of Kubernetes
security report
2024 edition
Key findings
Cloud-native technologies are changing the way organizations develop,
Key findings
For the 2024 edition of this report, Red Hat sponsored a survey of 600
United Kingdom (U.K.), and the English-speaking Asia Pacific region (APAC)
security. Data was gathered through 21-minute online and phone interviews with
Executive summary Finding 1:
About this report
Security issues forced 67% of companies to delay
or slow down application deployment.
microservices-based architectures to transform how they build, run, and scale
many refactor existing applications using container-based technologies. In either
flexibility to run and manage applications across hybrid environments. However,
deployment and maintenance—can diminish these valuable benefits. In fact, our
Executive summary Finding 2:
About this report
Security incidents lead to broad consequences,
including employee termination and loss of revenue.
delayed application deployments. 26% of respondents said that a security
was fined as a result of the incident. In these situations, the loss of valuable
and negative publicity can place significant financial burdens on businesses.
46% of respondents also revealed that their organization experienced revenue
to remediate issues. And as customers lose trust in a business’s data protection
Nearly 9 in 10 organizations had at least 1 container
or Kubernetes security incident in the last 12 months.
and Kubernetes-related security incidents can impact all phases of the
experienced runtime incidents in the last 12 months, an almost equal number
major vulnerabilities to remediate. At the same time, 40% said their organization
26% reported that their organization failed an audit.
cross-functional features and simplified operations. While Kubernetes provides
enhance security across your cluster, some features are overly permissive or
protection. Additionally, while security controls like SELinux can significantly
integrate into an operational environment. These difficulties frequently surface
of the application life cycle. Our survey results show that many organizations
Key findings
Detected misconfiguration 40%
Finding 4:
Current container security
strategies present concerns
42% of respondents believe that their company
Finding 12: does not sufficiently invest in container security
Tools support software
supply chain security or address related threats.
deployment and scalability, they must also adapt their security processes to
Executive summary threats, robust security measures are needed to protect against vulnerabilities,
About this report unauthorized access, and data breaches. Even so, some respondents are
Key findings skeptical of their company’s container strategy. In fact, 23% believe that their
Finding 1: organization’s strategy does not sufficiently address container security threats,
Security issues impact
business outcomes while 19% think that investment in container security is inadequate.
complexity and potential security risks of modern environments. By implementing
infrastructure, Kubernetes control plane, network, and container images and
Inadequate investment
Finding 9: in container security 19%
Security issues can lead
to serious consequences
It is progressing too slowly 19%
Executive summary Finding 5:
About this report
Only 1/3 of respondents say their security teams
are responsible for Kubernetes security.
in container-based Kubernetes environments. Our survey results show that there
What role at your company is most responsible for container and Kubernetes security?
Executive summary In fact, only 34% of respondents overall say that security teams are most
About this report responsible for container and Kubernetes security within their organization.
Key findings Various operations roles, including ITOps, DevOps, and DevSecOps, are
Finding 1: responsible for security at 50% of organizations. Interestingly, APAC
Security issues impact
business outcomes organizations are more likely to have a DevSecOps role most responsible (21%).
Finding 2:
Security breaches Advanced Kubernetes security technologies and processes can promote close
affect everyone
collaboration between diverse teams and remove barriers that isolate domain
Finding 3:
Security incidents occur experts. Developers can create and integrate custom software, open source
in all life cycle phases
components, and container images. Security experts can define and implement
Finding 4:
policies and controls across cluster resources. And operations teams can manage
Security strategies
present concerns cluster infrastructure, access controls, and authorization mechanisms—all using a
Finding 5: single set of common security solutions.
Responsibility for
security is decentralized
Finding 6:
DevSecOps practices
are common
Organizations continue to adopt DevSecOps practices to identify and mitigate
In fact, 42% of respondents say their organization integrates and automates
Enhance your container At the same time, 48% report that their organization understands the value of
and Kubernetes security
DevSecOps and is in the early stages of adoption, with development, operations,
Executive summary stage. For the remaining 10% of organizations, separate DevOps and security
About this report teams may lead to reactive processes that only address vulnerabilities at
Key findings deployment or runtime, resulting in decreased efficiency, speed, and software
Finding 1: quality, along with slower application delivery.
Security issues impact
business outcomes
where we’re integrating and DevOps and security collaborating security remain
Finding 7:
misconfigurations, and exposures in their container
Executive summary A top concern for 27% of respondents, incorrectly configured components—
About this report including base images, libraries, and dependencies—can introduce critical security
Key findings issues across entire environments. If not properly validated and maintained, these
Finding 1: components can serve as potential attack points and compromise the integrity
Security issues impact
business outcomes and confidentiality of critical applications and sensitive data.
security processes. For example, implementing automated, continuous security
configuration of security-sensitive components.
