What Are the Treacherous 12?
The Cloud Security Alliance (CSA) identifies 12 core risks that most organizations face when moving workloads to the cloud. These risks are common across public, private, and hybrid environments and can undermine confidentiality, integrity, and availability if left unchecked.
- What Are the Treacherous 12?
- 1. Misconfigured Cloud Storage
- 2. Inadequate Identity & Access Management
- 3. Unsecured APIs
- 4. Data Loss & Leakage
- 5. Insecure Software Development Lifecycle
- 6. Lack of Cloud Visibility
- 7. Insufficient Vendor Management
- 8. Shadow IT
- 9. Inadequate Incident Response Planning
- 10. Data Residency & Compliance Issues
- 11. Cloud Service Misuse
- 12. Lack of Continuous Security Posture Management
- Mitigation Strategies
More from this site
Keep reading the latest coverage
1. Misconfigured Cloud Storage
Unintended public access to object buckets or file shares often exposes sensitive data. Automated scans and strict IAM policies reduce this risk.
2. Inadequate Identity & Access Management
Over‑privileged roles, shared credentials, and weak MFA leave systems vulnerable to account takeover.
3. Unsecured APIs
APIs that lack proper authentication, rate limiting, or input validation become easy targets for injection and denial‑of‑service attacks.
4. Data Loss & Leakage
Improper data classification, lack of encryption at rest or in transit, and accidental deletion can lead to irreversible loss.
5. Insecure Software Development Lifecycle
Skipping security reviews, static analysis, or penetration testing in CI/CD pipelines lets vulnerabilities slip into production.
6. Lack of Cloud Visibility
Without comprehensive logging, monitoring, and threat detection, anomalous activity may go unnoticed.
7. Insufficient Vendor Management
Third‑party services that lack robust security controls can become a weak link.
8. Shadow IT
Unapproved cloud services bypass corporate controls, creating blind spots and compliance gaps.
9. Inadequate Incident Response Planning
Without a tested playbook, response times drag, amplifying damage.
10. Data Residency & Compliance Issues
Data stored in jurisdictions without proper legal safeguards can violate regulations like GDPR or HIPAA.
11. Cloud Service Misuse
Excessive resource allocation, running privileged containers, or enabling unused features increases attack surface.
12. Lack of Continuous Security Posture Management
Static security settings become outdated quickly; regular reassessment is essential.
Mitigation Strategies
- Implement automated configuration drift detection.
- Enforce least‑privilege IAM and mandatory MFA.
- Secure API gateways with WAF and rate limiting.
- Encrypt all data at rest and in transit; use key management services.
- Integrate security gates into CI/CD pipelines.
- Centralize logging with SIEM and enable real‑time alerts.
- Conduct regular vendor security assessments.
- Use cloud access security broker (CASB) to detect shadow IT.
- Develop and rehearse incident response playbooks.
- Map data flows to ensure residency compliance.
- Adopt automated resource tagging and cost‑control policies.
- Schedule periodic security posture reviews.