Published Security3 min read
One cloud baseline, three different estates: why multicloud hardening flatters itself
Intruder's 2026 index puts exposed services at 76% of AWS accounts and 8% of Google Cloud accounts. The same weakness, three different shapes, and one checklist that covers none of them well.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Intruder's 2026 Cloud Security Index report found weak IAM controls and missing logging and alerting were the most widespread security issues across all three cloud providers, affecting 80% to 98% of accounts.
- The same security issue can manifest differently across AWS, Azure and Google Cloud, often requiring a different approach to identify and remediate, according to Intruder's 2026 Cloud Security Index report.
- Exposed services showed the widest variation between platforms, affecting 76% of AWS accounts, 64% of Azure accounts and 8% of Google Cloud accounts.
- The gap between the highest and lowest platform rate for exposed services is 68 percentage points.
- Intruder attributes the differences in exposed service rates in part to the breadth of each provider's service portfolio and to differences in their approach to secure default configurations.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Intruder's 2026 Cloud Security Index reports that weak IAM controls and missing logging and alerting are the two most widespread cloud security issues, present in 80% to 98% of accounts across AWS, Azure and Google Cloud [1]. The more consequential finding for anyone running more than one provider is that the same underlying weakness surfaces at very different rates depending on the platform [2], which means a single hardening baseline stretched across a multicloud estate measures your paperwork rather than your exposure.
Exposed services is the clearest case. According to the report, they affect 76% of AWS accounts, 64% of Azure accounts and 8% of Google Cloud accounts [3] - a spread of 68 percentage points between the highest and lowest [4]. Intruder attributes the gap partly to the breadth of each provider's service portfolio and partly to differences in how each approaches secure defaults [5]. In other words, some of your posture is inherited, and it is not the same inheritance on each platform.
The per-platform profiles diverge accordingly. AWS environments are most frequently hit by storage, network access and identity management misconfigurations [6]. Azure's most common problems cluster around storage security and identity protection, specifically unrotated access keys, publicly accessible storage and missing MFA [7]. Google Cloud is primarily an IAM story: missing MFA, unused service accounts and overly permissive service accounts [8]. AWS recorded the highest prevalence in five of the six categories analysed, including permissive firewalls, exposed services and weak encryption [9]; Azure had the highest rate of misconfigured services [10]; Google Cloud came in lowest in four of six [11].
That matters because more than two-thirds of midmarket organisations use multiple cloud providers, each with its own security model, terminology and configuration settings [12]. Intruder CEO and founder Chris Wallis put it directly: "every platform has different weaknesses, and security teams have to understand and address the specific risks on each one. You can't just configure once and assume you're covered" [13]. Treat that as a vendor arguing for per-platform work, then check it against the numbers, which do support it. CISA, for its part, now mandates baseline cloud configuration practices for US federal agencies [14].
Two other patterns are worth lifting out. Most categories improve with organisational size - larger enterprises report fewer permissive firewalls, exposed services and weak encryption than smaller ones [15]. IAM is the exception, rising from 87% of SMEs to 95% of midmarket organisations to 98% of large enterprises [16], an 11 point climb [17] that tracks the complexity of managing users, roles and permissions at scale [16].
Remediation time follows a curve rather than a slope. Smaller organisations close cloud misconfigurations in 8 to 16 days on average; the average peaks at 35 days for organisations with 1,000 to 5,000 employees, falls to 19 days at 5,000 to 10,000, and reaches 10 days at the largest enterprises [18]. The worst-served band therefore takes about 3.5 times as long as the biggest firms [19]. Intruder's explanation is that midmarket teams often run enterprise-scale cloud estates without enterprise security resources [20].
What to watch: whether your posture tooling reports per-provider prevalence or a single blended score, because a blended score hides the 68 point gaps. Watch the 1,000-to-5,000-employee band in your own metrics - that is where the report says dwell time is worst [18]. And note that these are one vendor's figures from its own index [1], so treat the direction as more reliable than the decimal places.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Intruder's 2026 Cloud Security Index report found weak IAM controls and missing logging and alerting were the most widespread security issues across all three cloud providers, affecting 80% to 98% of accounts.
- [2]
The same security issue can manifest differently across AWS, Azure and Google Cloud, often requiring a different approach to identify and remediate, according to Intruder's 2026 Cloud Security Index report.
- [3]
Exposed services showed the widest variation between platforms, affecting 76% of AWS accounts, 64% of Azure accounts and 8% of Google Cloud accounts.
- [5]
Intruder attributes the differences in exposed service rates in part to the breadth of each provider's service portfolio and to differences in their approach to secure default configurations.
- [6]
AWS environments are most frequently affected by storage, network access and identity management misconfigurations.
- [7]
Azure's most common issues center on storage security and identity protection, particularly unrotated access keys, publicly accessible storage and missing MFA.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- helpnetsecurity.comAnamarija PogorelecAug 13Weak IAM affects up to 98% of cloud environments
Additional citations
- Intruder 2026 Cloud Security Index, via Help Net Security
- Intruder 2026 Cloud Security Index
- Chris Wallis, CEO and founder, Intruder



