Nearly all organizations surveyed—97%—suffered a confirmed breach or close call tied to security tool misconfigurations in the past year, according to a new report from Reach Security. The findings highlight configuration drift as a continuing cybersecurity threat that leaves security controls vulnerable even as teams conduct frequent reviews. Configuration drift happens when the actual settings of a computer system or cloud environment gradually shift away from their original planned state due to untracked modifications over time.

The report surveyed 250 U.S. cybersecurity professionals over a 12-month period to assess the impact of security control misconfigurations and configuration drift. Organizations take an average of 8.3 days to fix identified problems, even though they review security tool configurations an average of 6.5 times monthly. Firewalls were flagged as the most frequent source of drift-related data breaches, with 42% reporting a breach or near miss stemming from a firewall. Endpoints ranked second at 40%. In Reach's own telemetry analysis of more than 50 production environments, firewalls accounted for 47% of all alerts and nearly 88% of material security findings, while Endpoint Detection and Response systems generated 23% of alerts and 10% of material findings.

"Configuration drift is no longer just an operational issue; it is a growing security risk," said Garrett Hamilton, co-founder and CEO of Reach Security. The report also found that drift frequently spikes during predictable operational "danger zones," including vendor updates, patch cycles, holidays, end-of-week periods, and month-end activities. According to Hamilton, security teams need to move beyond reactive processes and adopt continuous assurance, with threat-informed prioritization essential because not every configuration change carries the same level of risk.

The report explains that configuration drift can be caused by manual changes, inconsistent automation, software updates, and external integrations. These instances allow security controls to deviate from their intended state, creating hidden exposures that enable new opportunities for attackers. Drift increases the risk of outages, security vulnerabilities, compliance failures, and unexpected costs. The research exposes a widening gap between how quickly attackers can exploit weaknesses and how long it takes organizations to identify and fix them, according to the report.

To address configuration drift, Reach recommends adopting continuous security assurance across the entire technology stack to move beyond reactive, point-in-time assessments. Organizations should prioritize remediation based on real-world exposure and attacker relevance rather than the volume of configuration changes, and reduce time between drift detection and remediation with clear, actionable, and risk-prioritized guidance. The report emphasizes focusing assurance efforts on high-risk areas such as firewalls and other network security controls, and strengthening monitoring during high-risk operational periods like patch cycles, major updates, and organizational change windows. By continuously validating control effectiveness and focusing on the exposures that matter most, organizations can reduce risk, respond faster, and ensure their security investments deliver the protection they were designed to provide. For channel partners and managed service providers, configuration drift represents both a critical client vulnerability and an opportunity to differentiate through proactive monitoring and remediation services that traditional break-fix models can't address. The gap between detection frequency and remediation speed suggests that many organizations lack the internal capacity or expertise to manage this operational challenge effectively.