State of Security 2026: Cloud Security

proudly sponsored by
Sumo Logic

The shift to the cloud has relieved organisations of the complexity of managing their own infrastructure, but it has introduced an entirely new set of challenges. As CISOs look out across technology landscapes that span multiple public clouds, hybrid environments, and SaaS providers, they face the need to maintain the security of a complex and diverse environment.

The cloud now dominates new workload deployment, accounting for the majority of IT spending and hosting a growing share of enterprise data. Forrester’s Data And Analytics Survey, 2025 for example reported that 62 percent of enterprise data was now stored in the cloud.

The result is that some enterprises now operate hundreds of sanctioned cloud services, alongside many more that remain undocumented.

This fragmentation has forced a fundamental rethink of how cloud security is managed. Identity has emerged as an important battle ground for cyber defenders, supplanting the network as the key point of vulnerability.

The problem is no longer unauthorised access to the network, but authorised access used in unauthorised ways. This has driven the adoption of zero trust principles, and increased investment in the tools required to enforce them across cloud environments.

This shift is also reshaping investment patterns for cloud security. One of the clearest beneficiaries have been makers of identity and access management (IAM) controls, as CISOs prioritise identity as the foundation of security. According to Forrester, spending on identity and access management (IAM) is growing at around 15 percent annually, significantly faster than the broader security market, and is estimated to be worth US$27.5 billion ($39.5 billion) by 2029.

Closely related to the rise of IAM as a key protection for cloud workloads is the growing market for identity threat detection and response (ITDR) tools, which focus specifically on detecting and responding to identity misuse, including attack vectors such as lateral movement and privilege escalation.

The rise of ITDR reflects a recognition that identity has become a primary attack surface requiring specialised detection and response capabilities. Markets and Markets already estimates ITDR as having been worth US$12.8 billion ($18.4 billion) in 2024, rising to US$35.6 billion ($51.1 billion) in 2029.

Expansion of this market is expected to be further fuelled by growth in machine identities, including the use of APIs, service accounts, and containers and microservices, as well as growth in bots, scripts, automation tools – and AI agents.

Another significant growth area for cloud security are cloud-native application protection platforms (CNAPP), which according to Gartner, describe a unified and tightly integrated set of security and compliance capabilities spanning cloud-native infrastructure and applications.

CNAPP brings together various product categories including cloud security posture management, cloud workload protection, entitlement management, and various other security tools to create a control layer for securing cloud workloads, reflecting a shift from fragmented tooling to integrated, cloud-native protection.

According to IDC, the CNAPP market will grow swiftly from 2024 to 2029, reaching US$14.7 billion ($21.1 billion) in revenue by 2029.

One further area of growth in cloud security is in the use of zero trust network access (ZTNA) as a means to access cloud services, displacing traditional VPNs. ZTNA has become central to cloud security because it replaces network-based access with identity-based control.

This aligns directly with zero trust principles and significantly reduces the risk of lateral movement, making ZTNA a foundational access layer for securing modern cloud environments.

Taken together, these shifts point to a fundamental change in how security is conceived and implemented. The growth of cloud has rewritten existing architecture, meaning security is embedded across identities, applications, and interactions.

The complexity of cloud environments is unlikely to diminish, and both human and machine identities are proliferating. In response, the tools and architectures emerging to address these challenges are becoming more integrated, more automated, and more aligned to the realities of distributed systems.

In a world where attackers are logging in rather than breaking in, the effectiveness of cloud security will be determined not by how well organisations defend their networks, but by how well they govern identity, enforce access, and detect misuse in real time.

Cloud Security Champion

Browse by Category

Click on the tiles below to see how each of the categories are responding to security threats in their sector.

Security Champions

The 2026 State of Security sponsors have worked tirelessly to improve the safety of end user organisations.

We are proud to present this year's State of Security champions, and showcase the work they do.

Sumo Logic
Saviynt
Virtual IT GroupVirtual IT Group
Coreview
Brennan
Checkmarx
AUSCERT

Log In

  |  Forgot your password?