Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

Container and Kubernetes Security Concerns are Inhibiting Business Innovation

cyber_lock
February 19, 2020
Nearly half of all companies surveyed in a report have delayed moving an application into production because of concerns over security of containers or Kubernetes.
 
StackRox's State of Kubernetes and Container Security report incorporates input from more than 540 IT professionals, representing a much broader perspective than previous reports (390 in Spring 2019, 230 in Fall 2018). This edition also uncovered new findings about the impact that security concerns are having on companies embracing Kubernetes and containers.
 
Containers, Kubernetes, and microservices application patterns are three of the leading drivers of enterprise IT innovation and digital transformation, says the report. Companies have moved quickly to embrace these technologies for their advantages in application development and deployment, from faster development and deployment to quicker bug fixes and patches, leading to faster feature delivery that drives competitive differentiation. 

 

"The latest edition of this report is our third time asking companies to comment on what aspects of their container strategy they’re most concerned with. Security has topped the list each time. We’re also not surprised because Kubernetes is complicated, and while containers and Kubernetes offer a lot of security advantages (declarative data, immutable infrastructure), getting the settings correct to protect the infrastructure is not intuitive," says Michelle McLean, Vice President of Product Marketing at StackRox."When you look at other feedback in the survey, particularly where people feel challenged with Kubernetes, you see that a skills gap and the steep learning curve top that list, which feeds into concerns about getting security correct. Plus, anecdotally, we see companies all the time who are at least partway down the path on their container and Kubernetes journey who feel like they have not yet taken the steps they need to have to secure this new cloud-native stack." 

 

McLean notes that "companies face two main risks by not having tooling and processes in place for container security:"

  1. The most obvious, of course, is exposure to a breach. The infrastructure has a lot of inherent security capabilities, but they are not enabled by default because containers and Kubernetes are – first and foremost – application development tools, and even when the CNCF releases updated versions with Kubernetes with more powerful security features, they’re off so that upgrading Kubernetes will not break any application functionality.
  2. The second big risk, which our survey identified – and which, to be honest, we were surprised to see – is that companies will have to delay the roll out of Kubernetes applications until security can “catch up.” Nearly half (44 percent) of our respondents acknowledged delaying moving an application into production because of a lack of security. Slowing application releases compromises one of the key advantages – faster application iteration – of using this technology, so the sooner companies can get this cloud-native stack deployed, the sooner their business will reap the rewards.
 
Key findings in the report include:
 

Nearly all – 94 percent – of the respondents have experienced security incidents in their container environments in the past 12 months. Data breaches and exposures due to human error, such as misconfigured containers and Kubernetes deployments, have become alarmingly common. Among those reporting security incidents, the majority – 69 percent – experienced a misconfiguration incident, while 27 percent reported a security incident during runtime and 24 reported having had a major vulnerability to remediate (respondents could select as many responses as applied).

Exposures due to misconfigurations dwarf all other security concerns.  In this third edition of the StackRox report, respondents once again identified exposures due to misconfigurations as the most worrisome security risk for their container and Kubernetes environments, with 61 percent citing this concern. Only 27 percent cited vulnerabilities as their main concern, and just 12 percent worry most about attacks at runtime. This data speaks to the importance of configuration management in securing container and Kubernetes environments – the flexibility of these powerful platforms brings its own challenges.

Managed Kubernetes services have enjoyed major growth.  Of the respondents running containerized applications, Kubernetes is being used by 86 percent of them – the same as the Spring 2019 survey showed. However, the way Kubernetes is being used has changed dramatically. No longer is self-managed the most dominant way to run Kubernetes – 37 percent of respondents cited using Amazon EKS compared to 35 percent managing Kubernetes themselves, down from 44 percent in Spring 2019. Use of both Azure AKS and Google GKE also climbed, with each cited by 21 percent of respondents. 

Hybrid deployments dropped while cloud-only environments grew. Hybrid deployments remain more popular than cloud-only deployments, at 46 percent compared to 40 percent. But hybrid deployments saw a big drop from our survey six months ago, when they represented 53 percent of respondents. Of the cloud-only deployments, multi-cloud gained steam, increasing from 9 percent to 13 percent, but single-cloud use still dominates, at 27 percent for cloud only plus another 24 percent running on prem and in a single cloud provider. On-prem-only deployments have fallen dramatically since the first survey in Fall 2018, from 31 percent to just 14 percent today.

Skill shortages and a steep learning curve present the biggest Kubernetes challenges. Knowledge of Kubernetes is impacting more than 60 percent of respondents, with 33 percent citing an internal skills gap and another 28 percent identifying the steep learning curve as the most significant Kubernetes challenge their organization is facing. Only 15 percent cited executive understanding as their main difficulty, indicating that the business side of organizations understands and has bought into the benefits of Kubernetes.

Other key survey findings:

  • For the third time in a row, security leads the list of top concerns users have about container strategies. 
  • Container security strategies continue to mature, with the percentage of respondents who lacked any form of security strategy dropping 68 percent, from 19 percent to just 6.
  • Despite misconfigurations topping the list of concerns and incidents, respondents remain most concerned about the runtime phase of the container life cycle (56 percent) vs. build and deploy.
  • The percentage of organizations with fewer than 10 percent of their containers running in production fell from 39 percent to 28 percent.

“Our survey data affirms what we hear anecdotally from customers, that security has become a high priority as customers seek to deploy containers and Kubernetes applications in production,” said Kamal Shah, CEO of StackRox. “Organizations have executive buy in – the challenge is understanding the security and compliance requirements so that they can be addressed early in the application development life cycle and prevent delays to application deployment.”

For the full report, visit StackRox.com 

KEYWORDS: application security container security cyber security cybersecurity data breaches

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Leadership and Management
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Security Leadership and Management
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Cybersecurity
    By: Charles Denyer
close

1 COMPLIMENTARY ARTICLE(S) LEFT

Loader

Already Registered? Sign in now.

Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Computer with binary code hovering nearby

Cyberattacks Targeting US Increased by 136%

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Person holding large ball of twine

Preventing Burnout in The Security Industry

Harrods

Harrods’ Cyberattack: Cybersecurity Leaders Weigh In

2025 Security Benchmark banner

Events

September 29, 2025

Global Security Exchange (GSX)

 

November 17, 2025

SECURITY 500 Conference

This event is designed to provide security executives, government officials and leaders of industry with vital information on how to elevate their programs while allowing attendees to share their strategies and solutions with other security industry executives.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • container shipments

    Rapid growth across container and kubernetes adoption, security incidents, and DevSecOps initiatives

    See More
  • UAV Drone Security

    Privacy and Security are Biggest Concerns about the Business Use of Drones

    See More
  • Security newswire default

    Cyber, Economy and Medical Costs are Top Business Concerns

    See More

Related Products

See More Products
  • databasehacker

    The Database Hacker's Handboo

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!