ChaptersEventsBlog

Download Publication

State of Cloud Security Risk, Compliance, and Misconfigurations
State of Cloud Security Risk, Compliance, and Misconfigurations

State of Cloud Security Risk, Compliance, and Misconfigurations

Release Date: 09/17/2021

Cloud misconfigurations consistently are a top concern for organizations utilizing public cloud. Such errors lead to data breaches, allow the deletion or modification of resources, cause service interruptions, and otherwise wreak havoc on business operations. With recent breaches due to misconfigurations making major headlines, this survey was conducted to better understand the current state of cloud security programs, tools utilized to mitigate security risks, organizations’ cloud security posture, and barriers organizations face in reducing security risks.

The goal of this survey is to assess organizational readiness for mitigating public cloud security and compliance risks due to configuration mistakes. 

Key research topics include:
  • Current state of cloud security programs, including top risks and usage of security tools
  • Cloud Security Posture Management (CSPM) challenges faced by organizations in mitigating misconfiguration vulnerabilities
  • Organizational readiness, success KPIs, and teams responsible for different aspects of cloud security posture management
Key findings from the survey:
  1. Lack of knowledge and expertise continues to plague security teams
  2. Information security and IT operations are held responsible for reducing cloud misconfigurations
  3. DevSecOps approach to security is still out of reach
Download this Resource

Bookmark
Share
View translations
Related resources
 Cloud Controls Matrix and CAIQ v4.1
Cloud Controls Matrix and CAIQ v4.1
The State of Non-Human Identity and AI Security
The State of Non-Human Identity and AI Security
Introductory Guidance to AICM
Introductory Guidance to AICM
AI Governance Framework Adoption in Cloud-Native AI Systems: Phased Approach and Considerations
AI Governance Framework Adoption in Cloud-Native AI Systems: Phased...
Published: 01/27/2026
Agentic AI Pen Testing: Speed at Scale, Certainty with Humans
Agentic AI Pen Testing: Speed at Scale, Certainty with Humans
Published: 01/26/2026
Securing AI in CMMC Level 2 Environments: A Strategic Guide for CISOs and Cloud Security Engineers
Securing AI in CMMC Level 2 Environments: A Strategic Guide for CIS...
Published: 01/23/2026
How Organizations are Addressing Cloud Investigation and Response
How Organizations are Addressing Cloud Investigation and Response
Published: 01/22/2026

Interested in helping develop research with CSA?

Related Certificates & Training