<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Securosis Research</title><link>https://securosis.com/</link><description>Recent research from Securosis</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 31 Jul 2026 19:24:52 +0000</lastBuildDate><atom:link href="https://securosis.com/research/feed/index.xml" rel="self" type="application/rss+xml"/><item><title>The Coming Cloudpocolypse: Disrupting the Cloud Shared Responsibility Model</title><link>https://securosis.com/research/presentations/cloudpocolypse/</link><pubDate>Mon, 28 Apr 2025 00:00:00 +0000</pubDate><guid>https://securosis.com/research/presentations/cloudpocolypse/</guid><description>
&lt;p&gt;Chris &amp;amp; Rich&amp;rsquo;s session at RSAC 2025 &lt;em&gt;&lt;strong&gt;The Coming Cloudpocolypse: Disrupting the Cloud Shared Responsibility Model&lt;/strong&gt;&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;You can also find the Slides here&lt;/p&gt;</description></item><item><title>Defining Security Invariants</title><link>https://securosis.com/research/howto/security-invariants/</link><pubDate>Thu, 09 Jan 2025 17:00:00 +0000</pubDate><guid>https://securosis.com/research/howto/security-invariants/</guid><description>
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Note:&lt;/strong&gt; This post has been revised to include the new capabilities released by AWS prior to re:Invent 2024.&lt;br&gt;
You can also check out the re:Invent presentation we did with Securosis: &amp;ldquo;Security invariants: From enterprise chaos to cloud order&amp;rdquo; slides - video&lt;/em&gt;&lt;/p&gt;</description></item><item><title>Implementing Security Invariants in an AWS Management Account</title><link>https://securosis.com/research/howto/payer-invariants/</link><pubDate>Tue, 24 Dec 2024 19:41:28 -0500</pubDate><guid>https://securosis.com/research/howto/payer-invariants/</guid><description>
&lt;p&gt;I&amp;rsquo;ve spoken a lot about Security Invariants, but all of them have been implemented using Organizational Policies. That&amp;rsquo;s great, but organizational policies don&amp;rsquo;t apply to the Organizational Management Account (aka &amp;ldquo;payer&amp;rdquo;). So how does one implement invariants in a payer account?&lt;/p&gt;
&lt;p&gt;AWS would tell you that you shouldn&amp;rsquo;t be giving anyone access to the payer account, so the need for invariants should be minimal. However, that doesn&amp;rsquo;t reflect the reality that AWS never protected its customers from themselves and prevented the enabling of Organizations or Control Tower in an account with existing workloads. I would say this is a failure of Customer Obsession and demonstrates Security is not the Top Priority. AWS would hide behind shared responsibility and blame the customer.&lt;/p&gt;
&lt;p&gt;Regardless, there are many cases where workloads are in a payer account, and as a security person, you need to live with those workloads while protecting the rest of the AWS Organization. So, how do we build invariants into a payer account when SCPs and RCPs don&amp;rsquo;t apply?&lt;/p&gt;
&lt;p&gt;Enter Permission Boundaries.&lt;/p&gt;</description></item><item><title>Security invariants: From enterprise chaos to cloud order</title><link>https://securosis.com/research/presentations/security-invariants/</link><pubDate>Tue, 03 Dec 2024 00:00:00 +0000</pubDate><guid>https://securosis.com/research/presentations/security-invariants/</guid><description>
&lt;p&gt;Rich and Chris&amp;rsquo;s session at re:Invent 2024 on &lt;em&gt;&lt;strong&gt;Security invariants: From enterprise chaos to cloud order&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Slides and an accompanying Blog Post that included the re:Invent releases that didn&amp;rsquo;t make it into our talk.&lt;/p&gt;</description></item><item><title>CloudSec Hero to Zero: Self-Obsolescing Through Prolific Efficiency</title><link>https://securosis.com/research/presentations/cloudsec-hero-to-zero/</link><pubDate>Tue, 07 May 2024 00:00:00 +0000</pubDate><guid>https://securosis.com/research/presentations/cloudsec-hero-to-zero/</guid><description>
&lt;p&gt;Chris &amp;amp; Rich&amp;rsquo;s session at RSAC 2024 &lt;em&gt;&lt;strong&gt;CloudSec Hero to Zero: Self-Obsolescing Through Prolific Efficiency&lt;/strong&gt;&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;You can also find the Slides here.
