Site navigation

Report: Cloud Complexity is Outpacing Cyber Defence

Tom Quinn

,

cloud security
“With attackers moving in minutes and defenders responding in days, the gap between detection and remediation is becoming a danger zone,” said Deryck Mitchelson, Check Point.

As hybrid, multi-cloud, and edge architectures continue to expand, new research shows that many organisations are relying on outdated security models that are struggling to keep up.

Cybersecurity firm Check Point’s 2025 Cloud Security Report has revealed systemic weaknesses in these distributed infrastructures, including a widespread inability for firms to detect lateral movement or defend against AI-driven attacks, leaving many dangerously exposed. 

Check Point’s survey of more than 900 CISOs and IT leaders found that 65% of businesses suffered a cloud-security incident in the past year – up from 61% the year before – but only 9% were able to detect the incident within the first hour, and just 6% managed to remediate it in that time.

Alarmingly, more than a third (38%) admitted it had taken them more than 24 hours to detect an incident, and 62% took more than a day to remediate a breach. 

According to the report, that lag is evidence enterprise cloud adoption is outpacing security readiness.

In the past year alone, 62% of organisations expanded their use of cloud edge technologies, while 57% increased their hybrid cloud footprint and 51% adopted multi-cloud strategies, but these fragmenting environments are proving too much for legacy perimeter-based defences.

The architectural shift is presenting new risks, with 43% of respondents saying their top concern is now safeguarding high-level assets and IP, followed by improving threat visibility (40%) and managing hybrid and multi-cloud security (38%).

It is also overwhelming traditional defences. More than half of the firms polled by Check Point said they face nearly 500 cloud-based security alerts every day, but only 35% of these incidents were detected via security monitoring platforms, with the majority identified through employees, audits, or external reports.

Tool sprawl is also adding extra layers of complexity and fueling alert fatigue, as 71% of organisations said they rely on more than ten different cloud security tools, while 16% utilise more than fifty.  

Meanwhile, 61% still rely on outdated, signature-based Web Application Firewalls, which are proving increasingly ineffective against AI-enhanced threats, and just 17% of organisations have full visibility into east-west cloud traffic, meaning once attackers breach the perimeter, they can move undetected within cloud environments.

Perhaps most worrying, while nearly seven in 10 organisations consider AI a strategic priority for cyber defence, only 25% feel prepared to counter AI-driven cyber-attacks, highlighting a critical capability gap.

Check Point’s research shows that the pace of technological change is creating dangerous blind spots, costing enterprises time and undermining progress, with 54% of firms saying it is proving difficult to keep up with evolving security challenges.

Those issues are being exacerbated further by a shortage of skilled security professionals (49%), poor platform integration (40%), insufficient budgets (33%) and overwhelming amounts of data (31%), all of which are further slowing response times. 


Recommended reading


To close these gaps, Check Point recommends a shift toward decentralised, prevention-first cloud security strategies, with firms encouraged to consolidate their toolsets, adopt AI-powered threat detection, and deploy real-time telemetry to gain full visibility across cloud environments.

“With attackers moving in minutes and defenders responding in days, the gap between detection and remediation is becoming a danger zone,” said Deryck Mitchelson, global CISO at Check Point.

“CISOs must consolidate fragmented tools into unified platforms, gain visibility into lateral movement, and prepare their teams and technologies to counter AI-driven threats, or risk ceding control of the cloud to increasingly sophisticated adversaries.”

Check Point’s study follows close behind a similar report from Gigamon, which found last month that nine in ten security and IT leaders are being forced to make compromises in securing and managing their hybrid cloud infrastructure as they deal with fragmented environments, outdated tools, and limited threat visibility.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data