Machine identities now outnumber humans 40,000 to 1, presenting major challenges to enterprise security, according to a new report from cloud security platform Sysdig.
The firm’s 2025 Cloud-Native Security and Usage Report found that the explosion in machine identity numbers has dramatically expanded attack surfaces for businesses, with machine identities 7.5 times more risky than human counterparts.
According to the report, the average organisation manages around 915 users and 41,605 service accounts, with excessive permissions across networks leading to increasing risks of cloud breach and opportunities for malicious access.
However, the study also found that nearly 15% of organisations have no connected user accounts, likely due to the use of third-party SSO verification processes for human users to log into cloud accounts rather than traditional local user and password combinations, which Sysdig claims is a sign of improving security maturity.
Overall, the report found that cloud defenders are gaining ground, with organisations of every size and industry across regions including North America, Europe, Asia-Pacific and Japan making measurable strides in identity and vulnerability management, artificial AI security, and threat detection.
The data shows that mature security teams are now detecting threats in under five seconds and initiating response actions within 3.5 minutes on average – outpacing the 10-minute cloud attack window that has historically given adversaries the upper hand.
Moreover, despite workloads using AI and machine learning packages growing by 500% over the last year, public exposure decreased by 38%, signaling a strong commitment to secure AI implementations.
Sysdig also found that in-use vulnerabilities have declined to less than 6%, reflecting a 64% improvement in vulnerability management over the past two years, which the study claims shows that firms are refining their approach to fixing vulnerabilities actively running in production workloads.
However, despite that decline, the report also highlights the problems posed by container image bloat, with the size of container images having quintupled, introducing unnecessary security risks and operational inefficiencies due to the increase in attack surfaces.
Recommended reading
- Cloud Spending Surged By 21% Last Quarter
- Cybersecurity and Cloud Still Top Priorities for Financial Firms
- Caution Over Cloud Adoption Is Holding UK Businesses Back
Sysdig’s study found that the shortened lifespans of containers are also posing risks, with 74% of containers now live for five minutes or less, and 60% live for one minute or less.
These containers, vital to the smooth running of cloud infrastructure, are used for brief tasks like running only a portion of a script or process that happens very quickly, such as batch processing or test execution, enhancing application agility, but also allows cloud adversaries to automate their reconnaissance to instantly identify and exploit weaknesses.
“When we first looked at container life spans in 2019, half lasted at least five minutes – today, 60% live for one minute or less,” said Loris Degioanni, Sysdig Founder and CTO.
“Given the short life span paired with how quickly attackers can move across cloud environments, I am encouraged to see defenders actively detecting and responding to threats in less than ten minutes.”





