3 signs your cloud security setup isn’t enough to stop a live attack


Last year, 43% of UK businesses said they’d sustained a cyber breach or attack, according to the government’s Cyber Security Breaches Survey. That’s about 612,000 firms. Company size changed the picture fast: 65% of medium businesses were hit, along with 69% of large ones. Once a business starts adding staff, suppliers, and cloud accounts, the original security plan can quickly become insufficient.

Businesses usually start in the right place. They scan for exposed systems, outdated software, unsafe settings, and excessive permissions. Still, your tools mainly tell you where an attacker could get in. They don’t always show whether somebody is already moving through the system.

Wiz is one platform addressing that problem. It earned much of its reputation by mapping cloud assets, vulnerabilities, identities, and routes to sensitive data, and that visibility remains its foundation. Wiz Sensor extends that same foundation into production workloads, watching live activity and connecting what it sees back to the identity, exposure, and data context Wiz already holds in its Security Graph, so a suspicious connection arrives with the context needed to act on it.

That combination matters because a list of what could go wrong is different from knowing what’s happening right now.

Key takeaways

  • A stolen login can cause plenty of damage before the morning scan arrives. Ask how the system spots unusual file access, strange connections, and movement between workloads.
  • “Continuous monitoring” needs a proper explanation. Some vendors mean regular checks for bad settings. You may be expecting live visibility into processes, connections, file changes, and user behaviour. Get the exact scope in writing.
  • A suspicious connection gains much more meaning when you can see the exposed workload it came from in runtime, the identity behind it, and the sensitive data sitting nearby. Wiz Sensor, Aqua, and Orca each take a different approach to surfacing that context.
  • New cloud accounts, test environments, contractors, AI tools, and supplier access permissions can create challenging gaps. Check what has been discovered, what has runtime protection, and what is still relying on hope.

1. You’ve never tested what happens during a real attack

Plenty of businesses can produce a vulnerability report. Far fewer can explain what happens five minutes after somebody uses one of those weaknesses – or can see when that’s actually happening.

Start with something like a stolen login. It’s a more believable test than the movie version of a hacker battering through a firewall. An attacker using a real employee or contractor account may look perfectly ordinary at first. The useful questions come next. Why is that person opening a production database at 2 a.m.? Why are they pulling files they’ve never touched before? Can anyone shut the session down before breakfast?

Aqua shows what deeper runtime control can look like. Its platform monitors activity inside live containers, virtual machines, Kubernetes clusters and serverless workloads. Drift prevention can stop an unexpected executable from running when it wasn’t part of the approved container image. That’s useful.

Still, blocking technology won’t decide who calls the insurer, nor will it decide whether a digital service must be taken offline or how long the business waits before telling affected clients.

Ask your provider:

  • Can your scans immediately pick up when an internet-facing resource starts behaving strangely?
  • Can your system kill active sessions and revoke tokens immediately?
  • Which responses happen automatically?
  • Who has authority to isolate a workload after hours?
  • When was the last exercise, and what broke?

2. Your security only runs on a schedule, not all the time

It’s worth being suspicious when a provider says “continuous monitoring” and leaves it there. Continuous in what sense? A tool can keep refreshing its list of missing patches and dangerous settings without watching a single process running inside the workload.

That makes a difference once somebody gets in. An intruder can move into other systems within minutes, then stay hidden for two weeks. Tomorrow morning’s scan is useless when the trouble started tonight.

The UK Cyber Security Breaches Survey figures make the same problem feel less remote. Among businesses that identified an attack, 29% said it happened at least weekly. It’s not a good idea to accept protection built around occasional check-ins against activity arriving that often.

Wiz Sensor watches workload execution, file changes and live connections. Wiz Defend combines those signals with cloud and SaaS logs, then pulls in the wider context already held in the Security Graph. That context is the most useful bit. An odd connection means more when the same screen shows that it came from an exposed container with a serious vulnerability and leads toward sensitive storage.

Ask your provider:

  • What exactly does “continuous” cover?
  • Can it see processes, file changes and live network activity?
  • Which events trigger blocking rather than an alert?
  • Can it show every workload missing runtime coverage?
  • Does the quoted package include the required agents and response features?

3. You’ve added systems or staff since your last review

Growth challenges old security assumptions rather quickly. A company hires developers, opens another cloud account, connects a payroll platform and gives a partner vendor temporary access. Six months later, nobody can say with confidence whether every new system appears in the security console.

The gap is less likely to show up as one dramatic mistake. It’s a test environment nobody decommissioned, a contractor’s access that was never revoked, a new cloud account spun up for a single project and then forgotten.

These don’t get flagged as a security incident on their own. They just sit there, unmonitored, until something else in the environment gets compromised and an attacker finds a path through a neglected system.

Orca is a useful benchmark for coverage. Its SideScanning technology discovers workloads across connected cloud accounts without installing an agent on each one. Orca has added an eBPF-based sensor for process-level runtime monitoring across Linux, Windows and Kubernetes. The purchasing question is where that deeper sensor coverage has actually been deployed.

Ask your provider:

  • Are new cloud accounts and workloads discovered automatically?
  • How long does discovery take?
  • Which visible assets lack runtime coverage?
  • Are development, backup and temporary environments included?
  • Can you see every unsupported system and accepted gap in writing?

Closing thoughts

Security bought for a ten-person company can do exactly what it was designed to do and still leave a 200-person company exposed. More accounts have appeared. More data has moved into the cloud. Suppliers now touch systems they didn’t know existed two years ago.

That doesn’t mean the answer is the biggest product bundle on the market. Start with three awkward but mission-critical questions: Have we tested the response? Are important workloads watched while they run? Can we prove every new asset is covered?

Finding the weak spot is useful, but catching someone using it is where the real test starts.

FAQs

What’s the difference between spotting a risk and stopping an attack?

A scanner tells you where trouble could start, such as an exposed database or an overpowered account. Runtime protection watches what happens after someone gets in. Depending on the product, it can cut a connection, kill a process, or isolate the affected workload before the damage spreads.

How often should a growing business review its cloud security?

Once a year is the bare minimum, but ideally it’s best to review things sooner after a cloud migration, acquisition, large hiring push, new AI project, or major application launch. Any change that adds users, data, suppliers, or infrastructure can leave the old coverage map badly out of date, and ideally, runtime scans should be running on an ongoing basis.

Will cloud security automatically cover new systems?

Sometimes an asset might appear unexpectedly. That still doesn’t prove it has live protection. Agentless tools can discover new workloads quickly, while sensors, logging, and response rules may need separate setup. Ask your provider to show which assets are visible and which ones are actually being watched.

What should I ask a vendor about real-time protection?

Ask what the platform can see while a workload is running and what it blocks without human approval. It’s also worth asking who deals with alerts overnight.

Read more

How to use a Web Application Firewall to keep hackers out of your company’s systems – Myra Sugg explains what a Web Application Firewall (WAF) is, why your business needs one and how they’re different to other firewalls

How a major glitch by Companies House revealed an uncomfortable truth about business data – The Companies House incident highlighted the outdated way business data is handled in a time where fraud is rife. This is how we overcome it



Source link