Cloud Security Misconfigurations Expose Major Risk Gaps Across Providers

A groundbreaking analysis of 3,000 organizations has revealed that cloud security misconfigurations vary dramatically across major cloud providers, challenging the assumption that a single security checklist can protect multi-cloud environments. The 2026 Cloud Security Index, conducted by security firm Intruder, examined misconfiguration data across AWS, Azure, and Google Cloud, exposing risk profiles that have almost nothing in common.

One Size Does Not Fit All in Cloud Security

The study categorized every misconfiguration into six groups: weak identity and access management (IAM), missing logging, misconfigured services, permissive firewalls, exposed services, and weak encryption. What researchers found was that while some issues are near-universal, others diverge sharply depending on which cloud provider an organization uses.

Weak IAM controls and missing logging affect between 80% and 98% of accounts regardless of provider, making them the most pervasive problems in cloud security today. However, the remaining four categories reveal striking differences:

  • Exposed services: AWS (76%), Azure (64%), Google Cloud (8%)
  • Permissive firewalls: AWS (83%), Azure (45%), Google Cloud (34%)
  • Weak encryption: AWS (49%), Azure (35%), Google Cloud (8%)
  • Misconfigured services: AWS (68%), Azure (80%), Google Cloud (37%)

The most dramatic gap appears in exposed services, where AWS leads at 76% compared to Google Cloud at just 8%. Permissive firewalls and weak encryption follow the same pattern, with AWS consistently highest and Google Cloud lowest. Misconfigured services is the sole exception, with Azure leading at 80%.

AWS: Firewalls and Encryption Lead the Problem List

For AWS environments, the most common misconfigurations paint a picture of sprawling infrastructure with insufficient hardening:

  • S3 Does Not Enforce HTTPS — 87% of accounts
  • Permissive Ingress to Sensitive Ports via ACL — 84%
  • Overly Permissive Network ACL — 83%
  • IAM Policy Allows Privilege Escalation — 83%
  • VPC Endpoint Not Enabled for EC2 — 82%

S3 buckets that do not enforce HTTPS affect the largest share of AWS accounts. While man-in-the-middle attacks against S3 are relatively rare, leaving plain HTTP available creates an unnecessary attack surface that costs nothing to close.

Even more concerning, IAM policies that allow privilege escalation were found in 83% of accounts. AWS IAM is notoriously complex, and managed policies that appear safe can still grant broader permissions than intended. In one documented incident, an attacker moved from exposed credentials to administrative privileges in under 10 minutes, compromising 19 AWS principals in the process.

Azure: Storage and Identity Dominate the Risk Landscape

Azure accounts reveal a different but equally troubling pattern. The top misconfigurations center on storage accounts and identity management:

  • Storage Account Key Rotation Not Enabled — 67%
  • Storage Account Access Keys Enabled — 66%
  • Storage Account Public Network Access Enabled — 61%
  • Entra User Without MFA — 55%
  • Trusted Launch Not Enabled — 45%

The top three issues all relate to Azure Storage Accounts, which frequently hold sensitive data such as personally identifiable information. When storage accounts are not properly hardened, multiple controls tend to be missing simultaneously, creating compounding risk.

More than half of Azure accounts have Entra ID users without multi-factor authentication. This is particularly significant because Entra ID governs access beyond cloud resources alone, covering Microsoft 365, third-party SaaS applications, and on-premises systems. The 2024 Midnight Blizzard breach of Microsoft’s own network began with a password spray attack against a legacy test account that lacked MFA, demonstrating how a single unsecured identity can become the entry point for a devastating attack.

Google Cloud: IAM Is the Primary Weak Point

Google Cloud shows the lowest prevalence across five of the six risk categories, which researchers attribute to its smaller service catalog and its Shared Fate model that ships more secure defaults out of the box. However, identity and access management remains a significant concern:

  • OS Login MFA Not Enabled — 77%
  • OS Login Not Enabled — 76%
  • Unused Service Account — 75%
  • Overly Permissive Service Account — 53%
  • Permissive Ingress to Sensitive Ports — 34%

More than three-quarters of Google Cloud accounts are missing OS Login controls, which provide a more secure alternative to traditional SSH key management. Unused and overly permissive service accounts further expand the attack surface, giving potential attackers dormant credentials to exploit.

Organization Size Changes the Equation

The research also examined how organization size affects cloud security posture. For most categories, prevalence drops as organizations grow larger. Enterprises are less likely to have permissive firewalls, exposed services, or weak encryption, suggesting that dedicated security teams and mature processes make a measurable difference.

However, IAM is the critical exception. Weak IAM controls affect 87% of small and medium enterprises (under 250 employees), 95% of midmarket organizations (251 to 10,000 employees), and 98% of large enterprises (10,000 to 100,000+ employees). This means that as organizations scale, their identity management becomes more complex and more vulnerable, not less. A single overprivileged identity is often all it takes to bypass controls that have been hardened elsewhere.

Midmarket organizations face a particularly difficult challenge. They take the longest to remediate cloud issues, averaging 35 days to fix problems, compared to 8 to 16 days for smaller businesses and 10 days for large enterprises. This suggests midmarket teams are managing enterprise-level cloud complexity without the dedicated security resources to match, creating a dangerous gap between risk exposure and remediation capacity.

Practical Steps to Close the Gap

For security teams managing multiple cloud providers, the findings underscore the need for provider-specific strategies rather than blanket policies. Key recommendations include:

  • Enforce HTTPS everywhere. S3 buckets and storage accounts should require encrypted connections. This is a zero-cost, high-impact fix.
  • Audit IAM policies regularly. Use automated tools to detect privilege escalation paths and remove unused accounts and service accounts.
  • Mandate MFA across all identity providers. This includes Entra ID, AWS IAM, and Google Cloud OS Login. No account, including test and legacy accounts, should be exempt.
  • Tighten network exposure. Review firewall rules, network ACLs, and public network access settings. Default to deny and explicitly allow only what is needed.
  • Rotate storage keys. Enable automatic key rotation for all storage accounts and disable access keys where managed identities can be used instead.
  • Invest in continuous monitoring. Given that remediation timelines can stretch to over a month for midmarket organizations, continuous configuration monitoring tools are essential for catching issues before attackers do.

The Bigger Picture

The 2026 Cloud Security Index reveals a fundamental truth about modern cloud security: the threats you face depend heavily on where your infrastructure lives. AWS users must prioritize firewall and encryption hardening. Azure users need to focus on storage account security and identity protection. Google Cloud users should concentrate on IAM hygiene and service account management.

For organizations operating across multiple providers, the challenge is even greater. Security teams need a consistent way to assess posture across all cloud environments while maintaining the platform-specific knowledge required to actually remediate issues. The era of generic cloud security checklists is over. In 2026, effective cloud security requires understanding the unique risk profile of each provider and allocating limited time and resources accordingly.

As cloud infrastructure continues to grow in complexity, the organizations that will stay secure are those that move beyond one-size-fits-all approaches and embrace provider-aware, continuously monitored, and rapidly remediated security strategies.


Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading