A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild

Steve Turner (Cloud Security Architect · Zealus)

fwd:cloudsec North America 2026 · Day 1

Overview

In his fwd:cloudsec talk, "Slaying the Sprawl: A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild," Steve Turner, a Cloud Security Architect at Zealus, addresses one of the most pressing challenges in modern cybersecurity: how to establish or rebuild an effective cloud security program with limited resources. Turner's presentation cuts through theoretical ideals, offering pragmatic, battle-tested strategies for small teams navigating the complexities of multi-cloud environments. The core thesis revolves around the idea that the biggest mistake isn't choosing the wrong software, but rather designing a workflow that a small team cannot sustain, leading to alert fatigue, morale drain, and ultimately, exploitable vulnerabilities.

Watch on YouTube

Visual summary for A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild by Steve Turner
Visual summary for A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild by Steve Turner

Key moments

  1. 0:00 Introduction: Building cloud security without a large team
  2. 2:50 The 'free sword' trap of native cloud tools
  3. 4:00 Overcoming alert fatigue and the 'logging everything' fallacy
  4. 6:00 The counter spell: Prioritization for small security teams
  5. 6:35 Forging a better artifact: Combining CSPM, CWPP, and KIM
  6. 7:15 Agentless-first strategy: Gain visibility before adding depth
  7. 8:00 Safest path: Gradual adoption, not rip and replace

Slaying the Sprawl: A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild

Speakers: Steve Turner, Cloud Security Architect, Zealus

Conference: fwd:cloudsec

YouTube: https://www.youtube.com/watch?v=wYW9tsYycao

Overview

In his fwd:cloudsec talk, "Slaying the Sprawl: A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild," Steve Turner, a Cloud Security Architect at Zealus, addresses one of the most pressing challenges in modern cybersecurity: how to establish or rebuild an effective cloud security program with limited resources. Turner's presentation cuts through theoretical ideals, offering pragmatic, battle-tested strategies for small teams navigating the complexities of multi-cloud environments. The core thesis revolves around the idea that the biggest mistake isn't choosing the wrong software, but rather designing a workflow that a small team cannot sustain, leading to alert fatigue, morale drain, and ultimately, exploitable vulnerabilities.

Turner emphasizes that success for small teams hinges on strategic prioritization and intelligent tooling choices, rather than simply working harder or hiring more staff. He argues that while native cloud tools, CNAP (Cloud-Native Application Protection Platforms), SIM (Security Information and Event Management) systems, agents, and sensors all have their place, they become "dungeon clutter" if they don't produce prioritized, actionable insights. The talk provides a comprehensive roadmap for identifying critical risks—termed "dragons"—and routing them to the right owners, thereby transforming a reactive, overwhelmed security function into a proactive, efficient defense.

This article delves into Turner's practical guidance, exploring how organizations can forge a resilient cloud security posture by balancing native controls with unified platforms, adopting an "agentless first" approach, and implementing a systematic consolidation blueprint. It's a vital discussion for any organization grappling with the "human glue problem" of integrating disparate security tools and striving to protect their cloud kingdom without the luxury of an expansive security guild.

Background

▶ Watch: Introduction: Building cloud security without a large team (0:00)

The rapid adoption of cloud computing has introduced unprecedented flexibility and scalability for businesses, but it has also ushered in a new era of security challenges often referred to as "sprawl." Organizations frequently find themselves with complex, multi-cloud environments, a mix of legacy and cloud-native applications, and a constant influx of new services. This complexity, coupled with the perennial challenge of limited security personnel, creates a fertile ground for misconfigurations, vulnerabilities, and potential breaches.

Historically, many organizations have fallen into common traps when attempting to secure their cloud infrastructure. One prevalent pitfall, as highlighted by Turner, is the assumption that simply "logging everything" to a Security Information and Event Management (SIM) system will solve all security problems. This approach, which he humorously calls "hoarding," often results in a "great hall of records" that is overwhelming and unsearchable during an incident, sending teams on a "search quest" to manually stitch together a narrative. The promise of "writing correlation rules later" becomes the "famous last words of a level one security mage," leading to a labyrinth from which escape is nearly impossible.

Another significant challenge stems from the allure of "free" native cloud security tools, such as AWS Security Hub or Azure Defender. While these tools are easy to activate and can be effective for enforcing controls closest to the cloud service, relying solely on them across multiple cloud providers creates a "human glue problem." The security team inadvertently becomes the integration layer, spending hundreds of engineering hours wiring together event bridges and Lambda functions to gain a coherent view. This not only negates the perceived cost savings but also leads to severe alert fatigue. Native tools are often "notoriously noisy," generating thousands of low-level warnings without cross-platform context. This constant barrage of notifications drains team morale, causes engineers to stop analyzing risk, and ultimately fosters an environment where "when everything is an emergency, nothing is," creating actual exploitable vulnerabilities as dashboards are ignored.

