Skip to main content
A bright red plastic disc in the shape of a cloud sits atop a computer console.
Analyst Insights

AI is disrupting hybrid cloud security. These 4 steps restore it

The data deluge from GenAI has cyber teams struggling to manage their hybrid infrastructures, but experts have identified a range of effective responses that can help companies regain control. The first step? Start with enhancing visibility....

The ground is shifting under hybrid cloud again, and cyber teams need to find new footing.

It was only about a decade ago when enterprises—for cost and efficiency—went all-in on public cloud computing, paying third-party providers for access to servers, networking, and storage resources. Last year, 83% of those folks had to recalibrate. Costs were climbing, attack volumes were surging, and leaders came to realize that the cloud model they’d relied upon was no longer delivering predictable value or acceptable risk. So they adjusted their data-storage strategy again, leaving some data and workloads in the public cloud but repatriating critical workloads back to private, on-premises environments, according to a DataCanopy survey.

Almost as soon as organizations made that adjustment, generative AI introduced a fresh set of problems. It sharply increased data volumes across these cloud environments and brought a wave of AI-enabled threats that quickly stretched security teams thin.

In fact, a recent Gigamon survey found that 91% of security and IT leaders are now “making compromises in securing and managing their hybrid cloud infrastructure.” Some have delayed security projects. Others have loosened access controls to maintain business continuity. Many have scaled back monitoring or compliance efforts to reduce costs.

“CISO budgets have been squeezed, threats are increasing, and AI is exacerbating everything,” said Mark Jow, EMEA technical advocate and evangelist at Gigamon, ticking off three evergreen concerns that are keeping chief information security officers up at night. “That means CISOs have to make compromises, because they just can’t do everything they would like to do.”

Still, some companies are identifying what they can do to get a handle on cloud security challenges. Here are four best practices experts say enterprises are increasingly applying to regain control over their hybrid environments:

1. To enhance hybrid cloud security, prioritize complete visibility

Nearly half (47%) of IT leaders lack comprehensive insight and visibility across their environments, the Gigamon study found. As organizations mix on-premises infrastructure, public cloud services, and software-as-a-service (SaaS) platforms, tracking workloads and data flows becomes increasingly complex.

CISO budgets have been squeezed, threats are increasing, and AI is exacerbating everything.
Mark Jow, EMEA technical advocate and evangelist, Gigamon

The stakes are high. Once they gain initial access, cyberattackers often move laterally within hybrid environments, exploiting internal pathways to escalate their reach. Without complete visibility, defenders may not spot this activity until it is too late.

Real-time monitoring is becoming a top priority. Gone are the days when IT asset management meant scheduled checks of computer network activity, which could take hours or days to deliver results. Even 10 or 15 minutes just won’t cut it. Real-time monitoring provides a steady stream of data with up-to-the-second reliability, allowing security teams and—in some cases—autonomous systems to assess network activity and anomalies in record time.

[Read also: Asset visibility—because you can’t protect what you can’t see]

In fact, 64% of the Gigamon survey respondents say their No. 1 focus this coming year will be achieving real-time threat monitoring to gain complete visibility into their data. That includes deploying sensors across hybrid environments, unifying data from disparate systems, and integrating monitoring with automated response workflows.

2. Streamline and filter data to ‘focus on signal, not noise’

AI is arguably the main culprit behind the recent surge in data volumes, with one in three IT leaders saying it has doubled their network traffic, according to Gigamon. The problem is so acute that 55% of organizations avoid generative AI (GenAI) for many use cases, a Deloitte survey found.

The issue isn't just about protecting a static perimeter—it’s about securing a dynamic network... that can act autonomously across on-premises and cloud environments at machine speed.
Ritu Jyoti, former IDC analyst and expert in autonomous AI agents

The data surge has direct implications for cost, performance, and security. More traffic means more to monitor, more blind spots, and higher infrastructure costs. Security teams struggle to extract meaningful insights from an ever-expanding stream of logs, alerts, and telemetry.

Organizations are responding by filtering and refining their data. Visibility platforms identify relevant traffic and expose hidden threats. Cloud security tools enforce consistent policies across environments. Data quality tools clean and standardize information for better analysis.

