Handle with Care: The Fragile Reality of Cloud Access

Handle with Care: The Fragile Reality of Cloud Access

Source: YouTube · SANS Cloud Security · published Oct 30, 2025 · 28:56

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: Break glass and root accounts are critical emergency access mechanisms that are frequently mismanaged, leaving organizations vulnerable to catastrophic breaches if not rigorously protected and tested 0:03.

Key Takeaways:
• Break glass accounts are essential for emergency access but are often overlooked and poorly discussed in cybersecurity strategies 0:07.
• Root accounts, particularly in AWS and Azure, are often mismanaged or stored insecurely, such as on personal devices or in physical safes, creating significant security risks 0:40.
• Attackers exploit weak break glass accounts by resetting passwords via service desks, highlighting the need for strict access controls and monitoring 0:46.
• Over-reliance on default cloud platform roles can grant excessive permissions; organizations must define specific, limited IR accounts and test them regularly 1:20.

Closing: Organizations must prioritize the secure design, strict monitoring, and regular testing of break glass accounts to prevent catastrophic failures during security incidents. Ignoring these mechanisms leaves critical infrastructure vulnerable to both external attacks and internal privilege escalation.

Sources:

  • 0:03 Introduction to break glass accounts.
  • 0:07 Lack of discourse on break glass accounts.
  • 0:40 Mismanagement of root accounts.
  • 0:46 Exploitation of break glass accounts.
  • 1:20 Importance of specific IR accounts and testing.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Uh good morning everybody. Um yeah, break glass accounts is one of the most undisussed things within cyber security I do believe. Um I've been working with organizations for the past 20 years. Uh in the last 10 years, a lot of that has been focused upon the cloud. Uh as uh uh Eric very kindly mentioned, yeah, I've been at SANS for seven years. It's like that anniversary came up. That's the definitely the longest job I've ever had. Um, and it's one of the coolest actually as well. Um, I get the benefits of essentially building out environments that nobody else would have the requirement to build. We have to build systems that are specifically vulnerable to attack uh that are hardened to the nth degree and then we invite four to 500 hackers at a time come in and break it and show us how wron…