Legacy Operating Models Can’t Keep Pace With IT Complexity, Cloud Security Alliance Survey Finds A Cloud Security Alliance survey commissioned by AlgoSec found that just 9% of enterprises have fully integrated security policy management into their development workflows, while 61% rely on manual or reactive approaches, leading to production outages and audit failures. The survey of IT and security professionals revealed that 65% experienced at least one business-critical application outage due to misconfigured security policies in the past 12 months, and 92% reported difficulty getting a unified view of policies across environments. Hillary Baron, AVP of Research at Cloud Security Alliance and lead author, said the traditional infrastructure-centric approach is ill-suited to today's hybrid and multi-cloud environments. CSA Official Press Release Published 08/18/2026 Legacy Operating Models Can’t Keep Pace With IT Complexity, Cloud Security Alliance Survey Finds Study reveals that fragmented ownership and limited visibility have made manual policy management a production risk SEATTLE – Aug. 18, 2026 — Fragmented operating models spanning teams, tools, and environments and which are still heavily reliant on manual processes are taking a measurable toll on production uptime, deployment velocity, and compliance readiness, according to a new survey from the Cloud Security Alliance CSA https://cloudsecurityalliance.org/ , the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education. Commissioned by AlgoSec https://www.algosec.com/ , global leader in application-centric security management, The State of Hybrid and Multi-Cloud Security Policy Management https://cloudsecurityalliance.org/artifacts/state-of-hybrid-and-multi-cloud-security-policy-management found that just 9% of enterprises have fully integrated security policy management into their development and deployment workflows. Meanwhile, the vast majority 61% continue to rely on manual or reactive approaches that are increasingly ill-suited to today’s hybrid and multi-cloud environments, resulting in production outages, multi-day remediation windows, and failed audit findings. “What was once primarily a network-configuration problem has become an application-connectivity problem. The traditional, infrastructure-centric approach, defining policy device by device and rule by rule, is increasingly ill-suited to today’s environment," said Hillary Baron, AVP of Research, Cloud Security Alliance, and the report's lead author. "Organizations that want to close this gap need to rethink the way they approach connectivity as an operational model centered on the applications they run, rather than simply adding more tools or effort to a model that is already straining under demands it was never designed to handle.” Among the report’s key findings: Production pays the price. Manual configuration errors emerge as the highest-impact bottleneck to deploying new applications, yet nearly half 48% of those surveyed describe their security policy changes as mostly or fully manual. The result shows up in production: 65% of organizations experienced at least one business-critical application outage caused by a misconfigured security policy in the past 12 months, and 46% experienced two or more. Misconfiguration comes from fragmented ownership. The responsibility for security policy is distributed across at least four teams—security operations 51% , network operations 46% , cloud architects 46% , and DevOps 41% . And more than two-thirds 67% of teams use three or more security management consoles daily. Manual compliance leads to mixed outcomes. Manual compliance checks alone aren’t sufficient for today’s continuously changing hybrid- and multi-cloud environments. While 40% of those surveyed reported manual review as their most common compliance posture, 25% also reported failing a compliance audit/audit finding in the last 12 months. Organizations are putting the cart before the horse. Risk or impact analysis performed before a policy change is committed was cited by 32% of respondents as the capability that would most improve their security policy management. Despite being chosen at more than twice the rate of any other capability, visibility remains lacking: 92% of organizations reported at least some difficulty getting a single, accurate view of policies across their environments. Operational redesign is the way forward. Fewer than half 44% of those surveyed said they expect a budget increase in 2026, even as only 9% claim to have fully integrated policy management into their development and deployment workflows. “Closing the gap won’t come from adding more tools or asking teams to work harder. It requires a fundamentally more connected approach to policy—one that gives organizations a unified view, anticipates risk before changes are made, automates routine work, and keeps compliance evidence current,” said Eran Shiff, Chief Product Officer, AlgoSec. “These capabilities build on one another to create a more predictable and resilient way to manage policy across today’s complex environments.” CSA conducted the survey online in May 2026 and received 515 responses from IT and security professionals from organizations of various sizes and locations. Although AlgoSec financed the project and co-developed the questionnaire with CSA research analysts, CSA's research analysts performed the data analysis and interpretation for this report. Hear what the survey’s findings mean for visibility, automation, and reducing policy risk, and discover how organizations are adapting security policy for distributed application environments. Register for the webinar When Policy Errors Reach Production https://www.algosec.com/lp/csa-algosec-cloud-survey-findings-2026 on September 8 at 11 am ET. Download The State of Hybrid and Multi-Cloud Security Policy Management https://cloudsecurityalliance.org/artifacts/state-of-hybrid-and-multi-cloud-security-policy-management . About AlgoSec AlgoSec, a global cybersecurity leader, empowers organizations to securely accelerate application delivery up to 100 times faster by automating application connectivity and security policy across the hybrid network environment. With two decades of expertise securing hybrid networks, over 2300 of the world's most complex organizations trust AlgoSec to help secure their most critical workloads. AlgoSec Horizon platform utilizes advanced AI capabilities, enabling users to automatically discover and identify their business applications across multi-clouds, and remediate risks more effectively. It serves as a single source for visibility into security and compliance issues across the hybrid network environment, to ensure ongoing adherence to internet security standards, industry, and internal regulations. Additionally, organizations can leverage intelligent change automation to streamline security change processes, thus improving security and agility. Learn how AlgoSec enables application owners, information security experts, SecOps and cloud security teams to deploy business applications faster while maintaining security at www.algosec.com http://www.algosec.com . About Cloud Security Alliance The Cloud Security Alliance CSA is the world’s leading not-for-profit organization committed to awareness, practical implementation, and credentialing of forward-looking cybersecurity topics, including AI, cloud, and Zero Trust. In an era where digital transformation drives business success, CSA stands as the global authority ensuring organizations can operate securely while harnessing cutting-edge technology. Through the 501 c 3 CSAI Foundation, volunteer-driven research, globally-accepted standards, and award-winning vendor-neutral education programs that unite varied associations, governments, chapters, and corporate members, CSA bridges the gap between innovation and pragmatic security execution. Visit CSA’s website to learn more. Media Contact Kristina Rundquist ZAG Communications for the CSA email protected /cdn-cgi/l/email-protection a9c2dbc0daddc0c7c8e9d3c8cecac6c4c4dcc7c0cac8ddc0c6c7da87cac6c4 About Cloud Security Alliance The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa. For press inquiries, email Zenobia Godschalk /cdn-cgi/l/email-protection 463c232829242f27063c272125292b2b33282f2527322f2928356825292b of ZAG Communications or reach her by phone at 650.269.8315.