CIO Brief: One Setting That Prevents the Most Common Cloud Breach
Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.
The short version: In 2018, AWS added a setting that prevents cloud storage from being made public at all. Turned on across an account, it stops the most common cause of cloud data leaks. Many companies still haven't enabled it everywhere.
Why one setting matters so much
Publicly exposed cloud storage has been behind many data leaks. Most were mistakes: a test setting left on, a vendor misconfiguration, a misunderstanding of permissions. A blocking setting at the account level means those mistakes simply cannot expose data.
The business impact
- Prevents headline-making leaks with almost no cost.
- Simplifies audits — one control answers a common assessment question.
- Reduces dependence on every engineer getting every setting right.
Questions to ask your team
- Is public access blocked at the account level in every AWS account we own?
- Can anyone turn it off, or is that prevented centrally?
- Which accounts genuinely need public storage, and how is that controlled?
What good looks like
Public access blocked in every account by default, a central policy preventing changes, and a small number of documented, isolated exceptions.
The decision
Ask for confirmation that every AWS account has public access blocked, with a list of exceptions. If you use Azure as well, ask the same question about storage account public access.
- S3 Block Public Access Launches (Nov 2018): The Feature That Should Have Existed Day One Platform Changes
- How to Enforce S3 Block Public Access at the AWS Organization Level How-To & Hardening
- S3 Public Access Audit Checklist How-To & Hardening