Four Things That Matter: Auth, Keys, Permissions, Exposure
82%
of cloud incidents = misconfiguration
95%
of cloud failures = customer's fault (Gartner)
64%
of cloud breaches involve identity misuse
43
avg misconfigs per cloud account
Responding, not preparing? If an attacker is in your cloud right now, go to Cloud Incident Response. This page is how you get ready.
Methodology: Cloud security posture varies wildly across tenants — the same misconfiguration has different risk profiles depending on environment maturity. See Investigation Automation for the context assembly approach.
The cloud security problem is four things. Not 200 CIS benchmark checks. Four things: who can authenticate (Auth), what credentials exist (Keys), what they can do (Permissions), and what's exposed to the internet (Exposure). Fix these four and you've addressed 82% of cloud incidents.
The Four Pillars
Pillar
The Problem
The Fix
1. Auth
Cloud admin accounts protected by SMS MFA or password alone. 40% of orgs fail to enforce MFA across all cloud users.
FIDO2 for all cloud admins. Conditional access with device trust + trusted location. No cloud admin access from personal devices or untrusted networks.
2. Keys
Long-lived API keys and service principal secrets that work from anywhere. Leaked in repos, logs, config files. Service accounts outnumber humans 5:1.
IP-restrict every API key. Use managed identities / IAM roles instead of keys wherever possible. Rotate what remains. Scan for leaked credentials with TruffleHog.
3. Permissions
Overprivileged IAM policies. 50%+ of enterprises have at least one service account with global admin. iam:PassRole and *:* policies everywhere.
Least privilege. No wildcard policies. Separate break-glass from daily accounts. Use IAM Access Analyzer to generate least-privilege policies from actual usage.
4. Exposure
Public S3 buckets (50% potentially misconfigured), open security groups, management ports on 0.0.0.0/0, default VPCs with permissive routing.
Block public access at account level (one toggle). No management ports open to internet. Delete default VPCs. Prowler scan to find everything else.
Entry Point: Cloud Security Posture Assessment
Run Prowler. Scan for leaked credentials. Check what's public. Most companies are shocked by finding #1.
1–2 daysEntry point
Assessment Steps
Run Prowler against all cloud accounts: prowler aws / prowler azure / prowler gcp
30 min to runFree / OSS
Run TruffleHog against all repos and S3 buckets — finds leaked credentials and verifies they're still live
1–2 hoursFree / OSS
Run Monkey365 against M365/Azure tenant — covers SaaS security that Prowler doesn't
1 hourFree / OSS
Enable AWS IAM Access Analyzer (free) — identifies resources shared externally and unused access
Findings organized by the four pillars: Auth gaps, exposed keys, overprivileged IAM, public resources. Each finding rated by exploitability. Prioritized action list.
1 Containment — Close the Obvious Holes
These are the things an attacker would find in the first 5 minutes of reconnaissance. Fix them before they do.
Quick Wins (Day 0, Free)
Enable S3 Block Public Access at account level (AWS) / deny public blob access (Azure) — one toggle, prevents any bucket/container from going public
5 minFree
Enforce MFA on all admin accounts — Azure mandatory MFA Phase 2 already requires this for all Azure service access
1–2 hoursFree
Delete unused IAM access keys — aws iam list-access-keys for each user, delete any not used in 90+ days
1–2 hoursFree
Add IP restrictions to admin IAM policies: "Condition": {"IpAddress": {"aws:SourceIp": ["office CIDR"]}}
1 hourFree
Create Azure Conditional Access policy: require MFA + trusted location for all admin roles
1–2 hoursFree
Disable default VPCs in all unused AWS regions — prevents accidental resource creation in unsecured network config
1 hourFree
Close any security group rules allowing 0.0.0.0/0 on management ports (SSH/22, RDP/3389, database ports)
1 hourFree
Enable AWS IAM Access Analyzer in every region and Azure Defender for Cloud free tier
15 minFree
Rotate and scope down overly broad service account keys — any key with *:* or admin-level permissions
2–4 hoursFree
Core Engagement (1–2 days)
Full credential audit: TruffleHog scan across all repos, buckets, and CI/CD logs. Revoke and rotate any live leaked credentials immediately.
Security group / NSG cleanup: Audit every rule. Remove overly permissive rules. Document what remains with owner + justification.
