Skip to content

Cloud Misconfiguration and Public Exposure

The handful of settings behind most cloud incidents, and how to catch them before someone else does.

Editorial team 2 min read

Cloud incidents are rarely exotic. A small set of misconfigurations accounts for most of them, and all are detectable from the provider's own API.

The recurring list

  • Storage open to the internet, including buckets exposed through a CDN or a misjudged policy.
  • Databases and caches with public endpoints, often created for a migration and never closed.
  • Over-broad identity policies: wildcards on actions or resources, roles assumable from any account, and keys with far more scope than the workload needs.
  • Disabled or unmonitored logging, which turns an incident into speculation.
  • Unrestricted egress, which is how data leaves once something is compromised.
  • Dangling DNS pointing at released addresses or deleted services.

Prevention beats detection

Policy as code in the pipeline stops the misconfiguration being created, which is cheaper than finding it afterwards. Service control policies and organisation-level guardrails prevent whole categories regardless of what a team writes.

Detection where prevention cannot reach

Continuous configuration scanning across every account — including the ones created by a project team last month — with findings routed to the owning team and a clock running. Reconcile against billing so no account is missed.

The question to answer monthly

"What of ours is reachable from the internet, and should it be?" If the answer takes more than a day to produce, that is the first thing to fix.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025