Close Menu
NCIJ Network NCIJ Network
    What's Hot

    John Healey backs growth but says Labour must be honest on spending | Economics

    September 7, 2026

    OpenAI chief scientist warns no one is prepared for consequences of AI

    September 7, 2026

    Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

    September 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • John Healey backs growth but says Labour must be honest on spending | Economics
    • OpenAI chief scientist warns no one is prepared for consequences of AI
    • Your Cloud Security Checklist Doesn’t Work the Way You Think It Does
    • Irish Gangs Are Renting Private Vaults to Hide Crypto Keys
    • Bhutan’s pursuit of happiness takes root on its farms
    • Oasis recordings up for auction despite band’s objections | Oasis
    • Germany’s AfD calls for parties to work with it after Saxony-Anhalt win
    • Trump Posts Map Suggesting New Mexico Be Renamed as ‘New America’
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 7, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    If managing security across multiple cloud providers wasn’t hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like.

    How risk differs across cloud providers

    Intruder grouped every misconfiguration into one of six categories: weak identity and access management (IAM), missing logging, misconfigured services, permissive firewalls, exposed services, and weak encryption. For each category, they compared how many accounts had at least one issue in it across the three providers.

    Weak IAM controls and missing logging are near-universal, affecting between 80% and 98% of accounts regardless of provider. The other four categories are where things diverge:

    • Exposed services: AWS (76%), Azure (64%), Google Cloud (8%)
    • Permissive firewalls: AWS (83%), Azure (45%), Google Cloud (34%)
    • Weak encryption: AWS (49%), Azure (35%), Google Cloud (8%)
    • Misconfigured services: AWS (68%), Azure (80%), Google Cloud (37%)

    The biggest gap is exposed services, at 76% on AWS versus 8% on Google Cloud. Permissive firewalls and weak encryption follow the same pattern with AWS highest and Google Cloud lowest. Misconfigured services is the exception to that pattern: Azure leads at 80%, with Google Cloud lowest at 37%.

    One explanation for AWS leading in prevalence across five of the six categories is that it’s the largest provider by range of services. More services means more configuration options, and more opportunity for misconfiguration.

    Google Cloud has the lowest prevalence across five categories – it also offers the fewest services. The lower prevalence could also be explained by the different approach to shared responsibility, with a Shared Fate model that ships more secure defaults out of the box – particularly around network exposure and encryption.

    Here’s what those categories look like as actual misconfigurations on each platform.

    AWS: firewalls and encryption

    Where AWS accounts go wrong most often:

    1. S3 Does Not Enforce HTTPS — 87%
    2. Permissive Ingress to Sensitive Ports (via ACL) — 84%
    3. Overly Permissive Network ACL — 83%
    4. IAM Policy Allows Privilege Escalation — 83%
    5. VPC Endpoint Not Enabled for EC2 — 82%

    S3 buckets that don’t enforce HTTPS is the issue that affects most AWS accounts. S3 is one of the most widely used cloud storage services, and while man-in-the-middle attacks against it are rare, there’s little reason to leave plain HTTP available.

    IAM policies that allow privilege escalation affect 83% of accounts. AWS IAM is notoriously complex, and a managed policy that looks safe can still grant broader permissions than intended. In one recent incident, an attacker went from exposed credentials to administrative privileges in under 10 minutes, compromising 19 AWS principals.

    Azure: storage and identity

    The most common misconfigurations on Azure accounts:

    1. Storage Account Key Rotation Not Enabled — 67%
    2. Storage Account Access Keys Enabled — 66%
    3. Storage Account Public Network Access Enabled — 61%
    4. Entra User Without MFA — 55%
    5. Trusted Launch Not Enabled — 45%

    The top three issues all relate to Azure Storage Accounts, which frequently hold sensitive data like personally identifiable information (PII). All three affect a similar share of accounts, which suggests that where storage accounts aren’t hardened, several controls tend to be missing at once.

    More than half of accounts also have Entra ID users without multi-factor authentication (MFA). That’s worth noting because Entra ID governs access beyond just cloud resources – it covers Microsoft 365, third-party SaaS apps, and on-premises systems. The 2024 Midnight Blizzard breach of Microsoft’s own network began with a password spray attack against a legacy test account without MFA.

    Google Cloud: IAM

    Almost every top issue on Google Cloud comes down to identity and access management:

    1. OS Login MFA Not Enabled — 77%
    2. OS Login Not Enabled — 76%
    3. Unused Service Account — 75%
    4. Overly Permissive Service Account — 53%
    5. Permissive Ingress to Sensitive Ports — 34%

    More than three-quarters of accounts are missing OS Login controls, which provide a more secure alternative to traditional SSH.

    How organization size changes the picture

    For most categories, prevalence drops as organizations grow. Larger enterprises are less likely to have permissive firewalls, exposed services, or weak encryption.

    The exception is IAM. Weak IAM controls affect 87% of SMEs (under 250 employees), 95% of midmarket organizations (251–10K employees), and 98% of large enterprises (10K-100K+ employees). This is significant as a single overprivileged identity is often all it takes to bypass controls that have been hardened elsewhere.

    Midmarket organizations also take the longest to remediate cloud issues, at 35 days on average, compared to 8-16 for smaller businesses and 10 for large enterprises. It suggests midmarket teams are managing enterprise-level cloud complexity without the dedicated resources to match.

    What this means for security teams

    For teams managing multiple providers, the hard part is understanding which risks matter most across the whole estate so that limited time and resources go to the right places. Security teams need a consistent way to assess posture across providers, while keeping the platform-specific detail needed to actually fix things.

    The full report, including the top 10 misconfigurations per platform and cloud security posture by organization size, is in Intruder’s 2026 Cloud Security Index.

    Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    checklist cloud doesnt Security Work
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Germany’s AfD calls for parties to work with it after Saxony-Anhalt win

    Trezor data breach impact now reaches 81,000 customers

    ChatGPT can now connect to your personal apps to mimic writing style

    ConnectWise warns of new ScreenConnect flaw without patch

    N-able patches max severity N-central flaw amid ongoing attacks

    Israeli ministers keep telling everyone their brutal plans – so why doesn’t the world take them seriously? | Nesrine Malik

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    John Healey backs growth but says Labour must be honest on spending | Economics

    September 7, 2026

    OpenAI chief scientist warns no one is prepared for consequences of AI

    September 7, 2026

    Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

    September 7, 2026

    Irish Gangs Are Renting Private Vaults to Hide Crypto Keys

    September 7, 2026
    Latest Posts

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    John Healey backs growth but says Labour must be honest on spending | Economics

    September 7, 2026

    OpenAI chief scientist warns no one is prepared for consequences of AI

    September 7, 2026

    Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

    September 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.