Cloud complexity and misconfiguration epidemic¶

Anyone who has stood in the middle of Ankh-Morpork and wondered how a city can be both thriving and permanently on fire already understands modern cloud architecture. It is a place of great promise and greater confusion, where good intentions go to retire and temporary solutions set down roots, apply for citizenship, and start families.
Many organisations now operate multi-cloud and hybrid environments that resemble a badly organised thieves’ guild: overlapping IAM policies contradicting one another like rival street gangs, storage buckets lingering like stains nobody remembers creating, service accounts that refuse to die, and VPNs meant to last two weeks that are now part of the cultural heritage. Misconfiguration has become the new malware because it is cheap, quiet, and grows like weeds between the cobbles. Malware requires skill. Misconfiguration requires only enthusiasm and a console login.
The promise and the invoice¶
The official pitch sounded simple: move to the cloud for simplicity, scalability and security, a convenient package of miracles for a monthly fee. In practice, simplicity turned out to be theoretical, scalability expanded faster than a guild budget, and security remained the customer’s responsibility. Providers secure the cloud; the customer secures what goes in it. This is technically accurate and practically confusing, since each side tends to assume the other has it covered. The result resembles buying the finest bricks in the world and constructing a building shaped like an imploding flan. The bricks were excellent. The building was not.
Accidental multi-cloud¶
There is a myth that organisations adopt multi-cloud through strategy, which is rather like claiming Ankh-Morpork’s traffic follows a plan. More usually it happens through a series of individually sensible decisions: email moves to one provider, development prefers another, marketing buys something shiny on a third, an acquisition arrives with a fourth, and a basement server survives because some ancient application will collapse if anyone looks at it funny. Four clouds, one basement, no map. Each provider brings its own arcane terminology, billing, and IAM philosophy, and a security team is expected to absorb all of them through osmosis.
Permission archaeology¶
Identity and access management ought to be simple: one person, one permission, one thing. It rarely is. Permissions accumulate on people like barnacles on a barge, few agree on what is safe to remove, and service accounts spawned for forgotten automation roam the infrastructure with ancient privileges that nobody dares revoke in case they are load-bearing. Somewhere a bucket named temp-project-files sits public because that was convenient at the time, containing test data, logs, credentials and possibly someone’s lunch; deleting it is unthinkable because something might break. And the temporary VPN raised during a long-ago emergency still grants broad access to everything, its promised MFA deployed for some, disabled for others during troubleshooting, and never quite re-enabled. IAM becomes archaeology: layers of sediment, fragments of rituals nobody recalls performing.
The gap between works and secure¶
Cloud platforms are magnificently complicated, teams are stretched, and training is rushed, so many people know enough to deploy a VM, create a bucket and launch an app, while fewer know how to harden any of it. The scanning tools produce alerts in numbers that ought to be illegal, alert fatigue sets in, and the tool stays installed mainly for compliance. Configuration drifts away from the infrastructure code until the code becomes fiction and the infrastructure becomes folklore. None of this is malice, and little of it is stupidity. The environment has simply grown too complex for any one head to hold, which is how misconfiguration thrives. Welcome to the modern cloud. It is not pretty. But it is yours.
The clerk’s brief¶
From the clerks, for the Patrician’s eyes
Compiled July 2026. Entries run newest first; what stops being news sinks into the forecast at the end. The clerks remind his Lordship that none of the incidents below required an attacker of any particular talent.
June 2025: The toxic trilogy, quantified¶
Tenable’s cloud security risk report, published June 2025, finds workloads that are simultaneously publicly exposed, critically vulnerable and highly privileged in 29 per cent of the organisations analysed. 54 per cent of organisations using AWS ECS had at least one task definition with an embedded secret, and 9 per cent of publicly accessible cloud storage contained sensitive data. The clerks note that a workload combining exposure, vulnerability and privilege is not so much a risk as an appointment.
June 2025: A case study in convenience¶
The Cloud Security Alliance published a case study of the 2024 Football Australia breach in June 2025: developers misconfigured storage buckets, and freely available search tools of the Shodan variety did the rest. The question with an unprotected repository is rarely whether someone will look, only when. The clerks file this one under precedents that will be cited again.
May 2025: The exposure census¶
Wiz’s analysis of real-world cloud accounts, published May 2025, found 54 per cent of environments with exposed virtual machines or serverless instances containing sensitive information, and 72 per cent with publicly exposed PaaS databases lacking access controls. In the same month, industry reporting put misconfiguration behind roughly a quarter of cloud security incidents and the large majority of cloud-related breaches. These are not edge cases, and the clerks have stopped calling the problem emerging.
The forecast, unchanged¶
The stratum underneath is dated: the remote-work scramble of March 2020 laid down temporary VPNs, relaxed controls and hasty accounts, and a visible share of that sediment was still in place years later. What changed in 2025 is measurement: the census reports of May and June 2025 put numbers on what had been anecdote, and the numbers describe an epidemic of convenience rather than of attack. The clerks’ standing assessment is that the cloud did not weaken anyone’s security so much as it made everyone’s shortcuts publicly routable, and that the next incident is more likely to arrive through a forgotten bucket than a brilliant adversary. They see little in the file, so far, to revise.