Cloud Security Package

Four Things That Matter: Auth, Keys, Permissions, Exposure

82%
of cloud incidents = misconfiguration
95%
of cloud failures = customer's fault (Gartner)
64%
of cloud breaches involve identity misuse
43
avg misconfigs per cloud account
Responding, not preparing? If an attacker is in your cloud right now, go to Cloud Incident Response. This page is how you get ready.
Methodology: Cloud security posture varies wildly across tenants — the same misconfiguration has different risk profiles depending on environment maturity. See Investigation Automation for the context assembly approach.
The cloud security problem is four things. Not 200 CIS benchmark checks. Four things: who can authenticate (Auth), what credentials exist (Keys), what they can do (Permissions), and what's exposed to the internet (Exposure). Fix these four and you've addressed 82% of cloud incidents.

The Four Pillars

PillarThe ProblemThe Fix
1. AuthCloud admin accounts protected by SMS MFA or password alone. 40% of orgs fail to enforce MFA across all cloud users.FIDO2 for all cloud admins. Conditional access with device trust + trusted location. No cloud admin access from personal devices or untrusted networks.
2. KeysLong-lived API keys and service principal secrets that work from anywhere. Leaked in repos, logs, config files. Service accounts outnumber humans 5:1.IP-restrict every API key. Use managed identities / IAM roles instead of keys wherever possible. Rotate what remains. Scan for leaked credentials with TruffleHog.
3. PermissionsOverprivileged IAM policies. 50%+ of enterprises have at least one service account with global admin. iam:PassRole and *:* policies everywhere.Least privilege. No wildcard policies. Separate break-glass from daily accounts. Use IAM Access Analyzer to generate least-privilege policies from actual usage.
4. ExposurePublic S3 buckets (50% potentially misconfigured), open security groups, management ports on 0.0.0.0/0, default VPCs with permissive routing.Block public access at account level (one toggle). No management ports open to internet. Delete default VPCs. Prowler scan to find everything else.

Entry Point: Cloud Security Posture Assessment

Run Prowler. Scan for leaked credentials. Check what's public. Most companies are shocked by finding #1.
1–2 days Entry point

Assessment Steps

  • Run Prowler against all cloud accounts: prowler aws / prowler azure / prowler gcp
    30 min to runFree / OSS
  • Run TruffleHog against all repos and S3 buckets — finds leaked credentials and verifies they're still live
    1–2 hoursFree / OSS
  • Run Monkey365 against M365/Azure tenant — covers SaaS security that Prowler doesn't
    1 hourFree / OSS
  • Enable AWS IAM Access Analyzer (free) — identifies resources shared externally and unused access
  • Check Azure Defender for Cloud Secure Score (free tier) — baseline cloud posture rating

Output

Findings organized by the four pillars: Auth gaps, exposed keys, overprivileged IAM, public resources. Each finding rated by exploitability. Prioritized action list.

1 Containment — Close the Obvious Holes
These are the things an attacker would find in the first 5 minutes of reconnaissance. Fix them before they do.
Quick Wins (Day 0, Free)
  • Enable S3 Block Public Access at account level (AWS) / deny public blob access (Azure) — one toggle, prevents any bucket/container from going public
    5 minFree
  • Enforce MFA on all admin accounts — Azure mandatory MFA Phase 2 already requires this for all Azure service access
    1–2 hoursFree
  • Delete unused IAM access keys — aws iam list-access-keys for each user, delete any not used in 90+ days
    1–2 hoursFree
  • Add IP restrictions to admin IAM policies: "Condition": {"IpAddress": {"aws:SourceIp": ["office CIDR"]}}
    1 hourFree
  • Create Azure Conditional Access policy: require MFA + trusted location for all admin roles
    1–2 hoursFree
  • Disable default VPCs in all unused AWS regions — prevents accidental resource creation in unsecured network config
    1 hourFree
  • Close any security group rules allowing 0.0.0.0/0 on management ports (SSH/22, RDP/3389, database ports)
    1 hourFree
  • Enable AWS IAM Access Analyzer in every region and Azure Defender for Cloud free tier
    15 minFree
  • Rotate and scope down overly broad service account keys — any key with *:* or admin-level permissions
    2–4 hoursFree
Core Engagement (1–2 days)
  • Full credential audit: TruffleHog scan across all repos, buckets, and CI/CD logs. Revoke and rotate any live leaked credentials immediately.
  • Security group / NSG cleanup: Audit every rule. Remove overly permissive rules. Document what remains with owner + justification.
  • Storage exposure audit: Verify every S3 bucket, Azure container, and GCS bucket is private. Check bucket policies for unintended public access grants.
Target State

Zero public storage. Zero management ports exposed to internet. Zero leaked live credentials. MFA enforced on all admin access. API keys IP-restricted.

