Press ReleaseCloud SecurityCyber Safety

Tenable’s 2025 Cloud Security Risk Report: Cloud Security Gaps Threaten SEA Businesses

9% of Cloud Storage Resources Contain Sensitive Data, While 54% of Organisations Have Secrets Embedded In Workloads, Exposing Critical Vulnerabilities

Businesses in Singapore and across Southeast Asia are facing a silent crisis of cloud vulnerabilities, according to the “2025 Cloud Security Risk Report released today by Tenable®, the Exposure Management company. The report uncovers alarming security gaps in cloud environments, from misconfigured storage exposing sensitive data to embedded secrets in workloads, that could lead to data breaches, financial losses, and serious regulatory repercussions.

The findings of the 2025 Cloud Security Risk are particularly relevant for organisations operating in regulated sectors or managing cross-border data flows. In Singapore, where data protection and cybersecurity are tightly governed under frameworks such as the Cybersecurity ActPersonal Data Protection Act (PDPA), and Monetary Authority of Singapore (MAS) Technology Risk Management Guidelines, poor visibility into cloud assets and misconfigurations can have serious compliance repercussions.

Similarly, Indonesia’s Personal Data Protection Law (PDP Law), Thailand’s Personal Data Protection Act (PDPA), Malaysia’s Personal Data Protection Act (PDPA), and the Philippines’ Data Privacy Act all impose stringent requirements on data protection, cross-border transfers, and cloud security. Together, these regulations highlight the urgent need for organisations across Southeast Asia to prioritise strong cloud governance and security to meet evolving compliance and cybersecurity demands.

The 2025 Cloud Security Risk report reveals a significant and widespread risk, finding that 9% of all analysed cloud storage resources contain restricted or confidential information. In environments housing vast volumes of data, this seemingly small percentage translates to millions of sensitive records potentially exposed. Even more alarming, nearly one in ten publicly accessible storage locations holds sensitive data, driven by common misconfigurations, weak access controls, and limited visibility, exposing organisations across industries to serious security and compliance threats in line with local/regional data residency expectations.

2025 Cloud Security Risk Report Uncovers Greater Risks

The risks do not end there. The 2025 Cloud Security Risk’s findings show that 54% of organisations with AWS ECS task definitions have a secret embedded within them, exposing businesses to the threat of full cloud environment takeovers or exploitation activities like unauthorised crypto mining. Even within AWS EC2 instances, 3.5% contain credentials embedded in user data, giving attackers a clear pathway to escalate privileges and compromise environments.

“Secrets are the keys to the kingdom, yet many organisations are unknowingly leaving them unguarded across their cloud infrastructures,” said Ari Eitan, Director of Cloud Security Research at Tenable. “In today’s threat landscape, complacency is costly. Organisations must treat secrets with the highest level of security hygiene to prevent attackers from gaining footholds that can spiral into full-blown breaches.”

With Singapore continuing to scale up cloud adoption, supported by national initiatives like IMDA’s Cloud Outage Incident Response (COIR) framework and regional efforts to enable secure digital economies, the report highlights the urgent need for a proactive, risk-driven security strategy. “The cloud offers incredible agility, but without strong controls and continuous monitoring, it also opens the door to significant exposures,” Eitan added. “Understanding where your sensitive data and credentials are and who can access them must now be a board-level priority.”

The 2025 Cloud Security Risk report reflects findings by the Tenable Cloud Research team based on telemetry from workloads across diverse public cloud and enterprise environments, analysed from October 2024 through March 2025.

To download the 2025 Cloud Security Risk report today, please visit: https://www.tenable.com/cyber-exposure/tenable-cloud-security-risk-report-2025.

Martin Dale Bolima

Martin has been a Technology Journalist at Asia Online Publishing Group (AOPG) since July 2021, tasked primarily to handle the company’s Disruptive Tech Asia and Disruptive Tech News online portals. He also contributes to Cybersecurity ASEAN and Data&Storage ASEAN, with his main areas of interest being artificial intelligence and machine learning, cloud computing and cybersecurity. A seasoned writer and editor, Martin holds a degree in Journalism from the University of Santo Tomas in the Philippines. He began his professional career back in 2006 as a writer-editor for the University Press of First Asia, one of the premier academic publishers in the Philippines. He next dabbled in digital marketing as an SEO writer while also freelancing as a sports and features writer.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *