Threat Intelligence

One-Size Cloud Security Checklists Don't Work: Each Provider Fails Differently

The Hacker News · 7 Sept 2026
Key Takeaway Don't rely on a generic cloud security checklist; review the specific default settings and permission structures of the exact cloud provider your business uses.

A new report from Intruder, the 2026 Cloud Security Index, has analysed misconfiguration data from 3,000 organisations using AWS, Azure and Google Cloud, and found that the risks vary significantly depending on which provider a business uses. Weak identity and access controls and missing logging are common problems across all three platforms, affecting between 80% and 98% of accounts. However, issues like exposed services, overly permissive firewalls and weak encryption are far more common on AWS than on Google Cloud, while misconfigured services are most common on Azure.

The report suggests these differences come down to how each provider is built. AWS offers the widest range of services, which creates more configuration choices and more chances for mistakes. Google Cloud, by contrast, offers fewer services and ships with more secure defaults, which may explain its lower rates of exposure and encryption issues. On AWS specifically, two common problems stand out: storage buckets that don't enforce secure HTTPS connections, and identity policies that unintentionally allow privilege escalation, the latter affecting 83% of accounts. In one real-world case, attackers used exposed credentials to gain full administrative access in under 10 minutes across 19 accounts.

For small businesses using cloud services, this research is a reminder that security settings are not automatically safe just because a big provider manages the infrastructure. Each platform has its own quirks, and the responsibility for locking down access, encryption and network exposure often sits with the customer, not the cloud provider.

Key Takeaway: Don't rely on a generic cloud security checklist; review the specific default settings and permission structures of the exact cloud provider your business uses. Key Takeaway

cloud security AWS Azure Google Cloud misconfiguration

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.