NIST Flags 23 Security Gaps in Multi-Cloud Setups

New guidelines highlight that managing identity and compliance across multiple cloud providers creates distinct risks for enterprises.
Key points
- NIST identifies 23 new security risks specific to multi-cloud environments.
- Key challenges include inconsistent identity management and fragmented data protection.
- The agency recommends centralized governance and automation to mitigate these risks.
The US National Institute of Standards and Technology has warned that companies using multiple cloud providers face a new set of cybersecurity hurdles. While single-cloud or on-premises setups follow predictable rules, multi-cloud environments introduce complexity because each provider uses different security models and frameworks.
NIST has cataloged 23 specific risks in this space. These issues span critical areas such as identity management, data protection, and disaster recovery. The agency emphasizes that these are not minor technical glitches but structural challenges that require a shift in how organizations govern their digital infrastructure.
Identity and access management struggles
One of the most pressing issues is keeping identity policies consistent across different platforms. According to MSSP Alert, ensuring that multi-factor authentication and access controls work seamlessly in a multi-cloud setting is difficult. If one provider changes its authentication rules, it can create gaps that attackers can exploit, leaving the overall system vulnerable.
There is a trade-off here: while using multiple clouds can offer resilience, it fragments visibility. Organizations often cannot see the full picture of who has access to what data across all providers simultaneously. This lack of centralized control makes it harder to enforce a uniform security policy.
Compliance and data protection risks
Data protection presents another significant challenge. NIST notes that encryption standards often vary between cloud service providers. This inconsistency makes it difficult to ensure that data remains secure in transit and at rest. For organizations subject to regulations like GDPR, proving compliance becomes a legal and technical headache when documentation is scattered or unavailable.
Furthermore, incident response is complicated by a lack of transparency. Cloud providers may delay sharing data or provide reports in different formats. This slows down the ability to detect and mitigate threats, as security teams cannot rely on a single, unified source of truth for their investigations.
Path forward for governance
To address these issues, NIST urges the cybersecurity community to collaborate on robust governance frameworks. The recommendation includes implementing centralized visibility tools and automating policy enforcement. By doing so, organizations can reduce the manual effort required to manage disparate cloud environments and lower the risk of compliance failures.






