NIST Warns of Unique Security Risks in Multi-Cloud Environments

Written by

The US government has warned organizations of the unique cybersecurity and compliance challenges presented by multi-cloud environments.

The National Institute of Standards and Technology (NIST) highlighted how using multiple cloud service providers (CSPs) makes it more difficult for organizations to maintain consistent security policies, apply uniform controls and enforce strong authentication protocols compared to single cloud or on-premises architectures.

This is largely because different providers have their own security models, tools, configurations and shared responsibility frameworks, NIST noted.

A growing number of organizations are moving to multi-cloud environments, which is defined as using two or more cloud providers.

A key cybersecurity advantage of this approach is that it reduces reliance on a single provider. Should a provider suffer an outage or cyber-attack, organizations can continue operating and maintain access to critical systems and data.

However, as NIST highlighted, it can also introduce significant security challenges.

The aim of NIST’s new report published on August 21, aims to encourage greater efforts from the cybersecurity community to explore and prioritize solutions to the issues associated with multi-cloud architectures.

The Unique Security Challenges of Multi-Cloud Environments

In total, NIST identified 23 novel challenges that arise in multi-cloud environments across areas including identity and access controls, vulnerability management, incident response and disaster recovery, and data protection.

Identity and Access Management

Security teams face significant challenges ensuring access control policies and authorization measures are implemented consistently across various CSP systems, each of which have unique native architectures.

This includes the ability to verify whether multi-factor authentication (MFA) or biometric verification have been employed by all their CSPs for the specific information systems that support their cloud services.

The report added that such challenges are exacerbated by the need to verify the access control policies and implementations of other vendors or third parties that are used by the CSPs.

Vulnerability Management

Vulnerability management can be more complicated for organizations operating in multi-cloud environments due to the different approaches of CSPs in this area.

Vulnerability reports are provided in differing timeframes and formats, making it impossible to have a uniformed approach to patch management across an enterprise architecture.

In addition, customers may be unable to conduct independent vulnerability scans due to a lack of direct access to the CSPs information systems.

Incident Response and Disaster Recovery

Some CSPs may not send timely and comprehensive incident data to their customers. This information may also not be received in a standardized way because of varied reporting formats and schemas used by different providers.

In addition, CSPs may not grant customers the required administrative access privileges to independently monitor their cloud services across different providers.

It is also difficult for security teams to effectively plan their organizations’ disaster recovery plans. This is because CSPs frequently withhold contingency planning policies from customers, citing concerns over privileged backend information and overall system security, while they also typically do not offer the results of contingency or disaster recovery plan tests.

Data Protection

The NIST report noted that customers rely on their CSPs to ensure that security, encryption and regulatory standards are met across their cloud environments.

Yet in multi-cloud environments, they are at significant risk of falling foul of data protection regulations in different jurisdictions due to the inconsistent implementations of data security measures such as encryption among CSPs.

Additionally, organizations often face challenges in obtaining information system security documentation from all providers involved in protecting their data, creating difficulties in proving they are meeting compliance requirements in laws such as the EU’s General Data Protection Regulation (GDPR).

NIST Urges Cybersecurity Community to Find Solutions

NIST said that robust governance frameworks, centralized visibility, consistent policy enforcement, and a strong emphasis on automation and standardization will be needed to address the challenges of multi-cloud environments. It added that this will require a collaborative effort across the cybersecurity community.

“By bounding the analysis, this IR aims to provide a structured problem statement and shared vocabulary that can inform future research, procurement, standards development, and solution design across government, industry, and academia,” the report stated.

The institute is inviting input from federal agencies, industry partners, researchers, and the broader cybersecurity community on its report, with a public comment period open until October 5, 2026.

Join Infosecurity’s Cloud Security in the Age of AI Virtual Summit on September 22 to discover more about multi-cloud security challenges. Register here to secure your spot.

What’s Hot on Infosecurity Magazine?