Is Cloud Infrastructure More Complex Than We Think?

Cloud complexity is increasing due to multiple stakeholders and fragmented processes. A recent Volkswagen breach highlights the risks of misconfigurations, particularly those introduced by third-party vendors.

January 11, 2026
5 Minute Read

In my previous post, I talked about how cloud security has become a reactive game - issues only being addressed after they are detected in production. At first glance, it seems there’s a solution in the form of “shift-left” practices - scanning IaC templates and managing configurations before deployment. However, these methods often assume a level of simplicity in cloud environments that just is not common in the real world.

Infrastructure as Code (IaC) was supposed to simplify and standardize cloud deployments, but only 13% of organizations have fully matured their IaC programs. Many still rely on manual processes, “ClickOps” or partial automation that are prone to countless misconfigurations. This complexity is compounded by the number of stakeholders touching the cloud environment: DevOps teams, IT departments, third-party vendors, and even M&A-driven “sub-organizations” operating under the same corporate umbrella. Each one adds a new layer, a new tool, and opens the door to misconfiguration.

The result? A lot more than just theoretical risk. Take the December 2024 incident at Volkswagen: a significant data breach exposed sensitive information including vehicle locations, customer information, and operational details on roughly 800,000 electric vehicles, all traced back to a cloud misconfiguration managed by a third-party provider. In cases like this, organizations relying on external vendors have limited control over their own security posture, leaving them exposed. Reactive cloud security measures and traditional CSPM approaches simply weren’t enough to prevent this incident. But then, what security approach could possibly work when an external vendor holds the keys to your cloud kingdom?

Isn’t it time we rethink cloud security entirely? Instead of resolving problems post-deployment, perhaps we need a truly proactive strategy - one that aligns with the realities of modern, multi-stakeholder, hyper-scaled cloud environments. If we don’t adapt now, we risk chasing one misconfiguration after another, never pausing to address the root cause: complexity itself.

About
Ariel Litmanovich

Ariel Litmanovich is Co-Founder & CTO of Aryon Security, the Cloud Security Enforcement Platform that prevents cloud risks by enforcing policy before deployment. At Matzov, the IDF's elite cybersecurity unit, he led the military's transition to the cloud and designed its secure cloud infrastructure.

Read more articles by author

Notes & Sources

  1. Is Something Missing in Cloud Security? https://lnkd.in/dKmUGTAj
  2. StackGen 2025 Report https://lnkd.in/d2M6ySQ
  3. Volkswagen Breach https://lnkd.in/dfD7gD4e

Continue reading

July 29, 2026
Ariel Litmanovich
Tom Tsabar
Ido Dar

Cloud ShutterGap: Millions of Cloud Resources Exposed - The Blind Spot CSPM/CNAPP Tools Don’t Cover

Aryon's research reveals millions of misconfigured ephemeral cloud resources, publicly exposed for only moments before being removed. Often, these exposures last only a few minutes, long enough for attackers to discover and exploit them, but too short for traditional CSPM and CNAPP tools to detect. Many of these resources contain highly sensitive information.

May 25, 2026
Ron Arbel

The Missing Link Between Security and Operation: Bringing Security Policy into the Moment of Deployment

In cloud environments, security and operations often meet too late. Security teams define the policies, best practices, compliance requirements, threat models, and risk tolerance that should guide how cloud resources are configured. DevOps and IT teams apply those decisions in practice as they create, configure, and change cloud resources every day.

May 3, 2026
Joshua Behar
Ron Arbel

Can We Kill the Kill Chain by Preventing Cloud Security Misconfigurations?

How Marriott, SolarWinds, and Salesloft/Drift expose a structural flaw in modern cloud security and how to fix it before the next breach starts.

April 27, 2026
Ron Arbel
Joshua Behar

A Year of Proof: Why Prevention is the Only Path Forward

As we close the chapter on 2025, we find ourselves reflecting on a year shaped by three powerful forces: curiosity that pushed boundaries, relentless execution that turned ideas into impact, and, above all, operational proof that our approach works.

April 20, 2026
Joshua Behar
Ron Arbel

Beyond the Alert: A Pragmatic Roadmap to Cloud Security Maturity Model (CSMM)

Cloud security has a fundamental structural problem, and most organizations are only beginning to fully recognize it. Despite significant investment in tooling and talent, security teams remain perpetually reactive, identifying misconfigurations after they have already reached production, triaging growing volumes of alerts, and working to remediate risks that have already existed in a potentially exploitable state, following the CSMM Model can change things around.

April 15, 2026
Ariel Litmanovich

Tackling Cloud Complexity with Proactive Security

“The cloud is just someone else’s computer.” It’s a funny saying that oversimplifies what cloud computing really means. In reality, anyone who has dealt with cloud security knows the cloud is far more complex than just renting another person’s server.

Ready to take your first proactive step?