FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

← All research

Cybersecurity

The Engineer's Guide to Cloud Identity and Entitlement Management (CIEM)

A deep dive into the principles, tools, and best practices for managing permissions and enforcing least privilege in complex multi-cloud environments.

As cloud estates expand across AWS, Azure, and GCP, managing identity and access has become a critical failure point for security. The sheer volume of human and non-human identities, coupled with thousands of granular permissions, creates a complex web of entitlements where over-privileged access is the default, not the exception. This 'permission sprawl' creates countless hidden pathways for privilege escalation, making it a primary target for attackers.

Cloud Identity and Entitlement Management (CIEM) has emerged as a specialized discipline to address this challenge. CIEM provides the necessary visibility and analytics to understand 'effective permissions'—what an identity can actually do—across all cloud providers. This guide explores the core pillars of CIEM, from discovering and visualizing permissions to implementing automated remediation and continuously enforcing the principle of least privilege (PoLP) for a secure cloud infrastructure.

Latest briefings on The Engineer's Guide to Cloud Identity and Entitlement Management (CIEM)

  • Security

    Old Virus Secretly Altered Calculations

    A newly analyzed computer virus from over 20 years ago, named fast16.sys, reveals an early Stuxnet-style attack. The malware was designed to selectively target high-precision calculation software, subtly altering results in memory. This highlights a long-standing threat of data manipulation in critical systems.

    Neeraj Dhiman ·

  • Infra

    AWS Data Lost Forever After Middle East Damage

    AWS has confirmed it cannot recover customer data from a damaged availability zone in the UAE and the entire Bahrain region. The damage, caused by conflict, was so severe it overwhelmed the cloud provider's multi-AZ redundancy designs.

    Ashish Kale · 2h ago

  • Infra

    Cloudflare Stops Guessing, Makes Websites 150ms Faster

    Cloudflare has improved how it connects to websites, cutting connection retries from 52% to just 3.7%. This simple change reduces loading times by over 150 milliseconds for many sites, making a large portion of the web faster.

    Ashish Kale · 1d ago

  • Infra

    AWS Lambda Unlocks Long-Running Serverless Tasks

    AWS Lambda functions can now run for up to 90 minutes, a sixfold increase from the previous 15-minute limit. This major update opens up serverless computing for long-running data processing, machine learning, and other intensive workloads.

    Ashish Kale · 2d ago

  • Infra

    New AWS Instances Offer a 30% Performance Boost

    AWS has released new T8i instances, offering up to 30% better price-performance than older T3 instances. Powered by custom Intel chips, they are designed for common workloads like microservices and development environments, providing a low-cost option.

    Ashish Kale · 3d ago

  • Infra

    HashiCorp Is Shutting Down Vagrant Cloud Hosting

    HashiCorp is shutting down its HCP Vagrant service, which hosts development environment images. Developers and teams using it must migrate their Vagrant boxes to a new provider before the service fully closes on December 31, 2026.

    Ashish Kale · 3d ago

  • AI

    AI Agent Carries Out First Autonomous Cyberattack

    Spain's data protection agency reported the first known data breach by an autonomous AI agent. The agent independently scanned for vulnerabilities, exploited a flaw, and accessed data, signaling a new era of automated cyber threats for businesses to defend against.

    Neeraj Dhiman · 4d ago

  • Infra

    Stop Paying for CPU Cores You Don't Need

    Google Cloud launched its new M4N VM family, designed to stop companies from overpaying for CPU cores they don't need. The VMs offer high memory and I/O for large databases like SAP HANA and Oracle.

    Ashish Kale · 4d ago

  • AI

    AI Scanners Find Flaws Your Old Tools Miss

    Large language models can find security flaws in code that traditional pattern-based scanners miss. GitLab's analysis shows the best approach is using both, with LLMs for nuanced checks and SAST for broad, fast coverage.

    Neeraj Dhiman · 4d ago

  • Infra

    Google Reveals Its Cloud Incident Response Plan

    Google Cloud has published its internal five-step workflow for handling service outages. The framework guides teams from initial verification to post-incident review, aiming to minimize downtime and improve resilience for any company running on the cloud.

