Managing the unseen: The new security challenge of cloud identities

Managing the unseen: The new security challenge of cloud identities

The adoption of cloud continues to gain momentum among enterprises in the Asia Pacific (APAC) region. According to a recent IDC report, almost 90% of APAC businesses now have meaningful workload deployments on multiple public clouds, writes Jeffrey Kok, Vice President of Solution Engineer, Asia Pacific and Japan, CyberArk

Most organisations in this region have also started embracing true hybrid cloud deployments. Another IDC report predicts that by 2027, over 50% of businesses will modernise up to half of their cloud architecture to boost efficiency and drive innovation. By 2028, more than 90% of newly developed applications will be multi-cloud enabled.

The benefits of deploying cloud infrastructure and running enterprise applications in the cloud include more business flexibility, economic savings from more efficient and automated operations and pay-as-you-go scalability. By leveraging these benefits, organisations can improve their security posture and productivity, reduce administrative burden, and accelerate seamless and secure user experience across various cloud services and applications

However, the rapid adoption of cloud architecture also necessitates a strategy shift in how enterprises secure their cloud identities. As technologies continue to advance, standard security methods will not be enough to tackle new and emerging cybersecurity challenges. Keeping the cloud secure is vital to an organisation’s business success.

But what exactly does it mean to secure the cloud? And what do ‘cloud identities’ mean in the first place? Let’s break things down and understand the fundamentals.

Exploring the various cloud identities

When we talk about securing cloud identities, we are referring to managing user permissions. Each type of identity possesses different access needs, and a different level of risk within an organisation:

·       Cloud operations identities are given to cloud operators, architects and site reliability engineers. Within cloud operations, administrators have complete administrative access and the ultimate permission to affect every service and resource within the cloud account.

·       Developer identities refer to any human engineers who write code, create applications or workloads. Developers will self-administer various cloud services, create cloud-native applications, push workloads into the cloud and access supporting resources. Developer identities also includes roles like Data Scientists, AI Applications teams, AI Agent creators, etc

·       Application and audit team identities refer to other non-developer application teams and any audit teams checking compliance. They require lesser privileges like read-only access to various services.

·       Machine identity workloads are cloud-native applications, services, automation tools, and processes required for business operations. 

The importance of cloud identity security

Rapidly expanding permissions pose a significant challenge for cloud security teams and organisations, especially if they engage the services of multiple cloud service providers (CSPs). For example, machine identities now outnumber human identities by a staggering 82-to-1 within enterprise environments. Managing permissions and identities across separate cloud platforms is a challenge, especially because of the proliferation of tools tailored for cloud architecture such as cloud monitoring, solutions that automate provisioning, repositories, scanning and more.

According to a 2025 survey by CyberArk, 61% of respondents globally do not have identity security controls in place to secure cloud infrastructure and workloads. 45% of APAC respondents indicated that the increase of new identities in their organisations was driven by the adoption of new cloud applications.

Compromising a single identity for an innocuous code-scanning tool may open the door to a serious breach, and it is a security issue that is worth closer scrutiny. Organisations must constantly challenge their comfort zones, particularly when securing their application environments. Even though building a secure and well-designed cloud architecture is a collaboration between organisations and CSPs, the responsibility of giving the right people access to the management consoles, cloud services, and infrastructure workloads (which is where cloud identities come in) is within the purview of the decision-makers.

The good news? Setting up a strong and secure cloud environment is entirely possible, if organisations adhere to a few essential guiding principles:

·       Zero standing privileges (ZSP): The ideal scenario for access is to give someone access to only the resources they need. However, this is often viewed as unrealistic in cloud security. The principle of ZSP is to remove persistent privileges, limit implicit trust, and provide several levels of control to verify access.

·       Time, Entitlements, and Approvals (TEA): Designing a better user experience without compromising user experience can be a significant challenge, especially for roles like developers. The key to this balanced cloud strategy is TEA:

o   Time: How much time is access granted for?

o   Entitlements: What level of access is granted to what resource?

o   Approvals: What level of checks is undertaken on access request?

Cloud security must be balanced with growth

As cloud architectures continue to evolve, managing access will continue to be a complex challenge. Securing access for all layers of cloud identities must be balanced with maintaining the ability of development teams to respond quickly to new market needs or critical system issues. This challenge cuts across numerous cloud environments and teams, a myriad of cloud-native tools, and both human and service credentials.

A holistic, centralised solution will help apply appropriate controls through policy-based access to help meet baseline compliance requirements, standardise audit and reporting, and enable continuous improvement into the future.

Browse our latest issue

Intelligent CIO Europe

View Magazine Archive