Dive Brief:
- Security policy misconfigurations are leading to application outages, failed audit findings and multiday remediation windows, according to a report from the Cloud Security Alliance published in August. The report, commissioned by cybersecurity provider AlgoSec, is based on responses from 515 IT and security professionals to a May 2026 survey.
- Roughly two-thirds of businesses have experienced at least one business-critical application outage due to a misconfigured security policy in the last 12 months, the report found. Another 92% said it was challenging to gain a comprehensive view of security policies across their cloud environments while only 9% of enterprises reported having security policy management integrated into workflows.
- “What was once primarily a network-configuration problem has become an application-connectivity problem,” Hillary Baron, AVP of research at the Cloud Security Alliance, said in a press release accompanying the report. “The traditional, infrastructure-centric approach, defining policy device by device and rule by rule, is increasingly ill-suited to today’s environment.”
Dive Insight:
Security policies aren’t keeping pace with hybrid cloud strategies, which are gaining popularity to accommodate increased AI workloads across enterprises.
Eight in 10 companies are reassessing their cloud plans to improve support for AI, with CIOs looking at a mix of public cloud, private cloud, edge and sovereign environments, and colocation to help meet AI demands, according to an Information Services Group report. Global sovereign cloud spend alone is set to increase more than 35% this year as companies seek to gain greater control over their cloud data, according to Gartner.
Hybrid and multicloud strategies are today’s “operating reality for most enterprise applications,” according to the Cloud Security Alliance report. While half of business-critical applications are most often housed on-premises, 53% are housed in multicloud environments. Another 46% are kept in private cloud, 29% in public cloud and 36% in hybrid cloud. Most organizations manage security policies across more than one environment simultaneously, the report said.
When there is a misconfiguration issue, only 48% of organizations said they could remediate the issue within three days, according to the report.
“The failures organizations are absorbing — outages, rollbacks, delayed releases, audit findings — are the downstream cost of managing a high-volume, high-consequence control surface largely by hand,” the report said. “This is the first movement of the story the data tells: manual policy management has crossed from inefficiency into operational risk.”
To address risks posed by manual security policy configurations, the Cloud Security Alliance recommends enterprises gain unified visibility across environments, followed by conducting a pre-change risk analysis. Automating routine policy changes will help reduce misconfigurations and shorten remediation windows, while continuous compliance assessment should replace periodic reviews, the report said.