gas cloud of data
REPORT

The State of Data Security: A Distributed Crisis

PUBLISHED APR 22, 2025 BY Rubrik Zero LabsREADING TIME: 22 Minutes

The transition from exclusively on-premises business IT to hybrid on-premises/cloud environments is among the most important events in the history of business computing.

Executive Summary

Escaping the Silent Crisis

The transition from exclusively on-premises business IT to hybrid on-premises/cloud environments is among the most important events in the history of business computing.

It has increased scalability, flexibility, and innovation opportunities. Often it has become essential for corporate workflows and inter-corporate collaborations. No wonder 90% of IT leaders say they are managing distributed hybrid environments.

But as the following data from Rubrik telemetry and Wakefield Research shows, hybrid environments have also created unprecedented hazards:

0%

Survey Respondents Attacked

0%

Companies Attacked Every Other Week

0%

Of All Attacks are Identity Attacks

IT leaders report challenges in securing data systemwide, say they lack visibility, and can't establish centralized control. Malicious actors know this, and they are exploiting hybrid cloud systems relentlessly. Attacks are coming over at least 10 vectors, far more than in the past.

Ninety percent of survey respondents say they've been attacked. Almost one-fifth say they're getting attacked every other week. And those are the ones they know about. Bad actors are changing their techniques, from malware to social engineering and identity-based strategies. Identity attacks may now account for three-quarters of all attacks.

The reason? It works. Successful attacks are on the rise, and time from entry to command and control of sensitive data is dropping fast.

Companies Paying Ransom
0%

As a result 86% of companies surveyed report paying a ransom when facing extortion demands. Nearly three-quarters say attackers were able to access and harm their data.

These hazards are becoming a crisis and no one is talking about it. Probably because few have a good plan. Instead, they slowly move to the cloud, say they’re counting on cloud providers to fix the issue, or simply ignore it and call it a cost of business.

It doesn’t have to be like this. Companies must get ahead of threat actors by thinking like them: Threat actors want to find and control the most valuable data, so they can stop operations. If they can do it, companies can too.

controls
Control

It begins with a focus on regaining control, through system awareness, then a plan of protection, defense, and recovery that prioritizes sensitive data and continuous operations.

folder
Classification

Sensitive data can be located and classified in categories such as personal information, financial details, and technical capabilities. This identifies targets before treat actors get there, asserting knowledge and control in the cloud.

upload
Cloud

A process of continuous backup and restoration should become part of the security process, as rigorously in the cloud as on premises.

Data and Methodology

Rubrik Zero Labs is committed to providing practical, unbiased intelligence aimed at helping organizations reduce their data  security risk. In pursuit of this goal, we have included information from three main sources.

01
Rubrik Telemetry

We employed Rubrik telemetry to gain insights into the typical organization’s data environment and associated risks

02
Wakefield Research

Perspectives from 1,600+ IT and security leaders through Wakefield Research

03
Contributing Organizations

Research from respected cybersecurity organizations and institutions

Rubrik Telemetry

We employed Rubrik telemetry to gain insights into the typical organization’s data environment and associated risks. It’s based on two sources:

  1. Backup Data is cloud, SaaS, and on-premises  data that we’ve backed up from customer environments.
  2. Production Data is cloud, SaaS, and production data that Rubrik actively monitors, so organizations can make decisions about how they manage risk in their environments.

Number of cloud files secured:

Data covers January 1, 2024 through December 31, 2024

Total secured files

5.8 Billion

total files across cloud and SaaS environments in production

Sensitive Files

175+ Million

sensitive files classified across all managed cloud and SaaS environments

Wakefield Research

We teamed up with Wakefield Research for a study that pulls in fresh viewpoints from both IT and security leaders. These viewpoints augment our Rubrik telemetry data, allowing us to balance the vision of these leaders with the realities they face in the trenches. To remove any chance of bias in the results, no Rubrik clients were part of this dataset.

generic flag
10 Countries

1,600+

IT and Security Leaders

50%+

CIO or CISOs

right half
50% CIO or CISOs

1,625

Decision-Makers at companies with at least 500 employees across 10 countries (Australia, France, Germany, India, Italy, Japan, Netherlands, Singapore, United Kingdom and the United States); in three regions (Americas, APAC and EMEA)

left half
50% Directors / VPs

Contributing Organizations

In order to provide a more well-rounded and impartial point of view, Rubrik has also incorporated crucial information from diverse organizations offering distinct perspectives. 

