State of Security 2026: Cloud Security

proudly sponsored by
Sumo Logic

The shift to the cloud has relieved organisations of the complexity of managing their own infrastructure, but it has introduced an entirely new set of challenges. As CISOs look out across technology landscapes that span multiple public clouds, hybrid environments, and SaaS providers, they face the need to maintain the security of a complex and diverse environment.

The cloud now dominates new workload deployment, accounting for the majority of IT spending and hosting a growing share of enterprise data. Forrester’s Data And Analytics Survey, 2025 for example reported that 62 percent of enterprise data was now stored in the cloud.

The result is that some enterprises now operate hundreds of sanctioned cloud services, alongside many more that remain undocumented.

This fragmentation has forced a fundamental rethink of how cloud security is managed. Identity has emerged as an important battle ground for cyber defenders, supplanting the network as the key point of vulnerability.

The problem is no longer unauthorised access to the network, but authorised access used in unauthorised ways. This has driven the adoption of zero trust principles, and increased investment in the tools required to enforce them across cloud environments.

This shift is also reshaping investment patterns for cloud security. One of the clearest beneficiaries have been makers of identity and access management (IAM) controls, as CISOs prioritise identity as the foundation of security. According to Forrester, spending on identity and access management (IAM) is growing at around 15 percent annually, significantly faster than the broader security market, and is estimated to be worth US$27.5 billion ($39.5 billion) by 2029.

Closely related to the rise of IAM as a key protection for cloud workloads is the growing market for identity threat detection and response (ITDR) tools, which focus specifically on detecting and responding to identity misuse, including attack vectors such as lateral movement and privilege escalation.

The rise of ITDR reflects a recognition that identity has become a primary attack surface requiring specialised detection and response capabilities. Markets and Markets already estimates ITDR as having been worth US$12.8 billion ($18.4 billion) in 2024, rising to US$35.6 billion ($51.1 billion) in 2029.

Expansion of this market is expected to be further fuelled by growth in machine identities, including the use of APIs, service accounts, and containers and microservices, as well as growth in bots, scripts, automation tools – and AI agents.

Another significant growth area for cloud security are cloud-native application protection platforms (CNAPP), which according to Gartner, describe a unified and tightly integrated set of security and compliance capabilities spanning cloud-native infrastructure and applications.

 

CNAPP brings together various product categories including cloud security posture management, cloud workload protection, entitlement management, and various other security tools to create a control layer for securing cloud workloads, reflecting a shift from fragmented tooling to integrated, cloud-native protection.

According to IDC, the CNAPP market will grow swiftly from 2024 to 2029, reaching US$14.7 billion ($21.1 billion) in revenue by 2029.

One further area of growth in cloud security is in the use of zero trust network access (ZTNA) as a means to access cloud services, displacing traditional VPNs. ZTNA has become central to cloud security because it replaces network-based access with identity-based control.

This aligns directly with zero trust principles and significantly reduces the risk of lateral movement, making ZTNA a foundational access layer for securing modern cloud environments.

Taken together, these shifts point to a fundamental change in how security is conceived and implemented. The growth of cloud has rewritten existing architecture, meaning security is embedded across identities, applications, and interactions.

The complexity of cloud environments is unlikely to diminish, and both human and machine identities are proliferating. In response, the tools and architectures emerging to address these challenges are becoming more integrated, more automated, and more aligned to the realities of distributed systems.

In a world where attackers are logging in rather than breaking in, the effectiveness of cloud security will be determined not by how well organisations defend their networks, but by how well they govern identity, enforce access, and detect misuse in real time.

 

Case Study – Perseus Mining

Potential instability in its operating markets has compelled the ASX-listed gold producer Perseus Mining to strengthen its cloud-based posture, as the company focuses on resilience and accessibility as key planks of its cybersecurity strategy.

Despite being headquartered in Perth, Perseus Mining operates entirely outside of Australia with mining projects spread across West Africa and another under development in Tanzania, as well as having an additional corporate office in Dubai.

Over the past five years the company has undertaken a significant cloud migration to reduce the risk posed by on-premises infrastructure.

According to Perseus’ general manager for technology, Stacey Squire, that geographic footprint and its inherent risk of power outages and fibre disruptions has shaped the company’s cybersecurity priorities.

“The goal (of cloud migration) was to give us room to maintain and improve access to our information should we lose access to a site,” Squire said.

“In the worst-case scenario it made sense that we could sustain operations by moving infrastructure, processing, storage, and backups, and all of those systems into the cloud, because it was infinitely more accessible and adaptable.”

Recently Squire has intensified the company’s focus on how those cloud assets were secured, with a layered security model built around native cloud controls, endpoint protection, application whitelisting, and multi-layered backup systems. Content monitoring across platforms such as email and SharePoint is used to detect and block sensitive data in transit.

“We don't take an all-in approach, so we do have quite a number of platforms in play,” Squire said.

“Overall I feel that we are in a relatively advanced place from a cyber maturity perspective.”

The company had also outsourced key security functions, including SOC and SIEM capabilities, to managed providers, reflecting a broader strategy to “commoditise” foundational IT services.

“I can’t sit up all night monitoring systems, and I don’t think we can do it better than a third party,” Squire said.

By standardising and offloading commodity IT services, Squire said the company could  now respond faster to both geopolitical and operational requirements.

The company had also increased scrutiny on suppliers and partners, reflecting growing concern that third-party risk can undermine even well-secured internal environments. Although not formally captured under Australia’s Security of Critical Infrastructure (SOCI) Act 2018, Squire said Perseus had voluntarily aligned its security posture with the legislation’s principles, applying critical infrastructure-style controls across its offshore operations.

A key focus for securing the cloud environment has been identity management. Squire described the company’s previous approach as fragmented, due in part to it having operated multiple payroll platforms, while also managing cultural naming conventions. That identity consolidation had become a cornerstone of Perseus’ security model, ensuring access was tied more tightly to role and organisational structure.

Squire said consolidating identity in the cloud enabled tighter governance and clearer alignment between roles and permissions.

“That was really difficult to establish when running on-prem environments, because you don't necessarily have the same attention to detail,” he said.

“Having this one system allowed us to build out the entire hierarchy of how the people and structure went together.”

Furthermore, he said simplifying the technology stack and reducing vendor sprawl had improved its security posture, allowing Perseus to respond faster to emerging risks.

Squire acknowledged that the balance between security and accessibility remained delicate, especially when many functions were managed remotely across multiple time zones and languages. However, he said the company had come to see usability itself as a frontline security control.

“There’s a fine line between protecting data and making it so hard to access that it stops generating value,” Squire said.

“If you can make your system convenient enough that shadow IT doesn’t appear to be an attractive option to bypass your controls you are doing pretty well.”

 

Cloud Security Champion

Browse by Category

Click on the tiles below to see how each of the categories are responding to security threats in their sector.

Security Champions

The 2026 State of Security sponsors have worked tirelessly to improve the safety of end user organisations.

We are proud to present this year's State of Security champions, and showcase the work they do.

Sumo Logic
Saviynt
Virtual IT GroupVirtual IT Group
Coreview
Brennan
Checkmarx
AUSCERT

Log In

  |  Forgot your password?