<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Onam Security — Blog &amp; Learn</title>
    <link>https://www.onamsecurity.com</link>
    <description>Cloud security posture, attack paths, identity risk and compliance — from the Onam Security team.</description>
    <language>en</language>
    <atom:link href="https://www.onamsecurity.com/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>What to ask in a cloud security POC: 7 questions for Wiz, Orca, Prisma Cloud and Onam</title>
      <link>https://www.onamsecurity.com/resources/blog/onam-vs-wiz-orca-prisma-cloud</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/onam-vs-wiz-orca-prisma-cloud</guid>
      <description>Running a proof of concept against Wiz, Orca Security or Prisma Cloud? These are the seven questions to ask during the POC that actually separate the platforms — with Onam's answers on the record, and a checklist to score every vendor on your shortlist.</description>
      <category>Buyer's Guide</category>
      <pubDate>Sun, 19 Jul 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Beyond GuardDuty: how three-tier behavioral detection catches what rules miss</title>
      <link>https://www.onamsecurity.com/resources/blog/cdr-behavioral-threat-detection</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/cdr-behavioral-threat-detection</guid>
      <description>Rule-based detection catches known attack signatures. Statistical behavioral baselines catch incremental privilege escalation. ML anomaly detection catches the rest. Here's why you need all three.</description>
      <category>CDR</category>
      <pubDate>Tue, 14 Jul 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>The 5 AWS misconfigurations we find in 90% of first scans</title>
      <link>https://www.onamsecurity.com/resources/blog/aws-misconfigurations-first-scan</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/aws-misconfigurations-first-scan</guid>
      <description>After thousands of first-time AWS scans, the same five misconfigurations show up in nearly every environment. Here's what they are — and how to fix them fast.</description>
      <category>CSPM</category>
      <pubDate>Thu, 09 Jul 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>CIEM vs IAM Security: what's actually the difference?</title>
      <link>https://www.onamsecurity.com/resources/blog/ciem-vs-iam-security</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/ciem-vs-iam-security</guid>
      <description>They sound identical. They aren't. Here's the practical split between IAM Security and Cloud Infrastructure Entitlement Management — and why you need both.</description>
      <category>Identity</category>
      <pubDate>Thu, 02 Jul 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>AI-powered cloud remediation: from finding to fix in minutes</title>
      <link>https://www.onamsecurity.com/resources/blog/ai-powered-cloud-remediation</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/ai-powered-cloud-remediation</guid>
      <description>The average MTTR for cloud security findings is 47 days. AI-powered remediation — context-aware code fixes, Ansible playbooks for CVEs, and threat narratives — is how we close that gap.</description>
      <category>Engineering</category>
      <pubDate>Mon, 29 Jun 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Attack paths vs. misconfigurations: why toxic combinations are your real cloud risk</title>
      <link>https://www.onamsecurity.com/resources/blog/attack-path-4000-to-3</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/attack-path-4000-to-3</guid>
      <description>Most CSPM tools surface hundreds of misconfigurations. The ones that actually lead to breaches are the ones that chain together — and most tools can't show you which chains are dangerous.</description>
      <category>Attack Path</category>
      <pubDate>Tue, 23 Jun 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>The FAIR model for cloud security: putting a dollar value on your attack surface</title>
      <link>https://www.onamsecurity.com/resources/blog/fair-model-cloud-risk</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/fair-model-cloud-risk</guid>
      <description>CVSS scores rank vulnerability severity. FAIR answers the question your board actually cares about: what does this attack surface cost if it's breached? Here's how we apply it at Onam.</description>
      <category>Risk</category>
      <pubDate>Tue, 16 Jun 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Kubernetes RBAC pitfalls that grant cluster-admin by accident</title>
      <link>https://www.onamsecurity.com/resources/blog/kubernetes-rbac-pitfalls</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/kubernetes-rbac-pitfalls</guid>
      <description>A ClusterRoleBinding here, an aggregated role there — and suddenly your read-only role can create pods that mount the host filesystem. Six patterns to audit today.</description>
      <category>Containers</category>
      <pubDate>Tue, 09 Jun 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>EPSS over CVSS: prioritising the CVEs attackers actually exploit</title>
      <link>https://www.onamsecurity.com/resources/blog/epss-over-cvss</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/epss-over-cvss</guid>
      <description>CVSS tells you how bad a vulnerability could be. EPSS tells you how likely it is to be exploited in the next 30 days. Guess which one predicts breaches.</description>
      <category>Vulnerability</category>
      <pubDate>Tue, 02 Jun 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>Why 90% of cloud IAM permissions are never used — and why that matters</title>
      <link>https://www.onamsecurity.com/resources/blog/why-cloud-iam-permissions-are-never-used</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/why-cloud-iam-permissions-are-never-used</guid>
      <description>Your IAM policies are accumulating unused permissions faster than your team can audit them. Here's what the data shows and how to close the gap.</description>
      <category>Identity</category>
      <pubDate>Wed, 27 May 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>MITRE ATT&amp;CK for Cloud: mapping real attacks to your posture score</title>
      <link>https://www.onamsecurity.com/resources/blog/mitre-attack-cloud-mapping</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/mitre-attack-cloud-mapping</guid>
      <description>How MITRE ATT&amp;CK for Cloud translates abstract threat techniques into concrete cloud misconfigurations — and how your posture score tracks each one.</description>
      <category>Threat Detection</category>
      <pubDate>Tue, 19 May 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>How we check thousands of rules without agents: the architecture behind Onam</title>
      <link>https://www.onamsecurity.com/resources/blog/agentless-cloud-security-architecture</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/resources/blog/agentless-cloud-security-architecture</guid>
      <description>A technical deep-dive into how Onam scans dozens of cloud services across 7 clouds using only read-only access — no agents, no network changes, no configuration drift.</description>
      <category>Engineering</category>
      <pubDate>Tue, 05 May 2026 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>What is CSPM (Cloud Security Posture Management)?</title>
      <link>https://www.onamsecurity.com/learn/cspm</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/cspm</guid>