We Used

CrowdStrike cloud and identity-based analytics around intrusions and breakout times.

Microsoft identity-based analytics and frequency of attacks data.

Allied Market Research cloud adoption information.

Data Sprawl in the Cloud Era

Locating and securing data has been a challenge since the first networked computer. However in the past decades, as companies have moved to cloud computing for more of their IT operations, the dimensions of the challenge have multiplied like never before.

Before, data was in the corporate data center or on people's computers, initially on desks and then on desks and laptops, connected to a single network. Today, data sprawls across many types of devices, relying on many networks to access the corporate jewels, now residing on premises and in the cloud.

At

some

point,

the

change

in

the

scale

and

complexity

means

that

professionals

are

in

a

new

world.

Over the last couple of decades, business has demanded the benefits that come with using cloud and SaaS services. And with good reason! Most of our lives are easier with the cloud.

Organizations are continuing to increase their utilization of cloud and SaaS services and hybrid and multi-cloud strategies are becoming the norm, with 89% of organizations utilizing multiple cloud platforms, according to Allied Market Research.[1]

In addition our survey results showed:

hybrid Cloud environments

0%

of IT and security leaders said they were managing hybrid cloud environments.
cloud & Saas-based workloads

0%

of all IT and security leaders reported that they're managing mostly cloud and SaaS-based workloads vs. on premises workloads.
using multiple platforms

0%

of IT and security leaders surveyed said they are using anywhere between 2 and 5 cloud and SaaS platforms for data storage, applications, and services
shift to cloud & Saas-based

0%

of IT and security leaders surveyed said they are planning to shift toward using more cloud and SaaS-based services over the next year while 31% will maintain their ratio of hybrid cloud and on-premise environments

Data Complexity in the Cloud Era

With every new cloud and SaaS use case, businesses lose a tiny bit of control over their data. IT and security leaders must send their data to more locations, to a point where many corporate data repositories effectively span the world. Then, they must figure out where it is and how to secure it. Figuring out how much data a company has, where it is, and how a range of third party services are securing it is an unprecedented challenge.

IT leaders see the challenge primarily across three categories:

Challenges in the Cloud Era

01
35% Securing sensitive data across multiple environments
02
30% Lack of centralized management
03
25% Lack of visibility and control over cloud-based data

Wakefield

Threat Actors Have Changed with the Times

Today’s adversaries operate with purpose, discipline, and business-like precision, constantly adapting their tradecraft to exploit modern enterprise environments.

The broader corporate shift toward cloud infrastructure, identity-driven access, and distributed workforces has forced threat actors to explore new ways to conduct and scale their operations. As threat actors evolve, they increasingly rely on techniques like valid credential abuse, hands-on-keyboard intrusions, and social engineering—often bypassing traditional malware entirely. Their methods reflect an enterprising mindset that prioritizes innovation, operational efficiency, and technical skill.

According to CrowdStrike 2025 Global Threat Report:

“In 2024, new and unattributed CLOUD INTRUSIONS INCREASED 26% compared to 2023, indicating more threat actors seek to exploit cloud services. CrowdStrike observed more intrusions in which attackers gained initial access via valid accounts, leveraged cloud environment management tools for lateral movement, and abused cloud provider command line tools.”Crowdstrike [1]
“Access broker activity surged in 2024, with advertised accesses increasing by nearly 50% over 2023. Meanwhile, valid account abuse was responsible for 35% of cloud-related incidents, reflecting attackers’ growing focus on identity compromise as a gateway to broader enterprise environments.” Crowdstrike [1]
Microsoft noted the eye-watering number of identity-based attacks in their Microsoft Digital Defense Report, where the company said that it blocks over 600 million identity-based attacks daily.Microsoft [2]
“In 2024, malware-free activity accounted for 79% of detections, a significant rise from 40% in 2019.”Crowdstrike [1]

And finally, they also observed a dramatic decrease in the amount of time it takes for a threat actor to move from the area they initially compromised to other systems (aka breakout time). “In 2024, the average breakout time for interactive eCrime intrusions fell to 48 minutes, down from 62 minutes in 2023.

Alarmingly, the fastest breakout was recorded at just 00:51 — meaning defenders may have less than a minute to detect and respond before attackers establish deeper control.”Crowdstrike [1]

These stats are alarming for any organization with data in cloud or SaaS environments.

Everyone's data is a potential target.

