Cloud security teams are in turmoil as attack surfaces expand at an alarming rate
This ITPro article examines how expanding cloud attack surfaces are creating operational strain for security teams. It highlights the need for stronger governance and visibility. Reach out to Precoh to explore approaches to managing cloud security at scale.
Why are cloud attack surfaces expanding so quickly?
Cloud attack surfaces are expanding mainly because organizations are scaling their cloud environments to support AI initiatives at speed. As they do this, they introduce more services, APIs, identities, and data flows than their security teams can comfortably manage.
Recent research from Palo Alto Networks highlights how significant this shift has become:
- In a survey of more than 2,800 security executives and practitioners, 99% said they had experienced an attack against AI applications and services in the past year.
- 99% of respondents are using generative AI-assisted coding, which is helping developers ship features faster but is also producing insecure code faster than security teams can review it.
- Among the 52% of teams that ship code weekly, only 18% say they can keep up with fixing the vulnerabilities created by this pace and tooling.
As a result, organizations are unintentionally opening the door to new attack vectors. Attackers are increasingly focusing on the foundational layers of the cloud—API infrastructure, identity, and lateral network movement—where misconfigurations and weak controls are common when environments grow quickly.
For security leaders, this means cloud and AI strategies need to be tightly aligned with security from the start, not bolted on later. Otherwise, the speed of AI-driven development will continue to outpace the organization’s ability to secure what it builds.
Where are attackers focusing in modern cloud environments?
Attackers are reimagining how they go after cloud environments, shifting their focus to the underlying building blocks that many organizations rely on but don’t always secure rigorously.
Key focus areas include:
- API infrastructure: API attacks are up by 41%, making APIs a primary entry point for sophisticated threats. As more services and AI workloads expose APIs, each new endpoint becomes a potential doorway for attackers.
- Identity and access management (IAM): 53% of respondents cited lenient IAM practices as a top challenge. Insufficient access controls are now a leading vector for credential theft and data exfiltration. A related Okta study found 85% of security leaders now view IAM as a critical security focus, up from the previous year.
- Lateral network movement: Once attackers gain a foothold, they increasingly move laterally across cloud networks, taking advantage of overly permissive connectivity and fragmented visibility.
At the same time, tool sprawl is making it harder to see and respond to these threats:
- Organizations are managing an average of 17 cloud tools from different vendors.
- This fragmentation creates blind spots and context gaps, prompting 97% of respondents to prioritize consolidating their cloud security footprint.
For cloud and security teams, the takeaway is to rethink how they secure APIs and identities, and to reduce complexity where possible. Consolidated tooling and stronger IAM practices can help close off the paths attackers are using most often.
How fast are cloud attacks moving, and what does this mean for SOC teams?
Cloud attacks are getting dramatically faster, and many SOC teams are struggling to keep up with the pace.
Palo Alto Networks’ research shows a sharp shift in attack timelines:
- Breaches that took an average of 44 days in 2021 can now unfold in as little as 25 minutes.
At the same time, internal processes haven’t kept pace:
- Nearly 30% of respondents say it takes them more than a full day to resolve an incident.
- Disjointed workflows and isolated data sources between cloud and SOC teams are a major factor in these delays.
This mismatch—attackers operating at “machine speed” while defenders rely on fragmented tools and manual processes—creates a widening gap in response capability. It’s pushing organizations to rethink how they structure their security operations:
- 89% of organizations believe cloud and application security must be fully integrated with the SOC to be effective.
- There is growing recognition that teams need to move beyond dashboards and manual triage, toward more agentic, automated platforms that span code, cloud, and SOC workflows.
For SOC leaders, this means aligning cloud and SOC teams, consolidating tools where possible, and investing in automation that can help them operate closer to the speed of modern attacks.

Cloud security teams are in turmoil as attack surfaces expand at an alarming rate
published by Precoh
The latest AI and technology news from Precoh - Advisory Work. Regulatory Platform. Together.
We share the most compelling AI, machine learning, products and technology news from across healthcare and life science business sectors.
Precoh provides expert consulting on clinical AI readiness and health data infrastructure — and the RegOS platform that turns that work into structured, defensible regulatory execution.
Most organizations need both: the expert advisory work to get AI-ready, and the regulatory infrastructure to evaluate, approve, and scale what they build. Precoh delivers both — and the two are designed to compound.
Learn how we work at https://precoh.ai/pages/services.html