Securing cloud accounts
Securing our cloud accounts is not the first thing we usually think about when we think about security. We usually think about the application security topics we will cover in the later sections of this chapter, such as authentication, authorization, and encryption. But if you step back and think about it, all our autonomous services run in our cloud accounts. So, if we do not focus first on securing our cloud accounts, then we have essentially just secured the front door and have left the back door wide open for attack.
There was a story that I read in 2014 about a security breach at a company named Code Spaces that drove home to me the importance of securing our cloud accounts. If you have never heard of this company, it is because the breach put it out of business. A hacker took their cloud account for ransom and when the company fought back, the hacker deleted everything in the account, including the backups, which were housed in the same account.
...