SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Enterprises still rely on manual cloud security policies

Enterprises still rely on manual cloud security policies

Thu, 20th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

A Cloud Security Alliance survey has found that most enterprises still manage hybrid and multi-cloud security policies through manual or reactive processes. Commissioned by AlgoSec, the study drew responses from 515 IT and security professionals.

The findings highlight a gap between the complexity of modern IT estates and how many organisations manage the rules governing application connectivity, access and compliance. Only 9% of respondents said security policy management was fully integrated into development and deployment workflows, while 61% said their organisations still rely on manual or reactive approaches.

That shortfall appears to be affecting production systems. Some 65% of organisations had suffered at least one business-critical application outage caused by a misconfigured security policy over the past year, while 46% reported two or more such incidents.

Nearly half of respondents, 48%, described their security policy changes as mostly or fully manual. Manual configuration errors were identified as the biggest bottleneck to deploying new applications.

Fragmented ownership

The survey suggests these problems are linked to how responsibility is divided across multiple teams. Security operations was cited by 51% of respondents as responsible for security policy management, while network operations and cloud architects were each cited by 46%, and DevOps by 41%.

The same fragmentation is reflected in the tools organisations use. More than two-thirds, 67%, said they work across three or more security management consoles each day, making it harder to maintain a consistent view of policy across environments.

Visibility was another recurring issue. A total of 92% of organisations said they had at least some difficulty obtaining a single, accurate view of policies across their environments, suggesting many teams are making changes without a complete picture of the effects.

Respondents also identified risk analysis before a policy change as the improvement most likely to help security policy management. Some 32% chose that option, more than twice the rate of any other capability listed in the survey.

"What was once primarily a network-configuration problem has become an application-connectivity problem. The traditional, infrastructure-centric approach, defining policy device by device and rule by rule, is increasingly ill-suited to today's environment," said Hillary Baron, AVP of Research, Cloud Security Alliance.

"Organisations that want to close this gap need to rethink the way they approach connectivity as an operational model centered on the applications they run, rather than simply adding more tools or effort to a model that is already straining under demands it was never designed to handle," Baron said.

Compliance strain

The survey also examined how organisations handle compliance in frequently changing environments. Manual review was the most common compliance posture, cited by 40% of respondents. Yet 25% said their organisations had failed a compliance audit or received an audit finding over the past year.

The result suggests manual checks are not keeping pace with hybrid and multi-cloud operations, where policy changes may need to be assessed across several platforms and teams. The report linked weak visibility and fragmented ownership to longer remediation periods and inconsistent compliance outcomes.

Budget pressures may limit how far organisations can respond by simply spending more. Fewer than half of respondents, 44%, said they expected a budget increase in 2026, even though only a small minority had fully integrated policy management into development and deployment processes.

The report argues that the issue is less about adding technology than changing operating models. It points to a need for a more connected approach that ties policy management more closely to application delivery while reducing reliance on manual intervention and siloed teams.

For AlgoSec, which commissioned the research, the findings show that many organisations are trying to manage rising complexity without first establishing a clear picture of risk and policy impact.

"Closing the gap won't come from adding more tools or asking teams to work harder. It requires a fundamentally more connected approach to policy-one that gives organizations a unified view, anticipates risk before changes are made, automates routine work, and keeps compliance evidence current," said Eran Shiff, Chief Product Officer, AlgoSec.

"These capabilities build on one another to create a more predictable and resilient way to manage policy across today's complex environments," Shiff said.

CSA said its analysts conducted the data analysis and interpretation after collecting online responses from organisations of different sizes and locations.