SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Cloud security report finds gaps differ by provider

Cloud security report finds gaps differ by provider

Wed, 12th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Intruder has published its 2026 Cloud Security Index, which compares security risks across AWS, Azure and Google Cloud using anonymised data from 3,000 organisations.

The report finds that the leading misconfigurations on the three platforms show almost no overlap, creating a challenge for companies running workloads across multiple providers. More than two-thirds of organisations now operate multi-cloud environments, meaning security teams often face different terminology, settings and remediation steps for similar types of risk.

AWS recorded the highest prevalence of misconfigurations in five of the six categories examined: weak identity and access management controls, missing logging and alerting, misconfigured services, permissive firewalls, exposed services and weak encryption.

Among the most common AWS issues, 87% of accounts had S3 buckets that did not enforce HTTPS. Permissive ingress to sensitive ports appeared in 84% of AWS accounts, while 83% had IAM policies that allowed privilege escalation.

Public exposure was one of the clearest gaps between providers. Publicly exposed services were found in 76% of AWS accounts, compared with 64% on Azure and 8% on Google Cloud.

Permissive firewalls followed a similar pattern, affecting 83% of AWS accounts, versus 45% on Azure and 34% on Google Cloud.

Azure's most common problems centred on storage accounts. Its top three misconfigurations all came from that area, affecting 61% to 67% of accounts, while 55% of Azure accounts included Entra users without multifactor authentication.

Google Cloud showed the lowest misconfiguration rates in four of the six categories measured. Even so, identity remained a notable weakness, with 75% of accounts missing OS Login controls.

Identity risks

Across all three providers, identity and access management was the area with the broadest exposure. Weak IAM controls affected 87% to 97% of accounts, making identity one of the few security themes that cut across provider boundaries.

IAM issues also dominated Google Cloud's top four misconfigurations. Identity weaknesses became more common as organisations grew, rising from 87% among small and medium-sized businesses to 95% in mid-sized companies and 98% in large enterprises.

That trend contrasted with other categories. Permissive firewalls and weak encryption both declined with company size, while logging gaps and misconfigured services were most acute in mid-sized organisations.

Midmarket strain

Remediation times also varied by company size. Smaller organisations fixed cloud issues in eight to 16 days, while companies with 1,000 to 5,000 employees took 35 days on average, more than three times longer than both smaller and larger groups.

The largest organisations, with more than 10,000 employees, brought average remediation time back down to 10 days. The pattern suggests mid-sized businesses carry much of the complexity seen in larger enterprises without the same depth of dedicated security resources or automation.

That finding matters because multi-cloud use is now widespread, and the study indicates that complexity does not produce a common set of controls. Instead, teams must address different operational problems depending on whether infrastructure sits in AWS, Azure or Google Cloud.

The report links AWS's higher rates to its broader range of services and configuration options, which increase the scope for user error. By contrast, Google Cloud's lower rates were linked to a smaller service set and more secure defaults in some areas.

For security leaders, the figures point to a practical rather than purely technical problem. A standardised cloud policy may cover broad governance requirements, but day-to-day security work still depends on provider-specific knowledge, especially around storage, firewall rules, access policies and account protections.

The report also suggests that cloud misconfiguration remains a routine source of exposure rather than an edge case. Prevalence rates were high across all three major providers, even where one platform performed better than another.

Chris Wallis, chief executive officer and founder at Intruder, said the data challenged assumptions about cloud security. "There's a common assumption that moving to the cloud makes you secure by default," Wallis said. "This data shows the opposite: every platform has different weaknesses, and security teams have to understand and address the specific risks on each one. You can't just configure once and assume you're covered."