Cybersecurity
The Engineer's Guide to Cloud Identity and Entitlement Management (CIEM)
A deep dive into the principles, tools, and best practices for managing permissions and enforcing least privilege in complex multi-cloud environments.
As cloud estates expand across AWS, Azure, and GCP, managing identity and access has become a critical failure point for security. The sheer volume of human and non-human identities, coupled with thousands of granular permissions, creates a complex web of entitlements where over-privileged access is the default, not the exception. This 'permission sprawl' creates countless hidden pathways for privilege escalation, making it a primary target for attackers.
Cloud Identity and Entitlement Management (CIEM) has emerged as a specialized discipline to address this challenge. CIEM provides the necessary visibility and analytics to understand 'effective permissions'—what an identity can actually do—across all cloud providers. This guide explores the core pillars of CIEM, from discovering and visualizing permissions to implementing automated remediation and continuously enforcing the principle of least privilege (PoLP) for a secure cloud infrastructure.
Latest briefings on The Engineer's Guide to Cloud Identity and Entitlement Management (CIEM)
Security
Old Virus Secretly Altered Calculations
A newly analyzed computer virus from over 20 years ago, named fast16.sys, reveals an early Stuxnet-style attack. The malware was designed to selectively target high-precision calculation software, subtly altering results in memory. This highlights a long-standing threat of data manipulation in critical systems.
Neeraj Dhiman ·
Infra
AWS Data Lost Forever After Middle East Damage
AWS has confirmed it cannot recover customer data from a damaged availability zone in the UAE and the entire Bahrain region. The damage, caused by conflict, was so severe it overwhelmed the cloud provider's multi-AZ redundancy designs.
Ashish Kale ·
Infra
Cloudflare Stops Guessing, Makes Websites 150ms Faster
Cloudflare has improved how it connects to websites, cutting connection retries from 52% to just 3.7%. This simple change reduces loading times by over 150 milliseconds for many sites, making a large portion of the web faster.
Ashish Kale ·
Infra
AWS Lambda Unlocks Long-Running Serverless Tasks
AWS Lambda functions can now run for up to 90 minutes, a sixfold increase from the previous 15-minute limit. This major update opens up serverless computing for long-running data processing, machine learning, and other intensive workloads.
Ashish Kale ·
Infra
New AWS Instances Offer a 30% Performance Boost
AWS has released new T8i instances, offering up to 30% better price-performance than older T3 instances. Powered by custom Intel chips, they are designed for common workloads like microservices and development environments, providing a low-cost option.
Ashish Kale ·
Infra
HashiCorp Is Shutting Down Vagrant Cloud Hosting
HashiCorp is shutting down its HCP Vagrant service, which hosts development environment images. Developers and teams using it must migrate their Vagrant boxes to a new provider before the service fully closes on December 31, 2026.
Ashish Kale ·
AI
AI Agent Carries Out First Autonomous Cyberattack
Spain's data protection agency reported the first known data breach by an autonomous AI agent. The agent independently scanned for vulnerabilities, exploited a flaw, and accessed data, signaling a new era of automated cyber threats for businesses to defend against.
Neeraj Dhiman ·
Infra
Stop Paying for CPU Cores You Don't Need
Google Cloud launched its new M4N VM family, designed to stop companies from overpaying for CPU cores they don't need. The VMs offer high memory and I/O for large databases like SAP HANA and Oracle.
Ashish Kale ·
AI
AI Scanners Find Flaws Your Old Tools Miss
Large language models can find security flaws in code that traditional pattern-based scanners miss. GitLab's analysis shows the best approach is using both, with LLMs for nuanced checks and SAST for broad, fast coverage.
Neeraj Dhiman ·
Infra
Google Reveals Its Cloud Incident Response Plan
Google Cloud has published its internal five-step workflow for handling service outages. The framework guides teams from initial verification to post-incident review, aiming to minimize downtime and improve resilience for any company running on the cloud.
Ashish Kale ·
Infra
Google Cloud Built a File System for AI Agents
Google Cloud released Filestore agent volumes, a new managed storage service built for AI agents. It provides a shared, persistent file system to simplify how agents access and process data, eliminating the need for complex custom solutions.
Ashish Kale ·
Infra
Amazon's Next Linux Update May Break Your Apps
Amazon's next-generation Linux, AL2027, is now in preview with a major security change. It enforces SELinux by default, which could break existing applications, forcing developers to update their systems for compatibility and improved security.
Ashish Kale ·
AI
Figma's AI Agents Resolve Security Alerts 70% Faster
Figma built custom AI agents that help its security team investigate alerts and prepare code fixes. The agents learn from past incidents, reducing repetitive work and resolving complex security issues about 70% faster.
Neeraj Dhiman ·
Infra
Cloudflare Now Lets Developers Offer Optional Permissions
Cloudflare now lets developers designate certain app permissions as optional. This means users can decline non-critical requests without breaking the login process, giving them more control and reducing unnecessary data access for applications.
Ashish Kale ·
Infra
Google Cloud Simplifies Its Toughest Security Control
Google Cloud has updated its VPC Service Controls with new policy intelligence tools. This helps security and IT teams more easily understand, troubleshoot, and enforce the digital perimeters that protect their sensitive data from exfiltration.
Ashish Kale ·
Data
Why AWS Is Buying the DuckDB Database Team
AWS is acquiring DuckLabs, the company behind the popular open-source DuckDB database. The move signals tighter integration of the fast, file-based analytics tool with core AWS services, potentially changing how developers work with data in the cloud.
