Cloud security teams are in turmoil as attack surfaces expand at an alarming rate
This ITPro article examines how expanding cloud attack surfaces are creating operational strain for security teams. It highlights the need for stronger governance and visibility. Reach out to Digital6 Technologies to explore approaches to managing cloud security at scale.
Why are cloud attack surfaces expanding so quickly?
Cloud attack surfaces are expanding mainly because organizations are scaling their cloud environments to support AI initiatives at speed. As they do this, they introduce more services, APIs, identities, and data flows than their security teams can comfortably manage.
Recent research from Palo Alto Networks highlights how significant this shift has become:
- In a survey of more than 2,800 security executives and practitioners, 99% said they had experienced an attack against AI applications and services in the past year.
- 99% of respondents are using generative AI-assisted coding, which is helping developers ship features faster but is also producing insecure code faster than security teams can review it.
- Among the 52% of teams that ship code weekly, only 18% say they can keep up with fixing the vulnerabilities created by this pace and tooling.
As a result, organizations are unintentionally opening the door to new attack vectors. Attackers are increasingly focusing on the foundational layers of the cloud—API infrastructure, identity, and lateral network movement—where misconfigurations and weak controls are common when environments grow quickly.
For security leaders, this means cloud and AI strategies need to be tightly aligned with security from the start, not bolted on later. Otherwise, the speed of AI-driven development will continue to outpace the organization’s ability to secure what it builds.
Where are attackers focusing in modern cloud environments?
Attackers are reimagining how they go after cloud environments, shifting their focus to the underlying building blocks that many organizations rely on but don’t always secure rigorously.
Key focus areas include:
- API infrastructure: API attacks are up by 41%, making APIs a primary entry point for sophisticated threats. As more services and AI workloads expose APIs, each new endpoint becomes a potential doorway for attackers.
- Identity and access management (IAM): 53% of respondents cited lenient IAM practices as a top challenge. Insufficient access controls are now a leading vector for credential theft and data exfiltration. A related Okta study found 85% of security leaders now view IAM as a critical security focus, up from the previous year.
- Lateral network movement: Once attackers gain a foothold, they increasingly move laterally across cloud networks, taking advantage of overly permissive connectivity and fragmented visibility.
At the same time, tool sprawl is making it harder to see and respond to these threats:
- Organizations are managing an average of 17 cloud tools from different vendors.
- This fragmentation creates blind spots and context gaps, prompting 97% of respondents to prioritize consolidating their cloud security footprint.
For cloud and security teams, the takeaway is to rethink how they secure APIs and identities, and to reduce complexity where possible. Consolidated tooling and stronger IAM practices can help close off the paths attackers are using most often.
How fast are cloud attacks moving, and what does this mean for SOC teams?
Cloud attacks are getting dramatically faster, and many SOC teams are struggling to keep up with the pace.
Palo Alto Networks’ research shows a sharp shift in attack timelines:
- Breaches that took an average of 44 days in 2021 can now unfold in as little as 25 minutes.
At the same time, internal processes haven’t kept pace:
- Nearly 30% of respondents say it takes them more than a full day to resolve an incident.
- Disjointed workflows and isolated data sources between cloud and SOC teams are a major factor in these delays.
This mismatch—attackers operating at “machine speed” while defenders rely on fragmented tools and manual processes—creates a widening gap in response capability. It’s pushing organizations to rethink how they structure their security operations:
- 89% of organizations believe cloud and application security must be fully integrated with the SOC to be effective.
- There is growing recognition that teams need to move beyond dashboards and manual triage, toward more agentic, automated platforms that span code, cloud, and SOC workflows.
For SOC leaders, this means aligning cloud and SOC teams, consolidating tools where possible, and investing in automation that can help them operate closer to the speed of modern attacks.

Cloud security teams are in turmoil as attack surfaces expand at an alarming rate
published by Digital6 Technologies
We are the go-to specialists to help small to mid-sized businesses and start-ups establish and maintain a credible online presence. Our training and experience ensure excellence in web development, mobile apps and web apps.
Digital6 expertise is solid. Our diverse team includes certified solutions architects for Microsoft Azure and Amazon Web Services and certified Microsoft Trainers. As a member of the Microsoft Cloud Solution Provider Program, we can also directly manage all the subscription and support services for Office 365 and Azure.
Because we specialize in cloud computing, Digital6 can support businesses in all industries to take advantage of the latest technology to open new opportunities. We help work through the decision to migrate to the cloud and then build the best cloud architecture possible on Azure or AWS.
At Digital6 we understand that moving to the cloud requires assurances about security, data backup and disaster recovery plans. We have every confidence that, whichever cloud solution is chosen, we can provide the software to make sure file management is reliable and secure with safeguards for seamless business continuity.
We respect the need for cost effectiveness and are pleased to provide proof of concept data necessary for compiling a sound business case. Our Digital6 Technologies team is engaged with our clients from the initial inquiry, through assessing needs, customizing cloud architecture and implementing the migration strategy to building in all the protection plans and software. We provide complete, integrated cloud cover for all business needs.