CIO Brief: The $80 Million Fine — What Regulators Expect From Cloud Security
Retrospective: this article looks back at events from July 2019, written in 2026 with the benefit of hindsight.
The short version: Capital One's 2019 breach exposed data on about 106 million people. It was caused by a misconfigured firewall combined with a server that had permission to read far more data than it needed. Regulators fined the bank $80 million, citing weaknesses in how it managed cloud risk.
What regulators expect
The fine wasn't for using the cloud. It was for failing to identify and manage the risks of moving to it — including appropriate controls, testing and oversight. Regulators in banking, healthcare and other sectors now expect boards and executives to oversee cloud security with the same rigor as other operational risks.
The business impact
- Fines and enforcement for risk management failures.
- Litigation and settlements with affected customers.
- Increased scrutiny of future cloud initiatives.
Questions to ask your team
- Do our cloud servers and applications have only the access they need, or broad permissions "to be safe"?
- Have we enabled the security features AWS released after Capital One, such as IMDSv2?
- Who independently reviews our cloud security configuration?
- Would we detect someone downloading large amounts of data from our cloud storage?
What good looks like
Least-privilege permissions, provider security defaults enforced, independent assessment at least annually, monitoring for unusual data access, and board-level reporting on cloud risk.
The decision
Ask for an independent review of your highest-privilege cloud identities — human and machine. Excessive permissions turned a single misconfiguration into one of the largest breaches in banking history.
- Capital One (July 2019): SSRF, the EC2 Metadata Service and 100 Million Records Incident Teardowns
- How to Enforce IMDSv2 and Lock Down EC2 Instance Role Permissions How-To & Hardening
- Detecting SSRF Metadata Credential Theft: CloudTrail, GuardDuty and Athena Queries Detection & Response