Finding 7: 16%
Kubernetes brings
new security challenges
33% Misconfigurations/
Finding 11:
Software supply chain
security worries are real Q10. Of the following risks, which one are you most worried about for your container and Kubernetes environments? Base size: Total = 600
Executive summary Finding 8:
About this report
Coding errors, unprotected sensitive data, poor
network security, and undetected malware present
errors (36%) and exposed sensitive data (34%) to poor network security (32%)
comprehensive strategies to mitigate vulnerabilities and safeguard against cyber
identify vulnerabilities and misconfigurations to help you implement targeted
measures tailored to application requirements can effectively mitigate risks,
controls integrated throughout the entire application life cycle can improve
Based on our survey results, organizations are actively working to reduce high-risk
half of companies surveyed are focusing on every potential high-risk security
exposed sensitive data, poor network security, overprivileged containers, and
Executive summary
About this report Which of the following are Which of the following high-risk issues
considered high-risk security are you addressing at your company?
Key findings
issues in your company? (Among those who cite each concern)
business outcomes Coding errors
Exposed/unprotected sensitive data like secrets
Finding 3: 34% 66%
Poor network security
Finding 8: Inadequate access controls
Organizations are working Identity access management (IAM) and role-based access control (RBAC)
on high-risk issues 26% 52%
26% 56%
Executive summary Finding 9:
About this report
More than half of organizations found unauthorized
process execution in their environments.
exposure of sensitive data (43%) to ransomware (41%)—concern respondents,
compromise the integrity, confidentiality, and availability of data and systems.
actors to infiltrate systems, disrupt operations, and access sensitive information.
financial and reputational damage resulting from data breaches. And ransomware
These concerns are justified. For every high-risk security issue identified in our
For example, the top worry was unauthorized process execution, cited by 45%
actually experienced some type of unauthorized process during the last 12
internal cloud resources, denial of service attacks, compromised credentials, and
worried about these high-risk issues.
Executive summary
About this report Which of the following Which of the following high-risk issues has your
high-risk issues worry company experienced in the past 12 months?
Key findings
you the most? (Among those who cite each worry.)
Security issues can lead
to serious consequences
Risk management is key
for software supply chains
Finding 11: Q15. Which of the following high-risk issues worry you the most? Base size: Total = 600
Software supply chain Q16. Which of the following high-risk issues has your company experienced in the past 12 months? Base size: Among those who cite
each worry = 189 - 270
security worries are real
Finding 12:
Tools support software
supply chain security
Finding 13:
Organizations use
open source tools for
Kubernetes security
Executive summary Finding 10:
About this report
44% of respondents say software vulnerabilities are
the highest-risk aspect of software supply chains, an
variety of commercial vendors and open source projects, so it is crucial to ensure
Finding 10:
maintained to reduce the risk of incorporating new vulnerabilities. And untrusted
Risk management is key content can compromise system integrity and allow unauthorized access.
for software supply chains
Finding 11: Notably, concerns about software vulnerabilities increased 9% from 35% in
Software supply chain
security worries are real 2023 to 44% this year. And respondents in the technology industry ranked
Finding 12: vulnerabilities even higher, at 51%. We also found that respondents from small
Tools support software
supply chain security companies ranked insider threats higher than average, at 36% versus 31% overall.
Finding 13:
Organizations use Organizations can address these challenges with a comprehensive approach
open source tools for
Kubernetes security to software supply chain security that includes rigorous supplier evaluations,
Executive summary
About this report What aspects of the software supply chain security represent the highest risk?
Key findings
Finding 1:
Security issues impact
Software vulnerabilities 44%
business outcomes
Images and dependencies 23%
Repositories 20%
Executive summary Finding 11:
About this report
57% of organizations detected vulnerable application
components in their software supply chain in the last
organizations can mitigate the risk of supply chain attacks, unauthorized access,
stakeholder trust.
Finding 8: organizations’ software supply chains—including vulnerable application
Organizations are working
on high-risk issues components (37%), insufficient access controls (32%), and insecure container
warranted. Almost every issue identified in the survey was experienced by more
nearly 60% of companies.
Finding 12: concerned about each issue. In fact, the 4 issues of lowest concern—lack of
Tools support software
supply chain security SBOMs, continuous integration/continuous deployment (CI/CD) pipeline
Finding 13: weaknesses, version control weaknesses, and insecure Infrastructure-as-Code
Organizations use
open source tools for (IaC) templates—were experienced by more than twice as many organizations as
Kubernetes security
were concerned about the issue.
