Security Insights

Identity & Access

Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.

Identity and Access Management: Why Deprovisioning Is Where Programs Actually Fail

API Discovery: Why You Probably Have More APIs Than You Think

Identity and access management programs get evaluated heavily on how well provisioning works — how quickly and correctly a new employee gets access to what they need — while deprovisioning, the reverse process of removing access when it’s no longer needed, receives disproportionately less attention despite being where most real IAM program failures actually originate. … Read more

Kubernetes RBAC Misconfigurations That Quietly Grant Too Much Access

Kubernetes RBAC Misconfigurations That Quietly Grant Too Much Access

Kubernetes role-based access control, commonly known as RBAC, provides powerful, granular access management capability, but its own flexibility and complexity make RBAC misconfiguration a common source of Kubernetes clusters quietly granting considerably more access than administrators intended or realized. Why Kubernetes RBAC Complexity Invites Misconfiguration Kubernetes RBAC offers considerable configuration flexibility – roles, cluster roles, … Read more

Cloud IAM Misconfigurations That Lead to Privilege Escalation

Shared Responsibility Model: Where Cloud Provider Security Ends

Identity and access management misconfigurations in cloud environments consistently rank among the most serious, commonly exploited security findings, and privilege escalation – where an attacker with limited initial access finds a path to considerably broader permissions – is often the specific mechanism that turns a comparatively minor initial compromise into a major, full-scale breach. Why … Read more