ITSecurityWire: Defending the Cloud: A Strategic Approach
ITSecurityWire examined how organisations can strengthen cloud security in the face of increasingly sophisticated attacks, in an expert article from NetSPI’s Nicholas Lynch. Read the preview below or view it online.
+++
Securing identity in the cloud era
Regarding “Defending the Cloud: A Strategic Approach” (ITSecurityWire, September 15): As over 94% of organisations rely on cloud services, attackers are adapting their tactics, exploiting APIs, identity gaps, and trusted relationships to slip under the radar. Nicholas Lynch, Principal Security Consultant at NetSPI, warns that identity is now the perimeter, and attackers are “logging in” rather than breaking in.
Lynch explained that modern adversaries, including groups like Midnight Blizzard and Scattered Spider, are refining their cloud-specific tradecraft, abusing legitimate authentication flows to maintain access. He emphasised that identity compromise is difficult to detect because it looks normal: stolen credentials, tokens and API keys rarely trigger alerts, while over-permissive roles can expose critical systems.
The article also challenges the notion that compliance equals security. Built-in compliance tools may tick boxes but can create a false sense of safety. Legacy approaches such as “lift and shift” migrations often replicate outdated models, leaving gaps that attackers exploit.
To defend against these risks, Lynch advises adopting a cloud-native mindset, enabling centralised logging, mandating multi-factor authentication, and using Cloud Security Posture Management (CSPM) tools to continuously monitor for misconfigurations and excessive permissions. Regular penetration testing, he adds, is key to validating controls and identifying vulnerabilities before adversaries do.
Ultimately, effective cloud defence demands reframing strategies around attacker logic. Continuous validation, strong identity governance and proactive monitoring will define which organisations stay resilient as cloud attacks continue to evolve.
You can read the full article here.
Explore More News
Solutions Review: AI and Enterprise Technology Predictions from Industry Experts for 2026
Nabil Hannan, Field CISO at NetSPI, contributed a 2026 cybersecurity prediction to Solutions Review's article, warning that AI will accelerate rather than eliminate tool sprawl in organizations.
DevOps Digest: 2026 DevOps Predictions – Part 7
Paul Ryan, Senior Director of Web Application Penetration Testing at NetSPI, contributed a prediction to DevOps Digest's article forecasting that API growth is still in its early stages despite significant expansion in 2025.
DevOps Digest: 2026 DevOps Predictions – Part 2
Aaron Shilts, President and CEO of NetSPI, contributes a cautionary prediction about AI security risks in the 2026 DevOps predictions article.