Exposed services affect 76% of AWS accounts but only 8% of Google Cloud accounts, according to Intruder's 2026 Cloud Security Index, which examined misconfiguration data from 3,000 organizations across the three major cloud providers. The analysis reveals that risk profiles across AWS, Azure, and Google Cloud have almost nothing in common, meaning security teams can't apply a single checklist across platforms.

Intruder sorted every misconfiguration into six categories: weak identity and access management, missing logging, misconfigured services, permissive firewalls, exposed services, and weak encryption. Weak IAM controls and missing logging are nearly universal, hitting between 80% and 98% of accounts regardless of provider. The other four categories show dramatic differences. Permissive firewalls appear in 83% of AWS accounts, 45% of Azure accounts, and 34% of Google Cloud accounts. Weak encryption strikes 49% of AWS accounts, 35% of Azure accounts, and just 8% of Google Cloud accounts. Misconfigured services break the pattern: Azure leads at 80%, compared to 68% on AWS and 37% on Google Cloud. On AWS, the most widespread issues are S3 buckets that don't enforce HTTPS (87% of accounts), permissive ingress to sensitive ports via access control lists (84%), and overly permissive network ACLs (83%). On Azure, the top three problems all relate to storage accounts: key rotation not enabled (67%), access keys enabled (66%), and public network access enabled (61%). More than half of Azure accounts also have Entra ID users without multi-factor authentication. On Google Cloud, more than three-quarters of accounts are missing OS Login controls, which provide a more secure alternative to traditional SSH.

The report finds that one explanation for AWS leading in prevalence across five of the six categories is that it's the largest provider by range of services, meaning more configuration options and more opportunity for misconfiguration. Google Cloud has the lowest prevalence across five categories and also offers the fewest services. The lower prevalence could also be explained by Google Cloud's Shared Fate model, which ships more secure defaults out of the box, particularly around network exposure and encryption. The analysis also shows that for most risk categories, prevalence drops as organizations grow, with one major exception: weak IAM controls affect 87% of small and medium enterprises, 95% of midmarket organizations, and 98% of large enterprises. A single overprivileged identity is often all it takes to bypass controls that have been hardened elsewhere, according to the report. Midmarket organizations also take the longest to fix cloud issues, at 35 days on average, compared to 8 to 16 days for smaller businesses and 10 days for large enterprises, which suggests midmarket teams are managing enterprise-level cloud complexity without the dedicated resources to match.

The report concludes that for teams managing multiple providers, the hard part is understanding which risks matter most across the whole estate so that limited time and resources go to the right places. Security teams need a consistent way to assess posture across providers while keeping the platform-specific detail needed to actually fix things. The full report, including the top 10 misconfigurations per platform and cloud security posture by organization size, is available in Intruder's 2026 Cloud Security Index. Organizations that treat multicloud security as a one-size-fits-all problem will continue to miss the platform-specific weaknesses that matter most, while those that invest in understanding each provider's failure modes can allocate remediation effort where it actually reduces exposure.