← All posts
Cloud Security14 Apr 2026·1 min read·By

Cloud access keys that outlive the people who created them

Share

A short note on long-lived keys and forgotten service accounts, plus a half-hour review you can do this week.

Short one this time.

A pattern we keep running into on cloud reviews: an access key created years ago by a developer who has since left, still active, with far more permission than whatever it's used for. Sometimes nobody knows what it's used for at all. Sometimes it's sitting in a CI pipeline, or in a Git repo that turned out to be public.

A review you can do in about half an hour, whichever cloud you're on:

  • List every access key and service account with its last-used date.
  • Anything unused for 90 days, disable it (don't delete yet). If nothing breaks in two weeks, delete it.
  • Anything with admin or owner rights, ask who needs that and write down the answer.
  • Check the break-glass admin account has MFA, and that its password isn't saved in someone's browser.

Where the platform supports it, move CI jobs and workloads to short-lived credentials (IAM roles on AWS, workload identity federation on GCP, managed identities on Azure) so there's no long-lived key to leak in the first place.

Then set a calendar reminder to do it again in three months. That part matters more than it sounds.

Share

Comments (0)

No public comments yet.

Leave a comment

Comments are checked by hand before they go live.

Most read on the blog

  1. 1What we'd put on a one-page security update for the board
  2. 2Zero trust when you have one IT person and three branches
  3. 3Logging for companies that can't justify a SIEM yet
  4. 4Ransomware prep for mid-sized companies: start with the restore
  5. 5Is your guest Wi-Fi on the same network as the accounts PC?

Related posts