Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Platform Changes

Microsoft Security Copilot Announced (Mar 2023): Generative AI Comes to the SOC

On March 28, 2023, Microsoft announced Microsoft Security Copilot, a generative AI assistant for security teams built on OpenAI's GPT-4 and Microsoft's...

Microsoft 365How-To & Hardening

How to Evaluate AI Assistants for Security Operations

AI assistants for security operations can speed up triage and investigation — or add cost and noise. Here is a practical way to evaluate them.

Microsoft 365How-To & Hardening

AI Security Tool Pilot Checklist: Data, Access and ROI

Use this checklist before and during a pilot of an AI security assistant.

Microsoft 365CIO Briefings

CIO Brief: AI in the SOC — Productivity Gains vs. Real Risks

The short version: In 2023, Microsoft launched Security Copilot, an AI assistant for security teams. Many vendors followed. AI can make security analysts...

AWSPlatform Changes

AWS Encrypts All New S3 Objects by Default (Jan 2023)

On January 5, 2023, AWS began automatically applying server-side encryption with Amazon S3 managed keys (SSE-S3) to all new objects uploaded to S3, at no...

AWSHow-To & Hardening

How to Choose Between SSE-S3, SSE-KMS and DSSE-KMS for S3

All new S3 objects are encrypted by default with SSE-S3. For sensitive data, you may want more control. Here is how to choose between SSE-S3, SSE-KMS and...

AWSHow-To & Hardening

S3 Encryption and KMS Key Policy Audit Checklist

KMS key policies decide who can decrypt your sensitive S3 data. Use this checklist to audit encryption and key policies.

AWSCIO Briefings

CIO Brief: Encryption by Default — What It Does and Doesn't Protect

The short version: Since January 2023, AWS automatically encrypts all new files stored in S3. That's good — but encryption by default doesn't stop someone...

Multi-CloudIncident Teardowns

CircleCI Secrets Breach (Jan 2023): Rotate Everything

On January 4, 2023, CircleCI, a widely used continuous integration and delivery platform, told customers to rotate all secrets stored in its platform...

Multi-CloudHow-To & Hardening

How to Run a Secrets Rotation Fire Drill Across AWS and Azure

When a provider tells you to rotate everything, the hardest part is knowing what "everything" is. A rotation fire drill — practiced in advance — makes it...

Multi-CloudDetection & Response

Detecting CI/CD Secrets Theft: Sentinel and GuardDuty Detections

After a CI/CD provider breach, attackers use stolen secrets to access your cloud. Detecting that use — and use of secrets after rotation — tells you whether...

Multi-CloudCIO Briefings

CIO Brief: When a Dev Tool Breach Forces a Company-Wide Credential Reset

The short version: In January 2023, CircleCI — a service many companies use to build and deploy software — told every customer to change every password and...

Multi-CloudIncident Teardowns

LastPass (Disclosed Dec 2022): Vault Backups Stolen From Cloud Storage

In August 2022, password manager LastPass disclosed that an attacker had accessed its development environment. In December 2022, it revealed that the...

Multi-CloudHow-To & Hardening

How to Protect Cloud Backup Storage With Separate Credentials and Immutability

In the LastPass breach, attackers stole backups from cloud storage using credentials taken from an engineer's home computer. Backups need their own...

Multi-CloudDetection & Response

Detecting Cloud Backup Theft: Sentinel and GuardDuty Detections

Attackers increasingly target backups — to steal data or to delete it before ransomware. These detections watch for unusual backup access and changes.

Multi-CloudCIO Briefings

CIO Brief: Password Manager Breaches and Your Enterprise Secrets

The short version: In 2022, attackers stole encrypted copies of LastPass customers' password vaults by hacking an engineer's home computer and using it to...

AWSPlatform Changes

re:Invent 2022: Amazon Security Lake and Verified Access Previews

At AWS re:Invent in November 2022, AWS announced previews of Amazon Security Lake and AWS Verified Access, alongside other security updates.

AWSHow-To & Hardening

How to Centralize AWS Security Logs With Amazon Security Lake

Amazon Security Lake centralizes and normalizes security logs from AWS and other sources into OCSF format in your own S3 buckets. Here is how to set it up.

AWSHow-To & Hardening

Security Lake Source and Retention Planning Checklist

Use this checklist to plan which data goes into Amazon Security Lake and how long you keep it.

AWSCIO Briefings

CIO Brief: Owning Your Security Data — The OCSF Shift

The short version: In 2022, AWS introduced Security Lake, which stores your security logs in your own cloud account, in a standard format any security tool...

Microsoft 365Platform Changes

Exchange Online Basic Auth Turned Off (Oct 2022): The End of an Era

Beginning October 1, 2022, Microsoft started permanently disabling Basic Authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Remote...

Microsoft 365How-To & Hardening

How to Verify Legacy Authentication Is Fully Blocked in Your Tenant

Microsoft retired Basic Authentication for most Exchange Online protocols in 2022, but legacy authentication can still appear through SMTP AUTH, other...

Microsoft 365How-To & Hardening

Post-Basic-Auth Cleanup Checklist: SMTP AUTH, Service Accounts and Scripts

After Basic Authentication was turned off in Exchange Online, many organizations found lingering dependencies. Use this checklist to clean up.

Microsoft 365CIO Briefings

CIO Brief: What Broke When Basic Auth Died — and What Got Safer

The short version: In October 2022, Microsoft permanently turned off older sign-in methods for its cloud email after a three-year warning. Some printers,...

← NewerPage 7 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.