Technical guide · Identity & access
Protect and recover your AWS root account
Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.
Independent cloud security research for the control plane.
Research that follows cloud controls through identity, telemetry, workload context, and recovery.
About the deskTechnical guide · Identity & access
Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.
Cloud Security Desk demonstration dataset · Controls observed
| Domain | Controls observed |
|---|---|
| Direct policies | 91% |
| Trust conditions | 78% |
| Inherited paths | 44% |
| Session context | 31% |
The illustrative review sees most direct policies but less than half of inherited paths and session context.
Four fictional review domains scored against a synthetic 100-control environment. Values demonstrate presentation only and are not research findings.
Trust is a path, not a policy.
27 publications02Detection & responseA detection is only as complete as its evidence path.
26 publications03Workload securityRuntime context decides whether a control matters.
26 publications04AI systemsAI risk begins before the model endpoint.
26 publications05ResilienceRecovery starts with an independent control path.
26 publicationsEvery conclusion identifies its evidence path, source, method, and material limits.
ExploreReview the editorial policy and the desk’s durable correction record.
ExploreNew research and corrections without an email form or subscription gate.
ExploreCloud Security Desk is an independent, open-access publication focused on the evidence behind cloud security controls and control-plane resilience.
The desk connects configuration, identity, telemetry, workload context, and recovery so a control can be evaluated as an evidence path rather than as an isolated setting.
The research covers identity and access, detection and response, workload security, AI systems, and resilience across modern cloud environments.
Each topic is a practical control boundary. A publication can belong to more than one boundary when its evidence and conclusions span them.
Cloud Security Desk is owned and editorially led by Umair Akbar and Ahmed Elshekh. Individual articles identify their byline and any AI assistance; the retrospective 2026 series uses the organizational byline.
Every public publication is free to read. Reuse still depends on the rights, credits, and licenses stated for individual figures, downloads, and third-party sources.
The catalogue, topic indexes, and RSS feed provide public discovery paths without a subscription or sign-in gate.
Illustrative scenarios, synthetic values, and demonstrations are labeled beside the relevant claim or figure so readers do not mistake them for measured customer or provider findings.
Readers can follow numbered references, source and method notes, accessible figure descriptions, stated limitations, and downloadable data when the underlying material can be shared.
Material corrections are recorded publicly, and revised publications retain a visible publication and revision date.