India has seen a sharp rise in ransomware-related breach costs, which have surged by 39 per cent since 2020
Ransomware attacks targeting cloud environments are on the rise, with attackers exploiting vulnerabilities and misconfigurations to infiltrate systems. Experts warn that traditional cybersecurity defences are often ineffective against the evolving tactics used by ransomware operators, underscoring the need for a proactive approach to cloud security.
Liat Hayun, Vice President of Product Management Cloud Security and Research at Tenable, points to the “toxic cloud trilogy”—publicly exposed, critically vulnerable, and overly privileged workloads—as a key factor driving the surge in ransomware demands. “Initial Access Brokers (IABs) play a key role by purchasing credentials from the dark web, infiltrating cloud environments, and selling access to ransomware groups,” said Hayun. These brokers exploit cloud vulnerabilities to move laterally within systems, eventually handing over access to ransomware operators who launch attacks.
Even organisations with robust backup systems are not immune. Hayun noted that attackers often threaten to leak sensitive data, rendering traditional defences less effective. “The nature of cloud-stored data makes traditional cybersecurity tools ineffective against these evolving tactics, demanding a proactive and comprehensive approach,” she added. She stressed the importance of continuously analysing cloud resources to identify critical risks, detect unknown threats, and address toxic combinations of security issues.
Rising Costs Of Ransomware Breaches In India
India has seen a sharp rise in ransomware-related breach costs, which have surged by 39 per cent since 2020, according to Rajnish Gupta, Managing Director and Country Manager at Tenable India. Gupta highlighted that more than a third of ransomware attacks in India now originate in the cloud. “Lost business and notification expenses have driven these rising costs, highlighting the increasing collateral damage of data breaches,” Gupta said. He emphasised that many cloud-based breaches result from unnoticed toxic combinations, similar to those identified globally.
Gupta advocates for making ransomware breaches more difficult, time-consuming, and expensive for attackers. “Deterrence must become a top priority,” he stressed. He called for organisations to shift towards preventive security measures rooted in strong cybersecurity fundamentals. These measures include effectively managing third-party risks and implementing least-privilege models for both human and machine identities.
He also highlighted the role of advanced security solutions such as Cloud-Native Application Protection Platforms (CNAPP) and Data Security Posture Management (DSPM). “Leveraging solutions such as CNAPP with capabilities like DSPM and AI-Driven Security Posture Management (AI-SPM) is essential to counter these threats,” Gupta said, underlining the importance of integrating AI-powered tools to bolster cloud security.
Global Imperative For Cloud Security
The surge in ransomware attacks targeting cloud environments is a stark reminder of the evolving threat landscape. As attackers become more sophisticated, organisations must adopt a proactive stance, continuously monitoring and fortifying their cloud environments. By addressing vulnerabilities and minimising privileges, businesses can reduce their exposure to ransomware and ensure greater resilience in the face of increasingly complex cyber threats.

