Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Incident Teardowns

Deloitte's Email Breach (Sept 2017): An Admin Account Without MFA

In September 2017, The Guardian reported that Deloitte, one of the world's largest accounting and consulting firms, had suffered a breach of its global...

Microsoft 365How-To & Hardening

How to Protect Global Admin Accounts in Microsoft 365 and Entra ID

Global Administrators can change every setting, read every mailbox and create new admins in Microsoft 365. Protecting those accounts is the highest-value...

Microsoft 365Detection & Response

Detecting Compromised Admin Account: Defender XDR and Sentinel Hunting Queries

Compromised administrator accounts give attackers control of an entire Microsoft 365 tenant. Detecting unusual admin behavior early is one of the...

Microsoft 365CIO Briefings

CIO Brief: Privileged Accounts Are the Keys to the Kingdom

The short version: Deloitte's 2017 email breach reportedly started with one administrator account protected only by a password. Admin accounts are the keys...

AWSPlatform Changes

Amazon Macie Launches (Aug 2017): Machine Learning for Finding Sensitive Data in S3

In August 2017, AWS launched Amazon Macie, a service that used machine learning to discover, classify and protect sensitive data stored in Amazon S3. It...

AWSHow-To & Hardening

How to Use Amazon Macie to Discover PII in Your S3 Buckets

Amazon Macie scans S3 buckets for sensitive data such as names, financial information and credentials. Here is how to run it effectively without a surprise...

AWSHow-To & Hardening

Amazon Macie Rollout Checklist: Cost Controls and Finding Triage

Use this checklist before and after enabling Amazon Macie to get value quickly while keeping costs predictable.

AWSCIO Briefings

CIO Brief: You Can't Protect Data You Haven't Found

The short version: In 2017, AWS released Macie, a tool that finds sensitive data like customer records hidden in cloud storage. Its premise is simple and...

AWSIncident Teardowns

Verizon Customer Records Exposed via a Vendor's S3 Bucket (July 2017)

In July 2017, UpGuard researchers reported that records belonging to millions of Verizon customers were sitting in a publicly accessible Amazon S3 bucket....

AWSHow-To & Hardening

How to Use S3 Bucket Policies and Access Points to Enforce Least Privilege

Bucket policies decide who can access data in Amazon S3. Written loosely, they leak data; written tightly, they make many attacks impossible. Here is how to...

AWSDetection & Response

Detecting S3 Bucket Policy Misconfiguration: CloudTrail, GuardDuty and Athena Queries

Overly broad bucket policies are a frequent root cause of S3 exposures. Detecting policy changes that widen access — and catching risky policies already in...

AWSCIO Briefings

CIO Brief: Third-Party Cloud Risk — Writing Security Into Vendor Contracts

The short version: In 2017, a Verizon vendor exposed customer records — including account PINs used for phone support — in a cloud storage folder anyone...

Microsoft 365Platform Changes

Microsoft 365 Arrives (July 2017): Security Bundled Into the Productivity Suite

In July 2017, Microsoft announced Microsoft 365: a single subscription bundling Office 365, Windows 10 Enterprise and Enterprise Mobility + Security. For...

Microsoft 365How-To & Hardening

How to Map Microsoft 365 E3 vs. E5 Security Features to Your Real Risks

Microsoft 365 E3 and E5 both include significant security capabilities, but they are packaged differently and named inconsistently over the years. Here is...

Microsoft 365How-To & Hardening

Microsoft 365 Security Baseline Checklist for New Tenants

New and long-neglected Microsoft 365 tenants share the same weaknesses. This checklist covers the baseline settings that stop the most common attacks. Treat...

Microsoft 365CIO Briefings

CIO Brief: E3 or E5? Making the Microsoft 365 Security Licensing Decision

The short version: Microsoft 365 E3 includes solid security basics. E5 adds advanced threat protection, risk-based identity controls and stronger compliance...

AzureIncident Teardowns

NotPetya (June 2017): How a Tax Software Update Wiped Out Global Networks

On June 27, 2017, a malware outbreak later called NotPetya began in Ukraine and spread to multinational companies within hours. Shipping giant Maersk had to...

AzureHow-To & Hardening

How to Tier Your Active Directory Admin Accounts to Contain Lateral Movement

NotPetya spread by stealing administrator credentials from memory and reusing them across the network. Tiering your Active Directory admin accounts stops...

AzureDetection & Response

Detecting Credential Theft Lateral Movement: Defender for Cloud and Sentinel KQL

NotPetya combined credential theft with legitimate admin tools to move across networks. Detecting that pattern early is one of the most effective ways to...

AzureCIO Briefings

CIO Brief: NotPetya and the True Cost of Flat Networks and Shared Admin Accounts

The short version: NotPetya, in 2017, entered companies through a trusted software update and then spread using administrator passwords stolen from one...

AWSIncident Teardowns

198 Million Voter Records in an Open S3 Bucket (June 2017): Anatomy of a Misconfiguration

In June 2017, researcher Chris Vickery of UpGuard found an Amazon S3 bucket containing personal data on about 198 million American voters. It belonged to...

AWSHow-To & Hardening

How to Find and Lock Down Public S3 Buckets Across Every AWS Account

Public S3 buckets were behind dozens of data leaks in 2017. AWS has since made buckets private by default, but older accounts, older buckets and deliberate...

AWSDetection & Response

Detecting Public S3 Bucket Access: CloudTrail, GuardDuty and Athena Queries

The best time to catch a public S3 bucket is the moment it becomes public. Detection rules on configuration changes close the window between a mistake and...

AWSCIO Briefings

CIO Brief: Your Vendors' Cloud Buckets Are Your Data Exposure

The short version: In 2017, a data company working for the Republican National Committee left personal details on 198 million voters in an unprotected cloud...

← NewerPage 19 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.