news.mlab.sh
Back to the feed
threat-intel

Your Cloud Security Checklist Doesn't Work the Way You Think It Does

High
Summary

A recent study by Intruder found significant differences in cloud security configurations across major providers – AWS, Azure, and Google Cloud. While some issues like weak identity and access management were prevalent across all platforms, AWS consistently led in the number of misconfigurations, particularly in areas like exposed services and permissive firewalls. Notably, AWS’s dominance stems from its vast service offerings, while Google Cloud exhibited the lowest prevalence of these issues due to its more secure default configurations. The study highlights a critical challenge for security teams managing multiple cloud environments, emphasizing the need for consistent posture assessment and targeted remediation efforts, especially considering that midmarket organizations struggle to address cloud complexity effectively.

A recent study by Intruder’s 2026 Cloud Security Index revealed substantial variations in cloud security configurations among AWS, Azure, and Google Cloud. The research analyzed misconfiguration data from 3,000 organizations, highlighting that while basic issues like weak identity and access management were widespread, significant differences emerged when looking at provider-specific vulnerabilities.

AWS consistently demonstrated the highest number of misconfigurations, particularly concerning exposed services (76%), permissive firewalls (83%), and weak encryption (49%). Azure followed with 64% and 35% respectively, while Google Cloud showed the lowest prevalence in these categories – 8%, 34%, and 8% respectively. The study attributes AWS’s lead to its extensive service range, creating more opportunities for misconfiguration.

AWS’s most common issues included S3 not enforcing HTTPS (87%), permissive ingress to sensitive ports (84%), and IAM policies allowing privilege escalation (83%). Azure’s top concerns were storage account key rotation not enabled (67%), storage account access keys enabled (66%), and storage account public network access enabled (61%). Google Cloud’s primary issues revolved around identity and access management, with OS Login MFA not enabled (77%), OS Login not enabled (76%), and unused service accounts (75%).

Interestingly, as organizations grow, the prevalence of many of these misconfigurations decreases. SMEs (under 250 employees) exhibited the highest rates of permissive firewalls and weak encryption, while large enterprises (10K-100K+) showed the lowest. However, IAM controls consistently remained a significant concern across all organization sizes, with 87% of SMEs, 95% of midmarket organizations (251–10K employees), and 98% of large enterprises experiencing weak IAM controls.

This suggests that even with increased resources, midmarket organizations struggle to effectively manage the complexity of cloud security, taking an average of 35 days to remediate issues, compared to 8-16 days for smaller businesses and 10 days for large enterprises. Ultimately, the study underscores the need for security teams managing multiple cloud providers to prioritize risk assessment and implement targeted remediation strategies, focusing on consistent posture evaluation and addressing platform-specific vulnerabilities.

Read the full article at The Hacker News