Salt Typhoon and the Long Game Against Telecom Infrastructure
November 25, 2025Holiday-Season Readiness: Why Attackers Love a Skeleton Crew
December 10, 2025By the end of 2025, a clear pattern held across the breaches we investigated: attackers increasingly did not break into networks, they logged into clouds. Stolen credentials, over-permissioned accounts, and misconfigured SaaS tenants were behind a large share of incidents. The uncomfortable reality for Canadian organizations is that moving to the cloud does not outsource security; it reshapes it, and the control plane is now the battleground.
The Shared Responsibility Gap
Cloud and SaaS providers secure their infrastructure, but you remain responsible for how you configure it, who can access it, and what your data does inside it. Default settings favor ease of adoption over security. Sharing links default to permissive, admin roles get handed out liberally, and logging is often off until someone turns it on.
Hardening the Control Plane
- Enforce phishing-resistant MFA on every administrative account in every SaaS platform.
- Audit privileged roles and remove standing admin access in favor of just-in-time elevation.
- Turn on and centralize logging. Many SaaS audit logs are disabled or short-retention by default.
- Review external sharing and third-party app grants, which quietly accumulate risk over time.
Visibility Is the First Step
Most organizations underestimate how many SaaS applications they actually use and how many identities and integrations have access to their data. You cannot secure what you cannot see. We often begin cloud engagements simply by inventorying tenants, admin accounts, and connected third-party applications, and the results routinely surprise the client.
Takeaway
In 2025 attackers logged in rather than broke in. Treat your SaaS and cloud control planes as critical infrastructure: enforce phishing-resistant MFA on all admins, eliminate standing privilege, enable and centralize audit logs, and continuously review sharing and third-party grants.
