Skip to content

Which Cloud Misconfigurations Create the Highest Risk of Data Exposure in Enterprise Environments?

Marketing 15 min read

Share

ChatGPT Image Oct 5, 2026, 05_21_43 PM

Ask ten security teams which cloud misconfiguration worries them most and nine will say public storage buckets. It is the classic story: easy to picture, easy to headline. It is also, more and more, the wrong place to start. The evidence now points at a quieter group of settings that decide who and what can reach your data, how long that access lasts, and whether anyone would notice if it went wrong. 

A 2026 dataset shows how wide the gap is. Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure and Google Cloud over the twelve months to July 2026. Weak identity controls and missing logging turned up in 80 to 98 percent of accounts, whichever provider was involved. These are not exotic findings. They are basics, missed at scale.  

This article ranks the misconfigurations that most often turn into data exposure, explains why the ranking has shifted, and sets out what an enterprise IT team should fix first. It pays particular attention to teams working under India's DPDP and CERT-In obligations.  

Highest-Risk Cloud Misconfigurations That Can Expose Enterprise Data

The cloud misconfigurations that create the highest risk of data exposure are, in this order: overprivileged identities and missing MFA on admin accounts; storage and data services reachable from outside the organization; long lived secrets and shareable access tokens; missing logging and alerting; permissive network paths; unchecked third party and SaaS trust; and, increasingly, ungoverned AI data pipelines. Public buckets still matter, but they are one item on the list and no longer the top of it. The ranking is my own analysis of the evidence below, not a published index. 

How to Assess Cloud Misconfiguration Risk in Enterprise Environments

I used three tests. The first is reach: if this setting is wrong, how much data can someone get to, and how directly? The second is prevalence: how often does it show up in real environments? The third is dwell time: how long does it typically stay unfixed, and would you see it being abused? 

A misconfiguration that is common, wide in reach and slow to fix scores highest. That is why identity sits above storage. A public bucket exposes one bucket. An overprivileged identity can expose everything that identity can touch. 

What Cloud Security Data Reveals About Misconfiguration Risk

Cost. IBM's 2026 Cost of a Data Breach Report puts the global average at $4.99 million, a 12 percent increase and a record, driven by higher detection, escalation and lost business costs. In India the average reached INR 25.5 crore in 2026, up 15.9 percent from INR 22 crore, with 39,500 records compromised on average. Financial services took the heaviest hit at INR 40.9 crore per breach, ahead of technology at INR 35.7 crore. These are averages for all breaches, not only cloud incidents, but they set the stakes.  

Prevalence. Verizon's 2026 report added a new dataset on the cloud posture of third party organizations. Only 23 percent had fully remediated cloud MFA gaps, weak password and permission misconfigurations took almost eight months to resolve for half of all findings, and 37 percent had at least one admin IaaS account with MFA disabled.  

Fix speed. Intruder found smaller organizations remediate fastest, in 7 to 16 days, while organizations with 1,000 to 5,000 employees peaked at 35 days, and those above 10,000 took around 10 days. The middle of the market, running enterprise scale cloud without enterprise scale resources, is where fixes stall.  

A note on conflicting numbers. You will see very different claims about how much of cloud risk misconfiguration explains. SentinelOne reported almost 23 percent of cloud security incidents in 2024 stemming from misconfigurations. An older Unit 42 study said misconfigurations were behind 65 percent of detected cloud security incidents. The CSA's 2026 survey moved the issue from first place to fifth, but that is a ranking of professional concern, not a count of incidents. The figures differ because the sources define incidents differently, count alerts versus confirmed breaches, and draw on different years and customer bases. Read them as three views of one problem, not as competing answers.  

Seven misconfigurations, ranked by risk 

1. Overprivileged identities and missing MFA 

This is the highest risk misconfiguration because it multiplies every other weakness. Intruder found weak IAM controls in 97 percent of AWS accounts, 90 percent of Azure accounts and 87 percent of Google Cloud accounts. Unlike most issues, it gets worse with size: 87 percent of small businesses, 95 percent of midmarket firms and 98 percent of large enterprises were affected. More people means more roles, more permissions and more forgotten access.  