2 Detection — See Misconfigs and Threats in Real Time
Quick Wins (Day 0, Free)
  • Enable AWS CloudTrail (free for management events, 90 days) — logs every API call
    15 minFree
  • Enable Azure Activity Log alerts for: role assignments, policy changes, resource deletions, security group modifications
    30 minFree
  • Enable GCP Cloud Audit Logs + Security Command Center (Standard tier, free)
    15 minFree
  • Increase log retention — don't rely on defaults. Store 365 days of cloud audit logs. Ship to a separate logging account/subscription that's isolated from production. Disks are cheap; missing logs during an investigation is not.
    1 hourLow cost
  • Enable AWS GuardDuty free trial (30 days) — threat detection for credential abuse, crypto mining, data exfiltration
    10 minFree 30-day trial
Core Engagement (2 days)
  • Schedule weekly Prowler scans — compare results week-over-week to detect new misconfigs
  • Deploy Steampipe for ad-hoc SQL queries against cloud APIs — SELECT * FROM aws_s3_bucket WHERE block_public_acls = false
  • Configure CloudTrail alerts for high-risk events: root account usage, IAM policy changes, S3 bucket policy changes, security group modifications, key creation
  • TruffleHog in CI/CD: Pre-commit hook that blocks pushes containing credentials. GitHub Actions integration for PR scanning.
  • Central logging architecture: Ship all cloud audit logs to a dedicated logging account/subscription. Immutable retention. Separate credentials. Attackers who compromise production cannot delete the audit trail.
  • Organization-level trail, not per-account: an AWS organization CloudTrail cannot be disabled from inside a member account (teams can still add their own trails). GCP: org-level log sink. Azure: diagnostic settings deployed by Azure Policy, not by hand.
  • Pair event alerts with a scheduled inventory query: change-triggered alerts only see what changes after they're switched on. Run a periodic asset-inventory query (AWS Config aggregator, Azure Resource Graph, GCP Cloud Asset export) to catch misconfigurations that were already there.
Target State

Every cloud configuration change logged with 365-day retention. High-risk changes trigger immediate alerts. Weekly posture scans detect drift. Credentials scanned before every code commit. Logs stored in isolated, immutable location.

3 Posture — Harden Each Pillar

Pillar 1: Auth

  • FIDO2 security keys for all cloud admin accounts — hardware-bound, phishing-resistant, origin-verified
    ~€50/key, 2 per admin
  • Conditional Access (Azure) / IAM policy conditions (AWS): admin access only from trusted locations + compliant devices
    Free
  • Federated identity (SSO) — use Entra ID / Okta as IdP for all cloud accounts. Eliminate local cloud users. Single sign-on = single MFA enforcement point.
    Architecture work
  • Separate break-glass accounts with unique credentials stored in a physical safe — not in any password manager or identity system

Pillar 2: Keys

  • Managed Identities (Azure) / IAM Roles (AWS) — eliminate credentials entirely for workloads running in the cloud. No secrets in code, no rotation burden.
    Free
  • IP-restrict every remaining API key — AWS: aws:SourceIp condition. GCP: Application restrictions. Azure: Conditional Access named locations.
    Free
  • Certificate-based auth for Service Principals (Azure) instead of client secrets — certificates are harder to exfiltrate than strings
  • 90-day key rotation policy for anything that can't use managed identities/roles. Automated via Cloud Custodian or custom script.
  • TruffleHog in CI/CD — block commits containing any credential pattern. 800+ credential types detected.
    Free / OSS

Pillar 3: Permissions

  • AWS IAM Access Analyzer — generates least-privilege policies from actual CloudTrail usage. Shows exactly what permissions are used vs. granted.
    Free
  • No wildcard policies — audit for "Action": "*" or "Resource": "*". Replace with specific permissions.
  • AWS SCPs / Azure Policy / GCP Org Policies — organization-level guardrails that prevent any account from creating public resources, disabling logging, or escalating privileges
  • Close the guardrail bypass paths — org-level controls have known blind spots: the AWS management account, service-linked roles and external principals (SCPs don't apply → add Resource Control Policies); Azure User Access Administrator can grant itself Owner; GCP project IAM admins can edit their own conditions. See Guardrail gaps per provider.
  • JIT privileged access — Entra PIM (Azure) or AWS IAM Identity Center with temporary role elevation. No standing admin access.
  • Separate admin accounts from daily-use accounts — cloud admins have a dedicated identity for admin tasks, not their email account

Pillar 4: Exposure

  • Account-level public access blocks on all storage services (S3, Azure Blob, GCS)
    Free
  • No management ports open to internet — SSH, RDP, database ports only via VPN or bastion host
  • Delete default VPCs in all regions. Create purpose-built VPCs with private subnets by default.
  • DNS rebinding protection — internal metadata endpoints (169.254.169.254) blocked from application code via IMDSv2 (AWS) or equivalent
  • External attack surface monitoring — Shodan ($49 lifetime) or Censys (free tier) for continuous external visibility
Target State

All cloud admin auth is FIDO2 + conditional access. Zero long-lived access keys (replaced by managed identities/roles). Every permission is least-privilege, verified by IAM Access Analyzer. Zero public exposure. Organization-level guardrails prevent any account from weakening posture.

4 Vulnerability Management — Continuous Cloud Hygiene
CadenceActionTool
ContinuousCredential leak detection in CI/CDTruffleHog pre-commit
ContinuousCloud audit log monitoringCloudTrail / Activity Log alerts
WeeklyCloud posture scanProwler (scheduled)
WeeklyIAM access analysisIAM Access Analyzer
MonthlyService account key rotation checkCustom script / Cloud Custodian
MonthlySecurity group / NSG auditProwler + manual review
QuarterlyFull Prowler + TruffleHog + Monkey365 auditCombined report
QuarterlyIAM permission review — remove unused accessIAM Access Analyzer
AnnuallyFull CIS benchmark assessmentProwler CIS compliance mode
5 Structural — Architecture That Prevents Misconfiguration
Core Engagement (5–8 days)
  • Organization-level guardrails: AWS SCPs that prevent disabling CloudTrail, creating public S3 buckets, or launching resources in unapproved regions. Azure Policy that denies public blob access org-wide. GCP Org Policies constraining external sharing.
  • Landing zone architecture: Separate accounts/subscriptions for production, staging, logging, and management. Logging account is immutable and unreachable from production. Management account uses separate identity and hosts nothing else (SCPs don't apply to it).
  • Security OU built for incident response: a read-only investigation account with read access across the whole estate, a separate break-glass account, and a quarantine OU (Azure: management group, GCP: folder) whose deny policy locks down a suspected-compromised account the moment it's moved in. Containment becomes one pre-tested move, not an improvised policy change mid-incident. Add an Exceptions OU for workloads that can't fit the guardrails yet, so they don't sit unmanaged.
  • Region lock with a responder exemption: deny unused regions at org level, but exempt the IR roles. A region-lock policy also blocks list/describe/delete, and attackers deliberately launch resources in regions nobody watches.
  • Second organization / tenant for guardrail changes: test new SCPs, org policies and core networking changes outside production before rollout. Costs ongoing engineering effort to keep both to standard — a staging OU is the cheaper, lower-signal fallback.
  • Infrastructure-as-Code (IaC) pipeline: All cloud resources defined in Terraform/CloudFormation. Checkov scans IaC before deployment — catches misconfigs before they hit production. No manual console changes. Once every change flows through the pipeline, drop human roles to read-only in production and give write access only to pipeline identities — that's where least privilege becomes real rather than nominal.
  • Roll out every guardrail audit-first: Azure Policy in Audit before Deny, AWS tag policies in report mode before enforcement, SCPs through the test org. Review accuracy and blast radius, fix what's flagged, then enforce. Note: AWS tag-policy compliance results leave out untagged resources, so the percentage looks better than reality.
  • Cloud Custodian auto-remediation — last resort, not default: YAML policies that auto-fix non-compliant resources — "find all S3 buckets without encryption and enable encryption." Order of preference: prevent > detect > auto-remediate. Auto-remediation drifts infrastructure away from IaC, can break running systems, and teaches teams nothing — on small dynamic resources it fixes the symptom forever. Reserve it for critical exposure (public buckets). Start in report mode, and before enforcing, look for resources flipping between compliant and non-compliant: that's two automations fighting.
  • Federated identity with SSO: All human access via corporate IdP. No local cloud users. Single enforcement point for MFA, conditional access, and deprovisioning.
  • NIS2 compliance package: Cloud security as part of Article 21 risk management measures. Documented controls, audit evidence, incident reporting procedures.
  • Insurance evidence: Prowler reports, IAM Access Analyzer outputs, key rotation logs, MFA enforcement evidence. Carriers want proof, not promises.
Target State

Misconfiguration is architecturally difficult. Organization-level guardrails prevent unsafe configurations. All resources deployed via IaC with security scanning; humans are read-only in production. Guardrails are prevented first, detected second, auto-remediated only for critical exposure. A suspected-compromised account can be quarantined in one move. Human error cannot create public exposure or disable logging.

Fix This Afternoon (Free)

  • Enable S3 Block Public Access (account-level) 5 min
  • Enable Azure "deny public blob access" 5 min
  • Enforce MFA on all cloud admin accounts 1–2 hrs
  • Run Prowler baseline scan 30 min
  • Run TruffleHog on all repos 1–2 hrs
  • Enable IAM Access Analyzer (AWS) 10 min
  • Enable Defender for Cloud free tier (Azure) 15 min
  • Delete unused IAM access keys 1–2 hrs
  • Add IP conditions to admin IAM policies 1 hr
  • Close 0.0.0.0/0 on management ports 1 hr
  • Disable default VPCs in unused regions 1 hr
  • Enable CloudTrail / Activity Log + increase retention to 365 days 1 hr

Needs Architecture (Weeks)

  • Migrate to managed identities/IAM roles — eliminate all long-lived access keys 1–2 weeks
  • Deploy FIDO2 to all cloud admins 1–2 weeks
  • Federated SSO for all cloud access 2–4 weeks
  • JIT privileged access (PIM) 1–2 weeks
  • Organization-level SCPs/Policies 1 week
  • Landing zone with separated accounts 2–4 weeks
  • Security OU: read-only IR account, break-glass, quarantine OU 1 week
  • IaC pipeline with Checkov scanning 1 week
  • Cloud Custodian auto-remediation 2–3 weeks
  • Replace default VPCs with purpose-built 2–4 weeks

Program Economics (200-seat reference)

EngagementDurationInvestment
Assessment (Prowler + TruffleHog + Monkey365)1–2 days€1,250 – 2,500
1 Containment1–2 days€1,250 – 2,500
2 Detection2 days€2,500
3 Posture3–4 days€3,750 – 5,000
4 Vuln Mgmt1 day + cadence€1,250 + €5,000/yr
5 Structural5–8 days€6,250 – 10,000
Full program13–19 days€16,250 – 23,750 + retainer
ROI: Average cloud misconfiguration breach: $3.86M. Multi-cloud breach: $5.05M. The assessment alone ($49 Shodan + free Prowler + free TruffleHog) costs less than one hour of incident response. The full program costs less than 1% of a single cloud breach.

Free / Open-Source Tools

Built-in Free Provider Tools

ToolProviderWhat It Does
IAM Access AnalyzerAWSLeast-privilege policy generation
S3 Block Public AccessAWSAccount-level public prevention
CloudTrailAWSAPI audit logging (free for mgmt events)
Security HubAWSFinding aggregation (free tier)
Defender for CloudAzureCSPM + Secure Score (free tier)
Azure PolicyAzure100+ built-in security policies
Activity LogAzure90-day control plane audit
Security Command CenterGCPVuln scanning + asset inventory (Standard free)
Org Policy ConstraintsGCPOrg-wide guardrails

Provider Guide: Big 3

How the four pillars map to each major cloud provider's specific tools and features.
PillarAWSAzureGCP
Auth IAM Identity Center (SSO), FIDO2 passkeys (up to 8/user), STS for temp creds. MFA enforced on root. Entra ID + Conditional Access (location, device, risk). FIDO2 native. Mandatory MFA Phase 2 (Oct 2025) covers CLI/PowerShell/IaC. Cloud Identity, BeyondCorp Enterprise, Access Context Manager (device+IP+geo+CEL rules). Advanced Protection Program mandates FIDO2.
Keys IAM Roles on EC2/Lambda/ECS (no long-lived keys). Secrets Manager auto-rotation. aws:SourceIp policy conditions. Managed Identities (system+user assigned) = gold standard. Key Vault (HSM-backed). Certificate auth for Service Principals over secrets. Workload Identity (GKE), Workload Identity Federation (external). Service account keys discouraged. API key IP+API restrictions. Secret Manager auto-rotation.
Permissions IAM policies + SCPs (org guardrails) + permission boundaries. IAM Access Analyzer generates least-privilege from CloudTrail. Free. Azure RBAC (300+ built-in roles) + Entra PIM (JIT elevation). Defender for Cloud permission creep index. Resource hierarchy (Org>Folder>Project). IAM Recommender suggests removing unused perms. 1000+ predefined roles. Deny policies available.
Exposure S3 Block Public Access (account-level, one toggle). Security Groups + NACLs + Network Firewall. VPC + PrivateLink. New buckets private by default. Deny public blob access (storage account toggle). NSGs + Azure Firewall + WAF. VNets + Private Endpoints. Encryption at rest by default. Org Policy: storage.publicAccessPrevention (org-wide). VPC Service Controls (API perimeter). Cloud Armor (WAF/DDoS). Domain-restricted sharing.
Guardrail gaps SCPs don't apply to the management account, service-linked roles, or principals from outside the org (e.g. a cross-account user reading your S3). Close the last one with Resource Control Policies (2024). Effective access = SCP ∩ permission boundary ∩ identity policy. User Access Administrator can grant itself Owner by default — block with a custom Azure Policy on the same scope. Managed identities are an escalation path (edit the function code, inherit its identity). Enforce team boundaries at resource-group level; subscriptions are often shared. projectIamAdmin lets a user edit their own IAM condition — delegate via group membership instead. Service account impersonation = full privilege; restrict setIamPolicy on service accounts. Enforce iam.disableServiceAccountKeyCreation / ...KeyUpload. Region lock only governs creation, not running or global resources.

Provider Guide: Mid-Market US

Honest assessment of security capabilities. These providers trade enterprise IAM depth for simplicity and price. Know the gaps.
FeatureDigitalOceanLinode (Akamai)Vultr
MFATOTP onlyTOTP + SMSTOTP + YubiKey
FIDO2/PasskeysNoSSH only (not console)YubiKey only (partial)
SSO/FederationOIDC (Okta, Auth0, JumpCloud)Enterprise Akamai accounts onlyNo
Conditional AccessNoNoNo
IP Restrict on API KeysNoNoYes
Managed IdentityNoNoNo
Granular IAMCustom roles (beta)New RBAC (2025-2026)ACL-based (next-gen in progress)
Audit TrailBasicLimitedLimited
Storage Private DefaultYesConfigurableYes
Cloud FirewallYesYesYes
VPCYesYesYes (VPC 2.0)
Key gap: None of the US mid-market 3 have conditional access, managed identities, or automated least-privilege tooling. Vultr is the only one with IP restrictions on API keys. DigitalOcean has the best SSO story (OIDC). Compensate with application-layer auth, short-lived tokens, and network segmentation.

Provider Guide: Mid-Market EU

EU data sovereignty + NIS2 compliance. Security maturity varies significantly.
FeatureHetznerOVHcloudScaleway
MFATOTP + YubiKey (U2F)TOTP + SMS + U2FTOTP + Passkeys (FIDO2)
FIDO2/PasskeysU2F only (predecessor)U2F onlyFull WebAuthn
SSO/FederationNoSAML 2.0 + OIDCNo
Conditional AccessNoNoNo
IP Restrict on API KeysNoPartialNo
Managed IdentityNoOAuth2 service accountsIAM Applications
Granular IAMNo (project-level only)Policy-based (permission groups)Full IAM (policies, groups, project scope)
Audit TrailNoLimited (can't trace to API key)Full (IP, principal, method, status)
Storage Private DefaultYesACL-dependentYes
Cloud FirewallYesVaries by productYes
VPC/Private NetworkYesvRack (cross-DC)Yes
Scaleway is the clear leader among EU mid-market providers: real FIDO2 passkeys, full IAM with policies, complete audit trail with IP/principal tracking, and IAM Applications for non-human identities. Hetzner has the most significant gaps (no IAM, no audit, no SSO) but compensates with unbeatable price/performance. OVHcloud has the best SSO story (SAML/OIDC) and vRack for cross-DC networking.

Google Workspace Hardening

About half of mid-market runs Google Workspace. Unlike M365, there's no one-click "Security Defaults" — hardening is manual, setting-by-setting. Use CISA ScubaGoggles (free) to audit.

