Dominic Jainy stands at the intersection of traditional enterprise stability and the rapid evolution of modern infrastructure. As a seasoned IT professional with a portfolio spanning artificial intelligence, machine learning, and blockchain, Jainy has witnessed firsthand how the complexity of the digital landscape can outpace the human ability to secure it. His insights are particularly vital now, as organizations grapple with the fallout of mismanaged security policies in an increasingly fragmented hybrid cloud environment. We sit down with him to discuss the findings of a recent industry report that highlights a growing crisis: the dangerous gap between infrastructure-centric security and the reality of application-driven connectivity.
The conversation explores how legacy security approaches are failing to keep up with the demands of AI-heavy workloads and the resulting rise in operational risks. We delve into the staggering frequency of critical outages, the struggle for visibility across multicloud landscapes, and the shift toward sovereign and private cloud solutions as enterprises attempt to regain control over their data.
With roughly two-thirds of organizations experiencing critical application outages due to security misconfigurations in the last 12 months, why are we seeing such a massive disconnect between policy intent and actual operational stability?
It really comes down to the sheer weight of manual labor in an environment that has become too fast for human hands. When you look at the fact that 66% of businesses suffered a critical outage this year, it highlights that our security policies are no longer keeping pace with our hybrid cloud strategies. The tension in a server room when a major app goes dark is palpable, and often, it’s because someone tried to apply an old-school, device-by-device rule to a modern, fluid connection. We are operating in a world where manual policy management has crossed the line from being a simple inefficiency to a full-blown operational risk. It’s no longer just about a single firewall; it’s about the intricate web of application-connectivity that defines how a business functions today.
Given that 92% of IT professionals report difficulty gaining a comprehensive view of their security policies, what is preventing enterprises from achieving true visibility across their cloud environments?
The visibility gap is perhaps the most daunting hurdle because you cannot secure what you cannot see, and right now, most teams are flying partially blind. Only 9% of enterprises have managed to actually integrate security policy management into their daily workflows, which leaves the vast majority of organizations working in silos. This fragmentation is exacerbated by the fact that applications are scattered: 53% are in multicloud environments, while 46% sit in private clouds and 36% in hybrid setups. Managing these different “languages” of security across multiple platforms simultaneously creates a tangled mess where a change in one area causes an unforeseen collapse in another. Without a unified dashboard, security teams are essentially playing a high-stakes game of Whac-A-Mole across several different dimensions at once.
How has the shift from traditional network-centric infrastructure to an application-connectivity model fundamentally changed the way security teams must approach their work?
The old way was very much about building walls around specific pieces of hardware, but as the research suggests, the infrastructure-centric approach is now ill-suited to our current reality. We have moved from defining rules for a specific box in a rack to managing how an application talks to a database across different continents and cloud providers. This shift requires a mental pivot where the application itself becomes the center of the security universe rather than the network it travels on. When 50% of critical applications are still on-premises while the rest are distributed, the connectivity becomes the most vulnerable point of failure. If we continue to define policy rule-by-rule instead of looking at the holistic application journey, we will keep seeing these “downstream” costs like failed audits and rollouts that have to be yanked back at the last minute.
With eight in 10 companies currently reassessing their cloud plans to better support AI, what impact is this massive technological shift having on the security landscape?
AI is the primary engine driving this current cloud rethink, and it’s forcing a diversification of where data actually lives. We are seeing a major push toward sovereign clouds—with spending set to jump more than 35% this year—as companies realize they need tighter control over the data fed into their models. This move toward a mix of public, private, edge, and colocation environments to meet AI demands makes the security policy “surface area” much larger and more complex. It’s a bit of a double-edged sword: AI requires immense power and flexibility, but that same flexibility often leads to the misconfigurations we’ve been discussing. To survive this, organizations have to stop treating AI as a separate project and start seeing it as a core driver that necessitates automated, intelligent security guardrails.
The report mentions that only 48% of organizations can remediate a misconfiguration within a three-day window; why is the recovery process so sluggish even in high-stakes scenarios?
That three-day window is a lifetime in the digital economy, and the fact that more than half of companies can’t even hit that mark is a red flag. The delay usually stems from the “manual movement” of the remediation process—people have to trace the error, verify the fix, and ensure it doesn’t break three other things in the multicloud stack. It’s a high-volume, high-consequence control surface that is still being managed largely by hand, which is inherently slow and prone to error. When you have a mix of 29% public cloud and 53% multicloud dependencies, the cross-checking required to fix a single policy change can be overwhelming for a human team. This is why we are seeing such a push for pre-change risk analysis and automation; we need to catch the spark before it becomes a three-day fire.
What is your forecast for the future of automated security policy management over the next few years?
I expect we will see a radical shift where “manual” becomes a dirty word in security circles, with at least 70% of enterprises moving toward fully automated, continuous compliance assessments within the next two years. We are moving toward a “self-healing” infrastructure model where automation doesn’t just flag a misconfiguration but preemptively blocks it based on real-time risk analysis. The days of periodic reviews are over because a policy that was compliant yesterday can be a vulnerability today the moment a new AI workload is spun up. Ultimately, the winners will be the organizations that can bridge the 92% visibility gap using AI-driven orchestration to ensure that security is as fluid and dynamic as the cloud environments it is meant to protect.
