NIST Flags Multi-Cloud Security Pitfalls
New NIST report outlines 23 unique challenges in multi-cloud environments, urging community-driven solutions.
As more organizations spread workloads across multiple cloud providers, the security picture grows more complicated. A new report from the National Institute of Standards and Technology (NIST) warns that multi-cloud environments introduce distinct cybersecurity and compliance hurdles that organizations must address.
Why Multi-Cloud Is Harder to Secure
NIST highlighted that using multiple cloud service providers (CSPs) makes it more difficult to maintain consistent security policies, apply uniform controls, and enforce strong authentication protocols compared to single-cloud or on-premises setups. Different providers each have their own security models, tools, configurations, and shared responsibility frameworks, which complicates a unified security posture.
A growing number of organizations are moving to multi-cloud environments, defined as using two or more cloud providers. The approach offers a key advantage: reducing reliance on a single provider. If one provider suffers an outage or cyber-attack, organizations can continue operations and maintain access to critical systems and data. But as NIST points out, it also introduces significant security challenges.
The 23 Novel Challenges
In total, NIST identified 23 novel challenges arising in multi-cloud environments, spanning identity and access controls, vulnerability management, incident response and disaster recovery, and data protection.
Identity and Access Management
Security teams face significant challenges ensuring access control policies and authorization measures are implemented consistently across various CSP systems, each with unique native architectures. This includes verifying whether multi-factor authentication (MFA) or biometric verification have been employed by all their CSPs for the specific information systems that support their cloud services. The report added that such challenges are exacerbated by the need to verify the access control policies and implementations of other vendors or third parties used by the CSPs.
Vulnerability Management
Vulnerability management becomes more complicated in multi-cloud settings due to the differing approaches of CSPs. Vulnerability reports are provided in varying timeframes and formats, making it impossible to have a uniform approach to patch management across an enterprise architecture. Additionally, customers may be unable to conduct independent vulnerability scans because they lack direct access to the CSPs' information systems.
Incident Response and Disaster Recovery
Some CSPs may not send timely and comprehensive incident data to their customers. This information may also not be received in a standardized way due to varied reporting formats and schemas used by different providers. Furthermore, CSPs may not grant customers the required administrative access privileges to independently monitor their cloud services across different providers.
Planning disaster recovery is also difficult. CSPs frequently withhold contingency planning policies from customers, citing concerns over privileged backend information and overall system security. They typically do not offer the results of contingency or disaster recovery plan tests either.
Data Protection and Compliance
The NIST report noted that customers rely on their CSPs to ensure that security, encryption, and regulatory standards are met across their cloud environments. Yet in multi-cloud environments, they are at significant risk of falling foul of data protection regulations in different jurisdictions due to inconsistent implementations of data security measures such as encryption among CSPs.
Organizations often face challenges in obtaining information system security documentation from all providers involved in protecting their data. This creates difficulties in proving compliance with laws such as the EU's General Data Protection Regulation (GDPR).
What NIST Proposes
NIST said that robust governance frameworks, centralized visibility, consistent policy enforcement, and a strong emphasis on automation and standardization will be needed to address the challenges of multi-cloud environments. It added that this will require a collaborative effort across the cybersecurity community.
“By bounding the analysis, this IR aims to provide a structured problem statement and shared vocabulary that can inform future research, procurement, standards development, and solution design across government, industry, and academia,” the report stated.
— NIST report, as quoted in the source article.
The institute is inviting input from federal agencies, industry partners, researchers, and the broader cybersecurity community on its report. The public comment period is open until October 5, 2026.
Why It Matters
For organizations running multi-cloud architectures, the report suggests that the benefits of redundancy come with real trade-offs. The lack of uniform security controls and visibility across providers could increase the risk of misconfigurations, compliance gaps, and delayed incident response. As multi-cloud adoption grows, these challenges may become more pressing, and the need for standardized solutions and greater transparency from CSPs will likely be a key focus for the cybersecurity community.
Sources
- Infosecurity Magazine Original source
Continue Reading
AI Coding Piles Up Remediation Debt
Enterprises face growing open-source vulnerability backlogs as AI tools accelerate code output.
August .NET Update Breaks WPF Printing
Printing and PDF export fail in some WPF apps after August 2026 .NET updates; Microsoft offers a risky workaround.
Keycloak flaw lets unauthorized password resets
CVE-2026-18963 allows full account takeover via reset flow; patches out.