The Policy Nobody Actually Enforced @SecurityWeekly
The Policy Nobody Actually Enforced  @SecurityWeekly
Uploaded June 2026 | Updated September 2026, 2 weeks ago
Many organizations generate least-privilege IAM policies but never deploy them. That leaves existing permissions available for attackers to abuse after compromising workloads like CI/CD runners.

Instead of depending on thousands of manually applied policies, Sandy Bird describes a behavioral approach: if an identity suddenly attempts a privileged action it has never performed before—like creating access keys—the request is blocked until approved. The goal is to stop attacker behavior even when permission cleanup hasn't happened.

Is it more effective to continuously reduce permissions, or should organizations focus first on enforcing guardrails around unexpected privileged actions?

Subscribe to our podcasts: securityweekly.com/subscribe

#CloudSecurity #IAM #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec
The Policy Nobody Actually EnforcedAI Killed the 5-Year RoadmapLegacyHive, ACR Stealer, Hugging Face, Route 53, and Kieran Human from Threatlocker - SWN #600Say Easy, Do Hard - Performance Through People - Greg Hoffman - BSW #459The End of SMS LoginsHidden Risks in Security DefaultsWhy AI Can’t Replace PentestersAttackers Find Bugs Before CVEsSystem Prompts Can FailSecurity Teams Become Their ToolsLegitimate Tools Became Attack ToolsAre Schools Falling Behind AI?
Security Weekly - A CRA Resource |

The Policy Nobody Actually Enforced

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER