What Cloud Misconfiguration Looks Like in a Real Audit

Cloud misconfiguration turns up in four recurring patterns. 1) Over-permissioned roles give an attacker a path to sensitive data. 2) Management interfaces sit reachable without MFA. 3) Account trust goes unreviewed, and 4) logging exists but nobody watches it. A CSPM tool flags each as a setting. What decides whether it's exploitable is whether a pentester can chain it into a real route an attacker would use.

cloud misconfiguration

Vulnerability exploitation overtook stolen credentials as the top way attackers broke into systems during 2025, according to Verizon's 2026 Data Breach Investigations Report. Look past that headline, though, and a different story shows up. In the same dataset, 83% of privilege escalation incidents involved no Common Vulnerabilities and Exposures (CVE) at all. The attacker didn't exploit a flaw in the code. They walked through a setting someone left open.

That's the pattern our cloud audits are built to catch. We test what a misconfiguration lets an attacker do, not just whether it exists. A cloud security posture management (CSPM) dashboard can tell a team that a role has broad permissions. It rarely proves whether that role gives a real path to sensitive data. 

We explain the cloud misconfiguration patterns that turn up most often in our assessments, and the cloud security risks each one creates.

Four Cloud Misconfiguration Patterns We Keep Finding

Cloud misconfiguration rarely shows up as one isolated mistake. In our assessments, it clusters into four recurring patterns. 

  1. IAM over-permissioning and role-chaining, where identities and service accounts gain more access than they need for the task at hand. 
  1. Exposed storage and management interfaces, reachable from outside the environment when they shouldn't be.
  1. Broken tenant and account isolation, where trust relationships between vendors, partners, and internal teams go unreviewed. 
  1. Missing or blind logging, where a control exists on paper but nobody's watching it in practice.

Each pattern gets its own look below. We explain what each misconfiguration tends to involve, why it’s dangerous, and how a tester goes beyond the CSPM flag to prove it out.

IAM Over-Permissioning and Role-Chaining

Identity and access management sprawl is the cloud misconfiguration pattern we see most. A role gets created for a one-off task and never gets trimmed back. A service account picks up broad read access because a narrower policy would've taken longer to write. None of this looks dramatic on its own.

The danger sits in the chain. Verizon's report mapped the MITRE ATT&CK techniques attackers use to escalate privilege once inside an environment. 

  • Privilege management covered 65% of the fixes that would stop those techniques. 
  • Patching covered just 10%. 

Escalation is mostly a permissions problem, not patching.

A CSPM tool flags an over-permissioned role as a line item. A pentester goes further. We take that role and try to walk from it to a database, a secrets store, or an admin console. That's the same route an attacker would take. If we can reach something sensitive in two or three hops, that role isn't a hygiene issue. It's a path.

Exposed Storage and Management Interfaces

Public storage buckets get most of the headlines, but management interfaces left reachable without Multi-factor Authentication (MFA) cause just as much damage. Verizon's third-party cloud dataset found that 37% of organisations had at least one admin account on an Infrastructure as a Service (IaaS) platform with MFA disabled. 

A scanner checks whether MFA is switched on for an account. It doesn't usually check what that account can reach once someone gets past login. Nor does it check whether the same credentials work across a wider set of services than intended. 

Testing exposed interfaces means confirming both whether the door's open and what sits behind it once you walk through.

Remediation in this category is often slow. According to the same report, only 23% of third-party organisations had fully closed their cloud MFA gaps. The tail of unresolved cases stayed high for months afterwards. 

Fixing one account is quick. Finding every account that needs fixing takes a while.

Broken Tenant and Account Isolation

Cloud environments rarely stay cleanly separated once a business connects vendors, partners, and internal teams to the same platform. A shared role built for convenience during a migration can become a bridge between environments that were never meant to touch. 

Third-party involvement in breaches reached 48% in 2026, up from 30% the year before. That's a 60% jump in a single year. Much of that growth traces back to trust boundaries, not malware. 

A vendor's access token gets compromised, and it turns out that token reaches further into a customer's environment than anyone had reviewed. Testing tenant isolation means mapping every cross-account trust relationship. Then we ask if the connection allows more than the business reason for it requires.

Missing or Blind Logging

The last pattern's the least noticeable, yet often the most consequential. Logging is enabled during setup, then drifts as accounts, regions, and services are added without anyone extending coverage to match. 

A CSPM tool can confirm that logging's switched on somewhere. It can't always confirm that the action a pentester just took would show up in anyone's queue.

We test this. During an assessment, we purposefully perform an action that should trigger an alert. Then, we check whether it was captured, routed anywhere useful, and visible to a human in reasonable time.

Logging that exists but nobody reviews gives a false sense of coverage. That gap only shows up once someone tries to use it.

Where to Prioritise Fixes First

Not every misconfiguration deserves the same urgency. Treating them all as equal usually means the highest-risk ones sit unfixed the longest. 

Start with anything that gives a direct path to sensitive data or broad account control. That means over-permissioned roles with reachable chains, exposed admin interfaces without MFA, and cross-tenant trust nobody's reviewed. Logging gaps matter too, but they change how fast you notice a problem rather than whether one can happen.

As necessary as finding vulnerabilities is, timely remediation is absolutely vital. Research shows that full closure of cloud MFA gaps sat at 23%. Fixes for weak passwords and permission issues combined took a median of close to eight months.

An assessment that only checks a box leaves that window wide open. That's why a one-off cloud audit rarely settles the question for long.

A CSPM Dashboard Is a Starting Point, Not an Answer

Our testers take the findings a scanner surfaces and prove, or rule out, whether they give an attacker a usable path through your environment. That's the difference between a list of settings and a prioritised risk list.

Book Your Cloud Security Assessment

Answers to Your Cloud Misconfiguration Questions

How Often Should Cloud Configuration Be Reassessed?

Cloud environments change constantly as teams add accounts, services, and integrations, so a one-off assessment goes stale fast. Reassessing at regular intervals, and after any major infrastructure change, keeps findings aligned with what's running today.

Is a Cloud Misconfiguration the Same as a Cloud Vulnerability?

Not quite. A vulnerability's usually a flaw in code, tied to a CVE. A misconfiguration is a setting that works as designed but was set up in a way that creates risk. That's why patching alone won't fix most cloud exposure.

What Makes a Misconfiguration Exploitable Rather Than Just Risky?

A setting becomes exploitable when it gives a tester, or an attacker, a working route to something valuable: data, credentials, or control over other resources. Proving that route is what separates a scanner finding from a confirmed one.

Find Out What Your Cloud Environment Is Hiding

A scanner’s output is a checklist (often littered with false positives and negatives). Our manual cloud audit goes further and tests whether the issues on that checklist are real and if they can be chained into something an attacker could use. You get a prioritised report, not a wall of low-context alerts.

Speak to Our Cloud Team
Want to Read More?