Cloud security · 3 min read
The IAM blast radius review, step by step
A compliance score tells you which policies are untidy. A blast radius review tells you what happens when one CI key leaks — which is the question you actually need answered.
Cloud security
What this covers
These posts cover cloud security the way incidents actually happen: a leaked long-lived key, a build role that can assume anything, storage exposed by a policy nobody re-read, and metadata endpoints reachable from a vulnerable application.
Cloud findings are rarely zero-days. They are permissions that accumulated faster than anyone reviewed them. These posts are about mapping that accumulation as an attack graph and cutting the blast radius down.
2 posts in Cloud security.
Cloud security · 3 min read
A compliance score tells you which policies are untidy. A blast radius review tells you what happens when one CI key leaks — which is the question you actually need answered.
Cloud security · 3 min read
During an incident you cannot add logging retroactively. Every question you will be asked depends on events you either recorded beforehand or did not.
Scope and a fixed quote within two working days. First consultation is free.