The specifics are telling. On AWS, 83 percent of accounts had an IAM policy that allows privilege escalation. On Google Cloud, 75 percent had unused service accounts. On Azure, 55 percent had Entra users without MFA. Palo Alto's Unit 42 analyzed more than 680,000 cloud identities in an earlier study and found 99 percent of cloud users, roles and services had excessive permissions; its 2026 incident response report says identity weaknesses played a material role in almost 90 percent of its investigations. That dataset is several years old, so treat the number as directional.  

Snowflake shows how this plays out. Mandiant traced a campaign against approximately 165 potentially exposed organizations to stolen customer credentials, not a breach of Snowflake itself. It named three factors: MFA was not enabled, credentials stolen by infostealers had not been rotated, and no network allow lists limited access to trusted locations. In many cases credentials had not been rotated for as long as four years.  

My analysis: permissions creep is usually a project leftover. Someone is granted broad access to complete a migration, the migration ends, and the access stays.

2. Storage and data services reachable from outside 

This is the classic exposure, and it still ranks second because reach is direct and no attacker skill is needed. Intruder found Block Public Access was not enabled at account level in 81 percent of AWS accounts, and on Azure 61 percent of accounts had storage accounts with public network access enabled, while 36 percent had blob public access enabled. Exposed services affected 76 percent of AWS accounts, 64 percent of Azure accounts and just 8 percent of Google Cloud accounts.  

Provider defaults have improved, with a catch. AWS announced that from April 2023 all new S3 buckets would have Block Public Access enabled and ACLs disabled, with no change for existing buckets. That matters for enterprises that migrated years ago: a lift and shifted estate carries its old settings with it. Defaults protect what you build tomorrow, not what you built in 2019. 

Speed makes it worse. Security researchers note that threat actors can discover exposed cloud assets in mere minutes.  

3. Shareable tokens and long lived secrets 

A token is a permission with a URL attached. The clearest example is Microsoft's own. Wiz found that a link meant to share open source AI models was configured to grant permissions on the entire storage account, exposing 38TB of additional private data, and was set to full control instead of read only. The exposed data included workstation backups containing secret keys, passwords and over 30,000 internal Teams messages. The token had been publicly accessible on GitHub for three years. Microsoft's own account says no customer data was exposed and the issue was not a vulnerability in Azure Storage or the SAS feature. That is the point: the platform worked as designed and a person configured it too widely.  

Static secrets are the everyday version. Intruder found 71 percent of AWS accounts had IAM access keys that were not rotated, 67 percent of Azure accounts had storage account key rotation switched off, and 41 percent had Key Vault secrets that never expire.  

4. Missing logging, alerting and inventory 

Missing logs do not create exposure by themselves. They decide how long an exposure lasts and whether you can prove what happened. Intruder found missing logging and alerting in 98 percent of AWS accounts, 80 percent of Azure accounts and 82 percent of Google Cloud accounts.  

In India this is also a compliance problem. DPDP Rule 6 requires logs and personal data to be retained for one year to detect unauthorized access and support investigation, unless another law requires otherwise, and CERT-In separately requires ICT system logs to be kept for at least 180 days within India. You cannot meet reporting clocks for incidents you never saw.  

5. Permissive network paths and exposed management interfaces 

These are the settings that turn a small mistake into an open door. Intruder found permissive ingress to sensitive ports via ACL in 84 percent of AWS accounts and overly permissive network ACLs in 83 percent. By category, 83 percent of AWS accounts had permissive firewalls against 34 percent on Google Cloud. Intruder attributes part of the gap to Google's more secure defaults.  

Intruder is candid that these may not expose anything today, but a tightly scoped firewall is what stops tomorrow's development work from introducing exposure. Rank this fifth because the risk is conditional, not because it is minor. 