Taranpreet Singh ·
Infra
AWS Is Adding Two Million More Nvidia GPUs
Amazon Web Services is massively expanding its AI infrastructure, planning to add two million more Nvidia GPUs by 2028. This move signals the immense, ongoing demand for AI computing power among cloud customers.
Ashish Kale ·
AI
AWS Wants AI Agents to Automate Your Dev Work
Amazon has open-sourced Kiro Crew, a new system for managing AI coding agents. It lets developers delegate background tasks like code migrations and incident response, freeing them up for more complex work.
Neeraj Dhiman ·
Infra
Cloudflare Workers Are No Longer Just for HTTP
Cloudflare Workers can now accept raw TCP connections, ending an eight-year limitation to just HTTP. This major update unlocks new, non-web use cases like gRPC, IoT, and gaming servers on Cloudflare's global edge network.
Ashish Kale ·
Infra
Pulumi's New AI Hunts for Hidden Cloud Security Flaws
Pulumi has launched Neo Security, an AI-powered tool that acts like an agent to find complex security vulnerabilities in cloud infrastructure that traditional code scanners often miss. It aims to secure systems by analyzing the entire setup.
Ashish Kale ·
Infra
Cloudflare Gives Good Bots a Way to Identify Themselves
Cloudflare has launched a new self-service portal for bot operators to register their bots. This makes Cloudflare's bot directory more accurate, helping website owners better distinguish between helpful automated traffic and malicious activity.
Ashish Kale ·
Tech
The Web Is Getting Hundreds of New Domain Endings
For the first time since 2012, hundreds of new web domain endings like .slop and .ai are coming. This creates new branding opportunities and security risks for businesses, who will need to adapt their strategies.
Navdeep Kaur Mahal ·
Tech
SoundCloud Lets Artists Keep 100% of Music Sales
SoundCloud is testing a new feature letting artists sell music directly to fans from their profiles. The platform is taking no commission on these sales, aiming to provide a better way for listeners to support musicians directly.
Taranpreet Singh ·
Data
AWS Acquires DuckDB and Pledges to Keep It Open
Amazon Web Services (AWS) has acquired DuckLabs, the company behind the popular open-source database DuckDB. Despite the acquisition, DuckDB's projects will remain free and open-source under the MIT license, managed by the independent DuckDB Foundation.
Taranpreet Singh ·
Infra
The Cloud Service That Started It All Turns 20
Amazon EC2, the service that launched the public cloud, just turned twenty. It started with a single server type in one location and has since become the foundation for millions of applications and businesses worldwide.
Ashish Kale ·
Infra
Google AI Now Plans Your Cloud Migration in Minutes
Google Cloud's Migration Center now uses AI to create rapid cost assessments for moving to the cloud. This new feature automates a complex process that previously took weeks of manual analysis, helping teams modernize infrastructure faster.
Ashish Kale ·
Infra
Cloudflare Built a Lightweight Browser for Automation
Cloudflare has launched Kitesurf, a lightweight browser engine designed for automated tasks. It runs on serverless Workers, making it far more efficient for tools like Playwright and Puppeteer than running a full version of Chrome.
Ashish Kale ·
AI
AI Agents Don't Fit Your Security Playbook
Companies are giving employees powerful AI agents, but these agents don't fit into existing security frameworks. This creates a major blind spot for identity and access management, leaving systems vulnerable to new kinds of attacks.
Neeraj Dhiman ·
Infra
Google Cloud Now Protects Keys From Quantum Attacks
Google Cloud's Key Management Service now lets you import your own encryption keys using a quantum-safe method. This protects sensitive data from the future threat of quantum computers powerful enough to break today's standard encryption.
Ashish Kale ·
Infra
Your Cloud Data Might Be Trapped Forever
A public TV station lost access to 70 years of archives after its cloud vendor failed. The data is safe on servers in a third-party data center, but a contractual dispute means no one can legally access it.
Ashish Kale ·
Frequently asked questions
How is CIEM different from Cloud Security Posture Management (CSPM)?
CSPM focuses on identifying misconfigurations in cloud resources, like an unencrypted S3 bucket or an exposed network port. CIEM, in contrast, focuses exclusively on the identity and access layer, analyzing permissions and entitlements to find risks like potential privilege escalation paths. The two are complementary pillars of a Cloud-Native Application Protection Platform (CNAPP).
What is a 'toxic combination' of permissions that CIEM tools find?
A toxic combination refers to a set of seemingly innocuous permissions that, when held by a single identity, create a privilege escalation path. For example, a role with permissions to pass a role to an EC2 instance and also create an EC2 instance could be used to launch a machine with administrator-level privileges. CIEM tools are designed to detect these complex, multi-step attack paths.
Why is managing non-human identity entitlements so critical?
Non-human identities, such as service accounts, roles, and serverless functions, vastly outnumber human users in modern cloud environments. They are often granted broad, static permissions for operational ease, making them a prime target for attackers seeking to move laterally or escalate privileges. CIEM is essential for scoping their permissions down to the bare minimum required.
What is 'Permissions Creep' and how does CIEM prevent it?
Permissions creep is the gradual accumulation of excessive entitlements by an identity over time as its role or function changes. CIEM helps prevent this by providing continuous monitoring of permission usage, identifying unused or redundant entitlements that can be safely revoked. This enforces a 'just-in-time' and 'least privilege' access model.