2026 Cloud Security Index: How Risk Differs Across AWS, Azure, And Google Cloud
Cloud Security Alliance, Friday, September 4th, 2026
Misconfiguration patterns barely overlap across the three major clouds, fragmenting how security teams understand risk.
Analysis of misconfiguration data from 3,000 organizations over the 12 months to July 2026 finds that the issues dominating AWS look almost nothing like those on Google Cloud, with Azure different again.
On AWS the most widespread findings are S3 not enforcing HTTPS at 87%, permissive ingress to sensitive ports at 84%, overly permissive network ACLs at 83% and IAM policies allowing privilege escalation at 83%.
Azure is led by storage account key rotation not enabled at 67%, access keys enabled at 66%, public network access at 61% and Entra users without MFA at 55%. The practical concern is that divergence fragments risk understanding and slows remediation.