Cloud defenders are making progress as organizations enhance security in the cloud environment, with 92% operating without risky human users.
Sysdig has published its 2025 Cloud-Native Security and Usage Report, revealing detailed insights into cloud security and usage trends. The report indicates overall advancement in enterprise security while highlighting areas needing immediate focus.
The analysis shows that organizations globally are improving identity and vulnerability management, artificial intelligence (AI) security, and threat detection and response. However, with increased AI adoption and complex cloud infrastructures, businesses face new challenges, including machine identities and container image bloat, raising security concerns.
“It has been fascinating to watch cloud security evolve since we started reporting on usage eight years ago,” said Loris Degioanni, Sysdig Founder and CTO. “Given the short life span paired with how quickly attackers can move across cloud environments, I am encouraged to see defenders actively detecting and responding to threats in less than 10 minutes.”
Among the report's findings:
- AI and machine learning use has surged, indicating a strong focus on secure implementations alongside a 38% decrease in public exposure.
- Mature security teams now detect threats in under 5 seconds and initiate responses within 3.5 minutes, reducing the typical attack window.
- Active vulnerabilities in production have dropped to less than 6%, a 64% improvement in management strategies.
- Globally, open source security tools are becoming the standard, with over 60% of the Fortune 500 using tools like Kubernetes and Falco.
The report also notes areas of concern moving forward:
- Machine identities outnumber human identities by 40,000 to 1, with the former more susceptible to breaches.
- With 60% of containers existing for one minute or less, real-time detection and response is critical as vulnerabilities can be exploited rapidly.
- Container images have increased in size significantly, posing both operational and security risks.
- Cybercriminals are also utilizing open source tools, illustrating a need for constant vigilance.
“Cybersecurity has long been an arms race between threat actors and defenders, but the battlefield is evolving,” said Crystal Morin, Sysdig Cybersecurity Strategist. “Organizations have made considerable progress, and the fact that mature security teams can now respond to threats within minutes is notable. But with machine identities multiplying, automation and rapid response remain essential.”
Comments