01
Identity and access (IAM)
Over-broad permissions, weak access control, and privilege-escalation paths, the primary cloud breach route.
02
Configuration
Misconfiguration of services, networking, and exposure, the leading cause of cloud incidents.
03
Data protection
Whether sensitive data is encrypted and shielded from public exposure.
04
Logging and monitoring
Whether suspicious activity would actually be detected.
05
Shared-responsibility gaps
The boundaries where responsibility is assumed but not actually covered.