Cloud security

Cloud & Infrastructure Security Articles

What this covers

These posts cover cloud security the way incidents actually happen: a leaked long-lived key, a build role that can assume anything, storage exposed by a policy nobody re-read, and metadata endpoints reachable from a vulnerable application.

Cloud findings are rarely zero-days. They are permissions that accumulated faster than anyone reviewed them. These posts are about mapping that accumulation as an attack graph and cutting the blast radius down.

2 posts in Cloud security.

Cloud security · 3 min read

The IAM blast radius review, step by step

A compliance score tells you which policies are untidy. A blast radius review tells you what happens when one CI key leaks — which is the question you actually need answered.

· updated 2 Apr 2026

Want this tested properly?

Scope and a fixed quote within two working days. First consultation is free.