
Cloud misconfiguration accounted for 14 per cent of confirmed breaches globally in the first quarter of 2026, up from 9 per cent in 2024, according to security analysis built on Verizon’s Data Breach Investigations Report (DBIR). It has not overtaken vulnerability exploitation as the leading cause of breaches overall, but it is the fastest-growing technical vector in the data, and the gap between how many organisations use multiple clouds and how many can actually secure them consistently is the reason why.
An Old Problem Getting Worse, Not Better
More than three quarters of organisations now run multiple cloud providers, and 66 per cent of them say maintaining consistent security controls across those environments is genuinely difficult. Nearly a third of cloud resources go unmonitored entirely, carrying an average of 115 unpatched vulnerabilities each, and the average configuration issue sits undetected for around 180 days before anyone finds it. Multi-cloud strategy has become standard practice faster than the tooling and staffing needed to secure it consistently, and 45 per cent of organisations admit they simply do not have adequate staff for the challenge.
What This Actually Looks Like
The consequences are not hypothetical. One documented incident exposed personal data and location details for 2.15 million connected vehicle users, left publicly accessible for nearly a decade because of a single unaddressed misconfiguration. Another exposed 38 million personal records, names, emails and phone numbers, across 47 separate organisations, including government agencies, through one configuration error in shared enterprise software. Neither incident required a sophisticated attacker. Both required someone to notice a setting that had been wrong for years.
A Global Technical Problem, Uneven Regulatory Response
This is not a story about one cloud provider or one region. AWS, Azure and Google Cloud environments all appear in the underlying breach data, and the DBIR’s own methodology draws on incidents reported by law enforcement agencies and computer emergency response teams worldwide. The regulatory response so far is patchier than the problem. The US has moved furthest, with Cybersecurity and Infrastructure Security Agency (CISA) mandating federal agencies secure their cloud environments to a defined standard, but most jurisdictions still treat cloud misconfiguration as a subset of general data protection obligations rather than a distinct, named risk category with its own enforcement expectations.
What a PMO Should Actually Check
A technology steering committee reviewing cloud risk should ask a narrower, more useful question than whether cloud security policies exist. It should ask what percentage of cloud resources are actively monitored right now, how long a misconfiguration typically sits before detection in this specific environment, and whether that number has ever been measured at all. A policy document proves intent. It does not prove that a setting exposing 2.15 million users has not been sitting open for years. Multi-cloud strategy delivered real flexibility. The security discipline to match it is still, for most organisations, a work in progress rather than a finished job.


On 19 September, the extortion group ShinyHunters broke into the dark web leak site run by Cl0p, one of the most prolific ransomware operations of the past two years, and defaced it. Three days later Cl0p was still trying to regain control, and every company that quietly paid Cl0p to make a breach disappear had a new, uncomfortable question to answer.




