VVenstap
Category

Cloud Security

13 articles

Testing Infrastructure-as-Code for Security Issues

Infrastructure-as-code lets misconfigurations scale as fast as your deployment pipeline. Catching security issues before they're applied is far cheaper than finding them in production.

Cloud Storage Misconfigurations: A Persistent Problem

Object storage misconfigurations remain one of the most common and consequential cloud security issues, years after they became a well-known risk. Here's why, and how to actually fix it.

Identity and Access Management in Cloud Environments

Identity is the primary security boundary in cloud environments, replacing the network perimeter of the data center era. A practical guide to getting cloud IAM right.

Serverless Security: What Changes and What Doesn't

Serverless removes the server from your responsibility list, but it doesn't remove security responsibility — it relocates it. A grounded look at what actually shifts.

Cloud Asset Discovery: Finding What You Forgot You Deployed

You cannot secure what you don't know exists. A practical look at why cloud asset inventories drift from reality, and how to build discovery that keeps up with actual deployment velocity.

Multi-Cloud Security: Unique Challenges and Approaches

Running workloads across multiple cloud providers multiplies operational flexibility and security complexity in roughly equal measure. Here's what actually gets harder, and how to manage it.

API Gateways and Security Testing Considerations

API gateways centralize a lot of security control, which makes them powerful and also makes their misconfiguration disproportionately dangerous. What to test and why.

Container Security Basics for Security Teams

Container security requires securing four distinct layers — image, registry, orchestrator, and runtime. A grounded overview for security teams who don't own the container platform day to day.

Securing Auto-Scaling Infrastructure Without Losing Visibility

Auto-scaling groups solve capacity problems but create a security visibility challenge: instances appear and disappear faster than most inventory and testing processes can track.

Shared Responsibility Model: What You're Actually Responsible For

The shared responsibility model is widely cited and often misunderstood. Here's a concrete breakdown of what the cloud provider secures, what you secure, and where the line actually moves.

Common Misconfigurations in Cloud Environments

A survey of the misconfiguration patterns that show up again and again across cloud environments, why they persist despite being well-known, and how to systematically catch them.

Testing the External Attack Surface of Cloud Infrastructure

How to systematically test what an attacker can actually reach from the internet, why asset inventories are usually wrong, and what a rigorous external assessment looks like.

Cloud Security Posture Management Explained

A practical breakdown of what Cloud Security Posture Management actually does, why manual review doesn't scale, and how to evaluate whether your CSPM approach is working.