6. Unchecked third party and SaaS trust 

Some of the most damaging exposures now run through trust relationships. Verizon found that breaches involving a third party reached 48 percent of its dataset, up from 30 percent. The CSA's 2026 survey moved insecure third party resources up to third place, and its definition of IAM risk explicitly includes misconfigured trust relationships, exposed credentials and excessive permissions. An OAuth grant or vendor role you approved and forgot is a misconfiguration with a business name attached.  

7. Ungoverned AI and data pipelines 

This is the newest entry. IBM's 2025 report found shadow AI was a factor in 20 percent of breaches, adding $670,000 to average costs, and its 2026 India findings say shadow AI adds an average of INR 1.79 crore where present. The CSA added AI system compromise to its top threats at sixth place. Training data buckets, vector databases, notebooks and agents that inherit broad permissions are all new places for an old mistake.  

Why these settings survive 

Three patterns explain most of the persistence. First, the cloud does not fail the same way twice. Intruder's data showed the top issues on AWS barely overlap with those on Google Cloud, and Azure looks different again. A team fluent in one platform can miss the controls that matter on the next.  

Second, environments change faster than reviews do. IBM's reporting notes attackers exploit periods of architectural change, which is exactly what a migration is. The CSA's incident analysis adds that many breaches start in development and testing environments, where controls are weaker than in production.  

Third, ownership is unclear. Verizon's eight month median fix time for permission problems is not a technology limit. It is what happens when nobody owns the ticket. 

Rules and guidance that apply 

DPDP Rules 2025. Rule 6 requires reasonable security safeguards, including encryption or masking, access controls, and visibility through logs and monitoring. Rule 7 requires notifying affected people without delay and giving the Board a detailed report within 72 hours of discovery. Penalties can reach ₹250 crore. Timing: the government told the Lok Sabha on 12 August 2026 that core obligations take effect within 18 months of the November 2025 notification, around May 2027.  

CERT-In Directions. Reportable incidents must be reported within 6 hours of noticing them, and the list includes data breach, data leak, and attacks or suspicious activity affecting cloud computing systems. My reading is that an exposed bucket with no proven theft can still count as a data leak once you notice it. Confirm this with counsel, because the clock runs from awareness, not from proof.  

Sector rules. SEBI's cloud framework points regulated entities to MeitY empanelled providers, with the entity retaining ownership of data, logs and encryption keys. The RBI's IT outsourcing directions took effect on 1 October 2023 and cover cloud computing services, and require an exit strategy for outsourced IT activities.  

A global baseline template. In December 2024 CISA issued BOD 25-01, which requires US federal civilian agencies to identify cloud tenants, deploy assessment tools and align to secure configuration baselines. It binds only federal agencies, but CISA strongly recommends all stakeholders implement the baselines. It is a useful model for writing your own.  

What to fix first 

This sequence follows the ranking above, and it is my recommendation. 

  1. Identities and MFA. Inventory every identity, including service accounts and API keys. Enforce MFA on all admin and console access. Remove unused permissions and make elevated access time bound. 

  1. Guardrails that block exposure by default. Enforce account level blocks on public access and use policy as code, so making something public needs a recorded exception. 

  1. Secrets and tokens. Move to short lived credentials where possible. Rotate what remains, scan code repositories, and cap the scope and expiry of shared links. 

  1. Logging baseline. Centralize logs, retain them to meet both the DPDP year and the CERT-In 180 days, and alert on changes to security policy. 

  1. Prioritize by reach. Rank findings by what sensitive data they can actually reach, not by raw count. Data classification comes first. 

  1. Third party access. Review OAuth grants and vendor roles on a fixed schedule. 

  1. Test the paths. IBM found in India that offensive security testing such as red teaming and penetration testing was the largest cost reducing factor, saving INR 2.47 crore on average.  

  1. Set fix deadlines by class. Measure time to remediate as a leadership metric. Eight months should be an embarrassment, not a median. 

Emerging Cloud Security Risks Enterprises Need to Prepare For

These are forecasts and reasoned expectations, not facts. The DPDP obligations arrive in May 2027, which will turn today's poor logging and access hygiene into a regulatory exposure. Attackers are also getting faster: IBM reports a 56 percent increase in AI driven attacks, and Unit 42 says exfiltration speeds for the fastest attacks quadrupled in 2025. Shorter attack windows leave less time to catch what missing logs hide.  

