Report
The State of Cloud Misconfiguration
A data-driven look at the IAM, storage, and network misconfigurations most commonly exploited in real intrusions.
- 400+ cloud security engagements analyzed
- Toxic IAM permission combinations found in the majority of environments
- Wildcard resource scoping: the single largest contributor
Overview
We analyzed configuration findings from over 400 cloud security engagements to identify the misconfiguration patterns most frequently chained into real compromise, rather than those simply flagged by benchmark scans.
The IAM permission sprawl problem
Toxic combinations of IAM permissions — individually reasonable, collectively dangerous — appeared in the majority of environments we reviewed. Wildcard resource scoping remains the single largest contributor.
Recommendations
Move from periodic access reviews to continuous least-privilege enforcement. Automate detection of permission combinations that enable privilege escalation, not just individually risky grants.
Keep Reading
More from Reports.
2026 Application Threat Landscape
Our annual analysis of the vulnerability classes and exploitation trends defining the year ahead.
Read the ReportRansomware Response Benchmarks
Detection and containment timing data from incident response engagements across 2025.
Read the ReportYour infrastructure is a target. Find out where before an adversary does.
Tell us what you're running and we'll scope an assessment around it — no generic package, no upsell call in disguise.
No obligation. Response within 1 business day.
