Jul. 31, 2024

Cloud Security Priorities: Stopping the Proliferation of Super Users and Zombie IDs

Companies’ clouds present much more complex risks than their static old computer networks. Clouds teem with unmonitored users holding top-level control, two recent studies found. One report found that 50 percent of Microsoft customers’ 209 million cloud identities (many not human) held super administrator access to “all permissions and all resources” across the customer company’s cloud – a mind-boggling situation that could increase “the blast radius” of any attacks. This article presents key findings from Microsoft’s and Sonraí Security’s studies, explains the operational binds exacerbating cloud security risks and offers measures that companies can take to harden security around cloud identity and authentication. See “Six Steps for Improving Cloud Security From CSRB’s Report on Microsoft Intrusion” (Jun. 12, 2024).

How Hedge Funds Are Approaching AI Use

Financial services firms’ use of Generative AI (Gen AI) tools has seen an uptick. Successful integration of AI tools requires proper investment in technology and people. The Alternative Investment Management Association (AIMA) recently asked more than 150 hedge fund managers about their adoption of Gen AI, as well as its potential benefits and challenges, including management of data security and privacy issues. The survey’s resulting report “is a useful strategic roadmap to help asset management firms engage with and harness the power of this evolving technology,” AIMA managing director Tom Kehoe told the Cybersecurity Law Report. This article synthesizes AIMA’s key findings, with additional insights from Kehoe. See our two-part series on the practicalities of AI governance: “AI Governance Gets Real: Tips From a Chat Platform on Building a Program” (Feb. 1, 2023), and “AI Governance Gets Real: Core Compliance Strategies” (Feb. 8, 2023).