Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

CIO Briefings

Articles in CIO Briefings.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AzureCIO Briefings

CIO Brief: From Alert Counts to Exposure Management

The short version: Security teams are drowning in alerts and vulnerability lists. In 2024, Microsoft and other vendors pushed a different approach:...

AWSCIO Briefings

CIO Brief: The Most Powerful AWS Credential — and How to Retire It

The short version: Every AWS account has a "root" login with unlimited power. Companies with many AWS accounts had many of these super-passwords to protect....

AzureCIO Briefings

CIO Brief: Microsoft Now Requires MFA — Is Your Automation Ready?

The short version: Since October 2024, Microsoft requires multi-factor authentication for anyone managing Azure through its web portals, and from 2025 also...

Microsoft 365CIO Briefings

CIO Brief: Scaling Copilot Safely Beyond the Pilot

The short version: In September 2024, Microsoft expanded Copilot with new features — and new tools to fix the "oversharing" problem that stalled many...

AWSCIO Briefings

CIO Brief: Leaked Configuration Files Are Leaked Keys

The short version: In 2024, attackers scanned the internet for websites accidentally publishing their configuration files — which contained cloud passwords...

Multi-CloudCIO Briefings

CIO Brief: When Your Security Tool Causes the Outage

The short version: On July 19, 2024, a faulty update to CrowdStrike's security software crashed about 8.5 million Windows computers worldwide. Airlines,...

Multi-CloudCIO Briefings

CIO Brief: SaaS Shared Responsibility — Snowflake Wasn't Hacked, Its Customers Were

The short version: In 2024, attackers stole data from about 165 companies' accounts on Snowflake, a cloud data platform — including Ticketmaster and AT&T....

Entra ID & IdentityCIO Briefings

CIO Brief: Passkeys Make Phishing-Resistant MFA Affordable

The short version: Since 2024, Microsoft lets employees use passkeys on their phones to sign in — the strongest common form of authentication, and immune to...

Microsoft 365CIO Briefings

CIO Brief: What the CSRB Findings Mean for Microsoft Customers

The short version: In April 2024, a US government review board concluded that a Chinese hack of Microsoft's email systems "should never have happened" and...

Multi-CloudCIO Briefings

CIO Brief: Open-Source Dependencies Are Third-Party Risk

The short version: In 2024, a hidden backdoor was discovered in XZ Utils, a small but widely used piece of free software in Linux systems. Someone had spent...

Multi-CloudCIO Briefings

CIO Brief: Change Healthcare and the Systemic Risk of One Missing Control

The short version: In February 2024, ransomware shut down Change Healthcare, disrupting pharmacies and medical billing across the US for weeks. The...

Microsoft 365CIO Briefings

CIO Brief: The Test Environment Nobody Remembered

The short version: In January 2024, Russian state hackers read email of Microsoft's senior leaders. They got in through an old test account that didn't...

Entra ID & IdentityCIO Briefings

CIO Brief: Microsoft Is Changing Your Defaults — Here's What to Know

The short version: In November 2023, Microsoft announced a major security push — the Secure Future Initiative — and began automatically adding security...

Microsoft 365CIO Briefings

CIO Brief: Copilot Will Find Everything Your Users Can Access

The short version: Microsoft 365 Copilot, available since late 2023, can find and summarize anything an employee has access to — instantly. In most...

Entra ID & IdentityCIO Briefings

CIO Brief: Your Identity Provider's Breach Is Your Breach

The short version: In 2023, attackers broke into Okta's customer support system and stole login sessions from files customers had uploaded for...

AzureCIO Briefings

CIO Brief: AI Projects Create New Data Exposure Paths

The short version: In 2023, Microsoft's own AI researchers accidentally exposed 38 terabytes of internal data — including passwords and private messages —...

Entra ID & IdentityCIO Briefings

CIO Brief: Social Engineering the Help Desk Is the New Ransomware Entry Point

The short version: In 2023, a phone call to MGM's IT help desk reportedly led to a ransomware attack that shut down casinos and hotels for days and cost...

Microsoft 365CIO Briefings

CIO Brief: Your Chat Tool Is an Email Inbox Without Spam Filters

The short version: In 2023, Russian state hackers used Microsoft Teams chat — not email — to trick people into approving login requests. Companies have...

Microsoft 365CIO Briefings

CIO Brief: Storm-0558 and Paying Extra for Security Logs

The short version: In 2023, Chinese hackers read US government email by forging digital keys in Microsoft's systems. A government agency caught it — because...

Entra ID & IdentityCIO Briefings

CIO Brief: Renames Don't Change Risk — But Licensing Might

The short version: In 2023, Microsoft renamed Azure Active Directory to Microsoft Entra ID. Nothing about security changed with the name. But renames are a...

Multi-CloudCIO Briefings

CIO Brief: Managed File Transfer — The Forgotten Crown Jewel

The short version: In 2023, a ransomware gang exploited a flaw in MOVEit, a file transfer product, stealing data from over 2,000 organizations — many of...

AWSCIO Briefings

CIO Brief: Secure Defaults Help — But Only for New Resources

The short version: In April 2023, AWS changed the defaults so new cloud storage buckets are private and simpler to secure. That's a big improvement — but it...

Microsoft 365CIO Briefings

CIO Brief: AI in the SOC — Productivity Gains vs. Real Risks

The short version: In 2023, Microsoft launched Security Copilot, an AI assistant for security teams. Many vendors followed. AI can make security analysts...

AWSCIO Briefings

CIO Brief: Encryption by Default — What It Does and Doesn't Protect

The short version: Since January 2023, AWS automatically encrypts all new files stored in S3. That's good — but encryption by default doesn't stop someone...

← NewerPage 2 of 6Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.