My expectation is that "configuration hygiene" will be redefined as "authority hygiene": less about whether a setting is switched on, more about what each person, service, integration and AI agent is allowed to do. The CSA's 2026 ranking already points that way. 

How NS3TechSolutions Helps Enterprises Strengthen Cloud Security

Cloud data exposure sits across several teams. The cloud team owns the settings, the network team owns the paths, the security team owns detection, and compliance owns the reporting clocks. NS3TechSolutions works across those areas, with cloud, enterprise networking, network security, SOC and NOC operations, managed services and IT consulting. 

In practice, that means three things. Before problems appear, NS3 can review identity design, network segmentation and firewall policy against the priorities above. Where exposure would be discovered, it can help design the logging and monitoring layer so that retention and incident reporting requirements are met without paying for the same telemetry twice. And after the review, managed services and a SOC or NOC give the fixes an owner, so configuration drift is caught on a schedule and not by a researcher, a journalist or a regulator. 

Practical checklist to save and share 

  1. Do we have a current inventory of human and non human identities? 

  1. Is MFA enforced on every admin and console account? 

  1. Have unused permissions and service accounts been removed in the last quarter? 

  1. Is public access blocked at account or organization level, with exceptions recorded? 

  1. Do we know which storage and databases hold personal data? 

  1. Do shared links and tokens have limited scope and short expiry? 

  1. Are access keys and secrets rotated, and are repositories scanned for them? 

  1. Do logs cover one year (DPDP) and 180 days in India (CERT-In)? 

  1. Do we alert on changes to security policy and public access settings? 

  1. Are third party integrations and OAuth grants reviewed on schedule? 

  1. Do we have remediation deadlines by severity, and do we measure them? 

  1. Have we tested our worst case attack path in the last year? 

Frequently asked questions 

Q. What is the most dangerous cloud misconfiguration? 


A. Overprivileged identities without MFA, in my ranking. They have the widest reach and are among the most common. Intruder found weak IAM in 87 to 97 percent of accounts across the three big providers. 

Q. Are public S3 buckets still a major risk? 

A. Yes, but mainly in older estates. AWS made blocking public access the default for new buckets from April 2023, but existing buckets were not changed. Intruder still found account level protection missing in 81 percent of AWS accounts. 

Q. Is misconfiguration or stolen credentials the bigger cause? 

A. They overlap. The Snowflake campaign used stolen credentials, but succeeded because accounts lacked MFA, credentials were not rotated and no allow lists existed. Verizon's 2026 report also found vulnerability exploitation overtook credential theft as the top initial access route, so neither is the whole picture. 

Q. Does an exposed cloud database count as a breach in India? 

A. Possibly. CERT-In's list includes data leaks and cloud related incidents, and the six hour clock runs from noticing. Whether an exposure without proven theft triggers DPDP notification depends on the facts, so get legal advice. 

Q. How long do organizations take to fix misconfigurations? 

A. It varies widely. Intruder found 7 to 35 days depending on company size, while Verizon found almost eight months for half of weak password and permission findings in third party cloud environments. The gap reflects different datasets. 

Q. Which cloud provider has the fewest misconfigurations? 

A. In Intruder's data, Google Cloud had the lowest prevalence in four of six categories and AWS the highest in five, but weak IAM and missing logging affected 80 to 98 percent of accounts on all three. Provider choice does not replace your own baselines. 

Q. How much does a data breach cost an Indian enterprise? 

A. IBM's 2026 report puts the average at INR 25.5 crore, and INR 40.9 crore in financial services. Those figures cover all breaches, not only cloud. 

The takeaway 

A misconfiguration is rarely a mistake in a setting. It is usually a decision nobody owned: who may reach this data, for how long, and who would notice if they should not. That is why the public bucket has slipped down the ranking while permissions, secrets and blind spots have moved up. The useful question for your next review is not how many findings you have. It is what the worst one lets someone reach, and how long it would take you to find out.