Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

CIO Briefings

Articles in CIO Briefings.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365CIO Briefings

CIO Brief: The Hidden Cost of Keeping Exchange On-Prem

The short version: In 2021, attackers exploited flaws in Microsoft Exchange email servers that companies ran themselves, compromising tens of thousands of...

Multi-CloudCIO Briefings

CIO Brief: IoT and SaaS Admin Access — The Overlooked Privilege

The short version: In 2021, hackers accessed about 150,000 security cameras — in hospitals, schools and factories — by finding a single "super admin"...

Microsoft 365CIO Briefings

CIO Brief: Security Vendors Are Part of Your Attack Surface

The short version: In 2021, Mimecast — an email security company — disclosed that a digital certificate its products used to connect to customers' Microsoft...

Entra ID & IdentityCIO Briefings

CIO Brief: Supply-Chain Risk After SolarWinds — What Boards Now Ask

The short version: In 2020, Russian intelligence hid malicious code inside updates for SolarWinds software used by thousands of organizations. For a smaller...

Entra ID & IdentityCIO Briefings

CIO Brief: Non-Human Identities Are Your Fastest-Growing Risk

The short version: In the SolarWinds attack, intruders read email by hijacking applications connected to Microsoft 365 rather than user accounts. Apps and...

AWSCIO Briefings

CIO Brief: Network Security Still Matters in the Cloud

The short version: Cloud servers can usually connect to anywhere on the internet by default. Attackers rely on that to steal data and control compromised...

AzureCIO Briefings

CIO Brief: Hybrid Identity Means On-Prem Flaws Become Cloud Flaws

The short version: In 2020, a flaw called Zerologon let attackers take over a company's core identity system — Active Directory — in seconds, without a...

Microsoft 365CIO Briefings

CIO Brief: Consolidating Security Tools Around Microsoft Defender

The short version: Many companies pay for Microsoft 365 E5 or similar licenses that include a full suite of security tools — and use only part of it....

Entra ID & IdentityCIO Briefings

CIO Brief: Social Engineering Your Employees Beats Hacking Your Systems

The short version: In 2020, attackers took over the Twitter accounts of world leaders and celebrities — not by hacking Twitter's systems directly, but by...

Microsoft 365CIO Briefings

CIO Brief: The Phishing Attack MFA Can't Stop

The short version: In 2020, attackers began tricking employees into clicking "Accept" on a Microsoft permission screen for a fake app. The employee signs in...

Multi-CloudCIO Briefings

CIO Brief: Third-Party Ransomware and Your Disclosure Obligations

The short version: In 2020, Blackbaud — software used by thousands of charities and schools — was hit by ransomware and paid the attackers. Its customers...

Microsoft 365CIO Briefings

CIO Brief: Collaboration Tools Are Now Critical Infrastructure

The short version: In 2020, uninvited strangers began crashing online meetings — "Zoom-bombing." It was a wake-up call: video meetings had become as...

Microsoft 365CIO Briefings

CIO Brief: Cleaning Up the Pandemic's Collaboration Mess

The short version: When COVID-19 sent everyone home in 2020, companies opened up collaboration tools as fast as possible. Many never tightened them again....

AWSCIO Briefings

CIO Brief: Faster Investigations Mean Smaller Breaches

The short version: Security tools generate alerts. The value comes from deciding quickly which ones are real. Amazon Detective, launched in 2020, is one of...

Multi-CloudCIO Briefings

CIO Brief: Customer Data Leaks and Reputational Damage

The short version: In 2020, personal details of more than 10 million MGM hotel guests appeared on a hacking forum, from an earlier breach of a cloud server....

AzureCIO Briefings

CIO Brief: If Microsoft Can Misconfigure Azure, So Can You

The short version: In 2020, Microsoft disclosed that a customer support database had been left exposed to the internet after a network setting change. If...

AWSCIO Briefings

CIO Brief: Who Outside Your Company Can Reach Your AWS Resources?

The short version: Companies routinely share cloud resources with vendors and partners. Over time, nobody remembers who has access to what. AWS released a...

Multi-CloudCIO Briefings

CIO Brief: When Ransomware Stops Revenue — The Travelex Timeline

The short version: On New Year's Eve 2019, ransomware shut down Travelex's systems for weeks. Attackers reportedly got in through a remote access device...

Microsoft 365CIO Briefings

CIO Brief: Insider Risk Without Spying on Employees

The short version: In 2019, Microsoft introduced tools to detect when employees might be taking or leaking company data — for example, downloading large...

AWSCIO Briefings

CIO Brief: How One AWS Setting Answers the Capital One Breach

The short version: After Capital One's 2019 breach, AWS released a setting — IMDSv2 — that blocks the technique the attacker used to steal cloud...

Entra ID & IdentityCIO Briefings

CIO Brief: The Free Setting That Blocks Most Identity Attacks

The short version: In 2019, Microsoft released Security Defaults: a free, one-click setting that turns on multi-factor authentication and blocks older,...

Microsoft 365CIO Briefings

CIO Brief: Legacy Protocols Are a Legacy Risk

The short version: In 2019, Microsoft announced it would switch off older sign-in methods for its cloud email because they couldn't use multi-factor...

AWSCIO Briefings

CIO Brief: When Your Security Vendor Loses Its Cloud Keys

The short version: In 2019, Imperva — a company that sells security protection — disclosed that customer data was exposed after an attacker stole a cloud...

AWSCIO Briefings

CIO Brief: The $80 Million Fine — What Regulators Expect From Cloud Security

The short version: Capital One's 2019 breach exposed data on about 106 million people. It was caused by a misconfigured firewall combined with a server that...

← NewerPage 4 of 6Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.