Tier Comparison: What Security You Get

FeatureBusiness Starter ($7)Business Plus ($18)Enterprise StdEnterprise Plus
2SV / Security KeysAllowedEnforcedEnforcedEnforced
Context-Aware AccessNoBasic (IP/device)Full (CEL rules)Full
DLPNoNoDrive/Chat/Chrome+ Gmail
Security InvestigationNoNoYesYes
Security Sandbox (Gmail)NoNoNoYes
Client-Side EncryptionNoNoNoYes
Multi-Party ApprovalNoNoNoYes

Top 10 Settings Most Admins Don't Enable

  • OAuth app blocking not enforced — Users can consent to any third-party app. Set "Unconfigured third-party apps" to "Don't allow users to access." (Security > API controls)
    #1 Miss
  • Security keys not enforced — Most allow SMS/TOTP. CISA says "Only security key." Set 2SV methods to security keys only.
  • Context-aware access not configured — Even on Enterprise, most admins never create access levels.
  • Session duration at 14 days — CISA says 12 hours max. (Security > Google session control)
  • Drive sharing left open — Default "Anyone with the link." Restrict to allowlisted domains. Disable "Anyone with the link" sharing entirely.
  • Groups publicly accessible — External access not set to Private. Group creation not restricted to admins.
  • Gmail protections at defaults — Attachment/link/spoofing protections exist but "move to quarantine" action rarely configured.
  • Advanced Protection Program not enabled — Not even for super admins. Most orgs don't know it exists.
  • Google Takeout not disabled — Compromised account can export all data as a zip. Disable it.
  • Alert Center rules not enabled — System-defined security alerts are off by default.

Quick-Start Hardening (Priority Order)

  • Enforce MFA — security keys/passkeys only, disable SMS
    1 hourFree
  • Lock down OAuth — block unconfigured apps, block user consent, allowlist only vetted apps
    1 hourFree
  • Restrict Drive sharing — allowlisted domains only, disable "Anyone with the link", default to private
    30 minFree
  • Lock Groups — external access = Private, creation = admins only
    15 minFree
  • Enable all Gmail protections — attachment, link, and spoofing scanning + pre-delivery scanning
    30 minFree
  • Configure SPF + DKIM + DMARC (p=reject) for all domains
    2–4 hoursFree
  • Reduce session duration to 12 hours
    5 minFree
  • Disable Google Takeout
    5 minFree
  • Enroll super admins in Advanced Protection Program
    30 minFree
  • Run ScubaGoggles to find everything you missed
    1 hourFree / OSS
Google vs M365 key differences: Google has better native phishing detection (Gmail AI) and passkey support, but M365 has deeper DLP, more granular conditional access (M365 = most restrictive wins, GWS = any match grants), and a much larger security tooling ecosystem. Google has no equivalent to M365's one-click Security Defaults or Attack Simulation Training. Business Plus ($18) is minimum viable; Enterprise is needed for serious security.

CASB for Mid-Market: Affordable Options

Enterprise CASBs (Netskope, Zscaler) are $15-25/user/month. Here's what mid-market can actually afford. Key finding: most M365 shops already have partial CASB and don't know it.

What's Already in Your M365 License

LicenseCASB CapabilityWhat's Missing
Business Premium ($22/user)Basic Cloud App Discovery (shadow IT via log upload)Full CASB: session controls, DLP, OAuth governance, real-time monitoring
E3 ($36/user)Same as Business PremiumSame
E5 ($57/user)Full Defender for Cloud Apps — complete CASBNothing — this is the full product

Standalone / Add-On Options

ProductPrice/User/MonthKey FeaturesBest For
MS Defender for Cloud Apps (standalone)~€3.50–5Full CASB: shadow IT, DLP, OAuth governance, session control, anomaly detectionM365 shops wanting just CASB
M365 E5 Security Add-on~€12 (bundle)CASB + identity protection + endpoint P2 + email P2Best value if you need the full stack
Coro (CASB module)~€4Shadow IT, OAuth, basic DLP. Full platform: €9.50–18 (CASB+EDR+email+SASE)Mid-market all-in-one
Cloudflare Zero Trust€7 (base)SWG included. CASB/DLP only on contract plan.Already on Cloudflare
Wing Security~€125/month flatSaaS discovery + OAuth governance. No DLP, no session control.SaaS-heavy, budget-constrained
Bottom line: The cheapest real CASB for M365 shops is the standalone Defender for Cloud Apps at ~€3.50–5/user/month. Most mid-market doesn't know this exists outside of E5. For 200 users that's €700–1,000/month. There is no viable open-source CASB — the closest free option is Wing Security's SaaS Pulse for discovery only.