A new report from Intruder, the 2026 Cloud Security Index, indicates that misconfigurations continue to be a primary threat to cloud environments, with a single error potentially leading to public network access, unrotated keys, or exposed services. The report highlights that weak identity and access management (IAM) controls and inadequate logging and alerting are the most pervasive security issues across major cloud providers, impacting 80% to 98% of accounts.
The study notes that over two-thirds of midmarket organizations utilize multiple cloud providers, each with distinct security models and configuration settings. This complexity means that a single security issue can manifest differently across AWS, Azure, and Google Cloud, often requiring varied identification and remediation strategies. The report challenges the assumption that cloud migration inherently provides security, emphasizing that each platform has unique vulnerabilities that security teams must specifically address.
Across the three major cloud platforms, the most common security issues vary based on their architectural differences. AWS environments frequently experience misconfigurations related to storage, network access, and identity management. Azure's primary concerns revolve around storage security and identity protection, specifically citing unrotated access keys, publicly accessible storage, and a lack of multi-factor authentication (MFA). Google Cloud environments are predominantly affected by IAM weaknesses, including missing MFA, unused service accounts, and overly permissive service accounts.
Weak identity controls, excessive permissions, and incomplete or insecure configurations are identified as consistent sources of cloud security risk across all three providers. AWS showed the highest prevalence of misconfigurations in five of the six security categories analyzed, including permissive firewalls, exposed services, and weak encryption. Azure had the highest rate of misconfigured services. Google Cloud recorded the lowest prevalence in four of the six categories. The report points out that exposed services exhibited the widest variation, affecting 76% of AWS accounts, 64% of Azure accounts, and 8% of Google Cloud accounts, attributing these differences to the breadth of service portfolios and varying approaches to secure default configurations.
Cloud security posture also correlates with organization size. Larger enterprises generally report fewer issues with permissive firewalls, exposed services, and weak encryption, suggesting more mature security processes and greater investment. However, IAM presents a unique challenge that escalates with scale. Weak IAM controls affect 87% of small and medium-sized enterprises (SMEs), 95% of midmarket organizations, and 98% of large enterprises, a trend attributed to the increasing complexity of managing users, roles, and permissions in larger environments.
Remediation times also vary by organization size. Smaller organizations typically resolve cloud misconfigurations within an average of 8 to 16 days. The average remediation time peaks at 35 days for organizations with 1,000 to 5,000 employees, then decreases to 19 days for those with 5,000 to 10,000 employees, and further drops to 10 days for the largest enterprises. Midmarket organizations often manage cloud environments comparable to enterprises but without the dedicated security resources available to larger companies. The Cybersecurity and Infrastructure Security Agency (CISA) now mandates baseline cloud configuration practices for US federal agencies.






