AWSCIO BriefingsRetrospectives

CIO Brief: One Setting That Prevents the Most Common Cloud Breach

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.

The short version: In 2018, AWS added a setting that prevents cloud storage from being made public at all. Turned on across an account, it stops the most common cause of cloud data leaks. Many companies still haven't enabled it everywhere.

Why one setting matters so much

Publicly exposed cloud storage has been behind many data leaks. Most were mistakes: a test setting left on, a vendor misconfiguration, a misunderstanding of permissions. A blocking setting at the account level means those mistakes simply cannot expose data.

The business impact

  • Prevents headline-making leaks with almost no cost.
  • Simplifies audits — one control answers a common assessment question.
  • Reduces dependence on every engineer getting every setting right.

Questions to ask your team

  • Is public access blocked at the account level in every AWS account we own?
  • Can anyone turn it off, or is that prevented centrally?
  • Which accounts genuinely need public storage, and how is that controlled?

What good looks like

Public access blocked in every account by default, a central policy preventing changes, and a small number of documented, isolated exceptions.

The decision

Ask for confirmation that every AWS account has public access blocked, with a list of exceptions. If you use Azure as well, ask the same question about storage account public access.

s3 block public access impactS3 Block Public Access2018

More on this story