Back to Field Notes
Alexa Research/Field Note

Alexa Research — The Half-Life of a Cloud Misconfiguration

Across 200 monitored environments, the median time-to-discovery for an exposed cloud resource is 49 minutes.

Author

Sofia Reyes

Distinguished Architect, Zero Trust Practice

Published

March 27, 2026

Read

9 min

Share
AI-generated illustration of a shipping terminal facility
AI-generated illustration of a shipping terminal facility
Key Takeaways
  • 01Cloud misconfigurations get found fast. Across 200 environments monitored throughout 2025, median time from publicly exposed cloud resource creation to discovery by external scanners was 49 minutes.
  • 02Discovery curve: first scan typically within 6 minutes, first targeted probe at median 49 minutes, first exploitation attempt for known-vulnerable services at median 4 hours, sustained reconnaissance within 24 hours for any internet-facing exposure.
  • 03Implication for change management: detection windows must close inside the discovery window. Continuous configuration scanning with same-day remediation is the bar; weekly scans miss most exposures by orders of magnitude. Preventive controls (admission policy, IaC scanning that blocks the change) are even better.
  • 04Where week-long exposures still appear: less-monitored regions (orgs operating in 5+ regions but only monitoring 2 well), forgotten dev/test environments, resources created outside the platform team's tooling. Each cluster needs explicit coverage; assuming they 'should not exist' is the wrong starting point.

Cloud misconfigurations get found fast. Across 200 cloud environments monitored by Alexa Research throughout 2025, the median time from a publicly exposed cloud resource being created to it being discovered by external scanners was 49 minutes.

The discovery curve

  • 01First scan: typically within 6 minutes
  • 02First targeted probe: median 49 minutes
  • 03First exploitation attempt for known-vulnerable services: median 4 hours
  • 04Sustained reconnaissance: within 24 hours for any internet-facing exposure

What this means for change management

Detection windows must close inside the discovery window. Continuous configuration scanning with same-day remediation is the bar; weekly scans miss most exposures by orders of magnitude. Preventive controls (admission policy, IaC scanning that blocks the change) are even better than detective.

Where we still see week-long exposures

Less-monitored regions (organizations that operate in 5+ regions but only monitor 2 well), forgotten dev/test environments, and resources created outside the platform team's tooling. Each of these clusters needs explicit coverage; assuming they 'should not exist' is the wrong starting point.

#Alexa Research#Cloud Security#Misconfiguration

/WRITTEN_BY

Sofia Reyes

Distinguished Architect, Zero Trust Practice · Alexa Cybersecurity