      <description>Cloud Security Posture Management (CSPM) is the continuous, automated inspection of cloud infrastructure configuration for misconfigurations, policy violations and compliance drift. It reads cloud provider APIs to evaluate resources — storage buckets, databases, security groups, IAM roles — against a rule set, then reports what is misconfigured and how to fix it.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is CNAPP (Cloud-Native Application Protection Platform)?</title>
      <link>https://www.onamsecurity.com/learn/cnapp</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/cnapp</guid>
      <description>A Cloud-Native Application Protection Platform (CNAPP) is a single platform that combines cloud posture management, workload protection, identity entitlement analysis, data security and runtime threat detection on one shared data model — so risks that span those domains are correlated rather than reported separately.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is CWPP (Cloud Workload Protection Platform)?</title>
      <link>https://www.onamsecurity.com/learn/cwpp</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/cwpp</guid>
      <description>A Cloud Workload Protection Platform (CWPP) secures the compute workloads running in a cloud environment — virtual machines, containers, serverless functions and managed hosts — by inspecting what is installed and running inside them, rather than how the surrounding cloud infrastructure is configured.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is CIEM (Cloud Infrastructure Entitlement Management)?</title>
      <link>https://www.onamsecurity.com/learn/ciem</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/ciem</guid>
      <description>Cloud Infrastructure Entitlement Management (CIEM) determines the effective permissions of every identity in a cloud environment — human users, service accounts and machine identities — after policies, role chains, service control policies and permission boundaries are resolved, then compares that against permissions actually used.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is DSPM (Data Security Posture Management)?</title>
      <link>https://www.onamsecurity.com/learn/dspm</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/dspm</guid>
      <description>Data Security Posture Management (DSPM) discovers where sensitive data resides across cloud storage, databases and warehouses, classifies it by sensitivity, and determines which identities and network paths can reach it — shifting the security question from how a store is configured to what is actually inside it and who can read it.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is SSPM (SaaS Security Posture Management)?</title>
      <link>https://www.onamsecurity.com/learn/sspm</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/sspm</guid>
      <description>SaaS Security Posture Management (SSPM) continuously assesses the configuration and identity posture of SaaS applications — such as Microsoft 365, Google Workspace, GitHub and Snowflake — detecting misconfigured sharing settings, unprotected admin accounts, excessive permissions and disabled audit logging.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is a cloud attack path?</title>
      <link>https://www.onamsecurity.com/learn/cloud-attack-path</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/cloud-attack-path</guid>
      <description>A cloud attack path is a chain of individually low- or medium-severity findings that together create a route from an entry point — usually the public internet — to a high-value asset such as a database holding sensitive data. Attack path analysis computes these chains across posture, identity, network and workload data.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is agentless cloud security?</title>
      <link>https://www.onamsecurity.com/learn/agentless-cloud-security</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/agentless-cloud-security</guid>
      <description>Agentless cloud security assesses cloud infrastructure and workloads without installing any software on them. Configuration is read through cloud provider APIs with read-only credentials, and workload contents are inspected by analysing point-in-time volume snapshots out-of-band, so nothing runs on the systems being scanned.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is cloud risk quantification?</title>
      <link>https://www.onamsecurity.com/learn/cloud-risk-quantification</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/cloud-risk-quantification</guid>
      <description>Cloud risk quantification is the practice of expressing security risk as a financial figure — a probable dollar loss — rather than a severity label or a proprietary score. It commonly uses the FAIR model (Factor Analysis of Information Risk), which combines how often a loss event is likely to occur with how much that event would cost.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is a choke point in cloud security?</title>
      <link>https://www.onamsecurity.com/learn/choke-point</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/choke-point</guid>
      <description>A choke point is a single resource — often an over-privileged identity or a shared network node — that appears on a large number of distinct attack paths. Because so many routes pass through it, remediating one choke point removes more risk than fixing many isolated findings, which makes it the highest-leverage fix in a cloud environment.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is KSPM (Kubernetes Security Posture Management)?</title>
      <link>https://www.onamsecurity.com/learn/kspm</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/kspm</guid>
      <description>Kubernetes Security Posture Management (KSPM) is the continuous evaluation of Kubernetes clusters against security baselines — RBAC bindings, pod security context, network policy, admission control and secrets handling. It reads cluster state through the Kubernetes API and reports which objects violate policy, why it matters, and how to correct it.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is code security in the cloud?</title>
      <link>https://www.onamsecurity.com/learn/code-security</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/code-security</guid>
      <description>Code security is the practice of finding security defects in the artefacts that build a system — application source, dependencies, infrastructure-as-code templates and pipeline configuration — before they are deployed. It combines static analysis, dependency analysis, IaC scanning and secret detection, applied continuously as code changes.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is cloud secrets management?</title>
      <link>https://www.onamsecurity.com/learn/secrets-management</link>
      <guid isPermaLink="true">https://www.onamsecurity.com/learn/secrets-management</guid>
      <description>Cloud secrets management is the practice of storing, distributing, rotating and auditing credentials — API keys, database passwords, tokens and certificates — so that no application holds a long-lived secret in code or configuration. Secrets live in a dedicated store, are fetched at runtime, and every access is logged.</description>
      <category>Learn</category>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
