Developing Proactive Threat Mitigation Strategies for Cloud Misconfiguration Risks in Financial SaaS Applications
Olufunke Cynthia Metibemu, Temilade Oluwatoyin Adesokan-Imran, Adekunbi Justina Ajayi, Olufisayo Juliana Tiwo, Abayomi Titilola Olutimehin, Oluwaseun Oladeji Olaniyi
Journal of Engineering Research and Reports · pp. 393–413 · Published 15 Mar 2025
10.9734/jerr/2025/v27i31442Abstract
Cloud misconfigurations in financial Software-as-a-Service (SaaS) applications pose significant cybersecurity risks, leading to data breaches, financial losses, and reputational harm. This study utilizes data from the Cloud Security Alliance (CSA) Top Threats Dataset, Verizon Data Breach Investigations Report (DBIR), and the MITRE ATT&CK Framework to examine the causes and types of misconfigurations, analyze their financial impact, and evaluate the effectiveness of mitigation strategies. A Chi-Square Test for Independence, Ordinary Least Squares (OLS) Regression, and Kaplan-Meier Survival Analysis were employed to quantify these risks. Findings indicate that IAM errors (183 occurrences) and exposed APIs (156 occurrences) are the most frequent misconfigurations, with high-severity misconfigurations resulting in an average financial loss of $7.6M and regulatory fines of $2.5M. Implementation of Zero Trust Architecture, Cloud Security Posture Management (CSPM), and strict IAM controls reduced breach probability from 70% to 40%. This study examines cloud misconfigurations in financial SaaS applications using datasets from 2018 to 2024, providing a risk quantification of security threats and a financial impact assessment of breaches. Findings reveal that IAM errors and exposed APIs are the most frequent misconfigurations, causing severe financial losses. The effectiveness of Zero Trust and CSPM in reducing breach probability is analyzed. Future research should explore AI-driven security solutions for real-time misconfiguration detection and automated risk prevention in cloud environments. Recommendations include automating security controls, enforcing Zero Trust policies, integrating security training, and strengthening regulatory compliance.
Cited by 5
C. V. Suresh Babu, M. Bhavesh, J. Janani · Advances in Computational Intelligence and Robotics · 2025
Dwibik Patra, Narendran Rajagopalan · Computers & Security · 2026
Nanyeneke Ravana Mayeke · Computer Science & IT Research Journal · 2025
Showing 3 of 5 known citations — external sources report more than can currently be individually listed.
Related research
- Exploring the Challenges of Artificial Intelligence in Data Integrity and its Influence on Social Dynamics — shares topic coverage
- Securing AI-Powered Healthcare Decision Support Systems: A Comprehensive Review of Attack Vectors and Defensive Strategies — shares topic coverage
- Occupational Health, Safety, and Environmental Impacts in Key Industrial Sectors of Sierra Leone: A Cross-sectoral Mixed-methods Study of Mining, Manufacturing, and Construction — shares topic coverage
- Leveraging Digital Transformation for Enhanced Risk Mitigation and Compliance in Pharma Manufacturing — shares topic coverage
- Strategic Regulatory Compliance and Service Delivery in Uganda’s State-owned Energy Sector: A Case Study of Uganda Electricity Distribution Company Limited — shares topic coverage
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
5
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.