Study: Increased Cloud Budget Does Not Fill the Security Gap
1,163 security leaders in the 2026 Cloud Security Report cite tool sprawl and complexity gaps as hindering maturity despite rising budgets.
1,163 security managers, one finding: the cloud is becoming more complex faster than teams can secure it. The 2026 State of Cloud Security Report by Cybersecurity Insiders (with Fortinet as an industry partner) calls this the Complexity Gap-and delivers numbers that are reshaping budget discussions.
Key Takeaways
- Complexity outpaces maturity. 88 % operate hybrid or multi-cloud (up from 82 % last year), 81 % with two or more providers. Yet 59 % still rate their cloud-security maturity as early/developing.
- Tool sprawl is the top brake. 69 % cite tool sprawl and visibility gaps as their biggest obstacle. 66 % lack strong confidence in real-time detection and response.
- Budget alone won’t close the gap. 62 % expect rising cloud-security budgets; on average they account for 34 % of the IT-security budget, yet maturity still lags spending.
Related:Flexera 2026: What SMEs Can Really Take On / The Cloud Maturity Level SMEs Persuade Themselves They’ve Achieved
The study is based on an online survey of 1,163 IT and cybersecurity professionals conducted in late 2025-spanning industries from tech and finance to healthcare and the public sector, and roles from specialists to C-level. Published by Cybersecurity Insiders, Fortinet is the report’s industry partner. It’s vendor research with a robust sample size, not a lab benchmark. For decision-makers, what matters is less the brand on the cover than the patterns that remain consistent across chapters.
What is the Cloud Complexity Gap? The Cloud Complexity Gap describes the structural distance between the pace of modern cloud environments and the ability of security teams to maintain real-time visibility, detection, and response. According to the 2026 State of Cloud Security Report, it arises from fragmented tools, scarce specialists, and attackers who scan faster with automation and AI than manual defenses can correlate.
Three Amplifiers, One Operating Model
The report distills the gap into three reinforcing factors. First, fragmented defenses: tools grow with the cloud, often without shared telemetry. Teams manually correlate alerts across systems never designed to work together. 69 % cite this as the top brake on effective cloud security.
Second, understaffed teams: 74 % report an active shortage of qualified security professionals, 77 % express high concern about the industry-wide skills gap. Cloud roles demand expertise in infrastructure, identity, data, and apps simultaneously-precisely the mix that’s hardest to fill. Third, adversaries operating at machine speed: automation and AI discover misconfigurations, permission paths, and exposed data faster than human queues can process them. 66 % lack strong confidence in real-time detect-and-respond capabilities-slightly up from last year (64 %).
The operating model behind this is clearly multi-cloud. 88 % operate hybrid or multi-cloud environments, 81 % use at least two providers for critical workloads, and 29 % rely on more than three. Each additional account, SaaS application, and non-human identity expands configurations and data paths. Infrastructure scales automatically-understanding the security posture often does not.
Where Risk Resides – and What the Numbers Mean for Architecture
The concentration of risk is hardly surprising-and that’s precisely why it demands action. Identity and access lead the way at 77 %, followed by misconfigured cloud services (70 %) and data exposure (66 %). Workload exploits and supply-chain attacks rank further down the list. The everyday path to compromise runs through permissions, configurations, and data.
This is where the exposure chain forms: a misconfiguration opens a resource, an overprivileged identity takes the next step, and sensitive data becomes the target. Posture, identity, and data tools each cover their own segment. Seventy-seven percent prioritize identity-and yet the shared context across the chain is often missing. Attackers automate exactly this correlation.
- Clear priorities among respondents: identity, configuration, data-architectural focus over tool shopping
- 64 % would choose a single-vendor platform from scratch across network, cloud, and app layers
- Success metrics shift to outcomes: fewer misconfigurations, less overprivilege, less alert noise
- Only 11 % report autonomous remediation-automation often stops at the alert
- Only 18 % have AI-driven detection fully operational; 32 % remain in pilot phase
- Reported figures should always be mirrored against your own inventory and maturity posture
The automation gap is the silent multiplier. Thirty-seven percent describe automation as largely alert-focused: they detect yes, but fix manually. Only 11 % report autonomous remediation without humans in the loop. Meanwhile, many experiment with AI in cloud defense, yet only 18 % say AI detection is fully operational across their cloud environments; 32 % remain in pilot mode. Attackers don’t need this level of maturity-they already scan, map, and prioritize at machine speed.
What Cloud Teams Across DACH Can Take Away
First: spend is not maturity. When 62 % increase budgets and 59 % still remain in early stages, the bottleneck lies in integration and operating model. Every new point tool without shared context adds operational overhead the team ultimately pays for.
Second: platform consolidation is both a survey signal and an operational priority. Sixty-four percent would choose a single-vendor platform “from scratch” across network, cloud, and application security; only 27 % would stick with pure best-of-breed without shared governance. Buyers prioritize coverage and depth (79 %), integration and orchestration (72 %), and automation and compliance (68 %) over pure usability or price.
Third: outcome metrics replace tool counting. Eighty-one percent prioritize security outcomes (fewer misconfigurations, less overprivilege), 76 % operational efficiency (faster detection, less noise), 66 % integration and automation, and 62 % continuous compliance. For platform and security leads, this means tying roadmaps to exposure reduction and MTTD/MTTR-not to the number of modules purchased.
Fourth: the complexity gap is an architecture and identity issue before it’s a pure SOC ticket. Teams running multi-cloud need a unified view of permissions, configuration drift, and data paths-or every new AI initiative becomes an additional attack-surface multiplier on an already fragmented foundation.
The report doesn’t provide a DACH-only snapshot or hands-on benchmarks per hyperscaler. It does deliver a robust sequence: first context across identity-config-data, then automation you can trust, then AI-driven detection built on that foundation. Reverse the order and you buy a sense of speed while keeping the gap wide open.
Frequently Asked Questions
Who is behind the 2026 Cloud Security Report?
Conducted and published by Cybersecurity Insiders, with Fortinet as an industry partner. The findings are based on an online survey of 1,163 IT and cybersecurity professionals conducted in late 2025 across industries and company sizes. It’s industry research with an industry partner-the core metrics (multi-cloud, tool sprawl, identity) are internally consistent and useful for prioritization, but do not replace your own asset and maturity assessments.
What does the Complexity Gap mean for multi-cloud teams?
More providers and SaaS offerings don’t just expand the attack surface; they fracture visibility and policy. When telemetry and entitlement paths don’t converge, alert volumes grow faster than remediation capacity. The gap is therefore primarily an integration and identity problem-pure SOC capacity alone won’t close it.
Should companies switch to a single-vendor platform?
64 % of respondents would plan to do so in a greenfield scenario. In practice, this means shared context, unified policy, and less manual correlation-rather than a big-bang migration. What matters most is whether identity, posture, data, and runtime converge into a usable situational picture; the brand is secondary.
Editor’s Picks
cloudmagazinFlexera 2026: What mid-market firms can realistically adoptcloudmagazinSovereign cloud isn’t limited to server locationMore from the MBF Media Network
MyBusinessFutureThe blind spot of digital leaders: Why banks need AI-ready dataDigital ChiefsKimi kills subscriptions: 7 checks for AI capital expenditureSecurityTodayOpenAI models hacked Hugging Face: what to verify nowImage source: AI-generated (July 2026)

