Cloud penetration testing: A practical guide
Cloud penetration testing is primarily about identities, permissions, trust relationships, and exposed services; it’s not just IP ranges and open ports.
Welcome to CloudSec Academy, your guide to navigating the alphabet soup of cloud security acronyms and industry jargon. Cut through the noise with clear, concise, and expertly crafted content covering fundamentals to best practices.
See how Wiz turns cloud security fundamentals into real-world results.
Cloud penetration testing is primarily about identities, permissions, trust relationships, and exposed services; it’s not just IP ranges and open ports.
External penetration testing assesses the exploitability of public-facing assets. It doesn’t just determine whether vulnerabilities exist; it also indicates whether attackers can actually reach and leverage them.
In this post, we’ll explore some of the challenges that can complicate cloud data classification, along with the benefits that come with this crucial step—and how a DSPM tool can help make the entire process much simpler.
In this article, we’ll explore what cloud risk management entails and take an in-depth look at the tools that can keep your systems safe.
Watch how Wiz turns instant visibility into rapid remediation.
Claude Mythos security explained: how Anthropic's vulnerability-finding AI reshapes the threat model and the practical steps teams can take to defend.
A cloud security architect designs the security model for cloud environments. That model includes the standards, patterns, controls, and guardrails that engineering teams use when building and operating in the cloud.
A configuration management database (CMDB) is a centralized repository of IT assets (also known as “configuration items”) and the relationships between them. The key word is relationships.
API security protects your APIs and the data behind them from threats. Learn the top OWASP risks, best practices, and how to secure APIs in the cloud.
Software as a service (SaaS) refers to cloud-based software applications that can be accessed over the internet without any installation or maintenance on local devices.
Container scanning detects vulnerabilities, misconfigurations, and secrets in container images and runtime environments. Learn how it works, what to scan for, and how to integrate it across the container lifecycle.
Learn the principles of cloud workload protection platforms (CWPP), how to apply them, and why a unified cloud security platform offers enhanced protection.
Compare the best vulnerability management tools of 2026, from open-source scanners to CNAPP platforms, and learn how to choose the right fit for your cloud.
Vulnerability scanning finds exploitable weaknesses across code, containers, and cloud before attackers do. Learn how it works & key types for better security.
Vulnerability prioritization helps you manage your cloud risk efficiently. Discover how to pinpoint threats with context, automation, and real-time insights.
Threat detection and response (TDR) is a cybersecurity discipline that combines continuous monitoring, threat identification, investigation, and containment to find and stop attacks before they cause damage.
Security as Code (SaC) is a methodology that integrates security measures directly into the software development process. It involves codifying security policies and decisions, and automating security checks, tests, and gates within the DevOps pipeline.
Learn to navigate the complexities of cloud security, including the knowledge and tools required to build a robust and proactive defense against ever-evolving cyber threats.
Google Kubernetes Engine (GKE), the managed Kubernetes solution from Google Cloud, is designed to help manage containerized applications through built-in security features that protect sensitive data and minimize potential risks.
Cloud infrastructure security describes the strategies, policies, and measures that organizations implement to protect cloud-based systems, data, and infrastructure from threats and vulnerabilities.