Weak IAM Controls Expose 80‑98% of Cloud Accounts Across AWS, Azure, and Google Cloud
What Happened — A 2026 Intruder Cloud Security Index report found that weak identity and access management (IAM) configurations affect between 80 % and 98 % of cloud accounts on AWS, Azure, and Google Cloud. The most common gaps are missing MFA, unused or overly‑permissive service accounts, and unrotated access keys, often combined with missing logging and alerting.
Why It Matters for Compliance & Audit Readiness
- Misconfigured IAM is a direct violation of SOC 2 CC6.1 (Logical Access) and CC6.2 (Principle of Least Privilege) – controls that must be demonstrated continuously.
- Continuous‑compliance programs need automated evidence that IAM policies are enforced, keys are rotated, and MFA is active across all cloud providers.
- Verisq’s Control Mapping capability can map each cloud‑specific IAM control to SOC 2 requirements and collect real‑time proof for audit reviewers.
Who Is Affected — Mid‑market and enterprise organizations that operate multi‑cloud environments, especially those in technology SaaS, cloud‑infra services, and financial services.
Recommended Actions
- Inventory all cloud IAM assets and map them to SOC 2 CC6.1/CC6.2 controls.
- Deploy automated key‑rotation and MFA enforcement policies across AWS, Azure, and Google Cloud.
- Enable continuous logging and alerting for IAM changes; feed logs into a centralized compliance dashboard.
- Use a control‑mapping solution to capture configuration snapshots as audit‑ready evidence.
Technical Notes – The report highlights platform‑specific weaknesses: AWS (permissive firewalls, exposed services), Azure (unrotated keys, missing MFA), Google Cloud (unused service accounts, overly permissive IAM). No single CVE is cited; the risk stems from systemic misconfiguration. Source: Help Net Security