Read more about the Universal Cloud Threat Model in the research library.&lt;/p&gt;</description></item><item><title>The Universal Cloud Threat Model</title><link>https://securosis.com/research/papers/the-universal-cloud-threat-model-for-cloud-native-security/</link><pubDate>Tue, 23 Apr 2024 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/the-universal-cloud-threat-model-for-cloud-native-security/</guid><description>
&lt;p&gt;The Universal Cloud Threat Model is a collaboration between PrimeHarbor Technologies and Securosis. It is a &lt;em&gt;cloud-centric&lt;/em&gt; threat model to help organizations focus security efforts on the most-common attacks most organizations will experience. The UCTM is designed as an adjunct to other threat models. From the introduction:&lt;/p&gt;</description></item><item><title>Modernizing SecOps for Cloud</title><link>https://securosis.com/research/papers/modernizing-secops-for-cloud/</link><pubDate>Fri, 23 Feb 2024 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/modernizing-secops-for-cloud/</guid><description>
&lt;p&gt;Security Operations, SecOps for short, has been one of the more difficult security domains to modernize for cloud. It requires a combination of new subject matter expertise, new technologies, process updates, and even a slightly different mindset. Cloud impacts SecOps in ways both obvious and subtle, and because most organizations still have datacenters and offices, teams need to add new skills and update operations while still supporting everything already on their plates. It’s a daunting challenge, but one that can be made much easier to tackle by distilling down, into the core of how cloud changes things, and taking lessons from the successes of early adopters.&lt;/p&gt;</description></item><item><title>Minimally Viable Cloud Governance</title><link>https://securosis.com/research/howto/multicloud/</link><pubDate>Wed, 14 Feb 2024 12:02:58 -0500</pubDate><guid>https://securosis.com/research/howto/multicloud/</guid><description>
&lt;h2 id="you-are-multi-cloud-whether-you-like-it-or-not"&gt;You are multi-cloud whether you like it or not.&lt;/h2&gt;
&lt;p&gt;Most organizations have a preferred cloud provider. This is the provider where they have the most engineering expertise, have negotiated the best discounts, and have built the paved road experience.&lt;/p&gt;</description></item><item><title>Deploying AWS Backup</title><link>https://securosis.com/research/howto/awsbackup/</link><pubDate>Tue, 05 Sep 2023 09:23:37 -0400</pubDate><guid>https://securosis.com/research/howto/awsbackup/</guid><description>
&lt;p&gt;tl;dr - here is a link to the scripts&lt;/p&gt;
&lt;h2 id="what-ransomware-in-aws-looks-like"&gt;What Ransomware in AWS looks like&lt;/h2&gt;
&lt;p&gt;In a typical ransomware attack, a threat actor will attempt to encrypt files on critical machines belonging to the victim. In exchange for a cryptocurrency payment, the threat actor will provide the decryption key and software to the victim, who then has to go through the arduous process of restoring their machines. The encrypted data is typically lost forever if the victim refuses to pay the ransom.&lt;/p&gt;</description></item><item><title>Leveraging AWS SSO (aka Identity Center) with Google Workspaces - version 2</title><link>https://securosis.com/research/howto/aws-identity-center-google-v2/</link><pubDate>Sun, 25 Jun 2023 18:25:26 -0400</pubDate><guid>https://securosis.com/research/howto/aws-identity-center-google-v2/</guid><description>
&lt;blockquote&gt;
&lt;p&gt;This is a revised version of the original post Leveraging AWS SSO (aka Identity Center) with Google Workspaces based on the new announcement AWS IAM Identity Center now supports automated user provisioning from Google Workspace The original post is still valid, and in someways may be better, but this version has it&amp;rsquo;s own advantages.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Setting up AWS IAM Identity Center (successor to AWS Single Sign-On), hereafter called AWS SSO (because I have to pay AWS for egress on this site), is an excellent service to help you get rid of IAM users and enforce identity best practices around second-factor authentication, on and off-boarding employees, and assigning the right level of access depending on job function.&lt;/p&gt;
&lt;p&gt;Companies using Google Workspaces for email and collaboration can also leverage their Google accounts to access AWS via AWS SSO. The process isn&amp;rsquo;t clearly documented, and the provisioning support isn&amp;rsquo;t integrated, so here is a post to help you set it all up.&lt;/p&gt;</description></item><item><title>Leveraging AWS SSO (aka Identity Center) with Google Workspaces</title><link>https://securosis.com/research/howto/aws-identity-center-google/</link><pubDate>Sat, 27 May 2023 06:25:26 -0400</pubDate><guid>https://securosis.com/research/howto/aws-identity-center-google/</guid><description>
&lt;p&gt;Setting up AWS IAM Identity Center (successor to AWS Single Sign-On), hereafter called AWS SSO (because I have to pay AWS for egress on this site), is an excellent service to help you get rid of IAM users and enforce identity best practices around second-factor authentication, on and off-boarding employees, and assigning the right level of access depending on job function.&lt;/p&gt;
&lt;p&gt;Companies using Google Workspaces for email and collaboration can also leverage their Google accounts to access AWS via AWS SSO. The process isn&amp;rsquo;t clearly documented, and the provisioning support isn&amp;rsquo;t integrated, so here is a post to help you set it all up.&lt;/p&gt;</description></item><item><title>Leveraging AWS SSO (aka Identity Center) with Azure AD</title><link>https://securosis.com/research/howto/aws-identity-center-azuread/</link><pubDate>Tue, 16 May 2023 20:33:45 -0400</pubDate><guid>https://securosis.com/research/howto/aws-identity-center-azuread/</guid><description>
