Is Cloud Infrastructure More Complex Than We Think?

Cloud complexity is increasing due to multiple stakeholders and fragmented processes. A recent Volkswagen breach highlights the risks of misconfigurations, particularly those introduced by third-party vendors.

January 11, 2026
5 Minute Read

In my previous post, I talked about how cloud security has become a reactive game - issues only being addressed after they are detected in production. At first glance, it seems there’s a solution in the form of “shift-left” practices - scanning IaC templates and managing configurations before deployment. However, these methods often assume a level of simplicity in cloud environments that just is not common in the real world.

Infrastructure as Code (IaC) was supposed to simplify and standardize cloud deployments, but only 13% of organizations have fully matured their IaC programs. Many still rely on manual processes, “ClickOps” or partial automation that are prone to countless misconfigurations. This complexity is compounded by the number of stakeholders touching the cloud environment: DevOps teams, IT departments, third-party vendors, and even M&A-driven “sub-organizations” operating under the same corporate umbrella. Each one adds a new layer, a new tool, and opens the door to misconfiguration.

The result? A lot more than just theoretical risk. Take the December 2024 incident at Volkswagen: a significant data breach exposed sensitive information including vehicle locations, customer information, and operational details on roughly 800,000 electric vehicles, all traced back to a cloud misconfiguration managed by a third-party provider. In cases like this, organizations relying on external vendors have limited control over their own security posture, leaving them exposed. Reactive cloud security measures and traditional CSPM approaches simply weren’t enough to prevent this incident. But then, what security approach could possibly work when an external vendor holds the keys to your cloud kingdom?

Isn’t it time we rethink cloud security entirely? Instead of resolving problems post-deployment, perhaps we need a truly proactive strategy - one that aligns with the realities of modern, multi-stakeholder, hyper-scaled cloud environments. If we don’t adapt now, we risk chasing one misconfiguration after another, never pausing to address the root cause: complexity itself.

‍

About
Ariel Litmanovich

Ariel Litmanovich is Co-Founder & CTO of Aryon Security, the Cloud Security Enforcement Platform that prevents cloud risks by enforcing policy before deployment. At Matzov, the IDF's elite cybersecurity unit, he led the military's transition to the cloud and designed its secure cloud infrastructure.

Read more articles by author →

Notes & Sources

  1. Is Something Missing in Cloud Security? https://lnkd.in/dKmUGTAj
  2. ‍StackGen 2025 Report https://lnkd.in/d2M6ySQ
  3. ‍Volkswagen Breach https://lnkd.in/dfD7gD4e

‍

Continue reading

October 5, 2026
Ariel Litmanovich
Tom Tsabar
Vlad Babiuk

The Key That Should Not Have Worked

A leaked cloud credential is usually treated as a detection problem. Find it, revoke it, rotate it, and move on. But the Volkswagen and Cariad data exposure raises a more important question: why was there a long-lived credential worth stealing in the first place? When a single reusable key can unlock sensitive cloud data, the leak is only part of the problem - the configuration that allowed that key to exist is the other.

September 28, 2026
Yair Ladizhensky
Vlad Babiuk

The Role That Should Never Have Existed

On 29 July 2019, Capital One disclosed that an attacker had taken data relating to roughly 106 million people across the United States and Canada. The attacker was Paige Thompson, a former Amazon Web Services engineer, who was arrested the same day and convicted on computer fraud charges in June 2022. The company's settlements reached around $190 million.

September 21, 2026
Tom Tsabar

Exploiting Cloud Misconfigurations: How Attackers Find Cloud Attack Paths (Part 1 - The Basics)

Cloud attacks don’t always begin with a vulnerability. Often, they begin with a misconfiguration that gives an attacker a path in. In Part 1 of this series, we look at cloud environments from the attacker’s perspective and break down the three conditions behind many exploitable cloud attack paths: Resource DIscovery, Network Accessibility, and Identity-Based Access.

September 14, 2026
Ariel Litmanovich
Vlad Babiuk

Five Reasons Your Cloud Security Solution Is Failing You

Your cloud security tools may be working exactly as designed. That’s the problem.

Security teams are still finding and fixing the same misconfigurations over and over. The issue isn’t the tools-it’s a reactive model that detects risk after it already exists. Here are five signs that model has reached its limit.

‍

September 7, 2026
Tom Tsabar
Ariel Litmanovich

50 Ways to Break Production - Why Cloud Security Remediation Is Harder Than It Looks

Cloud remediation is rarely as simple as changing a setting. Fixes can break production, require architectural changes or migrations, and conflict with IaC ownership. Prevention takes a different path: enforce the right configuration before deployment, while the resource is still cheap and safe to change. This article explores the challenges of remediating issues safely and effectively, and highlights what teams need to consider when remediation is unavoidable.

July 29, 2026
Ariel Litmanovich
Tom Tsabar
Ido Dar

Cloud ShutterGap: Millions of Cloud Resources Exposed - The Blind Spot CSPM/CNAPP Tools Don’t Cover

Aryon's research reveals millions of misconfigured ephemeral cloud resources, publicly exposed for only moments before being removed. Often, these exposures last only a few minutes, long enough for attackers to discover and exploit them, but too short for traditional CSPM and CNAPP tools to detect. Many of these resources contain highly sensitive information.

Ready to take your first proactive step?