[Read also: 4 critical leadership priorities for CISOs in the AI era]

“It’s about focusing on signal, not noise,” Jow said. “The more we can streamline what’s being analyzed, the faster teams can respond, and the less likely attackers are to slip through unseen.”

3. Apply zero trust and microsegmentation to limit lateral movement across hybrid cloud environments

The spread of workloads across hybrid environments gives attackers more opportunities to move laterally once they gain access. Every new cloud region, virtual private cloud (a logically isolated section of a public cloud provider’s infrastructure), microservice, or application programming interface (API, the connection between computers or computer programs that allows them to communicate and share data) creates another internal pathway for attackers to exploit. That makes identity-first security and granular segmentation essential.

The identity-first model is now the undisputed safer alternative to past perimeter-based security, where users, once inside a firewall or working on an approved device, had pretty much free reign to move throughout a network. Zero trust strategies—at the heart of identity-first—continuously verify users, services, and workloads, no matter where they sit in the architecture, reducing the blast radius when credentials or tokens are compromised. Supporting zero trust, microsegmentation divides networks into small, walled-off zones so intruders can’t easily travel if they manage to penetrate a network.

As AI-driven data volumes expand and attack surfaces grow, attackers are using automation to probe cloud pathways at machine speed. Enter: zero trust and microsegmentation, which can contain breaches early and prevent a single foothold from turning into a full-stack compromise.

4. Use AI-driven defenses to counter AI-driven threats

AI-enabled attacks are rising fast. More than half of organizations experienced an increase in AI-driven ransomware last year, according to Gigamon. A recent Ekco survey found that AI-enabled threats have surpassed traditional breaches as the top concern for IT leaders.

This was the first time that AI has been used to find a vulnerability in the wild. For defenders, that’s exciting stuff.
Sandra Joyce, vice president, Google Threat Intelligence

Ritu Jyoti, a former IDC analyst and expert in autonomous AI agents, warned that these tools pose a “profound and dual challenge” for hybrid environments.

“The issue isn't just about protecting a static perimeter—it’s about securing a dynamic network of non-human identities that can act autonomously across on-premises and cloud environments at machine speed,” Jyoti said. “Traditional security frameworks, built for human users, are no match for this.”

Sandra Joyce, vice president at Google Threat Intelligence, agreed, noting that as AI agents become more common in cloud environments, they’ll both expand the threat landscape and provide capabilities to help organizations keep the increased risk in check.

“We have seen AI used to flesh out code, we have seen it used for deepfakes, and we have seen it used for crafting spear-phishing emails,” Joyce said. “But we haven't seen anything like an agentic attack or some self-perpetuated campaign. I call this the ‘before times’ because I fully anticipate that type of thing is coming.”

[Read also: Ultimate guide to AI cybersecurity—benefits, risks, and rewards]

Google is already using AI at scale to counter AI. The company scans billions of malware samples with automated models, integrates AI into Gmail to reduce phishing and spam, and recently used an AI agent to detect and help patch a vulnerability in SQLite, a lightweight database embedded in many applications, before attackers exploited it.

“This was the first time that AI has been used to find a vulnerability in the wild,” Joyce said. “For defenders, that’s exciting stuff.”

The (lucrative) future of hybrid cloud security

Gartner’s latest information security forecast indicates security spending is surging, driven by investments in hybrid cloud security. According to the leading research and advisory firm’s Q3 2025 forecast, spending for cloud security posture management (CSPM) tools is projected to grow from $2.5 billion in 2023 to $13 billion in 2029—a compounded annual growth rate (CAGR) of 31.23%, making it the fastest-growing segment in the report. The market will reach $15.6 billion by 2032.

[Read also: Strengthening cloud security means bridging the gap between posture and runtime protection—take this module deep dive]

Modern hybrid cloud security depends on layering defenses so attackers meet resistance at every step. Visibility, microsegmentation, and AI-driven monitoring form a security fabric resilient enough to withstand data floods, lateral movement, and autonomous threats.

“The future of security and value creation isn't about building higher walls—it’s about architecting a trust fabric from the inside out,” said Jyoti. “This means shifting to an identity-first, zero-trust model where every single AI agent is treated as a privileged user. We have to bake in continuous monitoring to spot weird behavior, use granular access controls to lock things down, and—this is key—keep humans in the loop for the most critical decisions.”