Turner argues that these issues are exacerbated when security programs are designed for an idealized "20-person security team" rather than the lean teams most organizations actually possess. This mismatch between desired operational model and actual resources inevitably leads to "year 2 regret." The problem is not the existence of these tools, but the expectation that disjointed native stacks can magically form a coherent cloud security program without a unified strategy or platform.

Key Findings

▶ Watch: Overcoming alert fatigue and the 'logging everything' fallacy (4:00)

Steve Turner's talk offers several critical insights and contributions for building effective cloud security programs with limited resources, emphasizing a shift from reactive, resource-intensive approaches to proactive, prioritized defense.

Firstly, Turner's central contribution is the concept of prioritization as the "counter spell" to the "integration curse" and alert fatigue. Small teams, he asserts, do not win by "clearing every goblin" but by "finding the dragon at the treasury door." This means distinguishing between low-impact misconfigurations ("goblins") and findings that create a real, exploitable attack path ("dragons"). A "dragon" is characterized by the confluence of factors such as a public workload, an exploitable vulnerability, an overprivileged identity, and proximity to crown jewel data. This contextual understanding, rather than isolated alerts, is paramount for efficient resource allocation.

Secondly, Turner advocates for a balanced approach to native cloud tools. While acknowledging their strength in enforcing controls close to the service, he strongly recommends using a unified platform as a "campaign map." This platform, often a Cloud-Native Application Protection Platform (CNAP), is designed to correlate security signals across multiple clouds, identities, workloads, and attack paths, providing the cross-platform context that native tools inherently lack. This correlation happens before data hits the SIM, transforming raw logs into actionable intelligence and acting as a "magical index."

Thirdly, the talk introduces a strategic approach to deployment: "agentless first, then sensors." Turner suggests starting with agentless, read-only visibility to gain a comprehensive map of the environment, understand blast radii, and identify "dragons" without requiring any changes to production. This approach helps "earn trust" with engineering teams. Once value is proven, runtime sensors or agents can be selectively deployed to high-exposure, crown jewel, regulated, or actively exploited workloads, providing the necessary depth for prevention and forensics where the operational cost is justified. This intentional use of both coverage (agentless) and depth (sensors) defines a mature security program.

Finally, Turner provides a concrete consolidation blueprint for organizations dealing with existing, sprawling legacy security stacks. This four-phase plan includes:

  1. Scout (30 days): Inventorying existing tools, identifying duplicated findings, and quantifying lost engineering hours.
  2. Equip (60 days): Rolling out agentless visibility and establishing a unified risk baseline, selectively adding sensors for runtime depth.
  3. Purge (90 days): Systematically sun-setting legacy alerts where the new platform has proven coverage, consolidating ownership, and tuning severity.
  4. Shift Left (Ongoing): Integrating Infrastructure as Code (IC) scanning and CI/CD guard rails to prevent new flaws from reaching production environments, thereby stopping "new goblins" at the source.

These findings collectively underscore that effective cloud security in resource-constrained environments is less about acquiring more tools or personnel, and more about strategic prioritization, intelligent integration, and a phased, trust-building approach to deployment and consolidation.

Technical Deep Dive

▶ Watch: The counter spell: Prioritization for small security teams (6:00)

Turner's technical deep dive focuses on the architectural components and strategic considerations for building a robust cloud security program. He dissects common tooling choices, explaining their strengths, weaknesses, and how they should be integrated into a cohesive strategy, particularly for small teams.

At the foundation, native cloud security tools like AWS Security Hub and Azure Defender are acknowledged for their ability to enforce controls closest to the cloud service. For instance, an AWS Security Hub finding might alert on an insecure S3 bucket policy, directly leveraging AWS's internal telemetry. However, their primary limitation is a lack of inherent cross-platform context. In a multi-cloud setup, relying solely on these means the security team becomes the "integration layer," manually connecting disparate dashboards and alerts using custom scripts, EventBridge rules, or Lambda functions. This human integration is costly, time-consuming, and prone to error, leading to the "human glue problem."

The talk critically examines the role of Security Information and Event Management (SIM) systems. While essential for log aggregation, Turner challenges the "log everything" mentality. Forwarding raw data like CloudTrail logs, VPC Flow Logs, and unparsed native alerts to a SIM without prior correlation results in a "mess" that requires extensive manual querying and rule-writing to reconstruct incident timelines. This reactive "search quest" consumes significant engineering hours during critical incidents.

