Fortinet survey findings reported by TechRadar and CIO indicate that expanding hybrid and multi-cloud adoption—often tied to broader AI initiatives—is widening organizations’ cloud attack surfaces while security operations struggle with tool sprawl and limited end-to-end visibility. The research reports 88% of organizations operate hybrid or multi-cloud environments, and 81% rely on two or more cloud providers for critical workloads, increasing complexity across identities, permissions, configurations, and data paths.
The survey highlights persistent capability gaps: 69% cite cloud security barriers driven by tool sprawl and visibility gaps, and 59% say their cloud security maturity remains in early/developing stages. Confidence in real-time detection and response is weak (66% lack strong confidence), and automation is largely limited to alerting, with only 11% reporting autonomous remediation. The top anticipated risk areas are identity and access management (77%), misconfigurations/cloud security posture (70%), and data exposure (66%); Fortinet also notes cloud incidents often result from chained weaknesses along an “exposure path” (e.g., misconfiguration plus excessive privileges leading to sensitive data access). Despite these gaps, 62% expect cloud security budgets to increase, averaging 34% of IT security budgets, with Fortinet recommending unified visibility, tool consolidation, connecting risk domains, and greater automation to reduce operational burden and improve response.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
SC Media reported on Fortinet's findings that tool sprawl, limited visibility, and low confidence in real-time detection and response are hindering cloud security. The coverage emphasized that automation remains mostly limited to alerting and that integrated platforms and stronger automation are needed as cloud attack surfaces expand.
Fortinet reported that organizations are increasing cloud security investment, with many expecting budget growth, but 59% still rate their cloud security maturity as only early or developing. The findings also highlighted widespread hybrid and multi-cloud use, tool sprawl, visibility gaps, and leading risks around identity and access, misconfigurations, and data exposure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.