Cloud Security Foundation
Identity is the new perimeter. Learn how cloud environments are actually secured.
- Level
- Foundation
- Format
- Live online cohort with recorded sessions
- Modules
- 5 assessed modules
About this program
The control plane is an API, identity replaces the network boundary, and a misconfigured storage bucket does more damage than a missing patch ever did. None of that is intuitive if your mental model came from data-centre networking.
This program builds the cloud model properly, then applies it: how access is granted and abused, what the control plane records, which misconfigurations actually cause breaches, and how to prioritise fixing them.
It is Azure-led with substantial AWS coverage, because the concepts transfer and most enterprises run both. It assumes no prior cloud security experience.
What you will be able to do
- Explain the cloud identity model and where its weak points are
- Design access controls that hold up against common attack paths
- Read and interpret cloud control-plane logs
- Recognise the misconfigurations that cause real breaches
- Prioritise posture findings into work that actually reduces risk
- Apply shared-responsibility thinking to a real architecture
Syllabus
5 modules. Every one ends in assessed, written work that a practitioner reviews.
Shared responsibility, and where teams misread it • The control plane versus the data plane • Why the network perimeter stopped carrying the load • Cloud service models and their security implications
Cloud identity models across Azure and AWS compared • Conditional access, MFA design and the gaps attackers use • Roles, permissions and standing privilege • Service principals, managed identities and machine credentials
What cloud activity and sign-in logs record • What cloud logging does not capture by default • Centralising multi-cloud telemetry into one investigation surface • Cost-aware logging decisions
The misconfigurations behind real cloud breaches • Storage, database and secrets exposure • Triaging thousands of posture findings down to what matters • Network controls that still apply, and those that do not
Cloud attack paths from initial access to data access • Investigating a suspicious sign-in end to end • Containment in an environment you cannot unplug • Documenting a cloud investigation
What you finish with
Portfolio-grade work, reviewed by a practitioner — the part an interviewer can actually ask you about.
- 1A cloud identity design with documented trade-offs
- 2A prioritised remediation plan built from raw posture findings
- 3A cloud sign-in compromise investigation with timeline and root cause
Is Cloud Security Foundation the right starting point?
Forty-five minutes with a mentor will settle it. If a different program suits your background better, they will say so.
Prefer email? connectbluelayersacademy@gmail.com
What the call actually is
- 45 minutes, with a mentor rather than a sales team
- A written recommendation you keep either way
- An honest answer if a program is not right for you yet
We do not guarantee placement, and we will say so on the call. What we are accountable for is whether you finish able to do the work.