And with the growth in identity-based attacks, opponents are logging in, not breaking in, something that is a lot harder to detect and stop in any environment. That initial foothold also makes it much easier to move quickly across IT systems.

Here’s what IT and security leaders said about how these circumstances are affecting them on the front lines:

Experienced a cyber attack
0%
Experienced a cyberattack in the past year
25+ Cyber Attacks
0%
Experienced a cyberattack more than 25 times in the past year
Paid a Ransom
0%
Paid a ransom to recover data from successful attacks
partial Harm to backup & recovery
0%
Threat actors able to at least partially harm backup and recovery
complete harm to backup & recovery
0%
Threat actors completely successful in harming backup and recovery

Wakefield

Coming From All Directions

IT and security leaders said that the types of cyberattacks they were experiencing are coming from all directions.

Here’s what IT and security leaders said about how these circumstances are affecting them on the front lines.

Issue 01

40%

Increased anxiety about threats and attacks
Issue 02

37%

Damage to company reputation and loss of customer confidence
Issue 03

33%

Leadership now forced to report/disclose

However, it’s worth noting that as a whole, their experience ran the gamut from increased security measures and costs to unrecoverable data loss.

Moving From Chaos to Confidence: A Plan of Action

Given all this new complexity, and the new threats that have arisen in response to it, how can IT and security leaders feel confident in their data security solutions?

How

do

IT

and

security

leaders

inspire

confidence

at

the

executive

and

board

level,

so

that

when

something

happens

and

it’s

“when,”

not

“if”

their

“I’ve

got

it”

is

good

enough?

Many businesses also harbor misconceptions about the inherent security of cloud services, assuming that cloud providers will take full responsibility for safeguarding their data. This reliance can lead to a false sense of security, leaving organizations vulnerable to risks, such as data breaches or loss, particularly if something catastrophic occurs.

While cloud adoption has become a cornerstone of modern business practices, some organizations remain hesitant to fully embrace the shift. Challenges, such as understanding application dependencies, comparing on-premises and cloud costs, and assessing technical feasibility, often serve as significant barriers.

A Zero Trust Security Model

In contrast, other organizations are turning to a Zero Trust security model, which assumes no user or device can be inherently trusted, regardless of location.

While this approach can bolster security, it is laborintensive and requires meticulous planning, including the assessment of every device, application, and user within the organization. The rigorous nature of Zero Trust demands a significant cultural and operational shift, which can drive up costs, increase complexity, and disrupt workflows. This makes it difficult to implement without slowing business velocity, presenting a trade-off between security and operational efficiency.

There’s another way. Managing hybrid, globally dispersed data begins with an awareness of where things are. Sensitive data should be located and classified, so companies can identify and protect potentially sensitive targets as early as possible.

For example, through our Rubrik telemetry of production data, we can estimate that organizations typically store sensitive structured data sits in these environments:

DynamoDB

0.00%

Amazon DynamoDB (Key-Value Document Store) 

• Social Media User Profiles 

• IoT/Device Sensor Data or Telemetry 

• Product Catalogs (E-Commerce)

RELATIONAL DATABASE SERVICE

0.00%

Amazon RDS (Relational Database Service) 

• HR Employee Database 

• Order Management (E-Commerce) 

• Healthcare Patient Records

SNOWFLAKE

0.00%

Snowflake is a Cloud Data Warehouse 

• Customer Data (Retail/E-Commerce) 

• Financial Transactions (Banking) 

• Sales Transactions 

• Analytical Aggregates (Total Revenue, Customer Lifetime Value) 

• Security Logs (SIEM integration)

Virtual Machines

0.00%

Virtual Machines (EC2, AzureVM) 

• Hosting databases 

• Hosting applications 

• Legacy workloads 

• Configuration data 

• Log data used for analysis

And that its biggest caches of sensitive unstructured data are estimated to sit in these environments:

OneDrive
onedrive

0.00%

of all sensitive unstructured data is stored in OneDrive
SharePoint
sharepoint

0.00%

of all sensitive unstructured data is stored in SharePoint
S3
s3

0.00%

of all sensitive unstructured data is stored in S3

Securing Your Sensitive Data

As an IT and security leader, even with this amount of information, you can start to make some decisions. Ultimately, you care about all your data, but the stuff you really care about is your sensitive data.

Knowing how much of it you have and where it lives is your first step to  better securing it.

From there, you can start to break down just how sensitive your cloud and  SaaS data is. Here are some examples to get you started.

