Intruder has released its 2026 Cloud Security Index, analyzing differences in cloud security risk across AWS, Azure, and Google Cloud. Based on anonymized data from 3,000 Intruder customers, the report highlights provider-specific vulnerability profiles, top misconfigurations, and average remediation timelines.
AWS leads in misconfiguration prevalence across five of six categories.
76% of AWS accounts have publicly exposed services vs. 8% on Google Cloud.
Azure's top misconfigurations stem from storage accounts (61-67% of accounts).
55% of Azure accounts contain Entra users without MFA.
Midmarket organizations (1,000-5,000 employees) take 35 days to remediate, 3x longer than others.
Weak IAM controls affect 87-97% of accounts across all three providers.
The report groups cloud issues into six categories and compares prevalence across three providers. AWS leads in prevalence across five of the six categories, with the single most common issue being S3 buckets that do not enforce HTTPS at 87%, followed by permissive ingress to sensitive ports at 84% and IAM policies allowing privilege escalation at 83%. Azure's top three misconfigurations all stem from storage accounts, affecting between 61% and 67% of accounts, with more than half of Azure accounts containing Entra users without MFA. Google Cloud has the lowest misconfiguration rates across four categories, with just 8% of accounts having publicly exposed services compared to 76% on AWS and 64% on Azure.
Smaller organizations remediate cloud issues in 8 to 16 days. Remediation slows sharply in the 1,000–5,000 employee range, peaking at 35 days, before improving again at the largest sizes, with 10K+ organizations back down to 10 days. This mirrors the pattern seen in Intruder's 2026 Attack Surface Management Index: midmarket organizations face the longest remediation times, likely managing enterprise-level cloud complexity without the dedicated resources to match.
Weak IAM controls affect 87% to 97% of accounts across all three providers. IAM issues dominate Google Cloud's own top four misconfigurations, with three out of four accounts missing OS Login controls. IAM is also the only category that worsens steadily as organizations grow: 87% among SMEs, 95% among midmarket organizations, and 98% among large enterprises.
"There's a common assumption that moving to the cloud makes you secure by default," said Chris Wallis, CEO and founder at Intruder. "This data shows the opposite: every platform has different weaknesses, and security teams have to understand and address the specific risks on each one. You can't just configure once and assume you're covered."
About Intruder
Intruder's exposure management platform helps lean security teams stop breaches before they start by proactively discovering attack surface weaknesses. By unifying AI penetration testing, attack surface management, cloud security, and continuous vulnerability management in one intuitive platform, Intruder makes it easy to stay secure by cutting through the noise and complexity. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide.