Legacy Operating Models Can’t Keep Pace With IT Complexity, Cloud Security Alliance Survey Finds
Legacy Operating Models Can’t Keep Pace With IT Complexity, Cloud Security Alliance Survey Finds
Study reveals that fragmented ownership and limited visibility have made manual policy management a production risk
SEATTLE--(BUSINESS WIRE)--Fragmented operating models spanning teams, tools, and environments and which are still heavily reliant on manual processes are taking a measurable toll on production uptime, deployment velocity, and compliance readiness, according to a new survey from the Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education.
What was once primarily a network-configuration problem has become an application-connectivity problem.
Share
Commissioned by AlgoSec, global leader in application-centric security management, The State of Hybrid and Multi-Cloud Security Policy Management found that just 9% of enterprises have fully integrated security policy management into their development and deployment workflows. Meanwhile, the vast majority (61%) continue to rely on manual or reactive approaches that are increasingly ill-suited to today’s hybrid and multi-cloud environments, resulting in production outages, multi-day remediation windows, and failed audit findings.
“What was once primarily a network-configuration problem has become an application-connectivity problem. The traditional, infrastructure-centric approach, defining policy device by device and rule by rule, is increasingly ill-suited to today’s environment," said Hillary Baron, AVP of Research, Cloud Security Alliance, and the report's lead author. "Organizations that want to close this gap need to rethink the way they approach connectivity as an operational model centered on the applications they run, rather than simply adding more tools or effort to a model that is already straining under demands it was never designed to handle.”
Among the report’s key findings:
- Production pays the price. Manual configuration errors emerge as the highest-impact bottleneck to deploying new applications, yet nearly half (48%) of those surveyed describe their security policy changes as mostly or fully manual. The result shows up in production: 65% of organizations experienced at least one business-critical application outage caused by a misconfigured security policy in the past 12 months, and 46% experienced two or more.
- Misconfiguration comes from fragmented ownership. The responsibility for security policy is distributed across at least four teams—security operations (51%), network operations (46%), cloud architects (46%), and DevOps (41%). And more than two-thirds (67%) of teams use three or more security management consoles daily.
- Manual compliance leads to mixed outcomes. Manual compliance checks alone aren’t sufficient for today’s continuously changing hybrid- and multi-cloud environments. While 40% of those surveyed reported manual review as their most common compliance posture, 25% also reported failing a compliance audit/audit finding in the last 12 months.
- Organizations are putting the cart before the horse. Risk or impact analysis performed before a policy change is committed was cited by 32% of respondents as the capability that would most improve their security policy management. Despite being chosen at more than twice the rate of any other capability, visibility remains lacking: 92% of organizations reported at least some difficulty getting a single, accurate view of policies across their environments.
- Operational redesign is the way forward. Fewer than half (44%) of those surveyed said they expect a budget increase in 2026, even as only 9% claim to have fully integrated policy management into their development and deployment workflows.
“Closing the gap won’t come from adding more tools or asking teams to work harder. It requires a fundamentally more connected approach to policy—one that gives organizations a unified view, anticipates risk before changes are made, automates routine work, and keeps compliance evidence current,” said Eran Shiff, Chief Product Officer, AlgoSec. “These capabilities build on one another to create a more predictable and resilient way to manage policy across today’s complex environments.”
CSA conducted the survey online in May 2026 and received 515 responses from IT and security professionals from organizations of various sizes and locations. Although AlgoSec financed the project and co-developed the questionnaire with CSA research analysts, CSA's research analysts performed the data analysis and interpretation for this report.
Hear what the survey’s findings mean for visibility, automation, and reducing policy risk, and discover how organizations are adapting security policy for distributed application environments. Register for the webinar When Policy Errors Reach Production on September 8 at 11 am ET.
Download The State of Hybrid and Multi-Cloud Security Policy Management.
About AlgoSec
AlgoSec, a global cybersecurity leader, empowers organizations to securely accelerate application delivery up to 100 times faster by automating application connectivity and security policy across the hybrid network environment. With two decades of expertise securing hybrid networks, over 2300 of the world's most complex organizations trust AlgoSec to help secure their most critical workloads. AlgoSec Horizon platform utilizes advanced AI capabilities, enabling users to automatically discover and identify their business applications across multi-clouds, and remediate risks more effectively. It serves as a single source for visibility into security and compliance issues across the hybrid network environment, to ensure ongoing adherence to internet security standards, industry, and internal regulations. Additionally, organizations can leverage intelligent change automation to streamline security change processes, thus improving security and agility. Learn how AlgoSec enables application owners, information security experts, SecOps and cloud security teams to deploy business applications faster while maintaining security at www.algosec.com.
About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading not-for-profit organization committed to awareness, practical implementation, and credentialing of forward-looking cybersecurity topics, including AI, cloud, and Zero Trust. In an era where digital transformation drives business success, CSA stands as the global authority ensuring organizations can operate securely while harnessing cutting-edge technology. Through the 501(c)3 CSAI Foundation, volunteer-driven research, globally-accepted standards, and award-winning vendor-neutral education programs that unite varied associations, governments, chapters, and corporate members, CSA bridges the gap between innovation and pragmatic security execution. Visit CSA’s website to learn more.
Contacts
Media Contact
Kristina Rundquist
ZAG Communications for the CSA
kristina@zagcommunications.com
