Friday, 12 September 2025
25.7 C
Singapore
30.2 C
Thailand
19.7 C
Indonesia
27.8 C
Philippines

Organisations struggle with cloud security fundamentals, Tenable report reveals

Tenable report warns organisations remain exposed to breaches due to weak cloud security fundamentals, identity risks, and skills gaps.

Despite years of warnings, many organisations continue to fall short in mastering the basics of cloud security, leaving them vulnerable to breaches. A new report highlights significant gaps in identity management, expertise, and governance as cloud adoption accelerates worldwide.

Growing complexity in IT environments

The State of Cloud and AI Security 2025 report, commissioned by Tenable in collaboration with the Cloud Security Alliance (CSA), surveyed over 1,000 IT and security professionals across the globe, including in the Asia Pacific region. The study examined how organisations are managing risks in increasingly complex cloud and AI-driven infrastructures.

The findings show that 82% of organisations now operate hybrid environments, while 63% use multiple cloud providers. This layered approach has created an urgent need for unified visibility and consistent policy enforcement. However, most companies lack the necessary controls, creating blind spots that cyber attackers can exploit.

The report identifies identity as the primary battleground for cloud security. While 59% of organisations acknowledge that insecure identities and permissions are their biggest cloud risk, many are not taking sufficient action to mitigate it. Breach data shows that the leading causes of incidents are linked to poor identity governance, including excessive permissions (31%), inconsistent access controls (27%), and weak identity hygiene (27%).

These issues point to more than isolated errors. According to the study, they reflect systemic governance failures in how organisations manage identity across the enterprise.

Skills gap undermines progress

A lack of expertise is also hindering progress. More than a third of organisations (34%) cited a shortage of skilled professionals as their greatest challenge in cloud security. This skills gap contributes to unclear strategies, reported by 39% of respondents, and a disconnect between security teams and leadership. Almost one-third (31%) believe their executives do not sufficiently understand cloud security risks, limiting the support, budgets, and resources needed to address the problem effectively.

Liat Hayun, Vice President of Product and Research at Tenable, said: “Identity has become the cloud’s weakest link, but it’s being managed with inconsistent controls and dangerous permissions. This isn’t just a technical oversight; it’s a systemic governance failure, compounded by a persistent expertise gap that stalls progress from the server room to the boardroom. Until organisations get back to basics, achieving unified visibility and enforcing rigorous identity governance, they will continue to be outmanoeuvred by attackers.”

The report concludes that organisations need to strengthen their foundations in identity management, invest in expertise, and align leadership with security priorities if they are to reduce exposure in increasingly fragmented cloud environments.

Hot this week

Garmin launches fēnix 8 MicroLED smartwatch with record-breaking brightness

Garmin unveils the fēnix 8 MicroLED, the world’s brightest smartwatch with advanced health, navigation, and performance features.

New web licensing standard seeks to make AI companies pay for content use

Major publishers launch RSL Standard to set licensing terms for AI training data and push for fair compensation from tech companies.

The rise of the Fractional CMO is reshaping marketing leadership in modern organisations

Explore how the rise of Fractional CMOs is transforming marketing leadership in Southeast Asia, offering companies flexible, strategic expertise without full-time costs.

ASUS launches ProArt GeForce RTX 50 Series graphics cards in Singapore

ASUS introduces the ProArt GeForce RTX 50 Series in Singapore, featuring AI-ready performance, slim design, and USB-C display connectivity.

Microsoft removes publishing fees for Windows app developers

Microsoft removes publishing fees for Windows app developers, making it free to publish apps worldwide and encouraging broader innovation.

AMD executive says AI is underhyped and still in its early stages

AMD’s Jack Huynh says AI is underhyped, with AMD working on innovations not yet invented and set to reveal more at CES 2026.

Cisco unveils agentic AI-powered Splunk Observability for real-time insights

Cisco introduces agentic AI-powered Splunk Observability, providing enterprises with real-time insights and stronger digital resilience.

Agora expands OpenAI partnership to strengthen conversational AI offerings

Agora expands its partnership with OpenAI, integrating the Realtime API into its platform to power more natural multimodal conversational AI.

Reddit tests in-app article reading with new publisher tools

Reddit is testing in-app article reading with new analytics and AI tools for publishers, aiming to boost content sharing and engagement.

Related Articles

Popular Categories