Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

CIO Briefings

Articles in CIO Briefings.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSCIO Briefings

CIO Brief: Governance at Scale — Why Control Tower Matters

The short version: AWS Control Tower, released in 2019, sets up your AWS cloud as a well-organized group of accounts with security rules built in. It is the...

AzureCIO Briefings

CIO Brief: Exposed Remote Access Is Still the Front Door for Ransomware

The short version: In 2019, Microsoft warned about BlueKeep, a flaw that could let attackers take over older Windows computers through remote desktop...

Microsoft 365CIO Briefings

CIO Brief: Your Help Desk Is a Target — Protecting Support Workflows

The short version: In 2019, attackers got into Microsoft's consumer email support systems by compromising a single support agent's account. Help desks are...

Microsoft 365CIO Briefings

CIO Brief: Your Security Vendor Can Be Breached — Plan for It

The short version: In 2019, Citrix — a company that sells remote access technology to enterprises — was breached, likely through attackers trying common...

AzureCIO Briefings

CIO Brief: Cloud-Native SIEM vs. Legacy SIEM — The Cost and Coverage Trade-Off

The short version: In 2019, Microsoft released Sentinel, a security monitoring service that runs in the cloud. It made centralized security monitoring...

AWSCIO Briefings

CIO Brief: One Setting That Prevents the Most Common Cloud Breach

The short version: In 2018, AWS added a setting that prevents cloud storage from being made public at all. Turned on across an account, it stops the most...

AWSCIO Briefings

CIO Brief: Why One Big AWS Account Is a Security Liability

The short version: AWS recommends running your cloud as many separate accounts — one per application or environment — instead of one big account. In 2018,...

Entra ID & IdentityCIO Briefings

CIO Brief: Planning for the Day Your Identity Provider Is Unavailable

The short version: In 2018, Microsoft's multi-factor authentication service had a major outage, and many organizations couldn't sign in to their email and...

Multi-CloudCIO Briefings

CIO Brief: When You Buy a Company, You Buy Its Breaches

The short version: When Marriott bought Starwood in 2016, it also bought a hacker who had been inside Starwood's systems since 2014. The breach wasn't...

Entra ID & IdentityCIO Briefings

CIO Brief: Stolen Tokens Bypass Passwords and MFA — What That Means for You

The short version: In 2018, a Facebook bug let attackers steal the digital "keys" that keep users signed in, giving access to millions of accounts without...

Entra ID & IdentityCIO Briefings

CIO Brief: Passwordless Is a Productivity Win, Not Just Security

The short version: In 2018, Microsoft started pushing businesses toward signing in without passwords, using phones, fingerprints and security keys instead....

Entra ID & IdentityCIO Briefings

CIO Brief: Not All MFA Is Equal — The Case for Phishing-Resistant Methods

The short version: In 2018, Reddit was breached even though its employees used two-factor authentication — the attacker intercepted text message codes. All...

Entra ID & IdentityCIO Briefings

CIO Brief: Password Policy Is Still a Security Control

The short version: Most password rules produce predictable passwords like "Summer2018!", which attackers try first. In 2018, Microsoft introduced a way to...

Microsoft 365CIO Briefings

CIO Brief: GDPR Fines and Your Cloud Data Map

The short version: GDPR, enforceable since 2018, made organizations legally responsible for knowing where personal data lives and protecting it — with fines...

Microsoft 365CIO Briefings

CIO Brief: Who Approved That App? Governing OAuth Permissions

The short version: Cambridge Analytica obtained data on tens of millions of Facebook users through an app most of them never used. The same mechanism — apps...

Microsoft 365CIO Briefings

CIO Brief: Password Spraying Is Cheap for Attackers — Is Your Tenant Ready?

The short version: In 2018, the US indicted Iranian hackers who stole large volumes of data by trying common passwords against thousands of accounts. It is...

AWSCIO Briefings

CIO Brief: Cryptojacking — The Breach That Shows Up on Your Cloud Bill

The short version: In 2018, attackers broke into Tesla's cloud through an unprotected management console and used its computers to mine cryptocurrency....

Multi-CloudCIO Briefings

CIO Brief: Shared Responsibility When the Flaw Is in the Hardware

The short version: In 2018, researchers found flaws in nearly every computer processor that could let one program read another's data. Cloud providers had...

AWSCIO Briefings

CIO Brief: Breach Concealment, Disclosure Laws and the Uber Lesson

The short version: Uber's 2016 breach began with cloud passwords left in a code repository. What made it infamous was the cover-up: the company paid the...

AWSCIO Briefings

CIO Brief: Even Defense Agencies Misconfigure Cloud Storage — Here's Why

The short version: In 2017, cloud storage tied to US military programs was found open to the public. If defense organizations can make this mistake, any...

AWSCIO Briefings

CIO Brief: Managed Threat Detection — Build vs. Buy for AWS

The short version: Amazon GuardDuty, launched in 2017, watches your AWS accounts for signs of attack and costs relatively little. The decision is not really...

Multi-CloudCIO Briefings

CIO Brief: What the Equifax Hearings Mean for Executive Accountability

The short version: Equifax lost data on about 147 million people in 2017 because a known software flaw went unpatched for months, and monitoring that should...

Microsoft 365CIO Briefings

CIO Brief: Privileged Accounts Are the Keys to the Kingdom

The short version: Deloitte's 2017 email breach reportedly started with one administrator account protected only by a password. Admin accounts are the keys...

AWSCIO Briefings

CIO Brief: You Can't Protect Data You Haven't Found

The short version: In 2017, AWS released Macie, a tool that finds sensitive data like customer records hidden in cloud storage. Its premise is simple and...

← NewerPage 5 of 6Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.