Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

CIO Briefings

Articles in CIO Briefings.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Multi-CloudCIO Briefings

CIO Brief: When a Dev Tool Breach Forces a Company-Wide Credential Reset

The short version: In January 2023, CircleCI — a service many companies use to build and deploy software — told every customer to change every password and...

Multi-CloudCIO Briefings

CIO Brief: Password Manager Breaches and Your Enterprise Secrets

The short version: In 2022, attackers stole encrypted copies of LastPass customers' password vaults by hacking an engineer's home computer and using it to...

AWSCIO Briefings

CIO Brief: Owning Your Security Data — The OCSF Shift

The short version: In 2022, AWS introduced Security Lake, which stores your security logs in your own cloud account, in a standard format any security tool...

Microsoft 365CIO Briefings

CIO Brief: What Broke When Basic Auth Died — and What Got Safer

The short version: In October 2022, Microsoft permanently turned off older sign-in methods for its cloud email after a three-year warning. Some printers,...

AzureCIO Briefings

CIO Brief: Storage Misconfiguration Is a Cloud-Agnostic Problem

The short version: In 2022, researchers reported that a misconfigured Microsoft storage location exposed business documents involving Microsoft's customers....

Entra ID & IdentityCIO Briefings

CIO Brief: Contractors Need the Same Security as Employees

The short version: In 2022, Uber was breached through a contractor whose password had been stolen and who eventually approved one of many login prompts....

Microsoft 365CIO Briefings

CIO Brief: When to Finally Leave On-Prem Exchange

The short version: In late 2022, a third major wave of attacks hit company-run Microsoft Exchange email servers. Microsoft took about six weeks to release...

Entra ID & IdentityCIO Briefings

CIO Brief: The Case for Hardware Security Keys

The short version: In 2022, attackers sent text messages to employees at more than 130 companies, tricking them into entering passwords and MFA codes on...

Microsoft 365CIO Briefings

CIO Brief: Why Standard MFA No Longer Stops Phishing

The short version: In 2022, Microsoft reported a phishing campaign that hit more than 10,000 organizations and got past multi-factor authentication by...

Microsoft 365CIO Briefings

CIO Brief: Attackers Adapt When You Block Macros

The short version: For years, the main defense against malicious Office documents was blocking macros. In 2022, attackers used a new flaw, Follina, to run...

Entra ID & IdentityCIO Briefings

CIO Brief: Identity Is the New Perimeter — Now It Has a Brand

The short version: In 2022, Microsoft reorganized its identity products under a new brand, Entra — reflecting a shift the whole industry made: who you are...

Multi-CloudCIO Briefings

CIO Brief: Your Build Pipeline Has the Keys to Production

The short version: In 2022, attackers stole the digital access passes that Heroku and Travis CI used to connect to customers' GitHub code repositories, and...

Entra ID & IdentityCIO Briefings

CIO Brief: Insider Recruitment and Social Engineering — The Lapsus$ Playbook

The short version: In 2022, a group of teenagers called Lapsus$ breached Microsoft, Nvidia, Samsung and Okta — not with advanced hacking tools, but by...

Entra ID & IdentityCIO Briefings

CIO Brief: Why Revoking Access Used to Take an Hour

The short version: Until a few years ago, if you disabled a compromised employee account in Microsoft 365, the attacker could keep using it for up to an...

Multi-CloudCIO Briefings

CIO Brief: Software Bills of Materials After Log4Shell

The short version: In December 2021, a flaw was found in Log4j, a small piece of free software used inside thousands of products. Companies spent weeks just...

AWSCIO Briefings

CIO Brief: Concentration Risk in a Single Cloud Region

The short version: In December 2021, a problem in one AWS region disrupted major services like Netflix, Disney+ and Amazon's own deliveries for much of a...

AzureCIO Briefings

CIO Brief: One Dashboard for Multi-Cloud Posture — Hype or Help?

The short version: In 2021, Microsoft combined its Azure security tools into Defender for Cloud, promising one dashboard for security across Azure, AWS and...

AzureCIO Briefings

CIO Brief: The Software Your Cloud Provider Installs on Your Servers

The short version: In 2021, researchers found serious flaws in a management program Microsoft quietly installed on many Linux servers in Azure. Many...

AzureCIO Briefings

CIO Brief: When the Cloud Provider's Own Service Is Vulnerable

The short version: In 2021, researchers found a flaw in one of Microsoft's own Azure database services that could have let attackers access thousands of...

Microsoft 365CIO Briefings

CIO Brief: Repeated Exchange Zero-Days — A Signal to Move to the Cloud

The short version: In 2021, a second wave of attacks hit company-run Microsoft Exchange email servers, months after the first. Patches had been available...

Microsoft 365CIO Briefings

CIO Brief: Citizen Developers Need Guardrails

The short version: In 2021, about 38 million records — including vaccination data and Social Security numbers — were exposed through websites built with...

Multi-CloudCIO Briefings

CIO Brief: Your MSP Has Admin Rights — Are You Watching?

The short version: In 2021, ransomware spread through Kaseya — software that IT service providers use to manage their clients' computers — reaching up to...

Multi-CloudCIO Briefings

CIO Brief: Colonial Pipeline and the Business Case for MFA on Everything

The short version: In 2021, Colonial Pipeline shut down fuel deliveries across the US East Coast after ransomware. The attackers got in through one old...

Multi-CloudCIO Briefings

CIO Brief: What the Federal Zero Trust Mandate Means for Private Companies

The short version: In 2021, a US executive order made "zero trust" official federal policy and required multi-factor authentication, encryption and better...

← NewerPage 3 of 6Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.