The report highlights the widespread adoption of cloud technologies and the significant concerns organisations have regarding their security.
The report is based on data parsed from a survey conducted by Censuswide, which included 1,200 IT professionals from diverse sectors in France, Germany, Italy, Singapore, the UK, and the US, working in organisations with over 1,000 employees.
Cloud security concerns
Cloud computing’s constant availability and global accessibility present significant security challenges.
The survey revealed that 44% of respondents identified data breaches or leaks as a top concern, 43% expressed worries about unauthorised access to cloud services, and 42% were troubled by misconfigured cloud storage.
Notably, nearly half (47%) of organisations rely on native security offerings from their cloud service providers, assuming they are sufficient. However, these native tools often fall short as threats evolve, necessitating more advanced solutions that can detect and correlate data across multiple sources.
Human error and configuration issues
Human error remains a significant risk factor, with 32% of respondents concerned about it.
Other related concerns include 39% worrying about Identity and Access Management (IAM) and 34% concerned about misconfigurations.
The report emphasises that tools like Cloud Security Posture Management (CSPM) and Cloud Infrastructure Entitlement Management (CIEM) are essential for detecting misconfigurations and monitoring data access privileges, respectively.
The role of AI in cybersecurity
AI’s integration into cybersecurity strategies is a double-edged sword, according to the report.
While it offers benefits for decision-making and problem-solving, it also enhances the capabilities of cybercriminals. AI-driven tactics are now being used to craft sophisticated phishing emails and generate malicious content that bypasses conventional security measures.
The survey found that 96% of professionals view AI-assisted social engineering attacks as a concern and 41% consider it a very significant threat.
Despite this, 94% of professionals are confident in their organisation’s ability to respond to security threats, although only 37% feel very confident that their tools and strategies are sufficient.
AI is also being used to orchestrate narrative attacks or misinformation campaigns.
Nearly all (97%) of IT/security professionals consider the manipulation or creation of deceptive content a significant threat, with 36% viewing it as very significant.
Deepfakes, which can make fraudulent claims appear authentic, are particularly concerning. Although 74% of respondents are confident in their ability to identify deepfakes, 21% are not confident, and 5% are unsure.
Staffing challenges
The cybersecurity industry faces a chronic shortage of skilled professionals, with an estimated shortfall of nearly 4 million. This shortage exacerbates workload and burnout among existing staff, with over 70% of security professionals working weekends and 64% considering new job opportunities within the next year.
To address these challenges, the report states that organisations urgently need solutions that alleviate the burden on their security teams to help avoid burnout.
Such measures enhance the work environmentand improve the overall efficacy of security operations, ensuring that critical threats are not overlooked.
How can organisations combat these threats?
According to Bitdefender, a defense-in-depth strategy is essential.
This starts with establishing a secure foundation for cloud environments using Cloud Security Posture Management (CSPM) tools. CSPM automates the identification and remediation of risks from misconfigured cloud resources, preventing potential breaches and creating a robust baseline for cloud security.
Recommended reading
- Cloud Complexity and AI are Too Much for Traditional Security
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- Cybersecurity Readiness is Down Amid Rampant Attacks
As organisations increasingly adopt cloud technologies for efficiency and agility, they often outpace the implementation of adequate security measures. This leaves significant vulnerabilities: 44% of organisations worry about data breaches, 43% about unauthorised access, and 42% about misconfigured cloud storage.
Building on this foundation, organisations should integrate Extended Detection and Response (XDR) and Managed Detection and Response (MDR) to strengthen defenses. XDR provides holistic visibility and correlation across all data points, crucial for detecting abnormal behaviors and sophisticated threats like zero-day exploits and AI-specific attacks. Advanced analytics and machine learning enable XDR to predict and prevent incidents before they escalate.
MDR offers 24/7 monitoring and threat hunting, ensuring continuous oversight and expertise to navigate evolving threat landscapes. In the event of a security breach, MDR’s rapid incident response minimises downtime and restores operations swiftly.
Together, CSPM, XDR, and MDR form a multi-layered security strategy that allows organisations to proactively identify and mitigate threats, securing their infrastructure against the evolving nature of cyber threats.