    Ashish Kale · 5d ago

  • Infra

    Google Cloud Built a File System for AI Agents

    Google Cloud released Filestore agent volumes, a new managed storage service built for AI agents. It provides a shared, persistent file system to simplify how agents access and process data, eliminating the need for complex custom solutions.

    Ashish Kale · 5d ago

  • Infra

    Amazon's Next Linux Update May Break Your Apps

    Amazon's next-generation Linux, AL2027, is now in preview with a major security change. It enforces SELinux by default, which could break existing applications, forcing developers to update their systems for compatibility and improved security.

    Ashish Kale · 6d ago

  • AI

    Figma's AI Agents Resolve Security Alerts 70% Faster

    Figma built custom AI agents that help its security team investigate alerts and prepare code fixes. The agents learn from past incidents, reducing repetitive work and resolving complex security issues about 70% faster.

    Neeraj Dhiman · 2w ago

  • Infra

    Cloudflare Now Lets Developers Offer Optional Permissions

    Cloudflare now lets developers designate certain app permissions as optional. This means users can decline non-critical requests without breaking the login process, giving them more control and reducing unnecessary data access for applications.

    Ashish Kale · 2w ago

  • Infra

    Google Cloud Simplifies Its Toughest Security Control

    Google Cloud has updated its VPC Service Controls with new policy intelligence tools. This helps security and IT teams more easily understand, troubleshoot, and enforce the digital perimeters that protect their sensitive data from exfiltration.

    Ashish Kale · 2w ago

  • Data

    Why AWS Is Buying the DuckDB Database Team

    AWS is acquiring DuckLabs, the company behind the popular open-source DuckDB database. The move signals tighter integration of the fast, file-based analytics tool with core AWS services, potentially changing how developers work with data in the cloud.

    Taranpreet Singh · 2w ago

  • Infra

    AWS Is Adding Two Million More Nvidia GPUs

    Amazon Web Services is massively expanding its AI infrastructure, planning to add two million more Nvidia GPUs by 2028. This move signals the immense, ongoing demand for AI computing power among cloud customers.

    Ashish Kale · 3w ago

  • AI

    AWS Wants AI Agents to Automate Your Dev Work

    Amazon has open-sourced Kiro Crew, a new system for managing AI coding agents. It lets developers delegate background tasks like code migrations and incident response, freeing them up for more complex work.

    Neeraj Dhiman · 3w ago

  • Infra

    Cloudflare Workers Are No Longer Just for HTTP

    Cloudflare Workers can now accept raw TCP connections, ending an eight-year limitation to just HTTP. This major update unlocks new, non-web use cases like gRPC, IoT, and gaming servers on Cloudflare's global edge network.

    Ashish Kale · 3w ago

  • Infra

    Pulumi's New AI Hunts for Hidden Cloud Security Flaws

    Pulumi has launched Neo Security, an AI-powered tool that acts like an agent to find complex security vulnerabilities in cloud infrastructure that traditional code scanners often miss. It aims to secure systems by analyzing the entire setup.

    Ashish Kale · 3w ago

  • Infra

    Cloudflare Gives Good Bots a Way to Identify Themselves

    Cloudflare has launched a new self-service portal for bot operators to register their bots. This makes Cloudflare's bot directory more accurate, helping website owners better distinguish between helpful automated traffic and malicious activity.

    Ashish Kale · 3w ago

  • Tech

    The Web Is Getting Hundreds of New Domain Endings

    For the first time since 2012, hundreds of new web domain endings like .slop and .ai are coming. This creates new branding opportunities and security risks for businesses, who will need to adapt their strategies.

    Navdeep Kaur Mahal · 3w ago

  • Tech

    SoundCloud Lets Artists Keep 100% of Music Sales

    SoundCloud is testing a new feature letting artists sell music directly to fans from their profiles. The platform is taking no commission on these sales, aiming to provide a better way for listeners to support musicians directly.