Storage exposure audit: Verify every S3 bucket, Azure container, and GCS bucket is private. Check bucket policies for unintended public access grants.
Target State
Zero public storage. Zero management ports exposed to internet. Zero leaked live credentials. MFA enforced on all admin access. API keys IP-restricted.
2 Detection — See Misconfigs and Threats in Real Time
Quick Wins (Day 0, Free)
Enable AWS CloudTrail (free for management events, 90 days) — logs every API call
15 minFree
Enable Azure Activity Log alerts for: role assignments, policy changes, resource deletions, security group modifications
Increase log retention — don't rely on defaults. Store 365 days of cloud audit logs. Ship to a separate logging account/subscription that's isolated from production. Disks are cheap; missing logs during an investigation is not.
1 hourLow cost
Enable AWS GuardDuty free trial (30 days) — threat detection for credential abuse, crypto mining, data exfiltration
10 minFree 30-day trial
Core Engagement (2 days)
Schedule weekly Prowler scans — compare results week-over-week to detect new misconfigs
Deploy Steampipe for ad-hoc SQL queries against cloud APIs — SELECT * FROM aws_s3_bucket WHERE block_public_acls = false
Configure CloudTrail alerts for high-risk events: root account usage, IAM policy changes, S3 bucket policy changes, security group modifications, key creation
TruffleHog in CI/CD: Pre-commit hook that blocks pushes containing credentials. GitHub Actions integration for PR scanning.
Central logging architecture: Ship all cloud audit logs to a dedicated logging account/subscription. Immutable retention. Separate credentials. Attackers who compromise production cannot delete the audit trail.
Organization-level trail, not per-account: an AWS organization CloudTrail cannot be disabled from inside a member account (teams can still add their own trails). GCP: org-level log sink. Azure: diagnostic settings deployed by Azure Policy, not by hand.
Pair event alerts with a scheduled inventory query: change-triggered alerts only see what changes after they're switched on. Run a periodic asset-inventory query (AWS Config aggregator, Azure Resource Graph, GCP Cloud Asset export) to catch misconfigurations that were already there.
Target State
Every cloud configuration change logged with 365-day retention. High-risk changes trigger immediate alerts. Weekly posture scans detect drift. Credentials scanned before every code commit. Logs stored in isolated, immutable location.
3 Posture — Harden Each Pillar
Pillar 1: Auth
FIDO2 security keys for all cloud admin accounts — hardware-bound, phishing-resistant, origin-verified
~€50/key, 2 per admin
Conditional Access (Azure) / IAM policy conditions (AWS): admin access only from trusted locations + compliant devices
Free
Federated identity (SSO) — use Entra ID / Okta as IdP for all cloud accounts. Eliminate local cloud users. Single sign-on = single MFA enforcement point.
Architecture work
Separate break-glass accounts with unique credentials stored in a physical safe — not in any password manager or identity system
Pillar 2: Keys
Managed Identities (Azure) / IAM Roles (AWS) — eliminate credentials entirely for workloads running in the cloud. No secrets in code, no rotation burden.
Free
IP-restrict every remaining API key — AWS: aws:SourceIp condition. GCP: Application restrictions. Azure: Conditional Access named locations.
Free
Certificate-based auth for Service Principals (Azure) instead of client secrets — certificates are harder to exfiltrate than strings
90-day key rotation policy for anything that can't use managed identities/roles. Automated via Cloud Custodian or custom script.
TruffleHog in CI/CD — block commits containing any credential pattern. 800+ credential types detected.
Free / OSS
Pillar 3: Permissions
AWS IAM Access Analyzer — generates least-privilege policies from actual CloudTrail usage. Shows exactly what permissions are used vs. granted.
Free
No wildcard policies — audit for "Action": "*" or "Resource": "*". Replace with specific permissions.
AWS SCPs / Azure Policy / GCP Org Policies — organization-level guardrails that prevent any account from creating public resources, disabling logging, or escalating privileges
Close the guardrail bypass paths — org-level controls have known blind spots: the AWS management account, service-linked roles and external principals (SCPs don't apply → add Resource Control Policies); Azure User Access Administrator can grant itself Owner; GCP project IAM admins can edit their own conditions. See Guardrail gaps per provider.
JIT privileged access — Entra PIM (Azure) or AWS IAM Identity Center with temporary role elevation. No standing admin access.
