
- 01Cloud misconfigurations get found fast. Across 200 environments monitored throughout 2025, median time from publicly exposed cloud resource creation to discovery by external scanners was 49 minutes.
- 02Discovery curve: first scan typically within 6 minutes, first targeted probe at median 49 minutes, first exploitation attempt for known-vulnerable services at median 4 hours, sustained reconnaissance within 24 hours for any internet-facing exposure.
- 03Implication for change management: detection windows must close inside the discovery window. Continuous configuration scanning with same-day remediation is the bar; weekly scans miss most exposures by orders of magnitude. Preventive controls (admission policy, IaC scanning that blocks the change) are even better.
- 04Where week-long exposures still appear: less-monitored regions (orgs operating in 5+ regions but only monitoring 2 well), forgotten dev/test environments, resources created outside the platform team's tooling. Each cluster needs explicit coverage; assuming they 'should not exist' is the wrong starting point.
Cloud misconfigurations get found fast. Across 200 cloud environments monitored by Alexa Research throughout 2025, the median time from a publicly exposed cloud resource being created to it being discovered by external scanners was 49 minutes.
The discovery curve
- 01First scan: typically within 6 minutes
- 02First targeted probe: median 49 minutes
- 03First exploitation attempt for known-vulnerable services: median 4 hours
- 04Sustained reconnaissance: within 24 hours for any internet-facing exposure
What this means for change management
Detection windows must close inside the discovery window. Continuous configuration scanning with same-day remediation is the bar; weekly scans miss most exposures by orders of magnitude. Preventive controls (admission policy, IaC scanning that blocks the change) are even better than detective.
Where we still see week-long exposures
Less-monitored regions (organizations that operate in 5+ regions but only monitor 2 well), forgotten dev/test environments, and resources created outside the platform team's tooling. Each of these clusters needs explicit coverage; assuming they 'should not exist' is the wrong starting point.


