Cloud Security Report Reveals High Misconfigurations: AWS and Azure Under Scrutiny, Google Cloud Fares Better

September 7, 2026
Cloud Security Report Reveals High Misconfigurations: AWS and Azure Under Scrutiny, Google Cloud Fares Better
  • Security posture across cloud providers shows misconfigurations persisted at the user level, with AWS leading at 68% and Azure at 80%, while Google Cloud trails at 37%.

  • Exposed services underscore the provider gap, peaking with AWS exposure at 76%, Azure at 64%, and Google Cloud at 8%.

  • The report argues that security teams must measure posture consistently across providers and fix platform-specific issues within a single framework, with full findings in Intruder’s 2026 Cloud Security Index.

  • Organization size influences risk, as IAM issues remain high across all scales, but larger firms see fewer issues overall; midmarket organizations take about 35 days to remediate cloud problems.

  • Common AWS misconfigurations include S3 HTTPS enforcement gaps (87%), overly permissive port ingress (84%), lax network ACLs (83%), IAM policies enabling privilege escalation (83%), and unused VPC endpoints for EC2 (82%).

  • Across providers, weak IAM controls and missing logging are nearly universal, affecting 80% to 98% of accounts.

  • Azure misconfigurations are storage-centric, with rotation not enabled (67%), storage keys enabled (66%), public network access enabled (61%), Entra users lacking MFA (55%), and trusted launch not enabled (45%).

  • The 2026 Cloud Security Index analyzes misconfigurations from about 3,000 organizations across AWS, Azure, and Google Cloud to compare provider risk profiles.

  • Google Cloud misconfigurations are dominated by identity issues: OS Login MFA not enabled (77%), OS Login not enabled (76%), unused service accounts (75%), overly permissive service accounts (53%), and permissive port ingress (34%).

  • AWS shows the highest misconfiguration prevalence due to its broader service footprint, while Google Cloud appears comparatively lower, potentially due to fewer services and stronger defaults under a Shared Fate model.

  • Weak encryption is most prevalent on AWS (49%), followed by Azure (35%), with Google Cloud lowest at 8%.

  • Firewall permissions vary by provider, with AWS permissive rules at 83%, Azure at 45%, and Google Cloud at 34%.

Summary based on 1 source


Get a daily email with more Tech stories

More Stories