Security teams running multi-cloud environments cannot apply the same playbook across providers, according to Intruder's 2026 Cloud Security Index. Analysis of anonymised data from 3,000 customers reveals that the top misconfigurations on AWS, Azure, and Google Cloud share almost no overlap — meaning a policy that hardens one platform may leave another entirely exposed.
The report, drawing on 12 months of anonymised telemetry ending July 2026, found AWS leading in misconfiguration prevalence across five of six measured categories. The most common AWS issue is S3 buckets failing to enforce HTTPS, affecting 87% of accounts, followed by permissive ingress to sensitive ports at 84% and IAM policies allowing privilege escalation at 83%. Publicly exposed services, a headline metric for lateral-movement risk, affect 76% of AWS accounts — against 64% on Azure and just 8% on Google Cloud.
Azure's top three misconfigurations all stem from storage accounts, affecting between 61% and 67% of accounts. More than half of Azure accounts, 55%, contain Entra users without multifactor authentication. Google Cloud recorded the lowest misconfiguration rates across four categories, a pattern Intruder attributes to more secure default settings rather than any inherent superiority — the platform also offers fewer services overall, limiting the configuration surface.
The cross-provider gap sharpens on identity. Weak IAM controls affect 87% to 97% of accounts across all three providers, and IAM is the only category that worsens as organisations grow: 87% prevalence among SMEs rises to 95% in midmarket accounts and 98% in large enterprises. Permissive firewalls and weak encryption decline with organisational size, but IAM exposure tracks upward throughout.
Remediation timelines add another dimension. Smaller organisations fix cloud issues in 8 to 16 days. That window stretches to 35 days for those in the 1,000–5,000 employee band — more than three times longer than peers on either side — before falling back to 10 days among organisations above 10,000 headcount. Intruder links the midmarket slowdown to a familiar squeeze: enterprise-level cloud complexity without the automation resources that larger teams deploy.
Over two-thirds of the organisations in the dataset run multi-cloud estates. The near-zero overlap in top misconfigurations across providers means risk analysis and remediation prioritisation must happen platform by platform. The full index is available at intruder.io/blog/cloud-security-index.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter