Cloud Security Risks Diverge Across AWS, Azure, and Google Cloud
Event summary
- Intruder's 2026 Cloud Security Index analyzed anonymized data from 3,000 customers across AWS, Azure, and Google Cloud over 12 months ending July 2026.
- AWS leads in risk exposure with the highest prevalence of misconfigurations in five of six categories, including S3 buckets without HTTPS enforcement (87%).
- Azure's top risks stem from storage account misconfigurations (61-67%) and Entra users lacking MFA (55%).
- Google Cloud has the lowest misconfiguration rates, particularly in publicly exposed services (8% vs. 76% on AWS).
- Midmarket organizations (1,000–5,000 employees) take the longest to remediate cloud issues, averaging 35 days.
The big picture
Intruder's report underscores the fragmented nature of cloud security, where each provider presents unique risks. As multi-cloud adoption grows, organizations face the challenge of maintaining consistent security postures across platforms with divergent configurations and terminology. The data highlights a critical gap in midmarket security capabilities, where operational complexity outpaces resources.
What we're watching
- Multi-Cloud Defense
- How security teams will adapt to platform-specific risks in multi-cloud environments.
- Regulatory Compliance
- Whether CISA's baseline cloud configuration mandates will drive standardization across providers.
- Midmarket Vulnerability
- The pace at which midmarket organizations can improve remediation times amid enterprise-grade complexity.
Related topics
