Cloud incidents are rarely exotic. A small set of misconfigurations accounts for most of them, and all are detectable from the provider's own API.
The recurring list
- Storage open to the internet, including buckets exposed through a CDN or a misjudged policy.
- Databases and caches with public endpoints, often created for a migration and never closed.
- Over-broad identity policies: wildcards on actions or resources, roles assumable from any account, and keys with far more scope than the workload needs.
- Disabled or unmonitored logging, which turns an incident into speculation.
- Unrestricted egress, which is how data leaves once something is compromised.
- Dangling DNS pointing at released addresses or deleted services.
Prevention beats detection
Policy as code in the pipeline stops the misconfiguration being created, which is cheaper than finding it afterwards. Service control policies and organisation-level guardrails prevent whole categories regardless of what a team writes.
Detection where prevention cannot reach
Continuous configuration scanning across every account — including the ones created by a project team last month — with findings routed to the owning team and a clock running. Reconcile against billing so no account is missed.
The question to answer monthly
"What of ours is reachable from the internet, and should it be?" If the answer takes more than a day to produce, that is the first thing to fix.