---
title: Security Misconfigurations a Leading Cause of Cloud Data Breaches
description: Eight in 10 companies across the United States have experienced a data breach made possible by cloud misconfigurations, according to new research by IDC.
image: https://businessinsights.bitdefender.com/hubfs/caspar-camille-rubin-fPkvU7RDmCo-unsplash.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

 By [**Filip Truta**](https://businessinsights.bitdefender.com/author/filip-truta) / Jun 05, 2020

# Security Misconfigurations a Leading Cause of Cloud Data Breaches

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/security-misconfigurations-a-leading-cause-of-cloud-data-breaches&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/security-misconfigurations-a-leading-cause-of-cloud-data-breaches&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/security-misconfigurations-a-leading-cause-of-cloud-data-breaches&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/security-misconfigurations-a-leading-cause-of-cloud-data-breaches&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/security-misconfigurations-a-leading-cause-of-cloud-data-breaches&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/security-misconfigurations-a-leading-cause-of-cloud-data-breaches&utm_medium=social&utm_source=facebook)

Eight in 10 companies across the United States have experienced a data breach made possible by cloud misconfigurations, according to new research by IDC.

Misconfigured safeguards and protocols are a leading cause of data breaches today. A [survey](https://www.businesswire.com/news/home/20200603005175/en/Ermetic-Reports-80-Companies-Experienced-Cloud-Data) of 300 senior IT decision makers by IDC, on behalf of Ermetic, corroborates findings by Bitdefender researchers around the IT misconfigurations most leveraged by cybercriminals today.

According to the 300 CISOs that participated in the survey, **security misconfiguration** is a top concern associated with cloud production environments, as cited by 67% of respondents. Next in line was **lack of adequate visibility into access settings and activities** (64%), followed by **identity and access management (IAM) permission errors** (61%). One in 10 respondents also reported they are unable to identify excessive access to sensitive data in IaaS/PaaS environments.

[**An analysis by Bitdefender**](https://businessinsights.bitdefender.com/top-5-endpoint-misconfigurations-that-open-security-gaps-whitepaper?hsLang=en-us) of the security misconfigurations most frequently leveraged by bad actors revealed that configuration errors related to accounts, password storage and password management are the most common individual endpoint misconfigurations.

Of the most common categories of endpoint misconfigurations reported by our engines, Internet Settings is by far the most error-riddled category, with a combined share of 73.1%. Passwords & Accounts take second place with 13.8% and Microsoft Apps & Components rank third, at 13.1%.

“Driven by the dynamic and on-demand nature of public cloud infrastructure deployments, users and applications often accumulate access permissions beyond what is necessary for their legitimate needs,” reads the Ermetic-sponsored report. “Excessive permissions may go unnoticed as they are often granted by default when a new resource or service is added to the cloud environment. These are a primary target for attackers as they can be used for malicious activities such as stealing sensitive data, delivering malware or causing damage such as disrupting critical processes and business operations.”

Traditional endpoint protection platforms can’t assess risk associated with misconfiguration, while security teams are overwhelmed with reactive, repetitive tasks, such as vulnerability management, incident triage, and patching. Bitdefender puts risk analytics at the core of its GravityZone endpoint protection platform, enabling administrators to reduce the attack surface and limiting potential compromise while providing visibility into risks associated with misconfiguration.

Bitdefender GravityZone provides endpoint risk management, risk analytics, protection and EDR, all through a common agent and console. Learn more [**here**](https://businessresources.bitdefender.com/esg-report?utm_campaign=msp-risk-management&utm_source=white-paper&hsLang=en-us).

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/misconfigurations-an-open-door-to-compromise-and-data-breaches?hsLang=en-us>

### [Misconfigurations: An Open Door to Compromise and Data Breaches](https://businessinsights.bitdefender.com/misconfigurations-an-open-door-to-compromise-and-data-breaches?hsLang=en-us)

<https://businessinsights.bitdefender.com/10-months-into-covid-19-businesses-still-playing-catch-up-with-endpoint-security-in-hybrid-work-environments?hsLang=en-us>

### [10 Months into COVID-19, Businesses Still Playing Catch-Up with Endpoint Security in Hybrid Work Environments](https://businessinsights.bitdefender.com/10-months-into-covid-19-businesses-still-playing-catch-up-with-endpoint-security-in-hybrid-work-environments?hsLang=en-us)

<https://businessinsights.bitdefender.com/mishandling-cyber-risk-management-is-risky-business?hsLang=en-us>

### [Mishandling Cyber Risk Management is Risky Business](https://businessinsights.bitdefender.com/mishandling-cyber-risk-management-is-risky-business?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Filip Truta",
    "url" : "https://businessinsights.bitdefender.com/author/filip-truta"
  },
  "dateModified" : "2020-06-05T05:33:35.003Z",
  "datePublished" : "2020-06-05T05:33:35.000Z",
  "headline" : "Security Misconfigurations a Leading Cause of Cloud Data Breaches",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/caspar-camille-rubin-fPkvU7RDmCo-unsplash.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/security-misconfigurations-a-leading-cause-of-cloud-data-breaches",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```