In nearly every cloud assessment I run, the initial foothold isn't a zero-day — it's an identity mistake: an over-permissive role, a key committed three years ago, a dev account that can quietly become admin. The good news: a short hardening list closes most of these paths. Start here.
Delete the keys nobody owns
Long-lived access keys are the skeleton keys of cloud breaches. Inventory every key, delete anything older than your rotation policy, and move humans to short-lived SSO sessions. Attackers can't leak what doesn't exist.
Trace every path to admin
Tools that graph IAM privilege paths will show you the uncomfortable truth: which roles, groups, and trust policies chain to administrator. Remove the unused edges — especially cross-account trust and wildcard resource grants — and re-run the graph until no quiet path remains.
Make storage private by default
Public buckets and snapshots still top our exposure lists. Enforce block-public-access at the organization level, alert on any policy that grants the open internet access, and scan backups too — snapshots inherit the data's sensitivity but rarely its scrutiny.
Log like you'll be breached
When (not if) a key leaks, CloudTrail and Entra sign-in logs are the difference between a two-hour response and a two-month investigation. Centralize them, protect them from deletion, and alert on the classics: console logins without MFA, new access keys, and policy attachments at 3 a.m.

