Cloud Security Index Exposes Varying Levels of Risk Across AWS, Azure, and Google Cloud
A new study by Intruder has shed light on the varying levels of cloud security across different providers, revealing that each platform fails in distinct ways. The analysis, part of the 2026 Cloud Security Index, examined misconfiguration data from over 3,000 organizations using AWS, Azure, and Google Cloud. The results show that despite differences in risk profiles, weak identity and access management (IAM) controls and missing logging are common issues across all three platforms, affecting between 80% to 98% of accounts.
However, the study found significant variations in other areas. Exposed services were a major concern on AWS, with 76% of affected accounts, while Azure had the highest prevalence of misconfigured services at 80%. Google Cloud, which offers fewer services, had the lowest rate of exposed services and weak encryption.
One explanation for AWS's higher risk profile is its extensive range of services, which provides more configuration options but also increases the likelihood of misconfiguration. In contrast, Google Cloud's Shared Fate model, which prioritizes secure defaults, may contribute to its lower prevalence of security issues.
The study also highlighted differences in organization size and cloud complexity. Larger enterprises were less likely to have permissive firewalls, exposed services, or weak encryption, but IAM weaknesses remained a concern across all sizes. Midmarket organizations took the longest to remediate cloud issues, at an average of 35 days.
For security teams managing multiple providers, understanding which risks matter most is crucial to allocating limited resources effectively. The study emphasizes the need for a consistent approach to assessing posture across platforms and addressing platform-specific details to fix issues.