76% of AWS accounts in Intruder’s dataset showed exposed services, compared with 8% on Google Cloud — a gap that underlines a simple but uncomfortable truth: cloud checklists that treat providers as interchangeable are misleading.
How risk differs across AWS, Azure, and Google Cloud
Intruder’s 2026 Cloud Security Index analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and grouped findings into six categories: weak identity and access management (IAM), missing logging, misconfigured services, permissive firewalls, exposed services, and weak encryption. Weak IAM controls and missing logging are near-universal, affecting between 80% and 98% of accounts regardless of provider. Beyond those two, prevalence diverges sharply.
- Exposed services: AWS 76%, Azure 64%, Google Cloud 8%
- Permissive firewalls: AWS 83%, Azure 45%, Google Cloud 34%
- Weak encryption: AWS 49%, Azure 35%, Google Cloud 8%
- Misconfigured services: AWS 68%, Azure 80%, Google Cloud 37%
The largest single gap is exposed services (76% vs 8%). AWS leads prevalence in five of the six categories; Intruder suggests one explanation is that AWS is the largest provider by range of services — more services equal more configuration options and more chances for error. Conversely, Google Cloud shows the lowest prevalence across five categories and offers the fewest services; Intruder notes Google Cloud’s Shared Fate model ships more secure defaults out of the box, particularly around network exposure and encryption.
AWS: firewalls and encryption
AWS accounts in the dataset most commonly fail in areas tied to network controls and encryption. The top five AWS misconfigurations reported are:
- S3 Does Not Enforce HTTPS — 87%
- Permissive Ingress to Sensitive Ports (via ACL) — 84%
- Overly Permissive Network ACL — 83%
- IAM Policy Allows Privilege Escalation — 83%
- VPC Endpoint Not Enabled for EC2 — 82%
Intruder points out that S3 buckets not enforcing HTTPS affect the most AWS accounts; while man-in-the-middle attacks are rare, leaving HTTP available is an unnecessary risk. IAM policy misconfigurations that permit privilege escalation affect 83% of accounts. Intruder also highlights a real-world consequence: in one recent incident an attacker went from exposed credentials to administrative privileges in under 10 minutes, compromising 19 AWS principals.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAzure: storage and identity
Azure’s most frequent failures cluster around storage and identity controls. The top Azure issues in the dataset are:
- Storage Account Key Rotation Not Enabled — 67%
- Storage Account Access Keys Enabled — 66%
- Storage Account Public Network Access Enabled — 61%
- Entra User Without MFA — 55%
- Trusted Launch Not Enabled — 45%
Intruder notes that the top three items all relate to Azure Storage Accounts, which often hold sensitive data such as personally identifiable information; the similar prevalence across those three issues suggests that when storage accounts are not hardened, multiple controls tend to be missing simultaneously. More than half of accounts have Entra ID users without multi-factor authentication (MFA); Intruder calls attention to the 2024 Midnight Blizzard breach of Microsoft’s own network, which began with a password spray attack against a legacy test account without MFA.
Google Cloud: identity and OS Login
On Google Cloud the dominant theme is identity and access controls. The leading misconfigurations are:
- OS Login MFA Not Enabled — 77%
- OS Login Not Enabled — 76%
- Unused Service Account — 75%
- Overly Permissive Service Account — 53%
- Permissive Ingress to Sensitive Ports — 34%
More than three-quarters of Google Cloud accounts in Intruder’s sample are missing OS Login controls, which provide a more secure alternative to traditional SSH. These findings align with the earlier note that Google Cloud’s lower overall prevalence across several categories may reflect fewer services and secure defaults driven by a Shared Fate approach.
Organization size, IAM, and remediation times
Prevalence of most categories falls as organizations grow — larger enterprises are less likely to have permissive firewalls, exposed services, or weak encryption. IAM is the notable exception. Weak IAM controls affect 87% of SMEs (under 250 employees), 95% of midmarket organizations (251–10K employees), and 98% of large enterprises (10K–100K+ employees). Intruder emphasizes the outsized impact of IAM risk: a single overprivileged identity can bypass controls hardened elsewhere.
Remediation timelines also vary. Midmarket organizations take the longest to remediate cloud issues, at 35 days on average, compared to 8–16 days for smaller businesses and 10 days for large enterprises — a pattern Intruder interprets as midmarket teams managing enterprise-level complexity without equivalent resources.
What this means for security teams
Intruder’s conclusion is direct: for teams managing multiple providers, the hard part is understanding which risks matter most across the whole estate so that limited time and resources go to the right places. “Security teams need a consistent way to assess posture across providers, while keeping the platform-specific detail needed to actually fix things,” the report says. The dataset here makes that practical problem concrete: a single, one-size-fits-all checklist will miss provider-specific failure modes — from S3 HTTPS and network ACLs on AWS to Storage Account keys and Entra MFA on Azure, to OS Login gaps and service-account hygiene on Google Cloud.
The implications are straightforward: measure consistently, prioritize by provider-specific prevalence, and retain the platform-level detail necessary to remediate the specific failures the data exposes.
Read the original Intruder 2026 Cloud Security Index reporting




