The study compared how many accounts had at least one issue in each category. Key prevalence figures by provider:
- Exposed services: AWS 76%, Azure 64%, Google Cloud 8%
- Permissive firewalls: AWS 83%, Azure 45%, Google Cloud 34%
- Weak encryption: AWS 49%, Azure 35%, Google Cloud 8%
- Misconfigured services: AWS 68%, Azure 80%, Google Cloud 37%
Weak IAM controls and missing logging affect between 80% and 98% of accounts regardless of provider.
AWS shows high prevalence across five of the six categories. Intruder lists common concrete misconfigurations: S3 not enforcing HTTPS (87%), permissive ingress to sensitive ports via ACLs (84%), overly permissive Network ACLs (83%), IAM policies that allow privilege escalation (83%), and VPC endpoint not enabled for EC2 (82%). The breadth of AWS services increases configuration surface area and creates more opportunities for error.
Azure's most frequent issues cluster around Storage Accounts: lack of key rotation (67%), access keys enabled (66%), and public network access enabled (61%). Entra ID users without multi-factor authentication appear in 55% of accounts. These findings indicate storage configuration and identity hygiene as high-value targets for remediation on Azure.
Google Cloud's top issues are almost all identity-related: OS Login MFA not enabled (77%), OS Login not enabled (76%), unused service accounts (75%), and overly permissive service accounts (53%). Google Cloud shows much lower prevalence of exposed services and weak encryption compared with AWS and Azure.
How organization size affects risk and response
Most categories become less prevalent as organizations grow, except for IAM. Weak IAM controls increase with size: 87% of SMEs, 95% of midmarket organizations, and 98% of large enterprises have at least one IAM issue. Midmarket teams also take the longest to remediate findings — 35 days on average compared with 8–16 days for smaller businesses and about 10 days for large enterprises. The mismatch suggests midmarket teams face enterprise-level complexity without equivalent staffing or tools.
Practical implications for security teams
- Treat IAM and logging as cross-cutting priorities: they are almost universal failures and can bypass other controls when abused.
- Map risk to provider: focus on S3 and network controls for AWS, storage account hardening and Entra MFA on Azure, and service-account/OS Login controls on Google Cloud.
- Allocate remediation resources to midmarket accounts and long-lived identities: these areas show slower fixes and higher impact.
- Use the provider-specific prevalence data to order scanning and remediation work by expected risk and likely attack paths.
A single cloud security checklist that treats AWS, Azure, and Google Cloud the same will leave important gaps. Use provider-specific findings to prioritize controls and invest in IAM hygiene and logging across the entire estate.