The Cloud Misconfiguration Problem
When most people imagine a cyber breach, they picture a sophisticated attacker using advanced techniques to force their way through defences. The reality of most cloud data breaches is less dramatic but no less damaging: a misconfiguration that leaves data publicly accessible, or credentials that allow unauthorised access because multi-factor authentication was never enabled. According to multiple industry studies, cloud misconfiguration is consistently identified as a leading cause of data exposure — affecting organisations of every size.
Cloud platforms are extraordinarily capable, but that capability comes with complexity. Microsoft 365 alone has hundreds of configurable security settings across Exchange, SharePoint, Teams, OneDrive, Azure AD, and Intune. AWS manages security across dozens of services, each with its own access control model. A single misconfigured S3 bucket set to public access, a SharePoint site with permissions left open for a contractor who is no longer engaged, or an Azure AD tenant without conditional access policies can expose sensitive data to anyone who knows where to look.
Microsoft 365: Common Exposure Points
Microsoft 365 is the dominant cloud productivity platform for businesses, and it is a frequent source of security incidents — not because Microsoft's platform is insecure, but because the configuration responsibility lies with the customer. The most common exposure patterns include: email forwarding rules that automatically forward all emails to an external address (often created by a compromised account and then forgotten), SharePoint sites or OneDrive folders shared with "Anyone with the link" rather than specific users, Teams channels connected to external guests without proper governance, and email security settings that allow unauthenticated external senders to impersonate internal domains.
Microsoft 365 account compromise — where an attacker obtains valid credentials through phishing or password spraying — is one of the most common precursors to BEC fraud and internal data theft. Without multi-factor authentication, a compromised password is sufficient to give an attacker full access to email, files, contacts, and calendars.
AWS and Cloud Infrastructure Misconfigurations
For businesses using AWS or other cloud infrastructure services, the most common misconfiguration-related exposures involve storage buckets (S3 in AWS) set to public access, databases without network-level access controls, API endpoints without authentication, and overly permissive IAM roles that grant broader access than required. Many of these misconfigurations occur during development — where convenience is prioritised over security — and then persist into production environments.
The consequences can be significant: an exposed S3 bucket containing customer records, a publicly accessible database with user credentials, or an API endpoint that allows unauthenticated data extraction. In several documented cases, data exposed in this way was discovered and published by third parties before the business became aware of the exposure — triggering immediate Privacy Act obligations alongside the technical remediation challenge.
Accidental Exposure vs Active Attack
One of the important distinctions in cloud security incidents is between active attacks (where a criminal deliberately targets your systems) and accidental exposure (where misconfiguration makes data accessible without any active exploitation). From a Privacy Act perspective, both situations create the same notification obligations if personal information was accessible to unauthorised parties. From an insurance perspective, coverage depends on how the policy is drafted.
Most modern cyber insurance policies cover both active attacks and accidental data exposure events — including misconfiguration incidents. However, it is worth confirming this with your broker when taking out or renewing a policy, as older or more basic policies may require evidence of an active attack to trigger coverage.
What Cyber Insurance Covers for Cloud Breaches
A cyber insurance policy should respond to cloud breach incidents with: forensic investigation to determine what data was accessible and for how long, legal advice on Privacy Act notification obligations, the cost of notifying affected individuals, regulatory investigation response if the Privacy Commissioner initiates proceedings, and third-party liability if customers make claims arising from the exposure of their data. Business interruption coverage applies if the cloud service was rendered unavailable as part of the incident.
The business interruption component is particularly important for businesses that are highly dependent on cloud services for day-to-day operations. An extended Microsoft 365 outage caused by an account compromise — while forensic investigators work to remediate the breach — can halt operations just as effectively as an on-premises ransomware attack.
Reducing Cloud Risk Through Configuration
The most cost-effective action any business can take to reduce cloud security risk is enabling multi-factor authentication on all cloud accounts — particularly Microsoft 365, Google Workspace, and any cloud infrastructure management consoles. This single control eliminates the most common account compromise pathway. Beyond MFA, a periodic review of sharing permissions on cloud storage, external guest access in collaboration platforms, and email security settings can identify and remediate misconfiguration exposures before they become incidents.
Cyber insurance provides the financial protection when these controls fail or before they are put in place. For businesses in the process of improving their cloud security posture, insurers and brokers can often provide guidance on which controls have the greatest premium impact — creating a financial incentive to prioritise the right improvements.
About the Author
CyberCover Team is part of the CyberCover team — dedicated to making cyber insurance transparent and accessible for NZ businesses of all sizes.