Cloud and AI Security Report Reveals Critical Gaps: Cloud Adoption Outpaces Security Readiness

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer

Organizations' security strategies are failing to keep up with the rapid adoption of hybrid-cloud and AI technologies, according to a new report from Tenable and the Cloud Security Alliance (CSA), titled the "State of Cloud and AI Security 2025," which surveyed over 1,000 IT and security professionals.

Identity and Expertise Emerge as Key Challenges

The Tenable and CSA report found that while 82% of organizations operate in hybrid environments and 55% are actively using artificial intelligence (AI) for business needs, security measures remain reactive and fragmented. This disconnect leaves them exposed to significant risks.

The report stated that identity-related issues are the leading cause of cloud breaches, with excessive permissions (31%) and weak identity hygiene (27%) being the primary contributors. Despite this awareness, a lack of cloud security expertise was cited as the top challenge by 34% of respondents. 

Security measures taken by organizations in relation to risks in hybrid environments
Security measures taken by organizations in relation to risks in hybrid environments | Source: Tenable

This expertise gap creates a strategic obstacle, leading to unclear strategies and insufficient budgets, as leadership often misunderstands the shared responsibility model and overestimates the capabilities of native cloud provider tools. 

Factors that contributed to organization breaches
Factors that contributed to organization breaches | Source: Tenable

As a result, security teams are focused on measuring incident frequency rather than proactive risk prevention.

Organization protections
Organization protections | Source: Tenable

Despite recognizing the importance of Zero Trust and least privilege, many organizations struggle with security maturity due to structural and workflow gaps. Misalignment between cloud and IAM teams (28%) and challenges in enforcing least privilege (21%) highlight these issues, the report says.

While 44% of organizations prioritize implementing least privilege for identities in the next year, measurement practices remain basic, with 42% tracking MFA or SSO adoption rates. 

AI Security Risks and Strategic Recommendations

The report highlights alarming trends in AI security risks, with over a third of organizations using AI having already suffered a related breach. 

Security teams are often focused on novel threats like model manipulation, while neglecting foundational issues such as software vulnerabilities and misconfigured cloud settings, which are the actual primary causes of these breaches. 

To address these cloud security challenges, the report recommends a strategic reset. Organizations must:

Gary Brickhouse, Chief Information Security Officer at GuidePoint Security, spoke with TechNadu about the changing attack patterns across hybrid and SaaS environments.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: