The Log

Notes from the field

Practical write-ups on cloud security posture, compliance frameworks, and what auditors actually look for — from the team doing the assessments.

COMP-SOC212 min readJune 2026

SOC 2 Type II, six months out: what to fix first

Most SOC 2 findings trace back to five recurring gaps — access reviews that never happened, logging that isn't retained long enough, and change management that lives in someone's head instead of a ticket. Here's the order we'd tackle them in if your audit window opens in six months, and why sequencing matters more than working every control at once.

Read the file →
SEC-IAM7 min read

The IAM policy that looked fine and wasn't

A wildcard resource in an otherwise scoped policy statement quietly granted far more access than intended. How we found it, and a checklist for catching the same pattern in your own AWS and Azure roles.

Read the file →
SEC-CSPM6 min read

CIS benchmarks aren't a checklist — here's how to use them

Treating CIS controls as a pass/fail scan misses the point. A look at how to prioritize findings by actual exposure instead of raw count, so your team fixes the ten things that matter before the ninety that don't.

Read the file →
COMP-GDPR9 min read

Multi-cloud data residency, without the guesswork

Running workloads across AWS, Azure, and GCP makes GDPR data residency harder to reason about, not easier. A practical framework for mapping where data actually lives versus where you assume it does.

Read the file →
OPS-IR8 min read

The first hour of a cloud incident response

What to do — and specifically what not to do — in the first sixty minutes after a suspicious API call shows up in your CloudTrail logs, based on incidents we've actually responded to.

Read the file →
COMP-PCI10 min read

PCI-DSS in the cloud: scoping is the whole game

The single biggest lever for reducing PCI-DSS audit cost and effort is aggressive, correct network segmentation. A walkthrough of how we scope cardholder data environments before a single control gets tested.

Read the file →

Want this in your inbox?

Get one field note a month — no newsletter fluff, just what we're seeing in real assessments.