2021 Thales Cloud Security Study
Discover what @451Research recommends to secure your organization's dispersed business environment! Enter your business information here to download the 2021 @thalesgroup Cloud Security Study, courtesy of Thales.
What are the biggest cloud and AI security challenges highlighted in the 2025 research?
The 2025 Cloud Security Study shows that cloud has become a common and critical part of enterprise infrastructure, but many organizations are still struggling to secure it effectively.
Key themes from the research:
- Cloud is now a top security priority: Cloud security is treated as a pressing security discipline and is often the top security spending priority for respondents.
- Data in the cloud is getting more sensitive: A growing share of cloud data is classified as sensitive, rising from 47% last year to an even higher percentage in the latest study.
- Security complexity is increasing: More organizations now say that securing cloud environments is more complex than securing on‑premises environments, and this perception has increased from 51% in the previous year.
- Attack patterns are evolving: Respondents report an increase in direct attacks aimed at compromising cloud infrastructure, with credential theft and stolen secrets cited as the fastest‑growing tactics.
- AI is intensifying the pressure: The rapid push to support AI initiatives—often heavily cloud‑dependent—is forcing enterprises to rethink how they manage risk at scale. Many indicate that AI security spending is eating into or taking over existing security budgets.
In short, organizations are heavily invested in cloud and AI, but they need to strengthen their cloud security posture, streamline operations, and adopt more effective controls to keep up with the pace of change.
How are organizations responding to AI-enabled bot attacks and agentic AI risks?
Recent Thales research highlights that AI is not only an opportunity, but also a growing attack vector that requires a reimagined security approach.
From the 2026 Thales Bad Bot Report:
- AI-enabled bot attacks have surged: Daily AI-enabled bot attacks jumped from 2 million to 25 million in a single year.
- Financial Services are heavily targeted: 46% of account takeover attacks now target financial services.
- Retail is a major focus for AI bots: 20% of AI bot attacks are directed at retail websites.
These findings show that organizations need to:
- Secure agentic AI and LLM-powered applications at runtime with dedicated AI runtime security controls.
- Strengthen data security posture using capabilities such as sensitive data discovery, classification, and risk reduction—areas covered in Gartner’s research on Data Security Posture Management (DSPM) and Data Security Platforms.
- Align with industry-specific guidance, especially in regulated sectors like financial services, where Thales provides analysis on evolving security challenges, regulatory mandates, and emerging technologies.
Overall, the data suggests that security teams should treat AI-enabled bots and agentic AI as mainstream threats and integrate AI-specific protections into their broader cloud and application security strategies.
What practical steps can enterprises take to strengthen data security and prepare for future risks like post-quantum?
Thales research and guidance point to several practical steps enterprises can take to improve data security today while preparing for tomorrow’s risks.
1. Strengthen data protection in the cloud
- Recognize that a growing share of cloud data is sensitive (up from 47% last year) and treat it accordingly.
- Increase the use of encryption: many respondents now encrypt 80% or more of their cloud data.
- Rationalize key management: a rising share of organizations are using five or more key management systems, which adds complexity. Consolidating and standardizing key management can reduce risk.
- Use encryption and key management to support digital sovereignty objectives, regardless of where data is physically stored.
2. Use industry guidance and platforms to manage risk
- Leverage resources like the Gartner Buyer’s Guide for DSPM and the Gartner Market Guide for Data Security Platforms to evaluate solutions for sensitive data discovery, classification, and fine‑grained authorization.
- Align with regional and sector-specific guidelines (e.g., New York State Cybersecurity Requirements for Financial Services, Hong Kong cloud security and backup guidelines, India’s cloud adoption framework, Korea’s ISMS‑P).
- Take advantage of “safe harbor” clauses in data breach notification laws by implementing strong encryption and access controls that can mitigate disclosure obligations after an incident.
3. Prepare now for post-quantum risks
- Even though post-quantum threats are projected to be a few years away, enterprises are encouraged to start planning today.
- Use available risk assessments to understand whether your organization is at risk of a post-quantum breach and to prioritize remediation steps.
- Design architectures with future-proofing and portability in mind—many organizations now regard portability for workloads and data as a primary driver for digital sovereignty initiatives.
Thales, together with Imperva, supports these efforts with technologies and partner programs that help protect critical applications, data, identities, and software at scale, while enabling partners and customers to accelerate their digital transformation and licensing strategies.
