LAS VEGAS, NV – Only one-quarter of C-suite executives believe their organizations' security readiness and resilience is high, while zero trust has quickly become an operational imperative for organizations, Palo Alto Networks’ latest survey found.

The security vendor surveyed 1,300 C-suite leaders from around the world and across various industries, including CISOs, CIOs, CSOs, CTOs, and COOs. It found that almost all (96%) of respondents stated their organizations had experienced at least one security incident or a breach in the last 12 months, with 57% reporting three or more incidents.

The report also showed that ransomware and business email compromise were identified as the top attacks that organizations will continue to face, while phishing and software vulnerabilities are likely to remain the top means of elicit access.

When asked about top security priorities, executives selected data protection and privacy, followed by the automation of threat detection and response, and improving security operations and efficiency. Organizations prioritize those measures to address their top challenges, which include the lack of skilled employees, an increase in data management and perimeter complexities, and a lack of alignment between security and changes in the tech stack.

Palo Alto Networks: Zero-Trust Security Imperative

The Palo Alto Networks report also highlighted the importance of zero-trust adoption.

“In zero trust we trust,” the report cleverly stated. “Zero trust has quickly moved from a security concept to an operational imperative for organizations.”

Surveyed CXOs listed a growing supply chain or vendor ecosystem (52%), sophistication and frequency of attack (49%), and hybrid workforce (47%) as the main reasons to implement zero-trust strategies.

However, 98% of them also noted challenges, citing a lack of internal experience, not knowing where to start or how to prioritize, and a lack of qualified vendors with a complete and integrated solution.

Cloud Security Concerns

The report also looked at cloud security, finding that 67% of organizations use one to two cloud service providers, while 33% use three to five. And around half of them plan to increase investments in software firewalls on both public and private clouds.

The top three concerns for public cloud adoption were code vulnerabilities introduced by developers (36%), runtime threat detection and prevention (34%), and identity and overly privileged access being hard to monitor (34%).

To address these concerns, organizations are deploying web application and API security (37%), requiring developers to use code security and scanning tools (35%), and deploying virtual firewalls to protect cloud application perimeters (35%).