<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Onam Security — Blog &amp; Learn</title>
    <link>https://www.onamsecurity.com</link>
    <description>Cloud security posture, attack paths, identity risk and compliance — from the Onam Security team.</description>
    <language>en</language>
    <atom:link href="https://www.onamsecurity.com/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>DSPM implementation checklist: a practical rollout for cloud data</title>
      <link>https://www.onamsecurity.com/resources/blog/dspm-implementation-checklist</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/dspm-implementation-checklist</guid>
      <description>A step-by-step DSPM implementation checklist: inventory every data store, classify it, map who can reach it, and fix exposure in a sensible order.</description>
      <category>Data Security</category>
      <pubDate>Sun, 04 Oct 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Data lineage security: why encryption is a property of the flow, not the bucket</title>
      <link>https://www.onamsecurity.com/resources/blog/data-lineage-security-unencrypted-hops</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/data-lineage-security-unencrypted-hops</guid>
      <description>Every bucket passes its encryption check, yet the data still lands somewhere unprotected. How data lineage security finds the weak hop in a pipeline.</description>
      <category>Data Security</category>
      <pubDate>Sun, 04 Oct 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>IaC security scanning: fix the template, or the finding comes back</title>
      <link>https://www.onamsecurity.com/resources/blog/iac-security-scanning-fix-at-source</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/iac-security-scanning-fix-at-source</guid>
      <description>Console fixes are undone by the next terraform apply. A practical guide to IaC security scanning that traces cloud findings back to the template line.</description>
      <category>Code Security</category>
      <pubDate>Sun, 04 Oct 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>CI/CD security gates that engineers do not bypass</title>
      <link>https://www.onamsecurity.com/resources/blog/ci-cd-security-gates-delta-gating</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/ci-cd-security-gates-delta-gating</guid>
      <description>Security gates that fail every build get switched off. How to design CI/CD security gates around new findings, clear output and an exception path.</description>
      <category>Code Security</category>
      <pubDate>Sun, 04 Oct 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>AI SAST remediation: what an AI code fix should and should not do</title>
      <link>https://www.onamsecurity.com/resources/blog/ai-sast-remediation-fix-branch</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/ai-sast-remediation-fix-branch</guid>
      <description>AI can draft fixes for SAST findings, but it should never merge its own code. A practical look at safe AI SAST remediation, with a review checklist.</description>
      <category>Code Security</category>
      <pubDate>Sun, 04 Oct 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Cloud access reviews: a checklist that ends in decisions, not spreadsheets</title>
      <link>https://www.onamsecurity.com/resources/blog/cloud-access-review-checklist</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/cloud-access-review-checklist</guid>
      <description>Most cloud access reviews are a spreadsheet nobody answers. A practical checklist for reviewing cloud entitlements, including machine identities.</description>
      <category>Identity</category>
      <pubDate>Sun, 04 Oct 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Wiz alternatives in 2026: an honest shortlist, including us</title>
      <link>https://www.onamsecurity.com/resources/blog/wiz-alternatives</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/wiz-alternatives</guid>
      <description>Wiz alternatives in 2026: six cloud security platforms in their vendors' own published words, with links and dates, plus Onam. No scores.</description>
      <category>Buyer's Guide</category>
      <pubDate>Mon, 14 Sep 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>The best CSPM tools in 2026: an honest shortlist, and we are on it</title>
      <link>https://www.onamsecurity.com/resources/blog/best-cspm-tools</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/best-cspm-tools</guid>
      <description>Best CSPM tools in 2026: seven worth shortlisting, each in its vendor's own words with a link and date, plus the five things that now separate them.</description>
      <category>Buyer's Guide</category>
      <pubDate>Mon, 14 Sep 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>What to ask in a cloud security POC: 7 questions for Wiz, Orca, Prisma Cloud and Onam</title>
      <link>https://www.onamsecurity.com/resources/blog/onam-vs-wiz-orca-prisma-cloud</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/onam-vs-wiz-orca-prisma-cloud</guid>
      <description>Running a cloud security POC against Wiz, Orca or Prisma Cloud? Seven questions that separate the platforms, Onam's answers, and a scoring checklist.</description>
      <category>Buyer's Guide</category>
      <pubDate>Sun, 19 Jul 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Beyond GuardDuty: how three-level behavioral detection catches what rules miss</title>
      <link>https://www.onamsecurity.com/resources/blog/cdr-behavioral-threat-detection</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/cdr-behavioral-threat-detection</guid>
      <description>Cloud threat detection needs three levels: rules for single suspicious events, correlation across several events, and statistical behaviour baselines.</description>
      <category>CDR</category>
      <pubDate>Tue, 14 Jul 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>5 AWS misconfigurations that commonly show up on a first scan</title>
      <link>https://www.onamsecurity.com/resources/blog/aws-misconfigurations-first-scan</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/aws-misconfigurations-first-scan</guid>
      <description>Five AWS misconfigurations that commonly show up on a first scan: what they are, why they persist, and how to fix them fast.</description>
