According to a new report from security solutions firm Qualys, controls within Google Cloud Platform (GCP) are the most misconfigured by users of the big three cloud service provider (CSP) environments, thereby increasing susceptibility to security risks.
This is just one of the many findings highlighted in the Qualys Threat Research Unit’s recently published TotalCloud Security Insights report. The research utilises anonymised data from global cloud scans.
“Configurations” refer to control settings applied to both software and hardware aspects within a cloud environment. While the platforms themselves aren’t intrinsically insecure, the misconfiguration of controls by users can magnify security risk.
Misconfiguration can be caused by myriad reasons: from the complexity of cloud environments to a lack of expertise with evolving technologies, human error leading to insecure settings and permissions, or rapid deployment that compromises the implementation of security measures.
When looking at cloud misconfiguration issues in the three major CSPs, the researchers found that Google Cloud Platform was in the lead with an average failure rate of 60% when measured against Centre for Internet Security (CIS) Benchmarks. The CIS Benchmarks are a set of configuration guidelines and recommendations provided to help protect systems against cyber threats.
However, Azure wasn’t far behind the GCP misconfiguration rates with an average failure rate of 57%. The last of the big three, AWS, had an average failure rate of 34%.
Further, the misconfiguration of controls in GCP services that most failed against CIS Benchmarks was DataProc, BigQuery, and Logging, according to the research.
Recommended
- Misconfigured Cloud Account Leaks Data on Half a Million People
- Cloud-based Cyber-attacks Increased by 48% in 2022
- Microsoft and AWS Push Back Against Cloud Market Investigation
Encryption, identity and access management (IAM), and external-facing assets were highlighted as key misconfigurations across all clouds.
For instance, when it comes to encryption, 99% of the disks in Azure are either not encrypted or are not using a customer-managed key (CMK), despite the report noting that enabling encryption is usually as simple as selecting a checkbox within the configuration settings.
Meanwhile, regarding IAM in AWS, multi-factor authentication (MFA) is not enabled for 44% of IAM users with console passwords. Further, IAM Access Analyzer is not enabled in 96% of the accounts scanned by Qualys.
The report also underscored that a common misconfiguration by users of all three major cloud providers is inadvertently leaving data publicly accessible. For example, the research team found that 31% of S3 buckets are publicly accessible, which exposes them to a variety of potential cybersecurity vulnerabilities.