Separate admin accounts from daily-use accounts — cloud admins have a dedicated identity for admin tasks, not their email account
Pillar 4: Exposure
Account-level public access blocks on all storage services (S3, Azure Blob, GCS)
Free
No management ports open to internet — SSH, RDP, database ports only via VPN or bastion host
Delete default VPCs in all regions. Create purpose-built VPCs with private subnets by default.
DNS rebinding protection — internal metadata endpoints (169.254.169.254) blocked from application code via IMDSv2 (AWS) or equivalent
External attack surface monitoring — Shodan ($49 lifetime) or Censys (free tier) for continuous external visibility
Target State
All cloud admin auth is FIDO2 + conditional access. Zero long-lived access keys (replaced by managed identities/roles). Every permission is least-privilege, verified by IAM Access Analyzer. Zero public exposure. Organization-level guardrails prevent any account from weakening posture.
5 Structural — Architecture That Prevents Misconfiguration
Core Engagement (5–8 days)
Organization-level guardrails: AWS SCPs that prevent disabling CloudTrail, creating public S3 buckets, or launching resources in unapproved regions. Azure Policy that denies public blob access org-wide. GCP Org Policies constraining external sharing.
Landing zone architecture: Separate accounts/subscriptions for production, staging, logging, and management. Logging account is immutable and unreachable from production. Management account uses separate identity and hosts nothing else (SCPs don't apply to it).
Security OU built for incident response: a read-only investigation account with read access across the whole estate, a separate break-glass account, and a quarantine OU (Azure: management group, GCP: folder) whose deny policy locks down a suspected-compromised account the moment it's moved in. Containment becomes one pre-tested move, not an improvised policy change mid-incident. Add an Exceptions OU for workloads that can't fit the guardrails yet, so they don't sit unmanaged.
Region lock with a responder exemption: deny unused regions at org level, but exempt the IR roles. A region-lock policy also blocks list/describe/delete, and attackers deliberately launch resources in regions nobody watches.
Second organization / tenant for guardrail changes: test new SCPs, org policies and core networking changes outside production before rollout. Costs ongoing engineering effort to keep both to standard — a staging OU is the cheaper, lower-signal fallback.
Infrastructure-as-Code (IaC) pipeline: All cloud resources defined in Terraform/CloudFormation. Checkov scans IaC before deployment — catches misconfigs before they hit production. No manual console changes. Once every change flows through the pipeline, drop human roles to read-only in production and give write access only to pipeline identities — that's where least privilege becomes real rather than nominal.
Roll out every guardrail audit-first: Azure Policy in Audit before Deny, AWS tag policies in report mode before enforcement, SCPs through the test org. Review accuracy and blast radius, fix what's flagged, then enforce. Note: AWS tag-policy compliance results leave out untagged resources, so the percentage looks better than reality.
Cloud Custodian auto-remediation — last resort, not default: YAML policies that auto-fix non-compliant resources — "find all S3 buckets without encryption and enable encryption." Order of preference: prevent > detect > auto-remediate. Auto-remediation drifts infrastructure away from IaC, can break running systems, and teaches teams nothing — on small dynamic resources it fixes the symptom forever. Reserve it for critical exposure (public buckets). Start in report mode, and before enforcing, look for resources flipping between compliant and non-compliant: that's two automations fighting.
Federated identity with SSO: All human access via corporate IdP. No local cloud users. Single enforcement point for MFA, conditional access, and deprovisioning.
NIS2 compliance package: Cloud security as part of Article 21 risk management measures. Documented controls, audit evidence, incident reporting procedures.
Insurance evidence: Prowler reports, IAM Access Analyzer outputs, key rotation logs, MFA enforcement evidence. Carriers want proof, not promises.
Target State
Misconfiguration is architecturally difficult. Organization-level guardrails prevent unsafe configurations. All resources deployed via IaC with security scanning; humans are read-only in production. Guardrails are prevented first, detected second, auto-remediated only for critical exposure. A suspected-compromised account can be quarantined in one move. Human error cannot create public exposure or disable logging.
