Security Insights

Cloud Security

Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.

Cloud Security Posture Management: What CSPM Tools Actually Catch

Shared Responsibility Model: Where Cloud Provider Security Ends

Cloud Security Posture Management tools get sold on the promise of catching cloud misconfigurations automatically, and they genuinely do catch a real and important category of risk — but “catches misconfigurations” covers a wide range of actual capability, and teams that buy a CSPM tool expecting comprehensive cloud security coverage are usually disappointed by what … Read more

Cloud Detection and Response: What CDR Tools Actually Add

Shared Responsibility Model: Where Cloud Provider Security Ends

Cloud detection and response tools, commonly abbreviated CDR, have emerged as a distinct cloud security category. Organizations evaluating these tools alongside existing cloud security posture management and workload protection tools often lack clarity on exactly what additional capability CDR provides. Why CDR Addresses a Distinct Security Need From CSPM and CWPP Cloud security posture management … Read more

Cloud Workload Protection: What CWPP Tools Actually Do

Shared Responsibility Model: Where Cloud Provider Security Ends

Cloud workload protection platforms, commonly abbreviated CWPP, have become a standard component of mature cloud security programs, yet organizations evaluating these tools for the first time often lack clarity on exactly what protection CWPP tools provide beyond generic marketing descriptions. What Cloud Workloads Need Protecting Cloud workloads – virtual machines, containers, serverless functions – represent … Read more

Cloud Encryption: What Is Actually Protected and What Is Not

Shared Responsibility Model: Where Cloud Provider Security Ends

Cloud encryption provides real, important data protection, but organizations frequently misunderstand exactly what specific encryption protects against, leading to dangerous gaps where organizations mistakenly believe encryption addresses a security risk that, in reality, it honestly does not address at all. The Distinction Between Encryption at Rest and in Transit Cloud encryption operates in two distinct … Read more

Shared Responsibility Model: Where Cloud Provider Security Ends

Shared Responsibility Model: Where Cloud Provider Security Ends

Organizations migrating to cloud infrastructure frequently misunderstand the shared responsibility model – the division of security responsibility between cloud provider and customer – leading to dangerous security gaps where each party mistakenly assumes the other is handling a particular security responsibility that, in reality, honestly nobody is actively addressing. What the Shared Responsibility Model Establishes … Read more

Cloud Native Security Tools: CSPM, CWPP, and CNAPP Explained

Shared Responsibility Model: Where Cloud Provider Security Ends

Cloud security tooling has developed its own dense acronym landscape – CSPM, CWPP, CNAPP among others – that can obscure the actual practical purpose each tool category serves. Understanding what each does, and how they relate to each other, helps organizations build a coherent cloud security tooling strategy. It also helps them avoid accumulating overlapping … Read more

Cloud Misconfiguration: The Most Common Breach Cause Nobody Fixes

Shared Responsibility Model: Where Cloud Provider Security Ends

Ask security researchers what causes most cloud data breaches, and the answer is rarely a sophisticated zero-day exploit or a nation-state-level attack. It is almost always something far more mundane – a misconfigured storage bucket, an overly permissive access policy, a service left exposed to the public internet that was never meant to be reachable … Read more