Group Purchasing
Group Purchasing

Securing The Cloud: Persistent Challenges, Emerging Threats, and The Rise of AI Defense

Securing The Cloud: Persistent Challenges, Emerging Threats, and The Rise of AI Defense (PDF, 6.73MB)Published: 09 Sep, 2025

Thank You To Our Sponsors

Securing the Cloud: Persistent Challenges, Emerging Threats, and the Rise of AI Defense, published by SANS Institute in 2025, brings together security leaders from AWS, Google Cloud, and Microsoft Azure with independent SANS instructors to address the intersection of cloud security and artificial intelligence. Now in its third year, the collaboration covers securing generative AI applications, recurring cloud security failures across identity, data, network, and workload domains, and how Zero Trust architecture is adapting to AI-era threats.

Key findings:

  • More than 70% of cloud security incidents stem from customer misconfigurations or weak credential practices, not vulnerabilities in the cloud platforms themselves, per Google's 2024 Threat Horizons report
  • 66% of organizations are now prioritizing AI within their security operations, according to Capgemini research
  • 95% of US companies are using generative AI, per a Bain & Company survey
  • 66% of organizations expect AI to significantly impact cybersecurity in the coming year, yet only 37% have processes in place to evaluate the security of AI systems before deployment, according to the World Economic Forum's Global Cybersecurity Outlook 2025
  • Identity and access management remains the most significant recurring cloud security problem, driven by machine identity sprawl and over-permissioned roles
  • LLMs process all inputs with equal privilege, meaning no internal security boundaries exist within the model itself, making external guardrails and automated reasoning necessary rather than optional
  • Zero Trust, formally coined by Forrester's John Kindervag in 2010, is now treated as a best-effort model rather than a guarantee of perfect security, with AI acting as a force multiplier for detection and containment
  • A 2021 White House Executive Order mandating Zero Trust in federal agencies helped shift Zero Trust from a theoretical model to a board-level mandate

Across all three chapters, a consistent pattern emerges: the security fundamentals that organizations have struggled to fully implement in the cloud (identity governance, data classification, network segmentation) are the same fundamentals now determining how well organizations can secure AI systems and use AI defensively. Organizations that treat AI security as an extension of mature cloud security practices are better positioned than those approaching it as an entirely new discipline. Contributors: Dr. Paul Vixie and Brandon Evans (AWS and SANS), Dr. Anton Chuvakin and Dave Shackleford (Google Cloud and SANS), and Wesley Kuzma and Simon Vernon (Microsoft and SANS), with foreword by Frank Kim, SANS Fellow and Curriculum Lead.

SANS 2025 Cloud Security Exchange

Related Webcast

Prepare for the Next Era of Cloud Security.

Webcast Abstract Image

FAQ

More than 70% of cloud security incidents stem from customer misconfigurations or weak credential practices rather than vulnerabilities in the cloud platforms themselves, according to Google's 2024 Threat Horizons report.

Not fully. While 66% of organizations expect AI to significantly impact cybersecurity in the coming year, only 37% have processes in place to evaluate AI system security before deployment, per the World Economic Forum's Global Cybersecurity Outlook 2025.

Identity and access management (IAM) is the most persistent issue, largely due to machine identity sprawl, over-permissioned roles, and legacy on-premises IAM models like Active Directory being poorly adapted to cloud environments.

No. Zero Trust operates on a "best effort with dramatically improved odds" model — it raises the cost of an attack and increases detection probability, with AI serving as a multiplier for these layered defenses, but it does not promise perfect security.

John Kindervag of Forrester Research formally coined the term "Zero Trust" in 2010, shifting the security model to treat all interactions as hostile until verified.

Meet Your Authors