Cloud Security Isn't One Problem. It's Three.

A new Intruder study of 3,000 organisations finds AWS, Azure, and Google Cloud fail in different ways, and one checklist won't catch them all.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Intruder's 2026 Cloud Security Index reviewed misconfiguration data from 3,000 organisations using Amazon Web Services, Microsoft Azure, and Google Cloud.
  • The report finds risk profiles across the three cloud providers share almost nothing in common.
  • A single security checklist applied across all three providers will miss provider-specific weaknesses.
  • Misconfigurations, not clever hacking, remain the most common way attackers break into cloud accounts.
  • Security teams running workloads on more than one cloud need separate playbooks for each.

Running a business on the cloud used to mean picking one provider and learning its quirks. Today most companies use two or three at once. That means three sets of settings, three sets of default behaviours, and three sets of ways things can quietly go wrong.

A new report from the security firm Intruder, the 2026 Cloud Security Index, looked at misconfiguration data from 3,000 organisations. Misconfiguration is just a fancy word for a setting left in the wrong position: a storage bucket left open to the public internet, a database with no password, an admin account nobody remembers creating.

The finding, first reported by The Hacker News, is blunt. The kinds of mistakes companies make on Amazon Web Services look almost nothing like the mistakes they make on Microsoft Azure, which in turn look almost nothing like the mistakes they make on Google Cloud.

In other words, the security checklist you built for one provider will not protect you on the others.

Why do the three clouds fail differently?

Because they are built differently. Each provider makes its own choices about what is switched on by default, how permissions are handed out, and how services talk to each other. Those choices shape which mistakes are easy to make.

On one platform, the risky default might be storage that is readable by anyone who guesses the address. On another, it might be an identity system that hands out more access than the user actually needs. On a third, it might be logging that is off unless you turn it on.

None of these are exotic attacks. They are the digital equivalent of leaving a window open. But the windows are in different places on each house.

What does this mean for a company using more than one cloud?

One playbook is not enough. A team that has mastered Amazon's controls can still be caught out the first time it spins up a workload on Azure or Google Cloud, because the muscle memory does not transfer.

Intruder's numbers underline a point that cloud security specialists have been making for years. The biggest risk in the cloud is rarely a zero-day, meaning a brand-new software flaw the vendor did not know about. It is a setting somebody forgot to change.

Should ordinary customers worry about this?

Indirectly, yes. When a company leaves a cloud storage bucket open, the data inside, sometimes customer names, addresses, or account details, can be scraped by anyone who finds it. Most of the large data leaks reported in the past few years began exactly this way.

There is nothing a customer can do about a company's cloud settings. But you can limit the damage: use a different password on every site, turn on two-step login where offered, and be sceptical of unexpected emails claiming to be from a service you use, even if they get small details right.

The bigger picture

Cloud providers have spent years adding guardrails, warnings, and dashboards to nudge customers into safer settings. The Intruder data suggests those nudges work differently on each platform, and unevenly. For security teams, the honest read is that "cloud security" is not one skill. It is three, and treating them as one is where the trouble starts.

© 2026 Threat Vectr