TL;DR: Cloud permissions have become a primary cloud attack surface, and Sonrai Security says its Cloud Permissions Firewall drove 4x year-over-year ARR growth, 220% customer growth, and 60% expansion among existing customers, reflecting demand for default-deny and just-in-time controls at the permission layer. Legacy PAM assumptions no longer hold at cloud scale, especially across human, machine, and AI identities.
Editorial analysis by NHI Mgmt Group, based on content published by Sonrai Security: “Sonrai Closes 2025 with 4x ARR Growth as Cloud Permissions Firewall Adoption Surges”.
By the numbers:
- Sonrai Security says it saw 4x year-over-year ARR growth in 2025.
- Sonrai Security says it saw 220% growth in customers in 2025.
- Sonrai Security says 60% of customers expanded Cloud Permissions Firewall deployments.
Key questions
Q: What breaks when cloud PAM is still managed with static tools and manual processes?
A: Static tools struggle to keep pace with cloud systems that scale up and down continuously.
Q: Why do standing privileges in cloud infrastructure create outsized risk for engineering teams?
A: Standing privileges increase the blast radius of both human error and account compromise because access remains available after the task is complete.
Q: What are the signs that cloud resource governance is failing?
A: Common signs include unexpected cost spikes, resources being enlarged without review, new assets appearing outside approved procedures, and engineers not knowing the financial impact of what they deploy.
Practitioner guidance
- Map privileged cloud access to entitlement paths Identify which cloud roles, policies, and delegated permissions actually confer administrative reach, then classify them as privileged assets for review and approval.
- Replace standing cloud privilege with task-scoped grants Use just-in-time access for elevated cloud actions so approvals are tied to the task rather than permanently attached to the identity.
- Extend governance to third-party access paths Bring vendor users, contractors, and external integrators into the same permission review and logging process used for internal cloud access.
Bottom line: Cloud PAM is shifting from account-centric thinking to permission-centric governance because cloud privilege now lives in roles, policies, and delegated access paths.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Cloud permissions are becoming the practical boundary of privileged access. Traditional PAM was designed around human administrators and discrete elevated sessions, but cloud operations distribute privilege into policies, roles, tokens, and delegated paths. That makes the permission layer the real control surface for DevOps security, not the login prompt. Practitioners should treat cloud entitlements as the privileged asset.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations govern third-party and AI access the same way as internal cloud privilege?
A: Yes, because the risk comes from what the identity can reach, not whether it is human, vendor, workload, or agentic. Different identity classes may request access differently, but the governance question is the same: who approved it, what it can touch, and when it should expire. Separate models create blind spots.
👉 Read our full editorial: Cloud permissions are becoming the real PAM battleground in DevOps