Cloud security teams are in turmoil as attack surfaces expand at an alarming rate
This ITPro article examines how expanding cloud attack surfaces are creating operational strain for security teams. It highlights the need for stronger governance and visibility. Reach out to Guden Limited to explore approaches to managing cloud security at scale.
Why are cloud attack surfaces expanding so quickly?
Cloud attack surfaces are expanding mainly because organizations are scaling their cloud environments to support AI initiatives at speed. As they do this, they introduce more services, APIs, identities, and data flows than their security teams can comfortably manage.
Recent research from Palo Alto Networks highlights how significant this shift has become:
- In a survey of more than 2,800 security executives and practitioners, 99% said they had experienced an attack against AI applications and services in the past year.
- 99% of respondents are using generative AI-assisted coding, which is helping developers ship features faster but is also producing insecure code faster than security teams can review it.
- Among the 52% of teams that ship code weekly, only 18% say they can keep up with fixing the vulnerabilities created by this pace and tooling.
As a result, organizations are unintentionally opening the door to new attack vectors. Attackers are increasingly focusing on the foundational layers of the cloud—API infrastructure, identity, and lateral network movement—where misconfigurations and weak controls are common when environments grow quickly.
For security leaders, this means cloud and AI strategies need to be tightly aligned with security from the start, not bolted on later. Otherwise, the speed of AI-driven development will continue to outpace the organization’s ability to secure what it builds.
Where are attackers focusing in modern cloud environments?
Attackers are reimagining how they go after cloud environments, shifting their focus to the underlying building blocks that many organizations rely on but don’t always secure rigorously.
Key focus areas include:
- API infrastructure: API attacks are up by 41%, making APIs a primary entry point for sophisticated threats. As more services and AI workloads expose APIs, each new endpoint becomes a potential doorway for attackers.
- Identity and access management (IAM): 53% of respondents cited lenient IAM practices as a top challenge. Insufficient access controls are now a leading vector for credential theft and data exfiltration. A related Okta study found 85% of security leaders now view IAM as a critical security focus, up from the previous year.
- Lateral network movement: Once attackers gain a foothold, they increasingly move laterally across cloud networks, taking advantage of overly permissive connectivity and fragmented visibility.
At the same time, tool sprawl is making it harder to see and respond to these threats:
- Organizations are managing an average of 17 cloud tools from different vendors.
- This fragmentation creates blind spots and context gaps, prompting 97% of respondents to prioritize consolidating their cloud security footprint.
For cloud and security teams, the takeaway is to rethink how they secure APIs and identities, and to reduce complexity where possible. Consolidated tooling and stronger IAM practices can help close off the paths attackers are using most often.
How fast are cloud attacks moving, and what does this mean for SOC teams?
Cloud attacks are getting dramatically faster, and many SOC teams are struggling to keep up with the pace.
Palo Alto Networks’ research shows a sharp shift in attack timelines:
- Breaches that took an average of 44 days in 2021 can now unfold in as little as 25 minutes.
At the same time, internal processes haven’t kept pace:
- Nearly 30% of respondents say it takes them more than a full day to resolve an incident.
- Disjointed workflows and isolated data sources between cloud and SOC teams are a major factor in these delays.
This mismatch—attackers operating at “machine speed” while defenders rely on fragmented tools and manual processes—creates a widening gap in response capability. It’s pushing organizations to rethink how they structure their security operations:
- 89% of organizations believe cloud and application security must be fully integrated with the SOC to be effective.
- There is growing recognition that teams need to move beyond dashboards and manual triage, toward more agentic, automated platforms that span code, cloud, and SOC workflows.
For SOC leaders, this means aligning cloud and SOC teams, consolidating tools where possible, and investing in automation that can help them operate closer to the speed of modern attacks.

Cloud security teams are in turmoil as attack surfaces expand at an alarming rate
published by Guden Limited
Gudens helps global companies modernize IT, optimize data architectures, and ensure security and scalability across public, private, and hybrid clouds, so they can run their mission-critical systems and operations with confidence.
Why Gudens?
We are experts in cloud computing, with a deep understanding of the latest technologies and trends.
We offer tailored support for businesses of all sizes, from startups to Fortune 500 companies.
We are committed to helping our customers achieve their business goals through cloud computing.
Our services:
Cloud readiness assessment
Cloud strategy
Cloud migration
Cloud service ROI
Whether you are just starting out with cloud computing or looking to optimize your existing cloud environment, Gudens can help you every step of the way.
Contact us today to learn more about how we can help you achieve your cloud computing and digital transformation goals.