The first line.
WHY IT MATTERS MOST
Whoever holds a cloud account holds everything in it, and can create resources at your cost.
WHAT TO DO
A unique strong password A second authentication step, required for everyone Recovery details current and independent More than one administrator
WHAT TO SECURE MOST TIGHTLY
The root or owner account.
Use it rarely, and work from restricted accounts day to day.
WHAT TO AVOID
Sharing the owner account Daily use of administrative credentials Recovery to an address on a domain held in the same account
THAT LAST POINT
Circular dependency. If the domain fails, recovery fails.
WHAT TO MONITOR
Login activity Permission changes Resources created
WHAT TO REVIEW
Every account and role, quarterly.
WHAT TO DO IF CREDENTIALS MAY BE EXPOSED
Rotate them immediately Review what was created Check billing for unexpected activity
WHAT TO NEVER PLACE IN CODE OR A REPOSITORY
Access keys.
That is a common route to expensive compromise.