Shadow IT remains a growing problem
This quarter, the average number of cloud services in use per enterprise in EMEA rose to 845, up from 824 the previous quarter. Of those services in use, roughly 95 per cent are not enterprise ready. Shadow IT even affects sanctioned cloud services, as half of all users of sanctioned cloud storage services like Box or Dropbox also have personal instances of the same cloud service, which can make detection and mitigation of activities like data exfiltration more difficult.
Majority of cloud services still not GDPR ready
In 2016, Netskope created a unique methodology to score cloud services on GDPR compliance, including evaluating those services’ data retention policies, privacy features, and data protection regimens and normalising scores to a 1-100 scale. Services with a score above 70 are considered ready for GDPR compliance. This report found that 66 per cent of all cloud services do not meet this threshold, meaning they lack proper residency, privacy, and security controls to be considered compliant with the requirements of the GDPR, or near enough to be ready to comply by the May 2018 deadline. While this percentage has decreased from the 75 per cent reported in the June 2016 Netskope Cloud Report, enterprise cloud services have a long way to go in order to be ready over the next year-and-a-half. Drilling further into specific measures, 82 per cent of cloud services do not encrypt data at rest, 66 per cent do not specify that their customers own the data in their terms of service, and 42 per cent do not allow admins to enforce password controls.
“Until very recently, organisations had to take an all-or-nothing approach to allowing cloud services. If they sanctioned a cloud storage service for corporate use, they also needed to accept any additional personal instances of that cloud storage service or block the service entirely,” said Sanjay Beri, founder and CEO, Netskope. “As our customers make cloud services a strategic advantage for their businesses, when it comes to governing and securing those services, they are realising granular policies can ensure that sensitive data does not leak from the sanctioned instance of a corporate cloud service to an unsanctioned one.”
Additional findings
? Slack makes its way up the top 20 list, but Microsoft maintains top spot: Last quarter, Slack cracked the top 20 list for the first time, and shows no sign of slowing down, reaching the 16th position this quarter. Newcomers like ServiceNow also cracked the top 20, but Microsoft Office 365 continues to reign supreme, with Microsoft Office 365 OneDrive for Business and Office 365 Outlook.com taking the number 1 and 2 spots, respectively.
? IaaS on the rise: More than 90 per cent of Netskope customers use IaaS services like Amazon Web Services, Microsoft Azure, and Google Cloud Platform, with enterprises using an average of 4 IaaS services. This includes both sanctioned and unsanctioned services, across services like Amazon, Microsoft, Google, CloudShare, Linode, Rackspace, and more.
? Ransomware a larger threat than macros and mobile attacks: For the first time, Netskope analysed ransomware as a malware type, finding 7.4 per cent of all enterprise threats were ransomware. Other category percentages are as follows: 43.2 per cent of detections were backdoors, adware 9.8 per cent, Javascript malware 8.1 per cent, Mac 6.7 per cent, Microsoft Office macros 5.3 per cent, mobile 5.2 per cent, and other types 14.3 per cent. More than a quarter of the malware was shared with others (both internally and externally), a drop from last quarter’s 55.9 per cent. This may be attributable to the fact that Netskope customers are proactively taking steps to address cloud malware risks.
Average cloud services per enterprise by category
This quarter, the average amount of cloud services per enterprise across EMEA reached 845, compared to 824 last quarter. More than 94.8 per cent of these are not enterprise-ready, earning a rating of “medium” or below in the Netskope Cloud Confidence IndexTM (CCI) scoring system, meaning they lack key functionalities such as security, audit and certification, service-level agreement, legal, privacy, financial viability, and vulnerability remediation.
The technology & IT services industry has the highest number of services in use — 856 — followed by the healthcare & life sciences industry with an average of 844. Marketing, human resources and collaboration apps are the most popular apps, though more than 90 per cent are not enterprise ready.