Cloud-security policy is an operating-model problem
Only 9% of respondents to a Cloud Security Alliance survey said security policy management was fully integrated into development and deployment workflows. The conditions around that automation are more complex: responsibility spans several teams, 67% of respondents work across three or more security-management consoles each day, and 92% reported at least some difficulty obtaining a single, accurate view of policies across their environments.
The survey, commissioned by AlgoSec, collected online responses from 515 IT and security professionals at organisations of different sizes and locations. Cloud Security Alliance said its analysts conducted the analysis and interpretation. AlgoSec sells security-policy management technology, so it has a commercial stake in how enterprises assess this problem.
Manual policy management has operational consequences
Manual work remains widespread. Some 61% of respondents said their organisations use manual or reactive approaches to security policy management; 48% described policy changes themselves as mostly or fully manual. Respondents identified manual configuration errors as the biggest bottleneck to deploying new applications.
The operational stakes are substantial. Over the previous year, 65% said their organisation had experienced at least one business-critical application outage caused by a misconfigured security policy. Some 46% reported two or more such incidents.
Compliance creates another pressure point. Manual review was the most common compliance posture, cited by 40% of respondents, while 25% said their organisation had failed a compliance audit or received an audit finding during the previous year. These results put manual processes, outages and compliance problems in the same respondent group. They do not establish that manual management caused each outcome.
For executives, the practical question is whether teams can understand the effects of a proposed policy change across hybrid or multi-cloud environments.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Policy responsibility spans teams and tools
Policy responsibility sits across several functions:
| Function | Respondents citing responsibility |
|---|---|
| Security operations | 51% |
| Network operations | 46% |
| Cloud architects | 46% |
| DevOps | 41% |
Security policy management therefore crosses organisational boundaries. Executives evaluating an operating model need to define how these functions share responsibility for policy decisions.
Tooling is distributed too. Some 67% of respondents work across three or more security-management consoles each day. This gives technology leaders a concrete test for automation investments: whether a workflow improves policy management across all environments involved in a change.
Visibility makes that test sharper. A total of 92% reported at least some difficulty obtaining a single, accurate view of policies across their environments. Cross-environment visibility is a separate issue to examine alongside workflow automation.
Pre-change risk analysis is the leading improvement priority
Respondents put risk analysis before a policy change at the top of their improvement priorities. It was selected by 32%, more than twice the rate of any other capability listed in the survey.
That suggests a practical sequence for evaluation. Teams can assess the likely impact of a proposed change, then decide which routine work to automate. Technology leaders can judge automation partly by whether the people approving changes can see the likely policy impact before execution.
An application-centric model reframes policy management
Hillary Baron, AVP of Research, Cloud Security Alliance, argues for an application-centric approach. “What was once primarily a network-configuration problem has become an application-connectivity problem. The traditional, infrastructure-centric approach, defining policy device by device and rule by rule, is increasingly ill-suited to today’s environment,” Baron said.
Baron’s proposed operating principle centers policy on the applications organisations run and the connectivity those applications require across hybrid and multi-cloud environments. Under this model, management focuses on the application-level outcome that infrastructure rules collectively enable.
That framing offers executives another test for policy-management decisions: whether teams manage isolated infrastructure rules or the connectivity applications require across environments.
Eran Shiff, Chief Product Officer, AlgoSec, argues for unified visibility, pre-change risk assessment, routine automation and current compliance evidence. AlgoSec commissioned the research and sells technology in this market, giving the company a commercial stake in that framing. Leaders can treat those capabilities as evaluation criteria when assessing whether specific technologies or operating models deliver the claimed results.
2026 budgets sharpen the investment decision
Only 44% of respondents expect a budget increase in 2026. For technology leaders setting priorities, the key question is what each investment changes about policy decisions.
Does it clarify responsibility across security operations, network operations, cloud architects and DevOps? Does it improve the cross-environment view used to approve changes? And does it help teams assess risk before a policy change reaches production?
Those questions test investments against the conditions respondents reported: distributed responsibility, multiple management consoles and difficulty obtaining a single view of policy.
Key takeaways for decision-makers
- Manual policy management carries operational risk: 61% of respondents use manual or reactive approaches, while 65% reported at least one business-critical outage caused by a misconfigured security policy. Leaders should examine where manual changes create avoidable risk.
- Policy ownership needs to cross organisational boundaries: Security operations, network operations, cloud architects and DevOps all share responsibility. Leaders should clarify ownership and assess whether workflows provide a consistent policy view across teams and environments.
- Pre-change risk analysis should guide automation: Respondents ranked risk analysis before policy changes as their leading improvement priority. Automation investments should help teams understand likely impacts before changes reach production.
- Application-centric management offers a different operating model: Managing the connectivity applications require can reduce reliance on device-by-device policy thinking. Leaders should assess whether policy tools support application-level outcomes across hybrid and multi-cloud environments.
- Tighter budgets demand measurable policy improvements: With only 44% expecting budget increases in 2026, investments need clear operational value. Prioritise capabilities that improve ownership, cross-environment visibility and risk assessment before policy changes.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