Enhance your container
and Kubernetes security
Executive summary
About this report Which of the following software Which of the following software supply
supply chain security issues chain security issues has your company
Key findings
is your company most experienced in the past 12 months?
Finding 1: concerned about? (Among those who cite each concern.)
Security issues impact
business outcomes
Lack of software bills of materials (SBOMs) or provenance
Finding 9: 26% 58%
Security issues can lead
to serious consequences
Continuous integration/continuous deployment (CI/CD) pipeline weaknesses
Risk management is key
for software supply chains
Finding 13:
Organizations use Q32. Which of the following software supply chain security issues is your company most concerned about? Base size: Total = 600
open source tools for Q33. Which of the following software supply chain security issues has your company experienced in the past 12 months? Base size: Among those
Kubernetes security who cite each concern = 107 - 223
Executive summary Finding 12:
About this report
Nearly half of respondents view security attestation
as a key software supply chain security control.
with a variety of advanced security tools and technologies—including security
mechanisms (41%). By verifying each software component’s origin, authenticity,
the integrity and trustworthiness of applications. Vulnerability scanning lets you
Image signing, deployment signing,
pipeline attestation, etc.
Vulnerability scanning 45%
Access and authentication 41%
Configuration management 35%
Kubernetes security
Executive summary proactively address security risks—before they can be exploited—by identifying
About this report and remediating potential weaknesses and vulnerabilities in your software supply
Key findings chain. With access and authentication mechanisms like multifactor authentication
Finding 1: (MFA) and RBAC, you can reduce the risk of unauthorized access to sensitive
Security issues impact
business outcomes software components and data.
tools for Kubernetes security
Finding 7: popular open source Kubernetes security tools.
Kubernetes brings
new security challenges
Finding 9: containers and Kubernetes environments. Respondent organizations rely on many
Security issues can lead
to serious consequences of these open source security tools to protect their cloud-native applications:
Finding 12:
Benchmark using Kube-bench.
Organizations use
open source tools for
Kubernetes security ► 28% identify security issues in Kubernetes clusters and cloud-native
Enhance your container environments using Kube-hunter, a security testing and scanning tool.
and Kubernetes security
Executive summary
About this report Which of the following open source tools do you use for Kubernetes security?
Key findings
Finding 1:
Security issues impact
Open Policy Agent (OPA) 35%
business outcomes
Terrascan 12%
Checkov 10%
Enhance your container
Executive summary
Security issues impact
business outcomes
Containers and Kubernetes can speed application development and deployment
technologies throughout their life cycles helps you protect applications without
slowing development or increasing operational complexity. Safeguard sensitive
in all life cycle phases data, intellectual property, and customer information. Meet corporate, industry,
Security strategies
present concerns customer trust and confidence. Reduce the costs of late remediation efforts.
are common Use Kubernetes-native security controls
Kubernetes-native security uses declarative data and native controls
new security challenges to protect your container workloads.
risk-based insights into configuration management, compliance,
Finding 10: ► Simplify and speed analysis and troubleshooting using the same
Risk management is key
for software supply chains infrastructure and controls for development and security.
Executive summary
Extend security across application life cycles
identify and mitigate potential vulnerabilities early, reducing the risk of
Finding 1:
Security issues impact data breaches, cyberattacks, and compromised user trust.
business outcomes
About our respondents
Executive summary
Key findings
This section provides more details about our respondents and their organizations.
Kubernetes adoption
Google Kubernetes Engine (GKE) 45%
Finding 8: Any Red Hat
Organizations are working
on high-risk issues
Azure Red Hat OpenShift, Red Hat OpenShift
(self-managed), Red Hat OpenShift Service 39%
on AWS, Red Hat OpenShift Dedicated
Azure Kubernetes Service (AKS) 32%
Kubernetes (self-managed) 23%
security worries are real
About our respondents Q3. What Kubernetes platform do you use to orchestrate your containers? Base size: Those using Kubernetes = 390
Executive summary Common pain points
About this report
Lack of full life cycle security and slow deployments are the 2 most common
Key findings
complaints about current Kubernetes security solutions.
application life cycle 33%
It’s slowing down development 33%
We lack internal talent to
are common
use it to its full potential 30%
operationalized in our systems 26%
Alert fatigue 26%
We don’t have a solution 10%
Executive summary Supply chain security tools
About this report
Vulnerability scanners are the most used security tools, followed by CI/CD, static
Key findings
security analysis, and SBOM tools. Organizations use an average of 3 security
Which of the following types of security tools do you use for your software supply chain?
Vulnerability scanners 44%
Static security analysis 34%
Executive summary Other cloud-native technologies
About this report
Kubernetes-native CI/CD tools are among the top cloud-native technologies
Key findings
in use.
