Full Report
A new report from Fortinet reveals increased adoption of multi-cloud strategies and hybrid implementations combining on-premises and public cloud infrastructure
Analysis Summary
# Industry News: Multi-Cloud Adoption Accelerates Despite Heightened Security and Skills Gaps
## Summary
New data from Fortinet’s 2025 State of Cloud Security Report shows that multi-cloud adoption is rapidly increasing, with over 78% of organizations now using two or more cloud providers, up from 71% last year. This growth is occurring concurrently with persistent, high-level concerns over security and compliance, and significant internal skills shortages, driving demand for unified management platforms.
## Key Details
- Date: January 15, 2025 (Publication Date)
- Companies Involved: Fortinet (Report Originator), Apono, Oasis Security, Keeper Security (Commentators)
- Category: Market Analysis / Trend Reporting
## The Story
The report highlights a definitive organizational shift toward multi-cloud environments, driven by the pursuit of resilience and access to specialized cloud services. Hybrid cloud adoption also remains strong at 54%. However, these complex environments are straining security teams. Security and compliance are the foremost concerns for 61% of organizations. Compounding this is a severe skills shortage, with 76% reporting a lack of expertise, particularly in configuration management and threat detection. Consequently, there is a strong market consensus favoring centralized security tools; 97% prefer unified dashboards, and adoption of CSPM (67%) and CNAPP (62%) tools is climbing. Organizations are confirming this trend by planning to increase cloud security spending.
## Business Impact
### For the Companies Involved
- **Fortinet:** The report solidifies their data points for strategic product positioning, emphasizing the need for holistic, multi-cloud security solutions that integrate visibility and simplified policy management.
- **Cloud Security Vendors (CSPM/CNAPP):** The strong preference for unified platforms and high planned budget increases present significant revenue opportunities for providers offering integrated defense capabilities across disparate cloud environments.
### For Competitors
- **Point Solution Vendors:** Vendors lacking comprehensive multi-cloud visibility or consolidation capabilities may face increasing pressure as enterprises prioritize vendors that offer centralized management to combat complexity and skills gaps.
### For Customers
- **Immediate:** Customers face ongoing risks related to complexity, regulatory gaps, and slow threat response due to skill deficits.
- **Mid-Term:** Customers seeking relief will likely divest from siloed tools in favor of integrated platforms (CSPM, CNAPP), potentially leading to vendor consolidation efforts.
### For the Market
- The data confirms that cloud complexity is now a primary driver for security purchasing decisions, favoring vendors that can simplify multi-cloud governance rather than adding another layer of specialized tools. The market is maturing from simple lift-and-shift to sophisticated security orchestration.
## Technical Implications
The prevalence of configuration errors among the primary security concerns suggests that misconfigurations remain a leading risk factor in cloud deployments. The high adoption of CSPM and CNAPP indicates a technical shift towards capabilities like Infrastructure as Code (IaC) scanning, continuous posture monitoring, and workload protection across various cloud fabrics. The stated low confidence in real-time threat detection implies that current telemetry and correlation capabilities across multiple clouds are often inadequate.
## Strategic Analysis
- **Market Positioning:** The market is clearly leaning towards "Cloud Security Platform" consolidation rather than a "best-of-breed" point solution approach in the management layer. Vendors must position themselves as central command centers for hybrid and multi-cloud governance.
- **Competitive Advantage:** A vendor that can demonstrably reduce complexity, automate guardrail enforcement across CSPs (addressing Carmel's comment on engineering teams), and provide unified analytics gains a major advantage.
- **Challenges:** Vendors must overcome the inherent fragmentation of cloud-native APIs and security models to genuinely deliver unified visibility and policy enforceability without performance degradation.
## Industry Reactions
- **Analyst Opinions:** Analysts likely view this as validation that security effectiveness is lagging behind deployment speed. The investment shift toward unified platforms (97% preference) is a strong market signal.
- **Expert Commentary:** Experts like Carmel emphasize that organizational structure (IT Security vs. Engineering collaboration) is as critical as the technology used to manage the complexity, pointing to process and governance requirements.
- **Market Response:** Increased M&A activity focusing on technologies that bridge security intelligence gaps between major hyperscalers (AWS, Azure, GCP) is anticipated.
## Future Outlook
- **Predictions:** Spending on security automation and unified control planes will accelerate throughout the year, likely outpacing general IT spending growth.
- **What to watch for:** Future reports will track whether increased spending correlates with improved perceived threat detection capabilities (addressing the 64% doubt). Watch for vendor integrations that move beyond simple alerts to automated, unified remediation workflows.
## For Security Professionals
Cybersecurity professionals must prioritize acquiring cross-platform cloud security skills, especially around CSPM and IaC security. The emphasis must shift from managing individual cloud tools to mastering unified security platforms that abstract away the underlying cloud vendor differences for policy enforcement while maintaining fidelity for threat hunting. Collaboration between security teams and application engineering/DevOps teams is mandatory to embed compliant security practices early in the infrastructure lifecycle.