Survey reveals 90% of organizations cannot resolve cyber-threats in an hour

Cyber-threats

Share this content

Facebook
Twitter
LinkedIn

Palo Alto Networks has published its 2023 State of Cloud-Native Security Report, which surveyed more than 2,500 C-level executives around the world to better understand their cloud adoption strategies and how those strategies are working against cyber-threats.

Main findings from the survey:

Cloud use has grown, along with security concerns – the expansion of hybrid work during the pandemic drove organizations to expand their use of clouds by more than 25%. As a result, DevOps teams are being pressed to deliver production code at warp speed — making application security more complex and putting pressure on security organizations to keep pace.

Most organizations are slow to detect and respond to threats – 90% of organizations surveyed said they cannot detect, contain and resolve cyber-threats within an hour. Bad actors are working just as fast as developers to take advantage of organizations’ vulnerabilities. What could go wrong often does go wrong and any cloud asset that is inadvertently exposed to the internet can be compromised within minutes. Detecting threats in real-time represents the new frontier of cloud security.

Teams don’t understand their security responsibilities – when asked about the challenges of moving to the cloud, respondents’ top concerns included: struggles with comprehensive security, compliance and technical complexity. A large majority (78%) of organizations said they have distributed responsibility for cloud security to individual teams, but almost half (47%) said a majority of their workforce does not understand their security responsibilities.

A greater need for code-to-cloud security – as more applications are being built in the cloud using off-the-shelf software, there’s a risk that any vulnerability in the development process could compromise an entire application later on. That’s why more companies are encouraging a deeper level of engagement between application developers and security tools and teams — with 81% of respondents saying they have embedded security professionals inside their DevOps teams to prevent cyber-threats.

“With three out of four organizations deploying new or updated code to production weekly and almost 40% committing new code daily, no one can afford to overlook the security of cloud workloads,” said Ankur Shah, Senior Vice President, Prisma Cloud, Palo Alto Networks. “As cloud adoption and expansion continues, organizations need to adopt a platform approach that secures applications from code to cloud across multicloud environments.”

Moving towards consolidation – three quarters of the leaders surveyed said they struggle to identify which cybersecurity tools are necessary to achieve their objectives. This has led many of them to implement numerous single point solutions — with the average organization using more than 30 security tools, including six to ten dedicated to cloud security.

The sheer number of cybersecurity tools makes it difficult for leaders to have in-depth visibility into their entire cloud portfolio. Seventy-six percent of survey respondents reported that using multiple security tools creates blind spots that affect their ability to prioritize risk and prevent threats. A further 80% said they would benefit from a centralized security solution that sits across all of their cloud accounts and services.

A clear path forwards – despite the upheaval caused by the pandemic, organizations have mostly been able to succeed in their cloud expansions and organizations that made cloud infrastructure a strategic focus across the business were generally more successful against cyber-threats. This makes cloud security a clear enabler of business outcomes.

Newsletter
Receive the latest breaking news straight to your inbox