’s overall internal security, as opposed to relying on its IT department only.” – Duane Tharp, Vice President of Technical Sales and Services, Cloud-Elements

2. Enterprises Prioritize Security to Head Off Potential Data Breaches

Despite touting cloud security as a leading benefit of cloud computing, enterprises indicate that security is also the challenge they encounter most frequently, according to the same study from business-to-business research firm Clutch.

problems - enterprise cloud'16 - security

How can security both benefit and challenge enterprises?

One explanation posits that migrating to cloud infrastructure increases the visibility of cracks in data security and in turn increases the demand for better security measures.

“The big struggle for IT teams arises when businesses demand higher and higher levels of transparency. Because of this, the IT team needs to build new security policies to create the impression that a business is investing a lot more resources in security. Truthfully though, a company should already have had these security measures in place.” – Jason Reichl, CEO, Go Nimbly

3. To Combat Security Concerns, Enterprises Implement Additional Security Measures

The implementation of additional cloud security safeguards is a requisite step for enterprises. Cloud infrastructure is not secure enough on its own, out-of-the-box.

“A common mistake is that companies think the Cloud is secure enough out-of-the-box. But, in reality, the Cloud has two major components: the backend cloud vendor infrastructure, which is secured by the vendor, and the company-specific cloud infrastructure, which must be secured     by the company.” – Jose Alvarez, Director of IT Infrastructure, Auxis

What security measures do enterprises invest in the most?

The most common defense enterprises invest in is encryption.

Encryption is important because the most popular cloud storage services only encrypt data on their end: if it’s not their equipment, it’s not their problem.

In short, enterprises as a whole believe that the Cloud is more secure than legacy systems, but it is not impenetrable. Extra security measures are imperative to ensure a smooth transition to cloud infrastructure without compromising mission critical data.

Sarah Patrick_Headshot

Sarah is an analyst at Clutch. As a member of the marketing team, she conducts research that aims to help consumers select agencies and firms and use IT services and software that enhance their business. Clutch is a Washington, DC-based research, reviews, and ratings platform for B2B. It identifies leading software and professional services firms that deliver results for their clients.

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more