Protecting cloud resources.
WHAT TO CONFIGURE FIRST
Multi-factor authentication for every account with access Roles at the narrowest scope, assigned to groups Firewall rules denying by default No public access on storage unless deliberate
WHAT TO USE FOR SECRETS
The secret manager, accessed by attached service identity.
WHY
It removes credentials from configuration and code entirely.
WHAT TO ENABLE
Audit logging, retained Security posture and threat detection services Organisation policies constraining what may be created
WHAT ORGANISATION POLICIES CAN ENFORCE
Permitted regions Prohibition of external access Prohibition of service account key creation Required labels
WHY THAT THIRD ONE MATTERS
It prevents the commonest credential leak at source.
WHAT TO REVIEW REGULARLY
Public exposure of resources Role assignments, particularly broad ones Service accounts and their keys Findings from the posture service
WHAT THE COMMONEST EXPOSURES ARE
Storage buckets publicly readable Service account keys committed to repositories Over-broad roles Firewall rules permitting everything
WHAT TO PREPARE
A response procedure for a compromised project.