Cloud security teams are in turmoil as attack surfaces expand at an alarming rate
This ITPro article examines how expanding cloud attack surfaces are creating operational strain for security teams. It highlights the need for stronger governance and visibility. Reach out to TechnologyXperts, Inc. to explore approaches to managing cloud security at scale.
Why are cloud attack surfaces expanding so quickly?
Cloud attack surfaces are expanding mainly because organizations are scaling their cloud environments to support AI initiatives at speed. As they do this, they introduce more services, APIs, identities, and data flows than their security teams can comfortably manage.
Recent research from Palo Alto Networks highlights how significant this shift has become:
- In a survey of more than 2,800 security executives and practitioners, 99% said they had experienced an attack against AI applications and services in the past year.
- 99% of respondents are using generative AI-assisted coding, which is helping developers ship features faster but is also producing insecure code faster than security teams can review it.
- Among the 52% of teams that ship code weekly, only 18% say they can keep up with fixing the vulnerabilities created by this pace and tooling.
As a result, organizations are unintentionally opening the door to new attack vectors. Attackers are increasingly focusing on the foundational layers of the cloud—API infrastructure, identity, and lateral network movement—where misconfigurations and weak controls are common when environments grow quickly.
For security leaders, this means cloud and AI strategies need to be tightly aligned with security from the start, not bolted on later. Otherwise, the speed of AI-driven development will continue to outpace the organization’s ability to secure what it builds.
Where are attackers focusing in modern cloud environments?
Attackers are reimagining how they go after cloud environments, shifting their focus to the underlying building blocks that many organizations rely on but don’t always secure rigorously.
Key focus areas include:
- API infrastructure: API attacks are up by 41%, making APIs a primary entry point for sophisticated threats. As more services and AI workloads expose APIs, each new endpoint becomes a potential doorway for attackers.
- Identity and access management (IAM): 53% of respondents cited lenient IAM practices as a top challenge. Insufficient access controls are now a leading vector for credential theft and data exfiltration. A related Okta study found 85% of security leaders now view IAM as a critical security focus, up from the previous year.
- Lateral network movement: Once attackers gain a foothold, they increasingly move laterally across cloud networks, taking advantage of overly permissive connectivity and fragmented visibility.
At the same time, tool sprawl is making it harder to see and respond to these threats:
- Organizations are managing an average of 17 cloud tools from different vendors.
- This fragmentation creates blind spots and context gaps, prompting 97% of respondents to prioritize consolidating their cloud security footprint.
For cloud and security teams, the takeaway is to rethink how they secure APIs and identities, and to reduce complexity where possible. Consolidated tooling and stronger IAM practices can help close off the paths attackers are using most often.
How fast are cloud attacks moving, and what does this mean for SOC teams?
Cloud attacks are getting dramatically faster, and many SOC teams are struggling to keep up with the pace.
Palo Alto Networks’ research shows a sharp shift in attack timelines:
- Breaches that took an average of 44 days in 2021 can now unfold in as little as 25 minutes.
At the same time, internal processes haven’t kept pace:
- Nearly 30% of respondents say it takes them more than a full day to resolve an incident.
- Disjointed workflows and isolated data sources between cloud and SOC teams are a major factor in these delays.
This mismatch—attackers operating at “machine speed” while defenders rely on fragmented tools and manual processes—creates a widening gap in response capability. It’s pushing organizations to rethink how they structure their security operations:
- 89% of organizations believe cloud and application security must be fully integrated with the SOC to be effective.
- There is growing recognition that teams need to move beyond dashboards and manual triage, toward more agentic, automated platforms that span code, cloud, and SOC workflows.
For SOC leaders, this means aligning cloud and SOC teams, consolidating tools where possible, and investing in automation that can help them operate closer to the speed of modern attacks.

Cloud security teams are in turmoil as attack surfaces expand at an alarming rate
published by TechnologyXperts, Inc.
TechnologyXperts, Inc. is an Ohio registered corporation established in 1999 providing comprehensive IT services to enterprises of all sizes handling all aspects of computer desktop, server, network and telecommunications needs. We are a business enabler that helps companies achieve their business goals and objectives through the economical and effective use of information technology in their environment. We are trusted partners/advisors helping small and medium size businesses maximize their return on their IT investment while minimizing related IT expense. Our comprehensive and proactive approach towards IT management helps our customers minimize the risk inherent when a business depends upon IT to get work done. Our innovative approach towards managing IT smartly and cost-effectively is built upon years of management experience leading a crack team of business savvy, technical consultants in a wide range of business situations. Helping businesses leverage the latest technologies for maximum business effect is the key. Our business is IT. With TXI, you can get out of the IT business and get on with what really counts.