Fix This Afternoon (Free)
Enable S3 Block Public Access (account-level) 5 min
Enable Azure "deny public blob access" 5 min
Enforce MFA on all cloud admin accounts 1–2 hrs
Run Prowler baseline scan 30 min
Run TruffleHog on all repos 1–2 hrs
Enable IAM Access Analyzer (AWS) 10 min
Enable Defender for Cloud free tier (Azure) 15 min
Delete unused IAM access keys 1–2 hrs
Add IP conditions to admin IAM policies 1 hr
Close 0.0.0.0/0 on management ports 1 hr
Disable default VPCs in unused regions 1 hr
Enable CloudTrail / Activity Log + increase retention to 365 days 1 hr
Needs Architecture (Weeks)
Migrate to managed identities/IAM roles — eliminate all long-lived access keys 1–2 weeks
Deploy FIDO2 to all cloud admins1–2 weeks
Federated SSO for all cloud access2–4 weeks
JIT privileged access (PIM)1–2 weeks
Organization-level SCPs/Policies1 week
Landing zone with separated accounts2–4 weeks
Security OU: read-only IR account, break-glass, quarantine OU1 week
IaC pipeline with Checkov scanning1 week
Cloud Custodian auto-remediation2–3 weeks
Replace default VPCs with purpose-built2–4 weeks
Program Economics (200-seat reference)
Engagement
Duration
Investment
Assessment (Prowler + TruffleHog + Monkey365)
1–2 days
€1,250 – 2,500
1 Containment
1–2 days
€1,250 – 2,500
2 Detection
2 days
€2,500
3 Posture
3–4 days
€3,750 – 5,000
4 Vuln Mgmt
1 day + cadence
€1,250 + €5,000/yr
5 Structural
5–8 days
€6,250 – 10,000
Full program
13–19 days
€16,250 – 23,750 + retainer
ROI: Average cloud misconfiguration breach: $3.86M. Multi-cloud breach: $5.05M. The assessment alone ($49 Shodan + free Prowler + free TruffleHog) costs less than one hour of incident response. The full program costs less than 1% of a single cloud breach.
SCPs don't apply to the management account, service-linked roles, or principals from outside the org (e.g. a cross-account user reading your S3). Close the last one with Resource Control Policies (2024). Effective access = SCP ∩ permission boundary ∩ identity policy.
User Access Administrator can grant itself Owner by default — block with a custom Azure Policy on the same scope. Managed identities are an escalation path (edit the function code, inherit its identity). Enforce team boundaries at resource-group level; subscriptions are often shared.
projectIamAdmin lets a user edit their own IAM condition — delegate via group membership instead. Service account impersonation = full privilege; restrict setIamPolicy on service accounts. Enforce iam.disableServiceAccountKeyCreation / ...KeyUpload. Region lock only governs creation, not running or global resources.
Provider Guide: Mid-Market US
Honest assessment of security capabilities. These providers trade enterprise IAM depth for simplicity and price. Know the gaps.
Feature
DigitalOcean
Linode (Akamai)
Vultr
MFA
TOTP only
TOTP + SMS
TOTP + YubiKey
FIDO2/Passkeys
No
SSH only (not console)
YubiKey only (partial)
SSO/Federation
OIDC (Okta, Auth0, JumpCloud)
Enterprise Akamai accounts only
No
Conditional Access
No
No
No
IP Restrict on API Keys
No
No
Yes
Managed Identity
No
No
No
Granular IAM
Custom roles (beta)
New RBAC (2025-2026)
ACL-based (next-gen in progress)
Audit Trail
Basic
Limited
Limited
Storage Private Default
Yes
Configurable
Yes
Cloud Firewall
Yes
Yes
Yes
VPC
Yes
Yes
Yes (VPC 2.0)
Key gap: None of the US mid-market 3 have conditional access, managed identities, or automated least-privilege tooling. Vultr is the only one with IP restrictions on API keys. DigitalOcean has the best SSO story (OIDC). Compensate with application-layer auth, short-lived tokens, and network segmentation.
Provider Guide: Mid-Market EU
EU data sovereignty + NIS2 compliance. Security maturity varies significantly.
