TL;DR: 80% of organisations store sensitive data in the cloud, 53% experienced a cloud infrastructure cyberattack in the prior 12 months, and 49% saw unplanned remediation costs after an attack, according to Netwrix’s 2022 survey of 720 IT professionals. The governance gap is not cloud adoption itself, but the fact that data, access, and detection controls are still maturing unevenly.
Editorial analysis by NHI Mgmt Group, based on content published by Netwrix: “2022 Cloud Data Security Report”.
By the numbers:
- 80% of organizations store sensitive data in the cloud
- 53% of respondents experienced a cyberattack on their cloud infrastructure within the last 12 months
- 49% of IT pros said that an attack led to unplanned expenses to fix security gaps
Key questions
Q: How should security teams reduce cloud data exposure from misconfigured storage?
A: Start with continuous configuration monitoring on storage, snapshots, and backup locations, then block public access and unsafe sharing by default.
Q: Why do cloud incidents so often become expensive remediation events?
A: Cloud incidents spread cost because the same identity or misconfiguration can affect multiple services, regions, or accounts at once.
Q: What are the signs that security governance is failing in a cloud or platform organisation?
A: Common signs include executives giving inconsistent security numbers, production access with no action logging, outdated systems left unpatched, and unresolved questions about account ownership.
Practitioner guidance
- Inventory where sensitive data actually resides Map the cloud services, storage locations, and applications that hold regulated or business-critical data so ownership is clear before the next control review.
- Tighten entitlement scope around cloud data stores Review who can read, move, and administer data repositories, then remove standing access that is broader than current job need.
- Correlate identity and data telemetry Connect cloud logs, access records, and storage events so incident responders can tell which data sets were touched and by which accounts.
Bottom line: Cloud adoption is still expanding, but security maturity is not keeping pace across access, visibility, and remediation.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Cloud adoption has outpaced cloud governance. The report shows that organisations are continuing to move sensitive data into cloud environments while the operational controls around access, visibility, and remediation remain uneven. That imbalance is the real security problem, because cloud adoption without matching governance increases the number of places where identity and data controls must hold at once. The practitioner implication is simple: security maturity has to scale with cloud usage, not follow it years later.
A few things that frame the scale:
- 82% of breaches involved data stored in the cloud, according to IBM (2024).
A question worth separating out:
A: They need both, but the order depends on the failure mode. If users can log in but retain unjustified access, governance is the weaker layer. If access decisions are sound but entry controls are weak, authentication is the immediate gap. Cloud IGA becomes critical when the main problem is entitlement drift.
👉 Read our full editorial: Cloud data security remains weak as cloud adoption keeps expanding