For months, years actually, I've looked very closely at the external attack surface of every Fortune 500 company and well beyond. I’ve learned that almost none, "moved to the cloud.” That’s a falacy. Instead the added stuff to the cloud and left the legacy where it always was.
The vast majority of companies where the bulk of their external attack surface is currently hosted in the cloud, that’s how they originally started building their IT infrastructure. They didn’t MOVE their either.
Here’s some data from Investment Banking, Hotels, Payment Issuers, and Insurance industries on the percentage of their external attack surface that’s hosted in “the cloud.” There's notable outliers that I’m curious to lern more about.
You can follow @jeremiahg.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.