TL;DR: 80% of organisations store sensitive data in the cloud, 53% experienced a cloud infrastructure cyberattack in the prior 12 months, and 49% saw unplanned remediation costs after an attack, according to Netwrix’s 2022 survey of 720 IT professionals. The governance gap is not cloud adoption itself, but the fact that data, access, and detection controls are still maturing unevenly.
At a glance
What this is: This 2022 survey shows that cloud adoption is still rising while cloud data security, incident exposure, and remediation cost pressures remain persistent.
Why it matters: It matters because IAM, PAM, and cloud security teams have to govern data exposure, entitlements, and detection quality at the same pace as cloud expansion.
By the numbers:
- 80% of organizations store sensitive data in the cloud
- 53% of respondents experienced a cyberattack on their cloud infrastructure within the last 12 months
- 49% of IT pros said that an attack led to unplanned expenses to fix security gaps
Context
Cloud data security is the discipline of controlling where sensitive data lives, who can reach it, and how quickly security teams can detect misuse or exposure. In this report, Netwrix shows that cloud adoption keeps expanding while security maturity does not advance evenly across data protection, access governance, and response.
The practical problem is not cloud use itself. It is that organisations move sensitive data into cloud environments faster than they harden access paths, align monitoring, and close the operational gaps that make incidents expensive to fix. The survey frames cloud security as a governance problem as much as a technical one.
Key questions
Q: How should security teams reduce cloud data exposure from misconfigured storage?
A: Start with continuous configuration monitoring on storage, snapshots, and backup locations, then block public access and unsafe sharing by default. The key is to compare live state against an approved baseline and treat any drift as exposure until proven otherwise. Visibility without enforcement only tells you where the breach will happen.
Q: Why do cloud incidents so often become expensive remediation events?
A: Cloud incidents spread cost because the same identity or misconfiguration can affect multiple services, regions, or accounts at once. Once access is broader than intended, teams must investigate, reconfigure, and verify many control points. The cost is usually a sign that identity scope and monitoring were too loosely governed.
Q: What are the signs that security governance is failing in a cloud or platform organisation?
A: Common signs include executives giving inconsistent security numbers, production access with no action logging, outdated systems left unpatched, and unresolved questions about account ownership. Those symptoms suggest the organisation cannot reliably measure control coverage or tell the board what is actually happening. Mature governance depends on accurate reporting, continuous logging, and accountable remediation tracking.
A: They need both, but the order depends on the failure mode. If users can log in but retain unjustified access, governance is the weaker layer. If access decisions are sound but entry controls are weak, authentication is the immediate gap. Cloud IGA becomes critical when the main problem is entitlement drift.
Technical breakdown
Why cloud data exposure persists despite migration to the cloud
Cloud adoption often outpaces the control layer that should follow it. Sensitive data becomes distributed across storage, collaboration, and application services faster than teams can consistently classify it, restrict access to it, and verify who can still reach it. The result is not a single failure point but a widening control surface where data, identity, and workload permissions intersect. In practice, cloud data security depends on policy enforcement that keeps pace with deployment speed, not on the assumption that centralisation alone creates visibility.
Practical implication: treat cloud migration as a governance expansion exercise, not just a hosting change.
How cloud attacks turn weak entitlement control into cost
Cloud incidents often become expensive because the initial security gap is not the attack itself but the control weakness that lets it spread or persist. Excessive access, unclear ownership, delayed revocation, and incomplete logging make it harder to determine scope and recover quickly. When data, identities, and infrastructure controls are fragmented, remediation costs rise because teams spend time reconstructing exposure instead of containing it. This is why cloud security has to be managed as an access and visibility problem, not only as perimeter protection.
Practical implication: map cloud entitlements and logging coverage to the systems that hold sensitive data, not just to the network boundary.
Why detection time matters more when cloud data is highly distributed
Detection quality in cloud environments depends on whether teams can see meaningful activity across data stores, identities, and infrastructure in one operational view. When monitoring is partial, security teams may know an incident occurred but not which data sets were exposed, which accounts were used, or how far the event spread. That pushes the organisation into slower triage and broader containment than necessary. Cloud security therefore depends on reducing blind spots across identity, storage, and event telemetry, so that a breach can be bounded before it becomes a long investigation.
Practical implication: improve cross-domain detection before adding more cloud services or data stores.
Threat narrative
Attacker objective: The attacker aims to reach cloud-hosted sensitive data and create enough exposure that the organisation must spend time and money on containment and remediation.
- Entry begins when cloud environments hold sensitive data but governance over access scope and monitoring is uneven, creating an opening for attack.
- Escalation occurs when overly broad entitlements, weak visibility, or delayed security response let the attacker reach more cloud-hosted data and services.
- Impact follows when the incident forces unplanned remediation, extended investigation, and costs to fix the security gaps that remained in place.
