Palo Alto Networks white logo Palo Alto Networks logo
  • Introduction
  • Critical Industries
  • Key Findings
  • Outcomes
  • Threat Report
  • Read the report
CLOUD THREAT RESEARCH

Unit 42 Cloud Threat Report, 1H 2021

COVID-19’s global impact on security posture
Read the report
Introduction

Investment in cloud security
must match cloud spend

In the early days of the COVID-19 pandemic, there was a rapid uptick in demand for cloud services. Utilizing data pulled from our global array of sensors, our elite cloud threat researchers found a correlation: Organizations globally increased their cloud workloads by more than 20%, leading to an explosion of security incidents. Our research shows that cloud security programs for organizations globally are still in their infancy when it comes to security automation (i.e., DevSecOps and shift left). We concluded that rapid cloud scale and complexity without automated security controls embedded across the entire development pipeline are a toxic combination.

matt signature Matthew Chiodi
Chief Security Officer, Public Cloud
Watch the video
Get the infographic
COVID-19 critical industries suffer spike in security incidents

Organizations expanded their cloud workload deployments following the onset of the pandemic, but they also saw more cloud security incidents. Such incidents in the retail, manufacturing and government industries rose by 402%, 230% and 205%, respectively. These industries were among those facing the greatest pressures to adapt and scale in the face of the pandemic – retailers for basic necessities, and manufacturing and government for COVID-19 supplies and aid.

cloud growth vs cloud security incidents
KEY FINDINGS

Cloud security lags behind cloud adoption

Why it Matters: Organizations were able to quickly move more workloads to the cloud in response to the COVID-19 global pandemic, but they struggled many months later to automate cloud security and mitigate cloud risks. Our research indicates that cloud security incidents increased by an astounding 188% in the second quarter of 2020 (April to June).

Cloud growth vs cloud security incidents

Security incidents surge across the board

Why it Matters: Unit 42 research revealed significant increases in a wide variety of security risks during the pandemic, including unencrypted cloud data, exposure of cloud resources to public access, insecure port configurations and more. Taken as a whole, these incidents underscore the failure of most organizations to scale cloud governance and security automation at the same rate that they scaled their cloud workloads.

percentage organizations increased cloud workloads

COVID-19 and data security

Why it Matters: While they stored more data in the cloud, many organizations failed to enforce proper security controls over that data. Our research indicates that 35% of businesses globally permitted their cloud storage resources – many of which contain sensitive data – to be publicly accessible from the internet. While this may be necessary in some cases, it is likely that it usually results from oversights that remain undetected due to a lack of security monitoring and auditing.

security incidents biggest increase

Cloud, COVID-19 and Cryptocurrency

Why it Matters: Unit 42 researchers noted clear correlations between public cloud cryptojacking activity associated with Monero (XMR), a cryptocurrency that can be mined in the cloud, and events related to the pandemic. Mining connections fluctuated in response to pandemic-related health, political and economic developments.

sensitive content cloud storage
Read the report

Cloud security and governance assume new urgency

The key takeaway from our data is clear: Organizations have neglected to invest in the cloud governance and automated security controls necessary to protect their workloads as they move to the cloud. In turn, they have created serious business risks, such as exposing sensitive data to the internet and inviting breaches through sensitive open ports. While our Unit 42® Cloud Threat Reports in 2020 identified similar problems, the numerous crises unleashed by the COVID-19 pandemic have made the situation more widespread and challenging.

Read the report
infographic
THREAT REPORT

Unit 42 Cloud Threat Report, 1H 2021

Read the report
PRISMA CLOUD

See how Prisma Cloud can address the cloud threats in your enterprise.

Learn more
register brochure
Get your copy now!

Please complete reCAPTCHA to enable form submission.

By submitting this form, you agree to our Terms. View our Privacy Statement.

Your guide is ready for download!

We hope you find this research insightful as you work to scale your cloud adoption and security.
Download the report
guide brochure
prisma logo

Executive Summary: Unit 42 Cloud Threat Report, 1H 2021

Read the high level overview of research detailed in the latest Unit 42 cloud threat report.
Executive Summary
prisma logo

Infographic: COVID-19 Amplifies Cloud Security Challenges Around the World

Get a sneak-peek into the latest Unit 42 research to see how the pandemic amplified the cloud security challenges faced across the different industries globally.
Infographic
prisma logo

Explore Prisma Cloud: On Demand Demo

Check out the features and benefits of Prisma Cloud, the industry’s only comprehensive Cloud Native Security Platform.
Explore Prisma Cloud

Get the latest news, invites to events, and threat alerts

By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement.

Products and Services

  • AI-Powered Network Security Platform
  • Secure AI by Design
  • Prisma AIRS
  • AI Access Security
  • Cloud Delivered Security Services
  • Advanced Threat Prevention
  • Advanced URL Filtering
  • Advanced WildFire
  • Advanced DNS Security
  • Enterprise Data Loss Prevention
  • Enterprise IoT Security
  • Medical IoT Security
  • Industrial OT Security
  • SaaS Security
  • Next-Generation Firewalls
  • Hardware Firewalls
  • Software Firewalls
  • Strata Cloud Manager
  • SD-WAN for NGFW
  • PAN-OS
  • Panorama
  • Secure Access Service Edge
  • Prisma SASE
  • Application Acceleration
  • Autonomous Digital Experience Management
  • Enterprise DLP
  • Prisma Access
  • Prisma Access Browser
  • Prisma SD-WAN
  • Remote Browser Isolation
  • SaaS Security
  • AI-Driven Security Operations Platform
  • Cloud Security
  • Cortex Cloud
  • Application Security
  • Cloud Posture Security
  • Cloud Runtime Security
  • Prisma Cloud
  • AI-Driven SOC
  • Cortex XSIAM
  • Cortex XDR
  • Cortex XSOAR
  • Cortex Xpanse
  • Unit 42 Managed Detection & Response
  • Managed XSIAM
  • Threat Intel and Incident Response Services
  • Proactive Assessments
  • Incident Response
  • Transform Your Security Strategy
  • Discover Threat Intelligence

Company

  • About Us
  • Careers
  • Contact Us
  • Corporate Responsibility
  • Customers
  • Investor Relations
  • Location
  • Newsroom

Popular Links

  • Blog
  • Communities
  • Content Library
  • Cyberpedia
  • Event Center
  • Manage Email Preferences
  • Products A-Z
  • Product Certifications
  • Report a Vulnerability
  • Sitemap
  • Tech Docs
  • Unit 42
  • Do Not Sell or Share My Personal Information
PAN logo
  • Privacy
  • Trust Center
  • Terms of Use
  • Documents

Copyright © 2025 Palo Alto Networks. All Rights Reserved

  • Youtube
  • Podcast
  • Facebook
  • LinkedIn
  • Twitter
  • Select your language