Feature
Hetzner
OVHcloud
Scaleway
MFA
TOTP + YubiKey (U2F)
TOTP + SMS + U2F
TOTP + Passkeys (FIDO2)
FIDO2/Passkeys
U2F only (predecessor)
U2F only
Full WebAuthn
SSO/Federation
No
SAML 2.0 + OIDC
No
Conditional Access
No
No
No
IP Restrict on API Keys
No
Partial
No
Managed Identity
No
OAuth2 service accounts
IAM Applications
Granular IAM
No (project-level only)
Policy-based (permission groups)
Full IAM (policies, groups, project scope)
Audit Trail
No
Limited (can't trace to API key)
Full (IP, principal, method, status)
Storage Private Default
Yes
ACL-dependent
Yes
Cloud Firewall
Yes
Varies by product
Yes
VPC/Private Network
Yes
vRack (cross-DC)
Yes
Scaleway is the clear leader among EU mid-market providers: real FIDO2 passkeys, full IAM with policies, complete audit trail with IP/principal tracking, and IAM Applications for non-human identities. Hetzner has the most significant gaps (no IAM, no audit, no SSO) but compensates with unbeatable price/performance. OVHcloud has the best SSO story (SAML/OIDC) and vRack for cross-DC networking.
Google Workspace Hardening
About half of mid-market runs Google Workspace. Unlike M365, there's no one-click "Security Defaults" — hardening is manual, setting-by-setting. Use CISA ScubaGoggles (free) to audit.
Tier Comparison: What Security You Get
Feature
Business Starter ($7)
Business Plus ($18)
Enterprise Std
Enterprise Plus
2SV / Security Keys
Allowed
Enforced
Enforced
Enforced
Context-Aware Access
No
Basic (IP/device)
Full (CEL rules)
Full
DLP
No
No
Drive/Chat/Chrome
+ Gmail
Security Investigation
No
No
Yes
Yes
Security Sandbox (Gmail)
No
No
No
Yes
Client-Side Encryption
No
No
No
Yes
Multi-Party Approval
No
No
No
Yes
Top 10 Settings Most Admins Don't Enable
OAuth app blocking not enforced — Users can consent to any third-party app. Set "Unconfigured third-party apps" to "Don't allow users to access." (Security > API controls)
#1 Miss
Security keys not enforced — Most allow SMS/TOTP. CISA says "Only security key." Set 2SV methods to security keys only.
Context-aware access not configured — Even on Enterprise, most admins never create access levels.
Session duration at 14 days — CISA says 12 hours max. (Security > Google session control)
Drive sharing left open — Default "Anyone with the link." Restrict to allowlisted domains. Disable "Anyone with the link" sharing entirely.
Groups publicly accessible — External access not set to Private. Group creation not restricted to admins.
Gmail protections at defaults — Attachment/link/spoofing protections exist but "move to quarantine" action rarely configured.
Advanced Protection Program not enabled — Not even for super admins. Most orgs don't know it exists.
Google Takeout not disabled — Compromised account can export all data as a zip. Disable it.
Alert Center rules not enabled — System-defined security alerts are off by default.
Google vs M365 key differences: Google has better native phishing detection (Gmail AI) and passkey support, but M365 has deeper DLP, more granular conditional access (M365 = most restrictive wins, GWS = any match grants), and a much larger security tooling ecosystem. Google has no equivalent to M365's one-click Security Defaults or Attack Simulation Training. Business Plus ($18) is minimum viable; Enterprise is needed for serious security.
CASB for Mid-Market: Affordable Options
Enterprise CASBs (Netskope, Zscaler) are $15-25/user/month. Here's what mid-market can actually afford. Key finding: most M365 shops already have partial CASB and don't know it.
What's Already in Your M365 License
License
CASB Capability
What's Missing
Business Premium ($22/user)
Basic Cloud App Discovery (shadow IT via log upload)
Full CASB: session controls, DLP, OAuth governance, real-time monitoring
Shadow IT, OAuth, basic DLP. Full platform: €9.50–18 (CASB+EDR+email+SASE)
Mid-market all-in-one
Cloudflare Zero Trust
€7 (base)
SWG included. CASB/DLP only on contract plan.
Already on Cloudflare
Wing Security
~€125/month flat
SaaS discovery + OAuth governance. No DLP, no session control.
SaaS-heavy, budget-constrained
Bottom line: The cheapest real CASB for M365 shops is the standalone Defender for Cloud Apps at ~€3.50–5/user/month. Most mid-market doesn't know this exists outside of E5. For 200 users that's €700–1,000/month. There is no viable open-source CASB — the closest free option is Wing Security's SaaS Pulse for discovery only.