To address these limitations, Turner strongly advocates for a Cloud-Native Application Protection Platform (CNAP). A CNAP acts as a unifying "campaign map" that correlates security signals across various cloud environments (AWS, Azure, GCP), identities, workloads, and potential attack paths. Unlike a SIM, a CNAP provides this correlation before logs are ingested, offering a "magical index" that highlights critical risks. The CNAP concept is typically composed of several key capabilities:

  1. Cloud Security Posture Management (CSPM): Described as the "shield," CSPM continuously assesses the configuration of cloud resources against security best practices, regulatory compliance standards, and organizational policies. It ensures that "fortress walls are properly constructed," identifying misconfigurations in services like S3 buckets, security groups, or IAM roles.
  2. Cloud Workload Protection Platform (CWPP): Referred to as the "sword," CWPP focuses on defending the actual virtual machines and workloads from active threats. Turner provides examples such as Microsoft Defender for Endpoint (in its cloud context) and the Wiz sensor. These solutions provide runtime protection, vulnerability management for hosts, and often include features like anti-malware, host intrusion detection, and application control. Turner clarifies that CWPP solutions can come in both agent-based and agentless forms, with agentless gaining visibility through cloud APIs and snapshots.
  3. Cloud Identity Entitlement Management (CIEM), or KIM as referred to in the talk: This component, the "key," monitors identity and access management (IAM) configurations to ensure "no rogue peasant holds the keys to the royal treasury." CIEM solutions identify toxic combinations of permissions, excessive privileges, and potential identity-based attack paths. Turner notes that while traditionally a separate category, CIEM capabilities are increasingly being consumed and integrated into broader CSPM/CNAP platforms by major players like Palo Alto Networks and Wiz.

A crucial technical distinction made by Turner is the strategic use of agentless vs. agent-based/sensor-based approaches.

  • Agentless visibility is achieved by integrating with cloud provider APIs to collect configuration data, network flow logs, and audit trails. This provides broad "coverage" without requiring any software installation on workloads. It's ideal for initial discovery, understanding the blast radius, and identifying "dragons" without operational overhead for DevOps teams.
  • Runtime sensors or agents provide deeper "depth." These are deployed directly onto workloads (e.g., VMs, containers) and can offer granular insights into process activity, file integrity, network connections, and memory. They are essential for real-time threat detection, prevention, and forensic analysis. Turner advises using sensors selectively for "internet-facing, crown jewel, regulated, or actively exploited" workloads where the added depth justifies the operational cost.

The identification of a "dragon" is a sophisticated correlation task. It's not just a single S3 bucket being public, but understanding its context: Is it serving static images (a "goblin") or is it a "public workload with an exploitable vulnerability tied to an overprivileged identity sitting near crown jewel of data"? This multi-factor analysis, correlating exposure, vulnerability, identity, and data sensitivity, is where a CNAP truly shines by providing the contextual intelligence needed for prioritization.

Finally, the "Shift Left" strategy integrates security into the development lifecycle. This involves using Infrastructure as Code (IaC) scanning tools to identify misconfigurations in Terraform, CloudFormation, or ARM templates before deployment, and implementing CI/CD guard rails to prevent insecure code or configurations from ever reaching production. This proactive approach aims to stop "new flaws" at the earliest possible stage, significantly reducing the security debt in cloud environments.

Demo / Proof of Concept

▶ Watch: Agentless-first strategy: Gain visibility before adding depth (7:15)

Steve Turner's presentation focused primarily on strategic frameworks, architectural principles, and operational methodologies for building and refining cloud security programs. There was no explicit live demonstration or proof-of-concept of a specific tool or exploit during the talk. Instead, the emphasis was on conceptual models and a practical blueprint for implementation rather than showcasing software capabilities.

Defensive Implications

▶ Watch: Safest path: Gradual adoption, not rip and replace (8:00)

Steve Turner's guidance provides a clear and actionable roadmap for defenders seeking to establish or improve their cloud security posture, particularly within resource-constrained environments. The core defensive implications revolve around intelligent prioritization, strategic tooling, and a phased approach to implementation.

Firstly, ruthless prioritization is paramount. Defenders must shift away from trying to "clear every goblin" and instead focus on identifying and mitigating "dragons"—those critical attack paths that combine exposure, vulnerability, identity, and data sensitivity. This requires moving beyond siloed alerts to a contextual understanding of risk. Security teams should develop a clear framework for classifying findings based on their true impact and exploitability, ensuring that limited resources are directed towards the most significant threats. This also implies training engineering teams to understand this prioritization framework, fostering a shared responsibility model.

