Adtech PH | SINGAPORE | Despite repeated warnings, many organizations are still struggling to master the fundamentals of cloud security, leaving dangerous gaps that cybercriminals can exploit. As enterprises accelerate digital adoption, embracing hybrid and multi-cloud environments and even AI-powered infrastructure, the inability to properly secure identities and address a widening expertise gap is emerging as a critical weak point.
These are the key findings of the State of Cloud and AI Security 2025 report, commissioned by Tenable in partnership with the Cloud Security Alliance (CSA). The research surveyed more than 1,000 IT and security professionals worldwide, including leaders from Asia-Pacific, to understand how businesses are adapting their cloud security strategies to manage modern cyber risks.
The Fragmented Cloud Landscape
The report shows just how complex today’s IT environment has become. Nearly 82% of organizations now run hybrid setups, while 63% use multiple cloud providers. This move toward flexibility enables speed and scale but also creates fragmented visibility and inconsistent enforcement of cloud security policies.
Without unified oversight, companies face blind spots—openings that attackers are quick to exploit. For enterprises exploring best practices in cloud security, this makes centralized monitoring and governance essential.
Identity: The Weakest Link
Perhaps the most urgent takeaway is that identity governance in the cloud has become the top battlefield. While 59% of organizations admit insecure identities and poor permissions management are their greatest cloud risks, most still fail to address them effectively.
Breach statistics underscore the problem:
- Excessive permissions (31%)
- Inconsistent access controls (27%)
- Weak identity hygiene (27%)
These aren’t just isolated oversights; they reveal a systemic failure in identity and access management (IAM) across enterprises. In the age of AI and cybersecurity risks, the consequences of such lapses are amplified.
The Cybersecurity Skills Gap
Even when risks are understood, progress often stalls due to a persistent shortage of expertise. According to the study, 34% of organizations cite the lack of skilled professionals as their single biggest obstacle to improving cloud and AI security practices.
This skills gap creates ripple effects:
- 39% report unclear or fragmented security strategies
- 31% believe executives do not fully grasp cloud security risks
This leadership disconnect limits budgets, weakens alignment, and ultimately undermines the ability to implement responsible cloud security governance.
Expert Insights
“Identity has become the cloud’s weakest link, but it’s being managed with inconsistent controls and dangerous permissions,” said Liat Hayun, VP of Product and Research at Tenable. “This isn’t just a technical oversight; it’s a systemic governance failure, compounded by a persistent expertise gap that stalls progress from the server room to the boardroom. Until organisations get back to basics, achieving unified visibility and enforcing rigorous identity governance, they will continue to be outmanoeuvred by attackers.”
This underscores the importance of returning to cloud security best practices, focusing on unified visibility, strong identity management, and AI-ready governance frameworks.
Key Takeaways for 2025
- Cloud adoption is rising, but basics are being overlooked. Many firms are rushing into multi-cloud and AI integration without solid security foundations.
- Identity management is the central risk. Mismanaged permissions and weak controls continue to drive breaches.
- Cybersecurity talent is in short supply. Without skilled professionals, even the best tools fall short.
- Leadership buy-in is essential. Executives must understand risks and commit resources to protect against AI-driven cyberattacks.
Why This Matters for the Future
As we enter 2025, organizations that succeed in cloud security resilience will be those that:
- Invest in identity-first security
- Close the cloud security expertise gap with training and partnerships
- Implement AI-ready security frameworks to address emerging threats
- Align leadership and technical teams on unified, risk-based strategies
For businesses in Asia-Pacific and beyond, the message is clear: mastering the fundamentals of identity governance in cloud security is no longer optional; it’s the price of admission in today’s cyber battleground.
