42 Rue Broca, 75005 Paris, France
Internal Threats and the Misconception of Cloud Security
As specialists in cloud data storage, we often observe a common misconception: many believe that data in the cloud is automatically secure.
The cloud is indeed a powerful solution — it offers flexibility, accessibility, and scalability. However, to fully leverage its benefits, it is essential to understand the shared responsibilities regarding security and potential risks, particularly those related to internal threats and human errors.
The Reality of Internal Threats
When we talk about cybersecurity, we often think of hackers, malware, or DDoS attacks. Yet, internal threats — whether intentional or accidental — are just as significant. According to the ENISA Threat Landscape 2024 report, approximately 13% of cybersecurity incidents in 2023-2024 were linked to human errors. These errors can occur in various ways: imperfect configuration, a sensitive file mistakenly sent, or the use of an overly simple password.
Furthermore, Gartner predicts that by 2025, 99% of cloud security failures will result from human errors or user actions, not from vendor weaknesses. This finding underscores the importance of remaining vigilant and proactive against these risks.
Why the Cloud Is Not Automatically Secure
It is understandable to think that cloud providers handle everything. After all, they highlight their robust infrastructures, certifications, and cutting-edge technologies. However, these providers operate under a shared responsibility model. This means they protect their infrastructure, but managing access, configurations, and user awareness falls under our responsibility.
It is in this context that internal threats play a crucial role. Here are some common examples:
- Misconfigurations: Incorrectly configured settings can unintentionally make data accessible. ENISA reports that these errors are a frequent cause of data leaks.
- Abusive Access: An employee with excessive privileges can, even unintentionally, cause considerable damage.
- Social Engineering: Cybercriminals often exploit user trust to gain access to sensitive information. A well-designed phishing attempt can be enough.
To minimize risks, here are some practices we strongly recommend:
- Raise Team Awareness: Organize training sessions to help employees identify phishing attempts and adopt best practices for data security.
- Continuous Monitoring: Invest in tools capable of detecting unusual activities, such as unauthorized access attempts.
- Apply the Principle of Least Privilege: Ensure that each user has only the rights necessary for their work, which limits risks in case of error.
- Regularly Audit Configurations: Frequently check cloud settings to prevent accidental data exposure.
Shared Cloud Security
The cloud is an extraordinary technology that transforms how we work and store our data. However, it is important to remember that its security relies on a balance between advanced technology and good human practices. By investing in awareness, monitoring, and rigorous management, we can fully enjoy the benefits of the cloud while minimizing risks.
Let us never forget that in the cloud, as elsewhere, security begins with us.
Here are the sources used for the text on the impact of human errors in IT:
- 95% of cybersecurity breaches are due to human error
According to a World Economic Forum study, 95% of cybersecurity incidents result from human errors, highlighting the importance of training and awareness.
Source - Global IT outage caused by faulty CrowdStrike update
In July 2024, a faulty update to CrowdStrike’s Falcon Sensor software caused a global outage, affecting approximately 8.5 million Windows devices.
Source - Human errors and ransomware dominate security breaches in France
Verizon’s 2024 DBIR report reveals that human errors and ransomware are the main causes of security breaches in France.
Source - Through 2025, 99% of cloud security failures will be the customer’s fault.
Source - According to CIRAS, the Cybersecurity Incident Reporting and Analysis System, 13% of the reported incidents in 2023 and 2024 are ‘human errors.
- Source

