Palo Alto Networks' State of Cloud-Native Security report sheds light on how security is becoming an obstacle to software deployment in complex cloud environments and identifies the most pressing cloud security concerns.

The security giant surveyed more than 2,800 cloud security and DevOps professionals in 10 countries and five industry sectors.

The report found the surveyed organizations use an average of 12 cloud service providers (CSPs) for their deployed applications. There is also an overall trend of increasing cloud spending with over half of them investing more than $10 million annually in cloud services.

On the other hand, the need for simplification and consolidation rises as organizations on average have 16 cloud security tools. Almost all the respondents (98%) stated the importance of reducing the number of security tools and 90% say the number of point tools they use creates blind spots affecting their ability to prioritize risk and prevent threats.

The conflict between DevOps and security operations (SecOps)

The report findings underscored the tension between the need for rapid development and the imperative of maintaining security.

A majority (84%) of the respondents said security processes cause delays to their project timelines, while 86% stated security is a gating factor hindering software releases, according to Palo Alto Networks' report.

Meanwhile, the rush to accelerate time-to-market schedules often results in compromised security postures, with 71% attributing rushed deployments to increased vulnerabilities. Over half (52%) of respondents cite conflict between DevOps and SecOps as a significant source of stress.

Top 7 Cloud Security Concerns

Palo Alto Networks noted the cloud security concerns are “varied and far-reaching,” based on the findings. Here are the top seven concerns respondents have:

  1. Artificial intelligence (AI)-generated code: Near half (44%) of organizations are worried about the unforeseen vulnerabilities and exploits introduced by AI-generated code. The lack of human oversight in autonomous software creation may lead to undetected security flaws, while the rapid development of AI-generated code also could outstrip traditional security testing methods and leave vulnerabilities in production.
  2. API risks: About 43% of respondents cited API risks as a top concern, including unauthorized access, sensitive data exposure and creating vulnerabilities for cyberattacks.
  3. AI-powered attacks: As the potential for AI-powered attacks raises fears, 38% of organizations are concerned about the weaponization of AI and the uncertainty that makes it difficult to plan for and defend against.
  4. Inadequate access management: Facing the challenges of controlling who has access to what within the cloud, 35% of respondents said inadequate access management is their top concern.
  5. Continuous integration/continuous delivery (CI/CD)’s impact on the attack surface: The CI/CD pipeline’s impact on the attack surface concerns 34% of the respondents, with its potential to introduce vulnerabilities and quickly deploy them into production.
  6. Insider threats: About 32% of respondents are wary of the risks posed by insiders, including business partners, third-party vendors, contractors and employees.
  7. Unknown and unmanaged assets: The issue could leave a gap in asset management and visibility that could lead to vulnerabilities and breaches, which concerns 29% of respondents.