Cloud security isn’t a monolith, especially when you’re juggling infrastructure across AWS, Azure, and Google Cloud. A new study makes clear that many organizations still treat cloud checklists as universal — and that approach can leave gaping vulnerabilities.
What the Data Shows
The 2026 Cloud Security Index, based on misconfiguration scans of about 3,000 organizations through July 2026, reveals sharp contrasts in how AWS, Azure, and Google Cloud fare across six categories of risk. Weak identity and access management (IAM) controls and the absence of logging show up across 80–98% of accounts in all three environments. But beyond those two near-universal issues, the divergence is stark. Roles like permissive firewalls, exposed services, misconfigured services, and weak encryption are far more prevalent in AWS and Azure than Google Cloud. In some categories, AWS leads by a wide margin. Google Cloud’s more opinionated defaults under its so-called Shared Fate model seem to play a role in its lower misconfiguration rates.
For example, exposed services affect about 76% of AWS accounts compared to only 8% on Google Cloud. Permissive firewalls are problematic in 83% of AWS accounts, but only 34% on Google. The pattern repeats: weak encryption and overly permissive access are far more widespread in AWS and Azure than GCP.
Common Failure Points by Platform
Each cloud suffers from its own top misconfigurations. On AWS, nearly nine out of ten accounts don’t enforce HTTPS on S3 buckets; a similar number allow overly permissive access via network ACLs or allow IAM policies that enable privilege escalation. The recurring theme: network exposure and lax access controls.
Azure’s most frequent issues cluster around storage accounts: many have access keys enabled, public network access allowed, and lack of key rotation. More than half the Azure accounts examined also include users in Entra ID without multi-factor authentication.
Google Cloud carries a different set of weaknesses, though they’re still serious. OS Login MFA is missing in 77% of accounts, unused or overly permissive service accounts are present in roughly three-quarters of organizations, and sensitive ingress ports remain exposed in many accounts.
Team Size Matters — Complexity Trips Midmarket
The patterns of misconfiguration aren’t uniform across enterprise size. Smaller organizations tend to correct issues more quickly, within 7–16 days. But midmarket companies (1,000–5,000 employees) reported average remediation times of 35 days, significantly slower than both smaller and larger organizations.
Interestingly, the biggest exception to the trend of “bigger = safer” lies in IAM. Weak IAM controls become more widespread as companies grow: 87% of SMEs, 95% of midmarket organizations, and 98% of large enterprises show at least one IAM issue. That suggests that as infrastructure and identity systems scale, managing privileges becomes exponentially harder.
So What Should Your Checklist Do?
- Be flexible by provider. Checklist items shouldn’t assume the same severity across clouds — what’s critical in AWS may be less urgent (or less common) in GCP.
- Target identity and logging first. Given how ubiquitous weak IAM and poor alerting are, these should top every audit before networking or encryption.
- Adjust for size. Midmarket teams in particular need more focused resources — prioritize automated remediation and visibility tools to close that 35-day remediation gap.
- Account for defaults. If your cloud provider deploys opinionated secure defaults (as Google Cloud does with its Shared Fate model), build your checklist around where the defaults already protect you — then double down where they don’t.
The 2026 Cloud Security Index reminds security teams that checklists aren’t enough if they’re generic. For multi-cloud organizations, rigid, one-size-fits-all policies risk misallocating time and effort — or worse, overlooking what matters for a specific environment. Adapting checklists per cloud provider, constantly measuring exposure, and closing identity and logging gaps will offer far better protection than static, universal rules.