Skip to content
Cloud Security DeskSearch
Menu

Independent cloud security research for the control plane.

Evidence for decisions that live in the control plane.

Research that follows cloud controls through identity, telemetry, workload context, and recovery.

About the desk
Figure 01 · Illustrative evidence sample

Review coverage across the permission path

Cloud Security Desk demonstration dataset · Controls observed

Review coverage across the permission path
DomainControls observed
Direct policies91%
Trust conditions78%
Inherited paths44%
Session context31%

The illustrative review sees most direct policies but less than half of inherited paths and session context.

Source and method

Four fictional review domains scored against a synthetic 100-control environment. Values demonstrate presentation only and are not research findings.

View the evidence in “The permission path you didn’t review”
Publication ledger

Latest from the desk

View all
  1. 01
    Technical guide · Identity & accessProtect and recover your AWS root account
  2. 02
    Technical guide · Identity & accessRemove unused AWS access keys without breaking a job
  3. 03
    Technical guide · Workload securityCheck and stop anonymous access to Azure blobs
  4. 04
    Technical guide · ResilienceRecover a deleted Azure blob with soft delete
How we work

Evidence before assurance.

Every conclusion identifies its evidence path, source, method, and material limits.

Explore
The desk feed

Follow through RSS.

New research and corrections without an email form or subscription gate.

Explore

Questions answered

  1. What is Cloud Security Desk?

    Cloud Security Desk is an independent, open-access publication focused on the evidence behind cloud security controls and control-plane resilience.

    Supporting context

    The desk connects configuration, identity, telemetry, workload context, and recovery so a control can be evaluated as an evidence path rather than as an isolated setting.

  2. Which cloud security areas does the desk cover?

    The research covers identity and access, detection and response, workload security, AI systems, and resilience across modern cloud environments.

    Supporting context

    Each topic is a practical control boundary. A publication can belong to more than one boundary when its evidence and conclusions span them.

  3. Who writes and edits the research?

    Cloud Security Desk is owned and editorially led by Umair Akbar and Ahmed Elshekh. Individual articles identify their byline and any AI assistance; the retrospective 2026 series uses the organizational byline.

    Supporting context
  4. Is the research free to read and reuse?

    Every public publication is free to read. Reuse still depends on the rights, credits, and licenses stated for individual figures, downloads, and third-party sources.

    Supporting context

    The catalogue, topic indexes, and RSS feed provide public discovery paths without a subscription or sign-in gate.

  5. How does the desk separate observed research from demonstrations?

    Illustrative scenarios, synthetic values, and demonstrations are labeled beside the relevant claim or figure so readers do not mistake them for measured customer or provider findings.

    Supporting context
  6. How can readers verify a publication’s evidence?

    Readers can follow numbered references, source and method notes, accessible figure descriptions, stated limitations, and downloadable data when the underlying material can be shared.

    Supporting context

    Material corrections are recorded publicly, and revised publications retain a visible publication and revision date.