Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Multi-CloudIncident Teardowns

Blackbaud Ransomware (July 2020): When Your SaaS Provider Pays the Ransom

In July 2020, Blackbaud — a cloud software provider widely used by nonprofits, universities and healthcare organizations for fundraising and donor...

Multi-CloudHow-To & Hardening

How to Assess SaaS Vendors' Security Before You Sign

SaaS vendors hold your data, and their security directly affects yours. Here is a practical approach to assessing SaaS vendors before you sign —...

Multi-CloudDetection & Response

Monitoring Third-Party SaaS Risk Signals and Breach Notifications

You can't monitor a SaaS vendor's internal systems, but you can monitor signals that indicate rising risk — and your own exposure if something goes wrong.

Multi-CloudCIO Briefings

CIO Brief: Third-Party Ransomware and Your Disclosure Obligations

The short version: In 2020, Blackbaud — software used by thousands of charities and schools — was hit by ransomware and paid the attackers. Its customers...

Microsoft 365Incident Teardowns

Zoom-Bombing (Apr 2020): What It Taught Us About Teams Meeting Security

In early 2020, as remote work exploded, "Zoom-bombing" entered the vocabulary: uninvited people joined online meetings and classrooms to disrupt them with...

Microsoft 365How-To & Hardening

How to Lock Down Microsoft Teams Meeting Policies and Lobby Settings

Microsoft Teams meeting policies decide who can join, present and record. Here is how to tighten them without making meetings painful.

Microsoft 365Detection & Response

Detecting Meeting Hijacking: Defender XDR and Sentinel Hunting Queries

Meeting disruption and eavesdropping are rare, but when they happen in sensitive meetings the impact is high. These detections help you spot unusual meeting...

Microsoft 365CIO Briefings

CIO Brief: Collaboration Tools Are Now Critical Infrastructure

The short version: In 2020, uninvited strangers began crashing online meetings — "Zoom-bombing." It was a wake-up call: video meetings had become as...

Microsoft 365Incident Teardowns

The COVID-19 Remote Work Shift (Mar 2020): Teams Sprawl, Guest Access and Shadow IT

In March 2020, the COVID-19 pandemic sent much of the global workforce home almost overnight. Microsoft Teams usage exploded as organizations rushed to keep...

Microsoft 365How-To & Hardening

How to Govern Teams Creation, Guest Access and Expiration Policies

Teams sprawl and forgotten guest access create real security risk. Here is how to put lightweight governance in place without slowing collaboration.

Microsoft 365Detection & Response

Detecting Teams Guest Access Risk: Defender XDR and Sentinel Hunting Queries

Guest accounts and broad Teams access can quietly expose sensitive data. These detections highlight risky guest activity and sharing.

Microsoft 365CIO Briefings

CIO Brief: Cleaning Up the Pandemic's Collaboration Mess

The short version: When COVID-19 sent everyone home in 2020, companies opened up collaboration tools as fast as possible. Many never tightened them again....

AWSPlatform Changes

Amazon Detective Goes GA (Mar 2020): Investigation Graphs for AWS Security Findings

In March 2020, Amazon Detective became generally available. It helps security teams investigate findings from GuardDuty and other sources by automatically...

AWSHow-To & Hardening

How to Investigate a GuardDuty Finding With Amazon Detective

Amazon Detective helps you answer the key questions after a GuardDuty finding: is it real, what did the identity do, and how far did it go? Here is a...

AWSHow-To & Hardening

Cloud Incident Investigation Runbook for AWS

A short, consistent runbook helps small teams respond to AWS incidents calmly. Use this as a starting template.

AWSCIO Briefings

CIO Brief: Faster Investigations Mean Smaller Breaches

The short version: Security tools generate alerts. The value comes from deciding quickly which ones are real. Amazon Detective, launched in 2020, is one of...

Multi-CloudIncident Teardowns

MGM Resorts Guest Data Leak (Feb 2020): 10 Million Records From a Cloud Server

In February 2020, personal details of more than 10.6 million MGM Resorts hotel guests were posted on a hacking forum. MGM confirmed the data came from a...

Multi-CloudHow-To & Hardening

How to Classify and Monitor Customer Data Stores Across Clouds

You can't protect customer data you can't find. Here is a practical approach to classifying and monitoring customer data stores across Azure, AWS and...

Multi-CloudDetection & Response

Detecting Cloud Server Data Exposure: Sentinel and GuardDuty Detections

Data exposures from cloud servers and databases often go unnoticed until data appears for sale. These detections help you spot exposure and unusual data...

Multi-CloudCIO Briefings

CIO Brief: Customer Data Leaks and Reputational Damage

The short version: In 2020, personal details of more than 10 million MGM hotel guests appeared on a hacking forum, from an earlier breach of a cloud server....

AzureIncident Teardowns

Microsoft's 250 Million Support Records Exposed (Jan 2020): A Misconfigured Azure Database

In January 2020, Microsoft disclosed that a customer support database containing about 250 million records had been exposed on the internet without password...

AzureHow-To & Hardening

How to Prevent Public Database Exposure With Azure Policy and Private Endpoints

A single network rule change exposed a Microsoft database to the internet in 2019. Azure Policy and private endpoints let you prevent that class of mistake...

AzureDetection & Response

Detecting Exposed Cloud Database: Defender for Cloud and Sentinel KQL

Exposed databases are often found by internet scanners within hours. Detecting public exposure — and unexpected access — quickly is critical.

AzureCIO Briefings

CIO Brief: If Microsoft Can Misconfigure Azure, So Can You

The short version: In 2020, Microsoft disclosed that a customer support database had been left exposed to the internet after a network setting change. If...

← NewerPage 13 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.