Cloud complexity turns security policy into outage risk
Security policy misconfigurations emerge as significant operational risk for organisations running hybrid and multi-cloud environments.
A recent survey conducted by the Cloud Security Alliance (CSA) reveals that misconfigured security policies are causing significant operational risks for organisations utilising hybrid and multi-cloud environments. The survey of 515 IT and security professionals found that 65% of these organisations experienced at least one business-critical application outage due to a security policy misconfiguration in the past year, while 46% faced multiple such outages.
The survey highlights the growing complexity of managing security policies as applications increasingly span across public cloud, private cloud, and on-premises infrastructure. Manual management of security policies is a major challenge, with 48% of surveyed organisations relying mostly or fully on manual processes. This manual approach leads to errors and is a major bottleneck in deploying new applications, along with cross-team coordination and obtaining security policy approvals.
The consequences of policy misconfigurations extend beyond application outages. The survey found that these issues are associated with delayed application deployments (40%), near-miss security incidents (34%), unplanned rollbacks or emergency changes (31%), failed compliance audits or audit findings (25%), and actual security incidents or breaches (18%).
One of the key findings is that no single function has sole ownership of connectivity policy, with security operations teams involved in 51% of organisations, followed by network operations and cloud architects at 46% each, DevOps or application owners at 41%, Chief information security officer and security leadership at 35%, and governance, risk, and compliance teams at 23%.
The survey also points out a gap between organisations' compliance ambitions and the way compliance is managed, with manual review being the most common approach. Only 9% of respondents said security policy management is fully integrated into development and deployment workflows. This lack of integration, along with the use of multiple security management consoles, creates a structural visibility problem, making it difficult for teams to have a single, accurate view of security policies across their environments.
Written by urgent.news from ITWeb's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.