Cloud Security Insights & Guides

Cloud security requires more than reacting to threats. A strong security posture combines identity and access controls, secure architecture, continuous monitoring, vulnerability management, and clear operational processes to reduce risk without slowing down the business.

The articles below cover practical cloud security topics, including IAM, network security, threat detection, data protection, security monitoring, governance, and AWS security best practices. You’ll also find guidance on maintaining compliance with common frameworks and strengthening audit readiness as environments grow more complex.

Stratus10 helps organizations identify cloud security risks, improve their AWS security posture, and put practical controls in place to protect workloads, data, and users.

Capital One Data Breach And The Amazon Shared Security Model

Capital One Data Breach Analysis: Initial Discovery and FBI Involvement


On July 17 Virginia-based bank Capital One received an email tip that their data had been leaked on code-hosting site Github.  An initial investigation found that the data originated from a Capital One server hosted in the cloud that was accessed via a misconfigured firewall.

What Marriott and Quora Did Wrong

Really? Again?


When will companies learn how to properly protect their data?  Starting with Target and Yahoo in 2013, Sony and OPM in 2014, Ashley Madison in 2015, the Democratic National Committee in 2016, Equifax in 2017 and now Marriott and Quora back-to-back to cap off 2018, data breaches are becoming a mainstay in the news. It begs the question: what are so many of these organizations missing?  

And if it can happen to companies with big budgets like these, then how can a mid-market or small business be expected to keep up?

Post PetyaWrap - How To Prevent Ransomware Attacks

Now that most have recovered from the hangover of the PetyaWrap ransomware attacks, it is Monday morning quarterback time. PetyaWrap was not a new ransomware with a zero day vulnerability, but rather a combination of three common vectors of attack that companies do not always take seriously. But securing your assets go beyond just your servers (aka EC2 instances); you also need to ensure your AWS Account is equally as secure.

 

Newsletter Sign Up