AWSCIO BriefingsRetrospectives

CIO Brief: The $80 Million Fine — What Regulators Expect From Cloud Security

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2019, written in 2026 with the benefit of hindsight.

The short version: Capital One's 2019 breach exposed data on about 106 million people. It was caused by a misconfigured firewall combined with a server that had permission to read far more data than it needed. Regulators fined the bank $80 million, citing weaknesses in how it managed cloud risk.

What regulators expect

The fine wasn't for using the cloud. It was for failing to identify and manage the risks of moving to it — including appropriate controls, testing and oversight. Regulators in banking, healthcare and other sectors now expect boards and executives to oversee cloud security with the same rigor as other operational risks.

The business impact

  • Fines and enforcement for risk management failures.
  • Litigation and settlements with affected customers.
  • Increased scrutiny of future cloud initiatives.

Questions to ask your team

  • Do our cloud servers and applications have only the access they need, or broad permissions "to be safe"?
  • Have we enabled the security features AWS released after Capital One, such as IMDSv2?
  • Who independently reviews our cloud security configuration?
  • Would we detect someone downloading large amounts of data from our cloud storage?

What good looks like

Least-privilege permissions, provider security defaults enforced, independent assessment at least annually, monitoring for unusual data access, and board-level reporting on cloud risk.

The decision

Ask for an independent review of your highest-privilege cloud identities — human and machine. Excessive permissions turned a single misconfiguration into one of the largest breaches in banking history.

capital one breach impactCapital One2019

More on this story