Symantec Survey Reveals Organizations Concerned Yet Optimistic about Security in the Cloud

Oct 5, 2011 | Cloud, News, Security

SOURCE:  Symantec

BARCELONA, Spain – Symantec Vision 2011 – October 4, 2011 – Symantec Corp. (Nasdaq: SYMC) today announced the results of its 2011 State of Cloud Survey, which examined how organizations are adopting cloud computing and dealing with the changes it can impose on their approach to managing IT. According to the survey, organizations have mixed feelings when it comes to security – with a majority ranking it as both a top concern and top goal of moving to the cloud. The survey also revealed that IT organizations may not be adequately prepared for the move to the cloud, as almost half of the respondents said their IT staffs are not ready at this time.

Read more detailed blog post:

“These survey findings reinforce what our customers are telling us. Security is one of their top concerns when it comes moving to the cloud,” said Francis deSouza, group president, Enterprise Products and Services, Symantec. “To be confident in the cloud, IT organizations must take measures to ensure they have the same visibility and control of their information and applications whether they are in the cloud or residing on their own infrastructure.”

Click to Tweet: 87 percent of survey respondents expect moving to the cloud will improve security: http://bit.ly/q3XLCV

The survey focused on various forms of cloud computing including Public and Private Software-as-a-Service, Hybrid Infrastructure or Platform-as-Service, as well as Public and Private Infrastructure or Platform-as-a-Service.

Organizations Torn Over Security

According to the survey, organizations are conflicted about security – rating it both as a top goal and as a top concern with moving to the cloud. Eighty-seven percent of respondents are confident that moving to the cloud will not impact or will actually improve their security. However, achieving security for cloud environments is also a top concern for these organizations, which cited potential risks including malware, hacker-based theft and loss of confidential data.

“With the cloud, everything depends on how you secure your data,” said the CTO of a small technology company. “If there’s no security, there’s no point in moving to the cloud.”

IT Staff Not Quite Ready for the Cloud

Despite a great deal of consideration, many organizations claimed that they are not ready to adopt the cloud. The minority of respondents (between 15 and 18 percent) rated their staff as extremely prepared for the transition to cloud. Almost half of the respondents said their IT staffs are not ready at this time.

Part of the reason for this readiness shortfall is lack of experience, as just 25 percent of IT teams have any cloud experience. As a result, most organizations are currently turning to outside resources for help. In fact, when deploying hybrid infrastructure or platform-as-a-service, about 3 in 4 respondents said they are turning to value added resellers (VARs), independent consultants, vendor professional services organizations or systems integrators.

Few Have Crossed the Finish Line

Many organizations are talking about moving to the cloud, with 75 to 81 percent at least discussing all forms of cloud. Notably, the study found a high interest in cloud services. Seventy-three percent of respondents have adopted or are adopting some sort of cloud service, with security services leading the way. The top cloud services companies are adopting include email services (such as management or security); security management; and web and IM security.

However, few have fully migrated to the cloud. Less than 20 percent reported having completed implementing each of the cloud focus areas covered by the research. About 1 in 4 organizations are currently in an implementation phase. About two-thirds are still in early discussions, trials or not considering a move to the cloud at all.

Reality Not Meeting Expectations

The survey discovered that organizations having implemented cloud technologies are not seeing the results/benefits they had anticipated. Eighty-eight percent expected cloud to improve their IT agility, but only 47 percent said that it actually did. Results also fell short in the areas of disaster recovery, efficiency, lower operational expenses and improved security.

Recommendations

  • Take the lead in embracing cloud computing. IT needs to take a proactive role in embracing the cloud. Too many IT organizations today are taking a slow, methodical, conservative approach to moving to the cloud. As an IT leader, you should maintain control of important aspects such as security, availability and cost. That’s hard to do unless your staff has received the proper training and preparation.
  • Set information and application tiers.  Not all of your information and applications are created equally. Perform an analysis and place your information and applications into tiers to determine what you feel comfortable moving to the cloud.
  • Assess your risk and set appropriate policies. Assure critical information is only accessible by authorized users and that critical information doesn’t leave the company. You should also make sure cloud vendors can meet your compliance requirements. Finally, assess potential cloud vendors for operational issues such as high availability and disaster recovery abilities.
  • Get started now. You don’t have to take an all or nothing approach to cloud computing. Leveraging cloud services are an easy first step to moving to the cloud. While it may take time to prepare to move business-critical applications, you can start immediately with simpler applications and services.

Symantec’s 2011 State of Cloud Survey

Symantec’s 2011 State of Cloud Survey focused on various forms of cloud computing including Public and Private Software-as-a-Service, Hybrid Infrastructure or Platform-as-Service, as well as Public and Private Infrastructure or Platform-as-a-Service. The findings are the result of research conducted April-July 2011 by Applied Research, which surveyed IT and C-level professionals responsible for computers, networks and technology resources at both SMBs and enterprise organizations. This is one of the largest cloud surveys of its kind with findings based on 5,300 responses from 38 countries worldwide.

Resources

Connect with Symantec

About Symantec

Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.

Note to Editors: If you would like additional information on Symantec Corporation and its products, please visit the Symantec News Room at http://www.symantec.com/news. All prices noted are in U.S. dollars and are valid only in the United States.

Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners.

Forward-looking Statements: Any forward-looking indication of plans for products is preliminary and all future release dates are tentative and are subject to change. Any future release of the product or planned modifications to product capability, functionality, or feature are subject to ongoing evaluation by Symantec, and may or may not be implemented and should not be considered firm commitments by Symantec and should not be relied upon in making purchasing decisions.

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more
Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

July 24, 2026 | ITBriefcase.net Why it matters: OpenAI disclosed on July 21 that two of its AI models — GPT-5.6 Sol and an unnamed, more capable pre-release model — autonomously escaped an internal evaluation sandbox while being tested against the ExploitGym...

read more