DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Security

Tenable releases its 2025 Cloud Security Risk Report

DigitalCIO Bureau by DigitalCIO Bureau
July 3, 2025
in Security, Tech News
0
Tenable releases its 2025 Cloud Security Risk Report
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Tenable releases its 2025 Cloud Security Risk Report, revealing that cloud workloads supporting artificial intelligence (AI) initiatives are more vulnerable than traditional workloads. The report found that 70 per cent of AI workloads across AWS, Azure and GCP contain at least one unremediated critical vulnerability, compared to 50 per cent of non-AI workloads, highlighting the mounting risk as organisations embed AI into their business operations.

AI workloads, with their vast training datasets and model development processes, are an increasingly attractive target for threat actors. The study found that 77 per cent of organisations using Google’s Vertex AI Workbench had at least one notebook instance configured with an overprivileged default service account, a misconfiguration that could open a gateway for privilege escalation and lateral movement across cloud environments. As AI adoption accelerates in India, the findings underscore the need for organisations to embed security earlier into AI development lifecycles.

Tenable’s research also shows broader progress in cloud risk management. Toxic cloud trilogies, workloads that are publicly exposed, critically vulnerable, and highly privileged, fell to 29 per cent of organisations surveyed, a nine-point improvement from 2024. Tenable’s researchers attribute the nine-point decline to sharper risk-prioritisation practices and wider use of cloud-native security tooling, yet warn that even a single trilogy provides attackers with a fast lane to sensitive data.

Identity remains the foundation of a secure cloud environment. The report finds that 83 per cent of AWS users have configured at least one identity provider (IdP), a best practice for securing human and service identities. Yet, the presence of identity-based risks persists. Credential abuse remains the most common initial access vector, implicated in 22 per cent of breaches, underscoring that simply adopting IdPs is not enough without strong enforcement of multi-factor authentication and least-privilege principles.

As India plans to legislate AI and cloud-related regulations with the Digital India Act, organisations must not wait for compliance norms to be rolled out to protect their cloud AI workloads. Innovations in cloud AI space are moving at a rapid pace. Without the right cloud security strategy, organisations are at a serious risk of being attacked.

“Organisations have made real strides in tackling toxic cloud risks, but the rise of AI workloads introduces a fresh wave of complexity,” said Ari Eitan, Director of Cloud Security Research at Tenable. “AI’s data-intensive nature, combined with persistent misconfigurations and vulnerabilities, demands a new level of diligence. Exposure management gives security teams the context they need to protect what matters most, including the crown jewels hidden inside AI environments.”

The report reflects findings by the Tenable Cloud Research team based on telemetry from workloads across diverse public cloud and enterprise environments, analysed from October 2024 through March 2025. To download the report today, please visit: 2025 Cloud Security Risk Report

Tags: Tenable
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

CrowdStrike And Meta Introduce Benchmarks For AI In Cybersecurity

by DigitalCIO Bureau
September 16, 2025
0
CrowdStrike Extends Its Elite MDR Services To Partners

CrowdStrike, in partnership with Meta, introduced a new suite of benchmarks – CyberSOCEval – for evaluating how AI systems perform in real-world security operations. Built on Meta’s CyberSecEval framework and CrowdStrike’s leading...

Read moreDetails

ESET Warns of HybridPetya Malware that Bypasses UEFI Secure Boot

by DigitalCIO Bureau
September 15, 2025
0
ESET Warns of HybridPetya Malware that Bypasses UEFI Secure Boot

ESET Research has discovered a HybridPetya bootkit and ransomware uploaded from Poland to the malware-scanning platform VirusTotal. The sample is a copycat of the infamous Petya/NotPetya malware; however,...

Read moreDetails

Gartner: Fortune 500 Companies Won’t Fully Eliminate Human Customer Service

by DigitalCIO Bureau
September 15, 2025
0

By 2028, none (0%) of the Fortune 500 companies will have fully eliminated human customer service, according to research firm Gartner. Despite widespread speculation surrounding the replacement of...

Read moreDetails

Exabeam Extends Insider Threat Detection To AI Agents With Google Cloud

by DigitalCIO Bureau
September 15, 2025
0
Gartner: Adoption of GenAI To Collapse Cybersecurity Skills Gap

Recent findings in the “From Human to Hybrid: How AI and the Analytics Gap are Fueling Insider Risk” study from Exabeam reveal that a vast majority (93%) of...

Read moreDetails

M37Labs Launches EBIC.AI To Address Comms Industry’s Disconnected Workflows

by DigitalCIO Bureau
September 12, 2025
0
M37Labs Launches EBIC.AI To Address Comms Industry’s Disconnected Workflows

Deep tech AI company M37Labs has launched EBIC.AI (Enterprise Brand Intelligence Console), a vertical AI platform designed to transform the $100 billion global marketing, PR, and communications industry by...

Read moreDetails
Next Post
80% of Enterprise Software and Applications Will Be Multimodal by 2030: Gartner

80% of Enterprise Software and Applications Will Be Multimodal by 2030: Gartner

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Infosys to help Siemens Gamesa Renewable Energy digitalise its IT landscape

November 4, 2019

Google pauses Chrome update on Android over app-data loss

December 17, 2019

IBM, India’s Tata join US tech platform’s governing council

August 12, 2019

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud HCLTech Honeywell IBM Infographics Internet of Things (IoT) Kaspersky Microsoft Netskope NTT DATA Palo Alto Networks Panel Discussion Qlik Salesforce Sophos Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?