      <category>CSPM</category>
      <pubDate>Thu, 09 Jul 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>CIEM vs IAM Security: what's actually the difference?</title>
      <link>https://www.onamsecurity.com/resources/blog/ciem-vs-iam-security</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/ciem-vs-iam-security</guid>
      <description>They sound identical. They aren't. Here's the practical split between IAM Security and Cloud Infrastructure Entitlement Management — and why you need both.</description>
      <category>Identity</category>
      <pubDate>Thu, 02 Jul 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>AI-powered cloud remediation: from finding to a reviewed fix</title>
      <link>https://www.onamsecurity.com/resources/blog/ai-powered-cloud-remediation</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/ai-powered-cloud-remediation</guid>
      <description>AI-powered cloud remediation: fix prompts that name the resource, AI code fixes on a review branch, and attack-path stories that explain why a fix matters.</description>
      <category>Engineering</category>
      <pubDate>Mon, 29 Jun 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Attack paths vs. misconfigurations: why chained findings are your real cloud risk</title>
      <link>https://www.onamsecurity.com/resources/blog/attack-path-4000-to-3</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/attack-path-4000-to-3</guid>
      <description>CSPM tools surface hundreds of misconfigurations. The ones behind breaches chain together; attack path analysis shows which chains are dangerous.</description>
      <category>Attack Path</category>
      <pubDate>Tue, 23 Jun 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>The FAIR model for cloud security: putting a dollar value on your attack surface</title>
      <link>https://www.onamsecurity.com/resources/blog/fair-model-cloud-risk</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/fair-model-cloud-risk</guid>
      <description>FAIR model for cloud risk: CVSS ranks severity, FAIR asks what a breach of this attack surface would cost. How Onam applies a FAIR-style estimate.</description>
      <category>Risk</category>
      <pubDate>Tue, 16 Jun 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Kubernetes RBAC pitfalls that grant cluster-admin by accident</title>
      <link>https://www.onamsecurity.com/resources/blog/kubernetes-rbac-pitfalls</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/kubernetes-rbac-pitfalls</guid>
      <description>Kubernetes RBAC pitfalls: a ClusterRoleBinding here, an aggregated role there, and a role that can only create pods can mount the host filesystem. Six patterns to audit.</description>
      <category>Containers</category>
      <pubDate>Tue, 09 Jun 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>EPSS over CVSS: prioritising the CVEs attackers actually exploit</title>
      <link>https://www.onamsecurity.com/resources/blog/epss-over-cvss</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/epss-over-cvss</guid>
      <description>CVSS tells you how bad a vulnerability could be. EPSS tells you how likely it is to be exploited in the next 30 days. Guess which one predicts breaches.</description>
      <category>Vulnerability</category>
      <pubDate>Tue, 02 Jun 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Why cloud IAM permissions go unused — and why that matters</title>
      <link>https://www.onamsecurity.com/resources/blog/why-cloud-iam-permissions-are-never-used</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/why-cloud-iam-permissions-are-never-used</guid>
      <description>Your IAM policies are accumulating unused permissions faster than your team can audit them. Here's what the data shows and how to close the gap.</description>
      <category>Identity</category>
      <pubDate>Wed, 27 May 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>MITRE ATT&amp;CK for Cloud: mapping real attacks to your posture score</title>
      <link>https://www.onamsecurity.com/resources/blog/mitre-attack-cloud-mapping</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/mitre-attack-cloud-mapping</guid>
      <description>How MITRE ATT&amp;CK for Cloud translates abstract threat techniques into concrete cloud misconfigurations — and how your posture score tracks each one.</description>
      <category>Threat Detection</category>
      <pubDate>Tue, 19 May 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>How we check thousands of rules without agents: the architecture behind Onam</title>
      <link>https://www.onamsecurity.com/resources/blog/agentless-cloud-security-architecture</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/agentless-cloud-security-architecture</guid>
      <description>Agentless cloud security architecture: how Onam scans 7 clouds with read-only posture roles and agentless workload scanning that runs in your account.</description>
      <category>Engineering</category>
      <pubDate>Tue, 05 May 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>What is CSPM (Cloud Security Posture Management)?</title>
      <link>https://www.onamsecurity.com/learn/cspm</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/cspm</guid>
      <description>Cloud Security Posture Management (CSPM) is the continuous, automated inspection of cloud infrastructure configuration for misconfigurations, policy violations and compliance drift. It reads cloud provider APIs to evaluate resources — storage buckets, databases, security groups, IAM roles — against a rule set, then reports what is misconfigured and how to fix it.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is CNAPP (Cloud-Native Application Protection Platform)?</title>
      <link>https://www.onamsecurity.com/learn/cnapp</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/cnapp</guid>
      <description>A Cloud-Native Application Protection Platform (CNAPP) is a single platform that combines cloud posture management, workload protection, identity entitlement analysis, data security and runtime threat detection on one shared data model — so risks that span those domains are correlated rather than reported separately.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is CWPP (Cloud Workload Protection Platform)?</title>
