cd /news/ai-policy/legacy-operating-models-cant-keep-pa… · home topics ai-policy article
[ARTICLE · art-101260] src=cloudsecurityalliance.org ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

Legacy Operating Models Can’t Keep Pace With IT Complexity, Cloud Security Alliance Survey Finds

A Cloud Security Alliance survey commissioned by AlgoSec found that just 9% of enterprises have fully integrated security policy management into their development workflows, while 61% rely on manual or reactive approaches, leading to production outages and audit failures. The survey of IT and security professionals revealed that 65% experienced at least one business-critical application outage due to misconfigured security policies in the past 12 months, and 92% reported difficulty getting a unified view of policies across environments. Hillary Baron, AVP of Research at Cloud Security Alliance and lead author, said the traditional infrastructure-centric approach is ill-suited to today's hybrid and multi-cloud environments.

read5 min views1 publishedAug 18, 2026
Legacy Operating Models Can’t Keep Pace With IT Complexity, Cloud Security Alliance Survey Finds
Image: Cloudsecurityalliance (auto-discovered)

CSA Official Press Release

Published 08/18/2026

Study reveals that fragmented ownership and limited visibility have made manual policy management a production risk

**SEATTLE – Aug. 18, 2026 — **Fragmented operating models spanning teams, tools, and environments and which are still heavily reliant on manual processes are taking a measurable toll on production uptime, deployment velocity, and compliance readiness, according to a new survey from the Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education.

Commissioned by AlgoSec, global leader in application-centric security management, The State of Hybrid and Multi-Cloud Security Policy Management found that just 9% of enterprises have fully integrated security policy management into their development and deployment workflows. Meanwhile, the vast majority (61%) continue to rely on manual or reactive approaches that are increasingly ill-suited to today’s hybrid and multi-cloud environments, resulting in production outages, multi-day remediation windows, and failed audit findings.

“What was once primarily a network-configuration problem has become an application-connectivity problem. The traditional, infrastructure-centric approach, defining policy device by device and rule by rule, is increasingly ill-suited to today’s environment," said Hillary Baron, AVP of Research, Cloud Security Alliance, and the report's lead author. "Organizations that want to close this gap need to rethink the way they approach connectivity as an operational model centered on the applications they run, rather than simply adding more tools or effort to a model that is already straining under demands it was never designed to handle.”

Among the report’s key findings:

Production pays the price. Manual configuration errors emerge as the highest-impact bottleneck to deploying new applications, yet nearly half (48%) of those surveyed describe their security policy changes as mostly or fully manual. The result shows up in production: 65% of organizations experienced at least one business-critical application outage caused by a misconfigured security policy in the past 12 months, and 46% experienced two or more.Misconfiguration comes from fragmented ownership. The responsibility for security policy is distributed across at least four teams—security operations (51%), network operations (46%), cloud architects (46%), and DevOps (41%). And more than two-thirds (67%) of teams use three or more security management consoles daily.Manual compliance leads to mixed outcomes. Manual compliance checks alone aren’t sufficient for today’s continuously changing hybrid- and multi-cloud environments. While 40% of those surveyed reported manual review as their most common compliance posture, 25% also reported failing a compliance audit/audit finding in the last 12 months.Organizations are putting the cart before the horse. Risk or impact analysis performed before a policy change is committed was cited by 32% of respondents as the capability that would most improve their security policy management. Despite being chosen at more than twice the rate of any other capability, visibility remains lacking: 92% of organizations reported at least some difficulty getting a single, accurate view of policies across their environments.Operational redesign is the way forward. Fewer than half (44%) of those surveyed said they expect a budget increase in 2026, even as only 9% claim to have fully integrated policy management into their development and deployment workflows.

“Closing the gap won’t come from adding more tools or asking teams to work harder. It requires a fundamentally more connected approach to policy—one that gives organizations a unified view, anticipates risk before changes are made, automates routine work, and keeps compliance evidence current,” said Eran Shiff, Chief Product Officer, AlgoSec. “These capabilities build on one another to create a more predictable and resilient way to manage policy across today’s complex environments.”

CSA conducted the survey online in May 2026 and received 515 responses from IT and security professionals from organizations of various sizes and locations. Although AlgoSec financed the project and co-developed the questionnaire with CSA research analysts, CSA's research analysts performed the data analysis and interpretation for this report.

Hear what the survey’s findings mean for visibility, automation, and reducing policy risk, and discover how organizations are adapting security policy for distributed application environments. Register for the webinar When Policy Errors Reach Production on September 8 at 11 am ET.

Download The State of Hybrid and Multi-Cloud Security Policy Management. **About AlgoSec **

AlgoSec, a global cybersecurity leader, empowers organizations to securely accelerate application delivery up to 100 times faster by automating application connectivity and security policy across the hybrid network environment. With two decades of expertise securing hybrid networks, over 2300 of the world's most complex organizations trust AlgoSec to help secure their most critical workloads. AlgoSec Horizon platform utilizes advanced AI capabilities, enabling users to automatically discover and identify their business applications across multi-clouds, and remediate risks more effectively. It serves as a single source for visibility into security and compliance issues across the hybrid network environment, to ensure ongoing adherence to internet security standards, industry, and internal regulations. Additionally, organizations can leverage intelligent change automation to streamline security change processes, thus improving security and agility. Learn how AlgoSec enables application owners, information security experts, SecOps and cloud security teams to deploy business applications faster while maintaining security at www.algosec.com.

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading not-for-profit organization committed to awareness, practical implementation, and credentialing of forward-looking cybersecurity topics, including AI, cloud, and Zero Trust. In an era where digital transformation drives business success, CSA stands as the global authority ensuring organizations can operate securely while harnessing cutting-edge technology. Through the 501(c)3 CSAI Foundation, volunteer-driven research, globally-accepted standards, and award-winning vendor-neutral education programs that unite varied associations, governments, chapters, and corporate members, CSA bridges the gap between innovation and pragmatic security execution. Visit CSA’s website to learn more.

Media Contact

Kristina Rundquist

ZAG Communications for the CSA

[email protected]

About Cloud Security Alliance #

The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.

For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.

── more in #ai-policy 4 stories · sorted by recency
── more on @cloud security alliance 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/legacy-operating-mod…] indexed:0 read:5min 2026-08-18 ·