The Infrastructure You Built Is the Attack Surface You Defend

Gartner estimates that 40% of the average enterprise IT budget is spent maintaining technical debt rather than building new capabilities. That figure has held steady for three years. It means that for every pound an organisation spends on technology, nearly half goes towards keeping old systems running in a state that was never designed for the threat environment in which they now operate.
The CTO who inherited this architecture did not choose it. But they own it. And under frameworks like NIS2, DORA, and ISO 27001:2022, they are now personally accountable for the security posture of infrastructure they may not have had the budget, the mandate, or the political capital to modernise.
The architecture was built for a different era.
Most enterprise infrastructure was designed in the decade before cloud native security became a baseline expectation. The decisions that shaped it were rational at the time: consolidate on a platform, standardise the stack, optimise for availability. Nobody was thinking about lateral movement, identity-based attacks or API exploitation at scale. They were thinking about keeping the lights on, and the architecture reflects that priority.
Cisco’s 2026 research into critical infrastructure found that nearly half of all enterprise network assets were classified as ageing or already obsolete. In the United States, 80% of federal IT spending goes towards operating and maintaining existing legacy systems rather than replacing them. The pattern is not unique to government. It is structural across every sector that has built its digital architecture before cloud native security became the baseline.
The consequences are measurable. IBM’s 2024 Cost of a Data Breach report found that the average enterprise breach now costs $4.88 million, the highest figure on record. Unpatched legacy vulnerabilities ranked among the leading contributing factors. CISA’s Known Exploited Vulnerabilities catalogue grew by 34% year-on-year in 2025, with legacy system vulnerabilities accounting for 61% of the additions.
The infrastructure is not just old. It is actively targeted because it is old.
Cloud did not solve the problem. It multiplied the surface.
The promise of cloud migration was that it would retire legacy risk. For most organisations, it created a second layer of risk on top of the first. SentinelOne’s 2026 cloud security research found that over 94% of enterprises experienced at least one cloud security incident in 2025, up 14% from 2023. The average enterprise operates more than 3,000 misconfigured cloud assets across its environments at any given time.
The numbers behind those misconfigurations are uncomfortable. 23% of all cloud security incidents in 2025 stemmed directly from misconfigurations. 82% of those misconfigurations were caused by human error, not provider flaws. The average cost of a cloud misconfiguration breach is now $4.3 million, up 17% year-on-year.
The CTO who moved to the cloud assumed the provider would handle security at the infrastructure layer. In many cases, that assumption was partially correct. What it missed was the configuration, identity, and API layers, all of which remain the customer’s responsibility under every major shared responsibility model.
Palo Alto Networks’ Unit 42 found that 45% of cloud breaches involved insecure or exposed APIs. 84% of companies experienced at least one API incident in the past year. The attack surface is not the server. It is the integration.

The CTO’s visibility gap is the attacker’s advantage.
Palo Alto Networks’ 2026 Global Incident Response Report, based on more than 750 major engagements across 50 countries, found that 87% of intrusions involved activity across multiple attack surfaces simultaneously. Endpoints, networks, cloud infrastructure, SaaS applications, and identity systems were all compromised in the same incident chain.
That finding carries a specific implication for the CTO. If telemetry is siloed, if the endpoint team cannot see what the cloud team sees, if the network operations centre has no visibility into SaaS application behaviour, then the attacker is operating across surfaces that the defending organisation is monitoring in isolation. The attacker sees one environment. The CTO sees five dashboards that do not talk to each other.
Check Point’s 2026 Cyber Security Report documented that organisations faced an average of 1,925 attacks per week in the first quarter of 2025. That breaks down to roughly 275 attacks every day. The infrastructure that cannot correlate signals across those surfaces fast enough is not defending. It is recording its own compromise in fragments.
69% cannot maintain uniform security controls.
That figure comes from SentinelOne’s research into multi-cloud environments. 88% of organisations now operate hybrid or multi-cloud architectures. 69% of them cannot maintain uniform security controls across their cloud providers.
The gap is not just technical. It is organisational. The CTO who runs workloads across AWS, Azure, and a private cloud environment is managing three distinct identity models, three distinct logging architectures, three distinct configuration baselines, and three distinct shared responsibility agreements. The security team, if it exists as a distinct function, is expected to maintain consistent policy across all of them.
Protiviti’s 2026 Top Risks survey of CIOs and CTOs found that executives rank legacy IT that cannot meet current performance and security requirements among their top three risks over the next two to three years. Application modernisation is the number one priority for 71% of surveyed CIOs. The intent is there. The execution is not keeping pace with the threat.
What needs to change
The CTO’s infrastructure decisions are now, whether the organisation chart reflects it or not, security decisions. Every unpatched system, every misconfigured cloud environment, every API deployed without adequate authentication, every legacy application running beyond its supported lifecycle is a decision with security consequences that extend well beyond the technology function.
Three shifts are required. First, treat infrastructure debt as a quantified security risk, not a technology inconvenience. The board needs to see the cost of maintaining vulnerable systems expressed in the same language as the other categories in the risk register: financial exposure, regulatory liability, and insurance implications.
Second, consolidating telemetry. Unit 42’s recommendation is explicit: organisations must consolidate visibility across endpoint, cloud, SaaS, and network environments. The CTO who operates five monitoring platforms with no correlation layer is paying for visibility and receiving fragments.
Third, closing the configuration gap. When 82% of cloud misconfigurations stem from human error, and 23% of cloud incidents trace directly to those misconfigurations, the answer is not more cloud. It is better governance of the cloud that the organisation already has. Automated configuration management, continuous posture assessment, and enforced baselines across every cloud provider are no longer optional for organisations operating at scale.
The World Economic Forum’s Global Cybersecurity Outlook 2026 identified supply chain and third-party vulnerabilities as the greatest challenge for 65% of large companies, up from 54% the previous year. The CTO’s infrastructure does not end at the organisation’s perimeter. It extends through every vendor, every integration, and every third-party dependency that touches the production environment.
The question for every CTO is not whether the infrastructure works. It is whether the infrastructure is defensible, at the speed attacks now operate, across the surfaces they now target, with the resources the organisation actually has.
This is Part 3 of “The Threat You Are Already Inside,” a five-part series examining how cybersecurity risk intersects with every level of the organisation. Part 4 examines what the CFO needs to understand about quantifying cyber risk as a financial exposure.
Garzon Cyber Solutions provides cybersecurity advisory services, compliance architecture, and specialist recruitment for organisations building integrated security capabilities.
Where does this sit on your own risk register?
A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.
Start the Conversation →