Triad ICS
Menu

Insights/Triad Original Research

Cloud Security Posture Management: Lessons from AWS Assessments

Published

Reading time2 minutes

FromTriad ICS Research

Cloud breaches rarely need exotic exploits. The misconfigurations that keep recurring, and how to catch them continuously.

Cloud security incidents rarely begin with an advanced exploit. Far more often they begin with a configuration that was convenient on the day it was set. Cloud Security Posture Management (CSPM) is the practice of finding and fixing those configurations continuously, rather than once a year. These are the patterns that recur when we review AWS environments.

Identity is the new perimeter

  • The root user is still used for routine tasks, sometimes without multi-factor authentication.
  • Long-lived IAM access keys are in use, some unrotated for years and belonging to people who have left.
  • Policies grant broad wildcards such as “Action: *” because narrowing them was postponed.
  • Roles can be assumed by more principals than intended, including from other accounts.

Exposed services

  • Security groups allow SSH (22) or RDP (3389) from 0.0.0.0/0.
  • Databases or search clusters are reachable from the internet.
  • EC2 instances still allow IMDSv1, making credential theft through server-side request forgery easier.

Data exposure

  • Storage buckets or snapshots are shared publicly or with unknown accounts.
  • Encryption at rest is missing on older volumes, snapshots and databases.
  • Backups exist but are not protected from deletion.

Visibility gaps

  • CloudTrail is not enabled in every region, or its logs can be deleted by the same administrators it monitors.
  • GuardDuty and AWS Config are enabled in some accounts but not others.
  • Unused regions are not monitored, which attackers can exploit to run resources unnoticed.
  • Logs are not retained long enough to meet CERT-In’s 180-day direction.

Making posture management continuous

  • Adopt a benchmark, such as the CIS AWS Foundations Benchmark, as your baseline.
  • Use AWS Security Hub and AWS Config, or an open-source scanner such as Prowler, to check it automatically.
  • Use AWS Organizations with service control policies to prevent the riskiest changes, rather than only detecting them.
  • Route findings to the team that owns the resource, with clear severity and deadlines.
  • Review exceptions regularly; a temporary exception tends to become permanent.

The lesson

The same small set of misconfigurations accounts for a large share of cloud risk, and each one is detectable automatically. Assessments are useful for depth and judgement, but posture has to be managed continuously, because cloud environments change every day.

This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.

Turn Insight into Action