      <link>https://www.onamsecurity.com/learn/cwpp</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/cwpp</guid>
      <description>A Cloud Workload Protection Platform (CWPP) secures the compute workloads running in a cloud environment — virtual machines, containers, serverless functions and managed hosts — by inspecting what is installed and running inside them, rather than how the surrounding cloud infrastructure is configured.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is CIEM (Cloud Infrastructure Entitlement Management)?</title>
      <link>https://www.onamsecurity.com/learn/ciem</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/ciem</guid>
      <description>Cloud Infrastructure Entitlement Management (CIEM) determines the effective permissions of every identity in a cloud environment — human users, service accounts and machine identities — after policies, role chains, service control policies and permission boundaries are resolved, then compares that against permissions actually used.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is DSPM (Data Security Posture Management)?</title>
      <link>https://www.onamsecurity.com/learn/dspm</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/dspm</guid>
      <description>Data Security Posture Management (DSPM) discovers where sensitive data resides across cloud storage, databases and warehouses, classifies it by sensitivity, and determines which identities and network paths can reach it — shifting the security question from how a store is configured to what is actually inside it and who can read it.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is SSPM (SaaS Security Posture Management)?</title>
      <link>https://www.onamsecurity.com/learn/sspm</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/sspm</guid>
      <description>SaaS Security Posture Management (SSPM) continuously assesses the configuration and identity posture of SaaS applications — such as Microsoft 365, Google Workspace, GitHub and Snowflake — detecting misconfigured sharing settings, unprotected admin accounts, excessive permissions and disabled audit logging.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is a cloud attack path?</title>
      <link>https://www.onamsecurity.com/learn/cloud-attack-path</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/cloud-attack-path</guid>
      <description>A cloud attack path is a chain of individually low- or medium-severity findings that together create a route from an entry point — usually the public internet — to a high-value asset such as a database holding sensitive data. Attack path analysis computes these chains across posture, identity, network and workload data.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is agentless cloud security?</title>
      <link>https://www.onamsecurity.com/learn/agentless-cloud-security</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/agentless-cloud-security</guid>
      <description>Agentless cloud security assesses cloud infrastructure and workloads without installing any software on them. Configuration is read through cloud provider APIs with read-only credentials, and workload contents are inspected by analysing point-in-time volume snapshots out-of-band, so nothing runs on the systems being scanned.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is cloud risk quantification?</title>
      <link>https://www.onamsecurity.com/learn/cloud-risk-quantification</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/cloud-risk-quantification</guid>
      <description>Cloud risk quantification is the practice of expressing security risk as a financial figure — a probable dollar loss — rather than a severity label or a proprietary score. It commonly uses the FAIR model (Factor Analysis of Information Risk), which combines how often a loss event is likely to occur with how much that event would cost.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is a choke point in cloud security?</title>
      <link>https://www.onamsecurity.com/learn/choke-point</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/choke-point</guid>
      <description>A choke point is a single resource — often an over-privileged identity or a shared network node — that appears on a large number of distinct attack paths. Because so many routes pass through it, remediating one choke point removes more risk than fixing many isolated findings, which makes it the highest-leverage fix in a cloud environment.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is KSPM (Kubernetes Security Posture Management)?</title>
      <link>https://www.onamsecurity.com/learn/kspm</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/kspm</guid>
      <description>Kubernetes Security Posture Management (KSPM) is the continuous evaluation of Kubernetes clusters against security baselines — RBAC bindings, pod security context, network policy, admission control and secrets handling. It reads cluster state through the Kubernetes API and reports which objects violate policy, why it matters, and how to correct it.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is code security in the cloud?</title>
      <link>https://www.onamsecurity.com/learn/code-security</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/code-security</guid>
      <description>Code security is the practice of finding security defects in the artefacts that build a system — application source, dependencies, infrastructure-as-code templates and pipeline configuration — before they are deployed. It combines static analysis, dependency analysis, IaC scanning and secret detection, applied continuously as code changes.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is cloud secrets management?</title>
      <link>https://www.onamsecurity.com/learn/secrets-management</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/secrets-management</guid>
      <description>Cloud secrets management is the practice of storing, distributing, rotating and auditing credentials — API keys, database passwords, tokens and certificates — so that no application holds a long-lived secret in code or configuration. Secrets live in a dedicated store, are fetched at runtime, and every access is logged.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