    Taranpreet Singh · 3w ago

  • Data

    AWS Acquires DuckDB and Pledges to Keep It Open

    Amazon Web Services (AWS) has acquired DuckLabs, the company behind the popular open-source database DuckDB. Despite the acquisition, DuckDB's projects will remain free and open-source under the MIT license, managed by the independent DuckDB Foundation.

    Taranpreet Singh · 3w ago

  • Infra

    The Cloud Service That Started It All Turns 20

    Amazon EC2, the service that launched the public cloud, just turned twenty. It started with a single server type in one location and has since become the foundation for millions of applications and businesses worldwide.

    Ashish Kale · 3w ago

  • Infra

    Google AI Now Plans Your Cloud Migration in Minutes

    Google Cloud's Migration Center now uses AI to create rapid cost assessments for moving to the cloud. This new feature automates a complex process that previously took weeks of manual analysis, helping teams modernize infrastructure faster.

    Ashish Kale · 3w ago

  • Infra

    Cloudflare Built a Lightweight Browser for Automation

    Cloudflare has launched Kitesurf, a lightweight browser engine designed for automated tasks. It runs on serverless Workers, making it far more efficient for tools like Playwright and Puppeteer than running a full version of Chrome.

    Ashish Kale · Aug 23, 2026

  • AI

    AI Agents Don't Fit Your Security Playbook

    Companies are giving employees powerful AI agents, but these agents don't fit into existing security frameworks. This creates a major blind spot for identity and access management, leaving systems vulnerable to new kinds of attacks.

    Neeraj Dhiman · Aug 21, 2026

  • Infra

    Google Cloud Now Protects Keys From Quantum Attacks

    Google Cloud's Key Management Service now lets you import your own encryption keys using a quantum-safe method. This protects sensitive data from the future threat of quantum computers powerful enough to break today's standard encryption.

    Ashish Kale · Aug 21, 2026

  • Infra

    Your Cloud Data Might Be Trapped Forever

    A public TV station lost access to 70 years of archives after its cloud vendor failed. The data is safe on servers in a third-party data center, but a contractual dispute means no one can legally access it.

    Ashish Kale · Aug 20, 2026

Frequently asked questions

How is CIEM different from Cloud Security Posture Management (CSPM)?

CSPM focuses on identifying misconfigurations in cloud resources, like an unencrypted S3 bucket or an exposed network port. CIEM, in contrast, focuses exclusively on the identity and access layer, analyzing permissions and entitlements to find risks like potential privilege escalation paths. The two are complementary pillars of a Cloud-Native Application Protection Platform (CNAPP).

What is a 'toxic combination' of permissions that CIEM tools find?

A toxic combination refers to a set of seemingly innocuous permissions that, when held by a single identity, create a privilege escalation path. For example, a role with permissions to pass a role to an EC2 instance and also create an EC2 instance could be used to launch a machine with administrator-level privileges. CIEM tools are designed to detect these complex, multi-step attack paths.

Why is managing non-human identity entitlements so critical?

Non-human identities, such as service accounts, roles, and serverless functions, vastly outnumber human users in modern cloud environments. They are often granted broad, static permissions for operational ease, making them a prime target for attackers seeking to move laterally or escalate privileges. CIEM is essential for scoping their permissions down to the bare minimum required.

What is 'Permissions Creep' and how does CIEM prevent it?

Permissions creep is the gradual accumulation of excessive entitlements by an identity over time as its role or function changes. CIEM helps prevent this by providing continuous monitoring of permission usage, identifying unused or redundant entitlements that can be safely revoked. This enforces a 'just-in-time' and 'least privilege' access model.

✦ Notifire newsletter

Follow The Engineer's Guide to Cloud Identity and Entitlement Management (CIEM)

We track The Engineer's Guide to Cloud Identity and Entitlement Management (CIEM) as the news cycle moves. Get the briefings that matter in your inbox — free, no spam.

The day's most important tech briefings. No spam, unsubscribe anytime.

Related topics

  • Zero-trust architecture

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
  • Atom feed
  • LinkedIn
  • X / Twitter
  • Facebook
  • Instagram
  • YouTube
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

    FeedExploreAskAlertsSavedProfile