Your Cloud Security Checklist Doesn't Work the Way You Think It Does
Sep 07, 2026
Cloud Security / Data Security
If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index , Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers Intruder grouped every misconfiguration into one of six categories: weak identity and access management (IAM), missing logging, misconfigured services, permissive firewalls, exposed services, and weak encryption. For each category, they compared how many accounts had at least one issue in it across the three providers. Weak IAM controls and missing logging are near-universal, affecting between 80% and 98% of accounts regardless of provider. The other four categories are where things diverge: Exposed services: AWS (76%) , Azure (64%) , Google Cloud (8%) Permissive firewalls: AWS...