Secondly, strategic tooling choices are critical. Defenders should resist the temptation to rely solely on disparate native cloud security tools, which create an unsustainable "human glue problem." Instead, the focus should be on adopting a unified platform, such as a Cloud-Native Application Protection Platform (CNAP), that can provide cross-cloud correlation, context, and a consolidated view of risk. This platform acts as a "magical index," transforming noisy, low-level alerts into actionable intelligence. While native tools are valuable for control enforcement at the service level, they should feed into this central "campaign map" for holistic visibility and workflow management.

Thirdly, defenders should embrace an "agentless first" approach for initial visibility and risk assessment. This strategy allows security teams to gain comprehensive coverage of their cloud environment, map blast radii, and identify critical misconfigurations without imposing immediate operational overhead or requiring changes from DevOps teams. This builds trust and provides a foundational understanding before introducing more intrusive measures. For high-exposure, crown jewel, or regulated workloads, runtime sensors or agents should then be selectively and intentionally deployed to provide the necessary depth for real-time threat detection, prevention, and forensics. This balanced approach optimizes both coverage and operational efficiency.

Fourthly, for organizations with existing, sprawling security stacks, defenders must implement a systematic consolidation blueprint. The "Scout, Equip, Purge, Shift Left" methodology provides a structured way to inventory existing tools, deploy new unified platforms, systematically retire redundant or ineffective legacy alerts, and integrate security earlier into the development lifecycle. This phased approach minimizes disruption while progressively enhancing security posture and reducing alert fatigue.

Finally, shifting left is a non-negotiable defensive strategy. Integrating Infrastructure as Code (IaC) scanning and CI/CD guard rails ensures that security flaws are identified and remediated before they ever reach production environments. This proactive measure significantly reduces the attack surface, minimizes security debt, and prevents the accumulation of "new goblins" that would otherwise overwhelm a small security team. By embedding security practices directly into the development pipeline, defenders empower developers to build secure-by-design applications, ultimately strengthening the overall cloud security posture.

Key Takeaways

  • Prioritize Ruthlessly: Small security teams must focus on identifying and mitigating "dragons"—critical attack paths combining public exposure, exploitable vulnerabilities, overprivileged identities, and crown jewel data—rather than attempting to fix every low-impact "goblin" finding.
  • Strategic Tooling Decisions: Avoid the "human glue problem" by selecting unified platforms (like CNAPs) that provide cross-cloud context and correlation. While native tools are valuable for specific control enforcement, they should feed into a central "campaign map" for a coherent security program.
  • Beyond "Log Everything": Simply forwarding all cloud logs to a SIM is not a strategy; it leads to "search quests" and alert fatigue. A CNAP provides crucial correlation and a "magical index" before logs hit the SIM, delivering actionable intelligence.
  • Agentless First, Then Intentional Sensors: Begin with agentless, read-only visibility to gain broad coverage and prove value without impacting production. Then, selectively deploy runtime sensors/agents to high-exposure or crown jewel workloads for deeper threat detection, prevention, and forensics where the operational cost is justified.
  • Systematic Consolidation: For existing, sprawling environments, follow a structured "Scout, Equip, Purge, Shift Left" blueprint to inventory legacy tools, deploy new platforms, retire redundant alerts, and integrate security into the CI/CD pipeline.
  • Context is King: True risk assessment requires understanding the full context of a finding (e.g., what a public S3 bucket contains and who can access it) rather than reacting to isolated alerts, enabling more effective resource allocation.

About the Speaker(s)

Steve Turner is a Cloud Security Architect at Zealus, bringing a wealth of practical experience from the trenches of cloud security. He has a background in building cloud-native architectures and managing complex existing cloud environments. His expertise spans AWS, Azure, AI security, and identity architectures. Turner emphasizes that his insights are derived from real-world scenarios, focusing on what it genuinely takes to be responsible for infrastructure, rather than theoretical concepts. Outside of his professional endeavors, he enjoys tinkering with his home lab, modding vintage iPods, collecting Pokemon artifacts, and humorously battling the "ultimate raid boss"—sleep training a 2-year-old.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent, honest practitioner talk aimed squarely at small-team cloud security leads who are drowning in tool sprawl. Turner knows the material and the advice is sound, but this is a well-organized synthesis of established ideas — agentless-first, CNAP as correlation layer, shift-left CI/CD gates — rather than anything the fwd:cloudsec audience hasn't heard before. Fills a slot, serves its audience, won't be remembered in six months.

Heather Calloway (CISO) — SOLID

Turner delivers a competent, practitioner-focused talk on cloud security program design for lean teams, with genuinely useful framing around alert fatigue, tooling consolidation, and the agentless-first deployment model. The content is honest and operational, but it stays squarely in the architect's lane — there's no governance angle, no accountability structure, and no path for how this problem reaches a CISO, a board, or a regulator.

→ Top-rated talks at fwd:cloudsec North America 2026

All talks from fwd:cloudsec North America 2026