Concerns about the software supply chain have led to increased understanding of cloud native security strategies according to a new survey.

The cloud is swiftly becoming a non-negotiable part of a company’s technology stack, which means cloud security is paramount. At a recent European cloud expo, Aqua Security surveyed attendees to gain insights into the current state of cloud-native security. Let’s look at the key findings from the survey and what it means for cloud CTOs and technical professionals who must address evolving cybersecurity risks.
See also: Understanding Unified Security in a Cloud World
The study reveals a rise in the perceived risk associated with the software supply chain as compared to the previous year’s survey. 36.9% of respondents identified supply chain security as the most significant threat to their company, up from 18.6%. As companies shift operations to the cloud, this opens them up to new vulnerabilities across the cloud environment, especially if they’re still using legacy security strategies.
Open-source vulnerabilities were identified as the primary concern. As more companies look to open-source resources to build, maintain, and launch new technology initiatives, an increase in security-first approaches is critical. Companies need proactive measures to mitigate the risks associated with using open-source tools, which could present a burden for small to medium businesses without the resources or expertise.
The study shows encouraging progress in the adoption of cloud-native security strategies, however. 34% of organizations have already implemented a dedicated cloud-native security strategy, up from 21.2% last year. This is heartening because it shows a growing awareness of the importance of securing cloud-native environments.
Even more, there seems to be a positive shift in responsibility for this security posture. IT Security teams and DevOps seem to be sharing more responsibility. There’s a strong need for collaboration between these functions as companies deploy in the cloud because a security-first approach that’s also cloud-native requires a clear strategy from both departments.
The study seems to support the idea that companies are moving from simply knowing about cloud-native security to understanding it. Cloud-native applications require a unique approach to security, something that tripped up companies in the past. However, this year’s survey shows a remarkable uptick in understanding, with nearly half of respondents citing familiarity with CNAAP or “Cloud Native Application Protection Platform. This term, introduced originally by analyst firm Gartner, wasn’t nearly as well known last year. But with the evolving security landscape, it’s no wonder more companies are paying attention.
While progress has been made in awareness and implementation, several barriers continue to hinder companies as they seek to adopt cloud-native security. For one, budget limitations were a challenge for almost 39% of respondents, echoing a likely scenario for many tech deployments. Organizations will need to prioritize funds and resource allocation to ensure the continued security of cloud investments.
Security also means closely examining what aligns with the company’s specific risk profile and ensuring that sufficient resources are allocated to protect those investments. Not all companies will have the same risk profile, with certain sectors, such as healthcare dealing with more sensitive data.
Perception is another significant barrier. 29.1% of participants perceived that Cloud Native Security was complicated or difficult to implement. While companies must do more to educate employees and upskill them to prepare for these challenges, they also need to simply security frameworks and promote user-friendly solutions—easier said than done.
See also: Data Masking Methods for Data Centric Security
To streamline cloud-native security practices, companies can leverage the following:
Organizations need to be proactive about addressing the evolving landscape of cloud-native security, and the survey seems to back this up. Here is a quick checklist for companies looking to get started.
Mitigating security risks requires a proactive, multi-faceted approach. Cloud-native security specifically must be a top priority for organizations. Thanks to this survey’s findings, we know that companies are making progress but still have some challenges to overcome. It’s put to CTOs and other decision-makers to build robust security strategies and collaborate with both DevOps and IT security teams to ensure the integrity and resilience of the cloud-native environment. This helps pave the way for a secure and successful future in the cloud.
Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved
Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.