The Toxic Cloud Trilogy
DataQuest|December 2024
As Indian organisations increasingly migrate to the cloud, they face a complex and evolving security landscape. Ari Eitan, Director of Research at Tenable, highlights the "Toxic Cloud Trilogy" - a convergence of publicly exposed workloads, critical vulnerabilities, and over-privileged identities - as a critical threat to Indian organisations. In this interview, Eitan discusses the unique vulnerabilities of cloud environments, systemic issues preventing organisations from fully addressing weaknesses and practical steps Indian organisations can take to mitigate these risks.
Aanchal Ghatak
The Toxic Cloud Trilogy

Could you explain what the “toxic cloud trilogy” entails and why it poses such a critical threat to indian organisations?

The toxic cloud trilogy is a convergence of publicly exposed workloads, critical vulnerabilities, and overprivileged identities. Separately, each of these factors poses a security risk. Together, they create a scenario that warrants attention.

In the cloud, publicly exposed workloads can function as beacons, accessible from the internet. Such exposure, even when unintentional, allows cybercriminals to identify potential entry points with ease. Add unpatched vulnerabilities into the mix, and the risk is amplified. These gaps create a straightforward exploitation pathway.

The third factor – over-privileged identities – further raises the stakes. When access permissions exceed what is necessary, attackers can move more freely across systems, accessing data and services with fewer barriers. This toxic cloud trilogy turns what might have been a limited security issue into a broader operational concern, allowing attackers to extend their reach if they gain access.

Many organisations continue to face challenges in securing cloud data effectively. What specific aspects of the cloud make it uniquely vulnerable, particularly in complex environments?

It’s much easier to store data in the cloud because every time organisations want to store new data, they can increase cloud storage with the click of a button. With data storage becoming easier, organisations are motivated to store more data that they can leverage to advance their AI capabilities. Over the last few years, LLMs have become more accessible, introducing new challenges.

This story is from the {{IssueName}} edition of {{MagazineName}}.

Start your 7-day Magzter GOLD free trial to access thousands of curated premium stories, and 9,000+ magazines and newspapers.

This story is from the {{IssueName}} edition of {{MagazineName}}.

Start your 7-day Magzter GOLD free trial to access thousands of curated premium stories, and 9,000+ magazines and newspapers.

MORE STORIES FROM DATAQUESTView all
Rewriting Insurance with Data and Foresight: Lessons from Pramerica's CTO
DataQuest

Rewriting Insurance with Data and Foresight: Lessons from Pramerica's CTO

As insurance companies pivot from operational reliance on technology to embedding it as a core strategy, Pramerica Life Insurance leads by example. CTO Sunil Jain discusses how innovations in AI, cloud platforms, and data frameworks are not only solving current challenges but shaping the future of the industry.

time-read
7 mins  |
January 2025
Is AI on Batman's side or on Joker's side?
DataQuest

Is AI on Batman's side or on Joker's side?

Also, spoiler alert. Your body-guard is not your body double. Leave the couch. In an age where Cyber-insurers also look at security maturity before they undertake new enterprises, where security fatigue is a bitter reality, where the grey-matter of LLMs can easily be conned by benign chatter, and where AI is turning as much into a Robin as into a Harley Quinn - and with equal speed and probability - whose side is AI on? Philippa Cogswell, Managing Partner, Unit 42, Asia Pacific & Japan, Palo Alto Networks helps us unravel these complex plot lines.

time-read
7 mins  |
January 2025
Counting on Quantum - A quick peek inside India's Refrigerator
DataQuest

Counting on Quantum - A quick peek inside India's Refrigerator

The menu of tomorrow's IT courses would be completely changed by what's currently being marinated in quantum computing trays. From cryptography to heavy simulations to huge AI workloads to Cloud. Let’s open the doors of this cold, but busy, kitchen area for a minute to get a sense of what Indian ice-boxes are up to.

time-read
6 mins  |
January 2025
Digital Twins: The Blueprint Becomes the Blue-eyed Boy
DataQuest

Digital Twins: The Blueprint Becomes the Blue-eyed Boy

Ever wondered why people in offices are seen more around the photocopier or printer rather than their computers?

time-read
9 mins  |
January 2025
The Cloud Advantage: Infor's CloudFueled Growth in Asia-Pacific
DataQuest

The Cloud Advantage: Infor's CloudFueled Growth in Asia-Pacific

Senior VP Terry Smagh highlights Infor’s growth, cloud adoption, and AIdriven operations. With major investments in India, including an R&D hub and upcoming data center, Infor leads in innovation, efficiency, and sustainability.

time-read
3 mins  |
January 2025
How Onix is Making AI Accessible to All Business Teams
DataQuest

How Onix is Making AI Accessible to All Business Teams

Niraj Kumar, CTO of Onix, shares his extensive experience in IT and cloud technology to explore how the convergence of data, cloud infrastructure, and AIL is driving digital transformation. He discusses the critical role of data context, ethical practices, and security in ensuring that AI delivers its full potential across all levels of an organization.

time-read
6 mins  |
January 2025
Arka Fincap Redefining Finance Through Technology
DataQuest

Arka Fincap Redefining Finance Through Technology

Arka Fincap has embraced technology to streamline its operations and enhance customer experiences. By utilizing tools such as low-code platforms, automation, and cloud infrastructure, the company has significantly reduced processing times and operational costs. This approach has enabled efficient loan processing, seamless fintech integrations, and data-driven decision-making. Arka's journey highlights the role of technology in modernizing financial services while balancing scalability, compliance, and customer-centricity.

time-read
5 mins  |
January 2025
AWS is assuring that the AI that's being built is reliable, responsible and trustworthy
DataQuest

AWS is assuring that the AI that's being built is reliable, responsible and trustworthy

At AWS re:Invent 2024, Las Vegas Dr. Angela Shippy, Senior Physician Executive at AWS, discusses how technology is reshaping healthcare-from generative AI to predictive analytics and secure cloud solutions.

time-read
5 mins  |
January 2025
AI in Multiplexes, the 'cold open' scene is here
DataQuest

AI in Multiplexes, the 'cold open' scene is here

Would AI remove all the walls in, and around, Cinema; or would it create very personalized boxes for every viewer? Here's a peek. No Spoilers here. But some Stingers for sure.

time-read
5 mins  |
January 2025
e-Red Tape, virtual CAs and wait-and-watch hoops - a look at India's digital Selfie
DataQuest

e-Red Tape, virtual CAs and wait-and-watch hoops - a look at India's digital Selfie

Bertram D’Souza, Chief Product Innovation Officer, Protean eGov Technologies Ltd. helps us to unpack how India’s digital stacks, digital goods, fast interfaces, real-time financial lanes and tech-driven tax administration shine and where they do/can falter if we ignore some tough, but practical, questions.

time-read
6 mins  |
January 2025