Managing security across multiple cloud providers presents unique challenges, as each platform exhibits distinct vulnerabilities. According to reporting by The Hacker News, the 2026 Cloud Security Index from Intruder analyzed misconfiguration data from 3,000 organizations utilizing AWS, Azure, and Google Cloud, revealing that risk profiles vary significantly across these providers.
Variations in Risk Across Cloud Providers
Intruder categorized misconfigurations into six areas: weak identity and access management (IAM), missing logging, misconfigured services, permissive firewalls, exposed services, and weak encryption. The analysis showed that weak IAM controls and missing logging are prevalent, affecting between 80% and 98% of accounts across all providers. However, the other categories displayed notable differences:
- Exposed services: AWS (76%), Azure (64%), Google Cloud (8%)
- Permissive firewalls: AWS (83%), Azure (45%), Google Cloud (34%)
- Weak encryption: AWS (49%), Azure (35%), Google Cloud (8%)
- Misconfigured services: AWS (68%), Azure (80%), Google Cloud (37%)
The most significant disparity was found in exposed services, with AWS at 76% compared to just 8% on Google Cloud. This trend continued with permissive firewalls and weak encryption, where AWS consistently ranked highest and Google Cloud lowest. Interestingly, Azure led in misconfigured services at 80%, while Google Cloud was the lowest at 37%.
Common Misconfigurations by Provider
Each cloud provider has its own set of common misconfigurations:
AWS: Firewalls and Encryption
- S3 Does Not Enforce HTTPS — 87%
- Permissive Ingress to Sensitive Ports (via ACL) — 84%
- Overly Permissive Network ACL — 83%
- IAM Policy Allows Privilege Escalation — 83%
- VPC Endpoint Not Enabled for EC2 — 82%
Azure: Storage and Identity
- Storage Account Key Rotation Not Enabled — 67%
- Storage Account Access Keys Enabled — 66%
- Storage Account Public Network Access Enabled — 61%
- Entra User Without MFA — 55%
- Trusted Launch Not Enabled — 45%
Google Cloud: IAM
- OS Login MFA Not Enabled — 77%
- OS Login Not Enabled — 76%
- Unused Service Account — 75%
- Overly Permissive Service Account — 53%
- Permissive Ingress to Sensitive Ports — 34%
Impact of Organization Size on Misconfigurations
The prevalence of misconfigurations tends to decrease as organizations grow larger. However, weak IAM controls remain a significant issue, affecting 87% of small and medium enterprises (SMEs), 95% of midmarket organizations, and 98% of large enterprises. This highlights the critical nature of IAM, as a single overprivileged identity can compromise security.
Midmarket organizations also take longer to address cloud issues, averaging 35 days for remediation, compared to 8-16 days for smaller businesses and 10 days for larger enterprises. This suggests that midmarket teams are grappling with complex cloud environments without adequate resources.
For security teams managing multiple cloud providers, understanding which risks are most critical is essential for effective resource allocation. The full report, including detailed misconfigurations and security posture by organization size, is available in Intruder’s 2026 Cloud Security Index.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



