VMTech
Discuss a project

Cloud Security Risks Differ Widely Across AWS, Azure and Google Cloud

Cloud Security Risks Differ Widely Across AWS, Azure and Google Cloud

Intruder’s 2026 Cloud Security Index, based on misconfiguration data from 3,000 organizations using AWS, Azure and Google Cloud, finds that a single cloud-security checklist can obscure major platform differences. The study grouped issues into weak identity and access management (IAM), missing logging, misconfigured services, permissive firewalls, exposed services and weak encryption.

Weak IAM controls and missing logging were widespread on every provider, affecting between 80% and 98% of accounts. Beyond those common weaknesses, the data shows markedly different risk patterns for AWS, Azure and Google Cloud.

Provider risk profiles diverge

Exposed services were found in 76% of AWS accounts and 64% of Azure accounts, compared with 8% of Google Cloud accounts. Permissive firewalls followed a similar distribution: 83% for AWS, 45% for Azure and 34% for Google Cloud. Weak encryption affected 49% of AWS accounts, 35% of Azure accounts and 8% of Google Cloud accounts.

Misconfigured services were the exception. Azure recorded the highest prevalence at 80%, ahead of AWS at 68% and Google Cloud at 37%. Intruder notes that AWS’s broad service range creates more configuration options and, consequently, more opportunities for error. Google Cloud offers fewer services and uses a Shared Fate approach with more secure defaults, particularly for network exposure and encryption.

Common issues on each platform

On AWS, the most prevalent finding was S3 buckets not enforcing HTTPS, affecting 87% of accounts. Permissive ingress to sensitive ports through access control lists affected 84%, overly permissive network ACLs 83%, IAM policies allowing privilege escalation 83%, and EC2 VPC endpoints not enabled 82%.

Azure’s most frequent findings concentrated on Storage Accounts: key rotation not enabled affected 67% of accounts, access keys enabled 66%, and public network access enabled 61%. Entra users without multi-factor authentication were present in 55% of accounts, while Trusted Launch was not enabled in 45%.

Google Cloud’s leading issues were predominantly IAM-related. OS Login MFA was not enabled in 77% of accounts, OS Login itself was not enabled in 76%, unused service accounts appeared in 75%, and overly permissive service accounts in 53%. Permissive ingress to sensitive ports affected 34%.

Identity remains the cross-cloud weakness

Most categories became less prevalent as organizations grew, including permissive firewalls, exposed services and weak encryption. IAM did not follow that pattern: weak IAM controls affected 87% of SMEs, 95% of midmarket organizations and 98% of large enterprises. Intruder highlights that a single overprivileged identity can bypass controls hardened elsewhere.

Midmarket organizations took the longest to remediate cloud issues, averaging 35 days, compared with 8 to 16 days for smaller businesses and 10 days for large enterprises. For security teams operating across providers, the practical implication is to use a consistent posture assessment for the whole estate while retaining provider-specific remediation priorities: AWS network and encryption controls, Azure storage and identity settings, and Google Cloud IAM controls require different attention.

#cloudsecurity#iamsecurity#awssecurity#azuresecurity
Open analytics
On the site 0 views
min read 4 07.09.2026
Instagram

Cloud Security Risks Differ Widely Across AWS, Azure and Google Cloud

Open the post on Instagram ↗