Thursday, 11 December 2025
26.2 C
Singapore
19.7 C
Thailand
20.7 C
Indonesia
27.1 C
Philippines

Tenable finds AI workloads bring new cloud security risks in Southeast Asia

AI workloads on cloud platforms pose higher security risks, with 70% containing critical flaws, Tenable reports in its 2025 cloud risk study.

Tenable has released its 2025 Cloud Security Risk Report, highlighting that cloud workloads used in artificial intelligence (AI) are significantly more vulnerable than traditional cloud environments. According to the findings, 70 per cent of AI-related workloads across major platforms like AWS, Azure and Google Cloud Platform (GCP) contain at least one unremediated critical vulnerability. In comparison, the figure drops to 50 per cent for non-AI cloud workloads.

The report warns that as businesses in Singapore and Southeast Asia accelerate their adoption of AI, these vulnerabilities pose growing risks to cloud security. AI systems, which typically rely on vast training datasets and complex model development processes, are becoming increasingly attractive targets for cyber attackers.

Cloud AI environments raise privilege and identity risks

The report highlights specific risks related to Google’s Vertex AI Workbench, where 77 per cent of organisations were found using notebook instances configured with overprivileged default service accounts. These misconfigurations could allow attackers to escalate privileges or move laterally within cloud environments.

This concern is reflected in the growing focus on cloud and AI security by regulators across Southeast Asia. In Singapore, the Cybersecurity Act and the Monetary Authority of Singapore’s Technology Risk Management Guidelines mandate strict controls. In Indonesia, PP 71 and OJK regulations emphasise secure cloud usage and local data storage for financial institutions. Malaysia’s Risk Management in Technology (RMiT) framework outlines stringent requirements for banks, while Thailand’s PDPA and Bank of Thailand guidelines prioritise transparency and access control. In the Philippines, the Data Privacy Act and regulations from Bangko Sentral ng Pilipinas (BSP) call for strong authentication and robust third-party governance.

With these frameworks continuing to evolve, organisations are urged to integrate security early in AI development workflows to manage compliance and mitigate future threats.

Improvements in general cloud security, but challenges remain

Despite concerns around AI environments, Tenable’s research also shows some improvement in overall cloud risk posture. The presence of “toxic cloud trilogies”—cloud workloads that are simultaneously publicly exposed, critically vulnerable, and highly privileged—has dropped to 29 per cent of organisations, down from 38 per cent in 2024. This decline is attributed to stronger risk-prioritisation strategies and broader adoption of cloud-native security tools.

However, Tenable cautions that even a single toxic workload could provide attackers with rapid access to sensitive information. Identity and access management continues to be a foundational element of cloud security, with 83 per cent of AWS users now deploying at least one identity provider (IdP), aligning with best practices for safeguarding both human and machine identities.

Still, identity-based risks persist. Credential abuse remains the most common entry point for breaches, accounting for 22 per cent of incidents. The report stresses the need for strong multi-factor authentication (MFA) policies and adherence to least privilege access models, both to meet regulatory expectations and to secure critical data.

AI demands a new approach to exposure management

Ari Eitan, Director of Cloud Security Research at Tenable, said the findings reflect a mix of progress and emerging challenges: “Organisations have made real strides in tackling toxic cloud risks, but the rise of AI workloads introduces a fresh wave of complexity. AI’s data-intensive nature, combined with persistent misconfigurations and vulnerabilities, demands a new level of diligence. Exposure management gives security teams the context they need to protect what matters most, including the crown jewels hidden inside AI environments.”

The report highlights the importance of contextual understanding in risk mitigation, especially as cloud environments evolve to support increasingly complex AI applications.

Hot this week

2026 Predictions Part 1: The five forces reshaping Asia’s digital economy

Five forces are redefining Asia’s digital economy in 2026, from AI adoption and data sovereignty to new security and workforce demands.

Kyndryl and Microsoft report rising sustainability commitment among Singapore businesses

Most Singapore businesses are expanding sustainability efforts but face challenges with data quality and limited AI adoption.

Kayou debuts at Singapore Comic Con 2025 with focus on Southeast Asia expansion

Kayou marks its debut at Singapore Comic Con 2025 and outlines plans to expand its retail network and fan community efforts across Southeast Asia.

Tiger Brokers: Bringing institutional-grade AI intelligence to global retail investors

AI is redefining retail investing as platforms like Tiger Brokers’ TigerAI integrate verified intelligence, personalisation, and long-term wealth management to empower global investors.

Lofree introduces the Flow 2 low-profile mechanical keyboard for Mac users

Lofree’s Flow 2 brings improved low-profile mechanical typing to Mac users, with new POM switches, wireless support, and a solid build.

Adobe integrates Photoshop, Acrobat and Adobe Express into ChatGPT

Adobe brings Photoshop, Acrobat and Adobe Express to ChatGPT, allowing users to edit and create via natural language prompts.

DJI launches Neo 2, its lightest and most compact drone yet

DJI launches the Neo 2, a lightweight, compact drone with advanced shooting modes and obstacle avoidance.

Sony unveils 27-inch PlayStation monitor with DualSense charging hook

Sony unveils a 27-inch PlayStation monitor with a DualSense charging hook, HDR support, and variable refresh rates, set to release in 2026.

Google extends repair and warranty programme for Pixel 9 Pro and Fold devices

Google extends repair and warranty programmes for Pixel 9 Pro, Pixel 9 Pro XL, and Pixel 9 Pro Fold devices.

Related Articles

Popular Categories