Thehackernews iconThehackernewsSep 7, 2026 ~7 min source read

Cloud security checklists often miss provider-specific risks — Intruder’s 2026 index explains why

Intruder analyzed misconfigurations across 3,000 organizations on AWS, Azure, and Google Cloud and found that risk profiles vary dramatically by provider. Treating cloud security as a single checklist leaves important, platform-specific gaps.

Your Cloud Security Checklist Doesn't Work the Way You Think It Does

Share this story

Send the public story page.

Useful takeaways from this story.

Weak IAM and missing logging are nearly universal: 80–98% of accounts across providers have at least one issue in those categories.

Organization size matters: weak IAM increases with company size, and midmarket teams take the longest (35 days) to remediate cloud issues.

A single, unified checklist is insufficient — prioritize provider-specific controls and focus on IAM as a cross-cutting failure mode.

The study compared how many accounts had at least one issue in each category. Key prevalence figures by provider:

  • Exposed services: AWS 76%, Azure 64%, Google Cloud 8%
  • Permissive firewalls: AWS 83%, Azure 45%, Google Cloud 34%
  • Weak encryption: AWS 49%, Azure 35%, Google Cloud 8%
  • Misconfigured services: AWS 68%, Azure 80%, Google Cloud 37%

Weak IAM controls and missing logging affect between 80% and 98% of accounts regardless of provider.

AWS shows high prevalence across five of the six categories. Intruder lists common concrete misconfigurations: S3 not enforcing HTTPS (87%), permissive ingress to sensitive ports via ACLs (84%), overly permissive Network ACLs (83%), IAM policies that allow privilege escalation (83%), and VPC endpoint not enabled for EC2 (82%). The breadth of AWS services increases configuration surface area and creates more opportunities for error.

Azure's most frequent issues cluster around Storage Accounts: lack of key rotation (67%), access keys enabled (66%), and public network access enabled (61%). Entra ID users without multi-factor authentication appear in 55% of accounts. These findings indicate storage configuration and identity hygiene as high-value targets for remediation on Azure.

Google Cloud's top issues are almost all identity-related: OS Login MFA not enabled (77%), OS Login not enabled (76%), unused service accounts (75%), and overly permissive service accounts (53%). Google Cloud shows much lower prevalence of exposed services and weak encryption compared with AWS and Azure.

How organization size affects risk and response

Most categories become less prevalent as organizations grow, except for IAM. Weak IAM controls increase with size: 87% of SMEs, 95% of midmarket organizations, and 98% of large enterprises have at least one IAM issue. Midmarket teams also take the longest to remediate findings — 35 days on average compared with 8–16 days for smaller businesses and about 10 days for large enterprises. The mismatch suggests midmarket teams face enterprise-level complexity without equivalent staffing or tools.

Practical implications for security teams

  • Treat IAM and logging as cross-cutting priorities: they are almost universal failures and can bypass other controls when abused.
  • Map risk to provider: focus on S3 and network controls for AWS, storage account hardening and Entra MFA on Azure, and service-account/OS Login controls on Google Cloud.
  • Allocate remediation resources to midmarket accounts and long-lived identities: these areas show slower fixes and higher impact.
  • Use the provider-specific prevalence data to order scanning and remediation work by expected risk and likely attack paths.

A single cloud security checklist that treats AWS, Azure, and Google Cloud the same will leave important gaps. Use provider-specific findings to prioritize controls and invest in IAM hygiene and logging across the entire estate.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app