NHI Mgmt Group analysis
Cloud adoption has outpaced cloud governance. The report shows that organisations are continuing to move sensitive data into cloud environments while the operational controls around access, visibility, and remediation remain uneven. That imbalance is the real security problem, because cloud adoption without matching governance increases the number of places where identity and data controls must hold at once. The practitioner implication is simple: security maturity has to scale with cloud usage, not follow it years later.
The control gap is not just data placement, but entitlement sprawl. Cloud data becomes difficult to secure when access paths are broader than the business need and ownership is diffuse across teams and platforms. Once access scope and logging are fragmented, incident response turns into reconstruction work instead of containment. Practitioners should read this as an IAM and cloud governance issue as much as a data security one.
Unplanned remediation cost is the clearest sign that cloud security is still reactive. When an attack leads to spending on gap-fixing after the fact, the organisation has already lost the advantage of prevention and early detection. That pattern suggests security investment is still being applied unevenly across control layers. The practitioner takeaway is to prioritise controls that reduce blast radius before another incident forces the budget conversation.
Cloud data security is now a lifecycle issue, not a deployment issue. Data and access controls have to be managed continuously across onboarding, change, and offboarding as cloud usage expands. If that lifecycle is not explicit, the organisation ends up treating cloud risk as a one-time project rather than an operating condition. The implication is that governance, entitlement review, and detection must be managed as ongoing services.
Named concept: cloud governance lag. This report illustrates the gap between cloud adoption speed and the slower maturation of access, monitoring, and response controls. That lag is what allows cloud incidents to translate into avoidable remediation cost and persistent exposure. Practitioners should use this concept to frame cloud security investment around operational readiness, not migration volume.
From our research library:
- 82% of breaches involved data stored in the cloud, according to IBM (2024).
What this signals
Cloud governance lag: the time between cloud adoption and control maturity is where most avoidable exposure accumulates. If organisations keep adding services faster than they tighten entitlements and telemetry, cloud security becomes a backlog problem rather than an operating discipline.
When incident response has to reconstruct who accessed what after the fact, the programme is already paying for weak control design. The better signal is whether cloud teams can answer access and exposure questions before an incident forces them to.
For practitioners
- Inventory where sensitive data actually resides Map the cloud services, storage locations, and applications that hold regulated or business-critical data so ownership is clear before the next control review.
- Tighten entitlement scope around cloud data stores Review who can read, move, and administer data repositories, then remove standing access that is broader than current job need.
- Correlate identity and data telemetry Connect cloud logs, access records, and storage events so incident responders can tell which data sets were touched and by which accounts.
- Track remediation cost as a security signal Measure how often incidents create unplanned spend to fix gaps, because that is a strong indicator that preventive controls are not keeping pace.
Key takeaways
- Cloud adoption is still expanding, but security maturity is not keeping pace across access, visibility, and remediation.
- The report shows that cloud incidents translate into real operational cost when teams cannot bound exposure quickly.
- The practical response is to govern data location, entitlement scope, and cross-domain telemetry as one cloud security programme.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CSA Cloud Controls Matrix, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | The report centres on cloud access governance and entitlement control. |
| SEF — Security Event and Incident Management | Detection time and response maturity are part of the report's cloud security concern. | |
| Recommendation — Use IAM controls to tighten who can reach cloud-hosted sensitive data and under what conditions. Improve event visibility so cloud incidents can be identified and contained faster. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The survey links cloud risk to overbroad access and weak entitlement governance. |
| Recommendation — Review cloud entitlements continuously and remove access that exceeds current business need. | ||
| CIS Controls v8 | CIS-5 — Account Management | Cloud security gaps in the report are closely tied to account and access lifecycle control. |
| Recommendation — Reconcile cloud accounts and revoke unused or excessive access paths on a routine basis. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Least privilege directly addresses the excessive cloud access patterns highlighted in the report. |
| Recommendation — Limit cloud access to the minimum permissions needed for the task. | ||
Key terms
- Cloud data security: Cloud data security is the practice of discovering, classifying, and protecting sensitive information across cloud storage, collaboration, and SaaS platforms. In identity-led programmes, it is only effective when tied to who can access the data, how that access is granted, and how quickly it is removed when no longer needed.
- Entitlement Sprawl: The gradual accumulation of too many discrete permissions, often with overlapping access and unclear ownership. It makes access review noisy and offboarding fragile. Grouping entitlements into profiles is one way to reduce that sprawl, provided the groups are designed around real work patterns.
- Verification Time: Verification time is the interval between applying a fix and confirming that the vulnerability is actually removed. It matters because a patch or configuration change that is not checked can leave residual exposure, especially in complex systems where identity, secrets, or dependencies still point to the same weakness.
- Remediation Costs: Remediation costs are the direct and indirect expenses incurred after sensitive data exposure, including investigation, containment, cleanup, legal response, and customer impact management. They also include the less visible cost of trust loss, especially when a breach reveals that data was stored or shared without proper oversight.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org