Cloud security teams are in turmoil as attack surfaces expand at an alarming rate
This ITPro article examines how expanding cloud attack surfaces are creating operational strain for security teams. It highlights the need for stronger governance and visibility. Reach out to Five Nines IT Solutions Inc. to explore approaches to managing cloud security at scale.
Why are cloud attack surfaces expanding so quickly?
Cloud attack surfaces are expanding mainly because organizations are scaling their cloud environments to support AI initiatives at speed. As they do this, they introduce more services, APIs, identities, and data flows than their security teams can comfortably manage.
Recent research from Palo Alto Networks highlights how significant this shift has become:
- In a survey of more than 2,800 security executives and practitioners, 99% said they had experienced an attack against AI applications and services in the past year.
- 99% of respondents are using generative AI-assisted coding, which is helping developers ship features faster but is also producing insecure code faster than security teams can review it.
- Among the 52% of teams that ship code weekly, only 18% say they can keep up with fixing the vulnerabilities created by this pace and tooling.
As a result, organizations are unintentionally opening the door to new attack vectors. Attackers are increasingly focusing on the foundational layers of the cloud—API infrastructure, identity, and lateral network movement—where misconfigurations and weak controls are common when environments grow quickly.
For security leaders, this means cloud and AI strategies need to be tightly aligned with security from the start, not bolted on later. Otherwise, the speed of AI-driven development will continue to outpace the organization’s ability to secure what it builds.
Where are attackers focusing in modern cloud environments?
Attackers are reimagining how they go after cloud environments, shifting their focus to the underlying building blocks that many organizations rely on but don’t always secure rigorously.
Key focus areas include:
- API infrastructure: API attacks are up by 41%, making APIs a primary entry point for sophisticated threats. As more services and AI workloads expose APIs, each new endpoint becomes a potential doorway for attackers.
- Identity and access management (IAM): 53% of respondents cited lenient IAM practices as a top challenge. Insufficient access controls are now a leading vector for credential theft and data exfiltration. A related Okta study found 85% of security leaders now view IAM as a critical security focus, up from the previous year.
- Lateral network movement: Once attackers gain a foothold, they increasingly move laterally across cloud networks, taking advantage of overly permissive connectivity and fragmented visibility.
At the same time, tool sprawl is making it harder to see and respond to these threats:
- Organizations are managing an average of 17 cloud tools from different vendors.
- This fragmentation creates blind spots and context gaps, prompting 97% of respondents to prioritize consolidating their cloud security footprint.
For cloud and security teams, the takeaway is to rethink how they secure APIs and identities, and to reduce complexity where possible. Consolidated tooling and stronger IAM practices can help close off the paths attackers are using most often.
How fast are cloud attacks moving, and what does this mean for SOC teams?
Cloud attacks are getting dramatically faster, and many SOC teams are struggling to keep up with the pace.
Palo Alto Networks’ research shows a sharp shift in attack timelines:
- Breaches that took an average of 44 days in 2021 can now unfold in as little as 25 minutes.
At the same time, internal processes haven’t kept pace:
- Nearly 30% of respondents say it takes them more than a full day to resolve an incident.
- Disjointed workflows and isolated data sources between cloud and SOC teams are a major factor in these delays.
This mismatch—attackers operating at “machine speed” while defenders rely on fragmented tools and manual processes—creates a widening gap in response capability. It’s pushing organizations to rethink how they structure their security operations:
- 89% of organizations believe cloud and application security must be fully integrated with the SOC to be effective.
- There is growing recognition that teams need to move beyond dashboards and manual triage, toward more agentic, automated platforms that span code, cloud, and SOC workflows.
For SOC leaders, this means aligning cloud and SOC teams, consolidating tools where possible, and investing in automation that can help them operate closer to the speed of modern attacks.

Cloud security teams are in turmoil as attack surfaces expand at an alarming rate
published by Five Nines IT Solutions Inc.
Your business needs a solid technology platform upon which to build and operate. Despite all the hoopla, big monitors and fast computers are simply not enough. You need to consider the foundation and the underpinnings that make IT safe and reliable for your business.
Five Nines IT Solutions is here to blow away the smoke and to give you the straight goods. We'll help you find the weaknesses, plug the gaps, shore up your defences and keep an eye on things so that you can focus on your business. When you're ready, we'll work with you to move to the next level.
Five Nines delivers a team of IT professionals to work with you, your staff and your infrastructure. From strategic solution design and implementation through service and ongoing support, we combine best-of-breed hardware and software solutions with superlative technical expertise to provide you with the very best results.
Once everything is up to snuff, working well and helping you make money, the Five Nines offers "Help Desk as a Service" to watch your back as you move forward. With over a hundred highly-trained help desk mentors working from locations throughout Canada, top-notch support is available 24/7/365 to ensure you get the most out of your investment in technology.