&lt;p&gt;Setting up AWS IAM Identity Center (successor to AWS Single Sign-On) henceforth called AWS SSO (because AWS charges for egress), is an excellent service to help you get rid of IAM users and enforce identity best practices around second-factor authentication, on and off-boarding employees, and assigning the right level of access depending on job function.&lt;/p&gt;</description></item><item><title>Cloud Penetration Tests</title><link>https://securosis.com/research/howto/pentest/</link><pubDate>Sat, 15 Apr 2023 11:00:04 -0400</pubDate><guid>https://securosis.com/research/howto/pentest/</guid><description>
&lt;p&gt;This past weekend I spoke at BSides Nashville on offensive operations in AWS: &lt;em&gt;&lt;strong&gt;Get outta my host and into my cloud&lt;/strong&gt;&lt;/em&gt;. While I was finishing the talk, Nick Jones published a blog post of his own: On AWS Penetration Testing.&lt;/p&gt;</description></item><item><title>Incident Response in AWS</title><link>https://securosis.com/research/howto/aws-ir/</link><pubDate>Sat, 27 Aug 2022 12:50:04 -0400</pubDate><guid>https://securosis.com/research/howto/aws-ir/</guid><description>
&lt;p&gt;At BSides Atlanta today I gave a talk on how to handle an incident in AWS. The talk and this post is intended to help those already familiar with the principles of Incident Response to understand what to do when the incident involves the AWS Control Plane. You can find the Slides here.&lt;/p&gt;</description></item><item><title>The Cloud is Dark and Full of Terrors</title><link>https://securosis.com/research/presentations/dark-and-full-of-terrors/</link><pubDate>Sat, 02 Oct 2021 00:00:00 +0000</pubDate><guid>https://securosis.com/research/presentations/dark-and-full-of-terrors/</guid><description>
&lt;p&gt;Chris&amp;rsquo;s presentation to BSides Augusta in 2021 - &lt;em&gt;&lt;strong&gt;The Cloud is Dark and Full of Terrors&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Slides and Blog Post are available.&lt;/p&gt;</description></item><item><title>Data Security in the SaaS Age</title><link>https://securosis.com/research/papers/data-security-in-the-saas-age/</link><pubDate>Sat, 26 Jun 2021 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/data-security-in-the-saas-age/</guid><description>
&lt;p&gt;Data security remains elusive. You can think of it as something of a holy grail. We’ve been espousing the idea of data-centric security for years, focusing on protecting the data, so you can worry less about securing devices, networks, and associated infrastructure. As with most big ideas, it seemed like a good idea at the time.&lt;/p&gt;</description></item><item><title>Securing APIs: The New Application Attack Surface</title><link>https://securosis.com/research/papers/securing-apis-the-new-application-attack-surface-2/</link><pubDate>Sat, 26 Jun 2021 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/securing-apis-the-new-application-attack-surface-2/</guid><description>
&lt;p&gt;The way applications are built, deployed, and maintained in most organizations is being disrupted. Macro changes include the ongoing cloud migration disrupting the tech stack, new application design patterns bringing microservices to the forefront, and DevOps changing dev/release practices. As we’ve been slowly navigating this sea change, the common thread across these changes is increasing reliance on Application Programming Interfaces (APIs).&lt;/p&gt;</description></item><item><title>Security Hygiene: The First Line of Security</title><link>https://securosis.com/research/papers/security-hygiene-the-first-line-of-security/</link><pubDate>Sat, 26 Jun 2021 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/security-hygiene-the-first-line-of-security/</guid><description>
&lt;p&gt;After many decades as security professionals, it’s depressing to keep seeing the same issues and mistakes. It feels like we’re stuck in hacker Groundhog Day. Get up, clean up the mistakes made by users or administrators, handle a new attack, and fill out compliance reports, only to have to do it all over again the next day.&lt;/p&gt;</description></item><item><title>Enterprise DevSecOps</title><link>https://securosis.com/research/papers/enterprise-devsecops-2/</link><pubDate>Tue, 10 Dec 2019 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/enterprise-devsecops-2/</guid><description>
&lt;p&gt;This is our latest iteration on how to build a DevSecOps program. This research paper is the result of hundreds of hours of research and several hundred conversations with Fortune 1000 firms on the challenges companies face and the problems they are most interested in tackling. We go deep into covering all phases and facets of secure application development. And we did a complete reversal on the naming convention; from DevOps to DevSecOps. It became obvious during our calls that despite the idealism involved with leaving ‘Sec’ out of the title, security is getting short shifted and it needs to be called out.&lt;/p&gt;</description></item><item><title>Understanding and Selecting RASP 2019 Research Paper</title><link>https://securosis.com/research/papers/understanding-and-selecting-rasp-2019-research-paper-2/</link><pubDate>Tue, 19 Nov 2019 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/understanding-and-selecting-rasp-2019-research-paper-2/</guid><description>
&lt;p&gt;So what is RASP? Runtime Application Self-Protection (RASP) is an application security technology which embeds into an application or application runtime environment, examining requests at the application layer to detect attacks and misuse in real time. RASP functions in the application context, which enables it to monitor security – and apply controls – very precisely. This means better detection because you see what the application is being asked to do, and can also offer better performance, as you only need to check the relevant subset of policies for each request.&lt;/p&gt;</description></item></channel></rss>