security analysts

Security analysts lose half their time to data correlation – report

Share

Mumbai: Security analysts are spending a significant proportion of their working hours managing fragmented data rather than responding to cyber threats, finds a new cloud security report.

The State of Cloud Security Report 2025 released found that while organisations are detecting cyber threats faster than before, their ability to fully respond and recover remains slow. The findings highlight growing challenges for security analysts as attackers move at increasing speed and cloud security environments become more complex.

According to Palo Alto Networks‘ new report, nearly three-quarters of organisations surveyed (74%) said they can detect and contain cloud-based attacks within 24 hours. However, this speed is not sustained through resolution. One in three organisations require more than a day to fully close an incident, with 9% taking between a week and a month to resolve data breaches.

A major factor behind these delays is operational fragmentation. Half of respondents reported that 50% of security analysts’ time is spent correlating data across systems instead of actively responding to threats. For one in five security analysts, this figure rises to as much as 80%, limiting their ability to act quickly against attackers.

The report shows that attackers are now operating at unprecedented speed. Breaches that took an average of 44 days in 2021 can now occur in as little as 25 minutes, driven by AI-assisted attack techniques. Despite this acceleration, one in three organisations still take more than a day to fully resolve incidents, leaving them exposed to further cyber threats.

Fragmented tooling continues to overwhelm security analysts. Disconnected cloud, application and security operations centre systems prevent teams from forming a single, coherent view of threats, slowing investigation and response efforts. As a result, cloud security incidents are becoming broader in scope. The report found that 70% of incidents now span three or more attack surfaces, including cloud, network, endpoint and identity layers.

The findings also challenge assumptions around cloud maturity. Organisations that have spent more than five years operating in the cloud reported higher rates of SaaS misuse and misconfigured public access than less mature peers. These organisations face subtler risks, including persistent oversharing, token abuse and uncontrolled synchronisation between SaaS systems, increasing exposure to data breaches.

High-risk issues are also remaining unresolved for extended periods. One in five organisations said more than a quarter of high or critical security issues remain in production for over 30 days, even as attackers measure success in minutes.

Identity and API exposure continue to play a growing role in modern cyber threats. API attacks recorded the steepest year-on-year increase at 41%, while overly permissive identities and compromised tokens enable attackers to move laterally and extract data at scale.

The report concludes that without more unified approaches to cloud security, security analysts will continue to lose valuable time to data correlation, leaving organisations struggling to keep pace with increasingly fast and sophisticated attackers.

This report findings are based on a global survey of more than 2,800 security and technology leaders across 10 countries including India.