AWSCIO BriefingsRetrospectives

CIO Brief: Even Defense Agencies Misconfigure Cloud Storage — Here's Why

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2017, written in 2026 with the benefit of hindsight.

The short version: In 2017, cloud storage tied to US military programs was found open to the public. If defense organizations can make this mistake, any organization can — which is why automated guard rails matter more than careful people.

Why "be careful" is not a strategy

Cloud environments change constantly. Hundreds of settings across thousands of resources are adjusted by many people and automated tools. Relying on everyone to configure everything correctly guarantees occasional mistakes. The question is whether those mistakes are prevented, caught quickly, or found by a researcher.

The business impact

  • Data exposure from a single wrong setting.
  • Public embarrassment when outsiders discover it first.
  • Contract and compliance risk for organizations handling government or regulated data.

Questions to ask your team

  • Which risky cloud settings are technically impossible in our environment, rather than just discouraged?
  • How quickly would we know if someone made storage public by mistake?
  • Who reviews cloud configuration findings, and how often?
  • Do contractors and project teams follow the same rules?

What good looks like

Preventive policies that block the most dangerous settings outright, continuous monitoring for the rest, findings routed to owners with deadlines, and a monthly summary to leadership.

The decision

Ask your cloud team to name the five most dangerous configuration mistakes for your environment and show how each one is prevented or detected. If any answer is "we're careful," that is your next project.

pentagon s3 leak impactPentagon S3 buckets2017

More on this story