In the Cloud
0%High
36.29% of overall sensitive files (including structured/unstructured files) is classified as HIGH
0%High
14.66% of all unstructured data is classified as HIGH
0%Medium
45.49% of overall sensitive files (including structured/unstructured files) is classified as MEDIUM

And you can start to pinpoint just where that highly sensitive data is.

Cloud S3
High

34.70% of all sensitive files exist in the S3 and are classified as HIGH

Medium

41.68% of all sensitive files exist in the S3 and are classified as MEDIUM

High

13.58% of all sensitive files are unstructured and classified as HIGH

Medium

0.51% of all sensitive files are unstructured and classified as MEDIUM

Then, you can start to draw a clearer picture of what sensitive data might include:


Personal
Personally Identifiable Information (PII)
0%
of all sensitive data is PII
0%
of all unstructured data is PII

Digital
Digital credentials, source code, and encryption keys
0%
of all sensitive data is DIGITAL
0%
of all sensitive unstructured data is DIGITAL

Business
Business plans, contracts, and strategic documents
0%
of all sensitive data is BUSINESS
0%
of all sensitive unstructured data is BUSINESS

Financial
Financial records, transactions, and account data
0%
of all sensitive data is FINANCIAL
0%
of all sensitive unstructured data is FINANCIAL

This exercise is the first step in reasserting knowledge and control. It’s also a great way to get board-level support for your security strategy. The high-level message changes from “We have sensitive data spread across several unknown points, with varying security” to:

The

high-level

message

changes

from

“We

have

sensitive

data

spread

across

several

unknown

points,

with

varying

security”

to:

Here

is

a

list

of

how

our

sensitive

data

is

being

used

and

how

we

are

protecting

it.

Establish Clear and Comprehensive Policies

After increasing awareness of data location and data type across the hybrid system, it’s important to establish clear and comprehensive policies. Unfortunately, at present many companies have a haphazard approach.

Comparing the data that we monitor in production environments to the data that we back up, we have seen the huge disparity between how organizations protect on-premises data and how they protect their cloud and SaaS data.

How organizations handle data backups is particularly stark. On-premises data is routinely backed up with strict retention policies, air-gapped copies, and disaster recovery plans that have been refined over years.

Cloud and SaaS data, in the meantime, is often backed up haphazardly, if at all.  The implications for a cloud-centered ransomware attack are sobering.

This information leads us to believe that organizations are relying on their cloud providers’ native backup tools to secure their data. Unfortunately, native backup tools are often limited, infrequent, or tied to the provider’s infrastructure in ways that may not align with an organization’s recovery needs. Even assuming state of the art performance at every cloud and SaaS provider, surrendering your awareness and control is a problematic security approach.

No sensible risk management approach assumes everything is state of the art. The fact is, critical business data stored in cloud applications and SaaS platforms is more vulnerable to accidental deletion, ransomware attacks, and policy misconfigurations than its on-premises counterpart.

Controlling your backup capability, off prem as well as on, is a crucial part of controlling  corporate security.

This is beyond a technical problem. It’s a strategic blind spot. The question IT and security leaders should ask themselves:

Is

our

cloud

and

SaaS

backup

strategy

as

mature

and

robust

as

our

on-premises

backup

strategy?

Let’s refer to a real world example with the Gitlab database incident of January 31, 2017.

trash can
01

An engineer accidentally deleted the production database, resulting in the loss of six hours worth of critical data. This included issues, merge requests, and comments.

recurring warning
02

The recovery process failed due to multiple backup failures—primary backups were corrupt, LVM snapshots were outdated, and replication was unreliable.

cloud with an X
03

This incident exposed the risks of assuming cloud-native environments inherently provide robust backup protections. GitLab's postmortem revealed that their backup strategy was insufficient compared to traditional on-premises practices.

Addressing the problem requires action: a unified approach to data protection that extends backup and recovery policies beyond on-premises systems into the cloud-native world.

Recommendation

Here’s how IT and security leaders can increase their capabilities and confidence in their ability to protect their data across cloud, SaaS, and on-premise environments. 

01 First, know where your data, particularly your sensitive data, is, at motion and at rest.

Prioritization matters, since everyone has scarce resources. Don’t secure a folder of five-year-old marketing videos with the same intensity required for an organization’s most precious intellectual property.

Keep in mind this might be a bigger undertaking than it sounds. Like all data, sensitive data can change over time. For instance, an idea could go from a single employee’s random musing to one of the main building blocks of an organization’s strategy in a matter of weeks. Still, you need to know where it all is and protect  it accordingly.

