Cloud security firm Intruder published its 2026 Cloud Security Index on August 14, analyzing misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud over the 12 months to July 2026. The headline finding: weak identity and access management controls affect 87 percent of small and midmarket organizations, rising to 98 percent of large enterprises with 10,000 or more employees, the only misconfiguration category in the report that consistently worsens as organizations grow rather than improving with more mature security programs.

Why it matters: the report groups cloud risk into six categories, weak IAM, missing logging, misconfigured services, permissive firewalls, exposed services, and weak encryption, and finds each cloud provider fails differently. AWS leads in weak IAM at 97 percent and missing logging at 98 percent, with 76 percent of accounts carrying exposed services. Azure’s worst category is misconfigured services at 80 percent, with 55 percent of accounts lacking MFA entirely. Google Cloud performs best on exposed services and encryption but is dominated by OS Login misconfigurations affecting 76 to 77 percent of accounts.

The original insight: the near-zero overlap between each provider’s top misconfiguration category is the actual finding, not the individual percentages. A security team that standardizes its cloud hardening checklist across a multi-cloud estate, rather than tailoring it to each provider’s specific weak points, will systematically miss the risk that matters most on at least one platform, a gap that compounds the kind of platform-specific trust failures and privilege-escalation bugs CyberTech has tracked this year. IAM, uniquely, needs its own line item regardless of provider.

Source: Intruder