Malicious insiders could hurt cloud computing
The future will see many businesses asking questions about how their data is secured in the cloud.
A Symantec security expert has warned companies offering services in the cloud that malicious insiders could render security controls useless.
Guy Bunker, chief scientist at Symantec, said that cloud service administrators had "god-like status" when it came to accessing confidential data.
He said that there were already low-key legal cases being taken against cloud service providers, where administrators had access to data.
Bunker said: "This isn't just cases in the cloud we've seen this in enterprises where somebody within the organisation who has access to the data has decided to take it and sell it on to somebody else."
Bunker was speaking at a Symantec-held event about how businesses should cope with cloud computing in terms of security.
The Symantec expert also said that enterprises often didn't know what their sensitive information was or even where it was, and that the cloud compounded the issue.
He said: "The reality moving forward in two to three years is that there will be a much shorter relationship [between businesses and cloud computing vendors]."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He added: "What happens to the data that you put out there and process? Apparently there's no assured delete has the data actually been deleted from the cloud?"
Other speakers suggested that there was no possible international regulatory solution when it came to securing cloud computing, and that the best hope was for businesses to organise a technical standards body.
John Carr, secretary of the UK's Children Charity Coalition for Internet Safety, suggested that there should be a kitemark' - a technical standard for cloud computing.
He said: "Only the businesses can do that. I seriously doubt there is any governmental institution that can get even close."
- 
What does modern security success look like for financial services?Sponsored As financial institutions grapple with evolving cyber threats, intensifying regulations, and the limitations of ageing IT infrastructure, the need for a resilient and forward-thinking security strategy has never been greater
 - 
Yes, legal AI. But what can you actually do with it? Let’s take a look…Sponsored Legal AI is a knowledge multiplier that can accelerate research, sharpen insights, and organize information, provided legal teams have confidence in its transparent and auditable application
 
- 
Power stations under attack from long-running hacking campaignNews Dragonfly threat group is ramping up activities, say researchers
 - 
Symantec profits surge as firms prop up their cyber defencesNews The company also announced plans to sell its web certificate business
 - 
Symantec to pay $4.65 billion to acquire Blue CoatNews Greg Clark to become Symantec CEO, promising new cloud security
 - 
Symantec ditches reseller guilty of scamming PC usersNews Silurian told people they had malware, then sold them Norton Antivirus for $249
 - 
NATO builds up cyber alliance with Symantec tie-inNews Military industrial link up to fight cyber attacks
 - 
Junk emails fall to their lowest rate in 12 yearsNews Spam is dropping, says Symantec, but other malware threats are on the rise
 - 
Kaspersky: "We have never been asked to whitelist malware"News A company blog has revealed neither government nor any other entity has asked it to stop detecting malware
 - 
Symantec confirms split into separate security & storage entitiesNews Storage and security will be separated as Symantec tries to boost sales in both