02 Inform your policies, processes, and procedures with data awareness and data prioritization.

Inform your policies, processes, and procedures with data awareness and data prioritization.

Policies

Set appropriate policies. For instance, control the conditions under which sensitive files are downloaded. For example, maybe it’s a policy to restrict editing access to your organization’s source code on a public WiFi network if you aren’t using a VPN. These may seem like obvious ideas, but you’d be surprised how often people forget to employ them in a systemic way.

Processes and Procedures

Define methods for enforcing policies. For instance, if users aren’t allowed to download specific files under specific circumstances, then:

  • How are you going to enforce that policy? 
  • How are you going to track when it’s violated? 
  • How are you going to deal with the fallout of that violation? 
  • Who is responsible for making sure that happens?

Companies must answer all these questions to ensure data safety and to give boards and leadership confidence that you know where all your sensitive data is and you have a plan for protecting it.

03 Use automation to help your security and IT teams level the playing field.

There’s no way anyone can expect security and IT teams to keep up with what’s happening with the vast amount of data an organization generates without some significant help. Even with monitoring and aggregation tools, the amount of alerts coming at often short-staffed teams is enough to make even the most talented and hardened IT and security professionals want to bury their heads in the sand.

The only way to effectively ensure that policies are enforced and processes and procedures are followed is through automation.

For example, when a security incident occurs, a root-cause analysis is necessary. Without automation, security analysts must manually sift through large volumes of data—a tedious and time-consuming process. As we know, repetitive tasks increase the likelihood of human error. A common example is an analyst in the SOC mistakenly marking a true positive as a false positive, potentially leaving a threat unaddressed.

By automating routine and repetitive tasks, organizations not only reduce errors but also free up skilled professionals to focus on more strategic and high-value security efforts.

Data Backup & Recovery

IT teams manually manage backups, requiring them to monitor schedules, validate data integrity, and coordinate recovery processes during an incident. The approach is not only time-consuming but also prone to errors, such as missed backups or failed recoveries, leaving the organization vulnerable during critical moments.

Threat Detection and Alert Triage

Security analysts manually sift through thousands of security alerts, leading to alert fatigue and potential missed threats.

Incident Response and Root-Cause Analysis

Security teams must manually correlate logs from various sources (firewalls, SIEMs, endpoint protection systems) to determine the root cause of an incident.

Vulnerability Management & Patching

IT teams manually track vulnerabilities, assess risks, and deploy patches—a time-consuming and error-prone process.

Access Control & Identity Management

IT admins manually provision and revoke user access, increasing the risk of lingering privileged accounts.

Behavioral Anomaly Detection

Security teams rely on static rules to flag suspicious activities, which can lead to excessive false positives

Conclusion

The transition to multi-cloud hybrid environments marks one of the most significant milestones in the history of business computing.

It has become essential for corporate workflows and inter-corporate collaboration. Yet, as this analysis has shown, these benefits come at a high cost in terms of security risks. Hybrid environments introduce unprecedented hazards: IT leaders report challenges with system-wide data security, lack of visibility, and the inability to establish centralized control. Threat actors are exploiting these weaknesses relentlessly and employing evolving techniques like identity-based strategies, which now account for the majority of attacks. The results are alarming:

The Results

01

90%

About 90% of organizations surveyed have been attacked, with many facing repeated assaults

0%
02

86%

86% of companies paying ransom when faced with extortion demands report

0%
03

75%

75% of companies confirm attackers were able to breach and harm their data

0%
Acknowledgements

Rubrik would like to extend our appreciation to all outside organizations providing their hard-earned data knowledge to this study.

 

As with all things Rubrik Zero Labs, it takes a village to pull off these studies. Wakefield Research provided external data to make this research as objective as possible. ShapedBy found a way to take the data and bring it to life. Finally, many Rubrikans worked hard to provide capability, context, and guidance. We’d like to extend a specific appreciation to Amanda O’Callaghan, Linda Nguyen, Lynda Hall, Ben Long, Peter Chang, Ajay Kumar Gaddam, Dan Eldad, Gunakar Goswami, Prasath Mani, Ethan Hagan, Kevin Nguyen, Caleb Tolin, Sindhu Nagendra, Trinetra Reddy, Heather Webb, Meghan Fintland, Görkem Otman, and Fareed Fityan.

Latest Reports