THE SECORVIA BLOG

Cloud security,
explained plainly.

The concepts the platform is built on, posture, reachability, blast radius, identity risk and vulnerability prioritisation , written out properly, without the acronym soup.

Identity · 3 October 2026 · 7 min read

Who can walk into your AWS account from outside?

OIDC, SAML and cross-account trust let outsiders assume roles in your AWS account. How to find each one, plus a free open source CLI that audits them.

Fundamentals · 3 October 2026 · 6 min read

What is an attack path in cloud security?

An attack path is the chain of real hops from an exposed entry point to a sensitive target in your cloud. What the hops are and how tools detect them.

Prioritisation · 5 September 2026 · 5 min read

CVSS, EPSS and KEV: three scores, three different questions

CVSS measures how bad a flaw is, EPSS how likely it is to be exploited, and KEV whether it already has been. How to combine all three in one patch queue.

Identity · 4 September 2026 · 6 min read

CIEM: the over-permissioned identity problem

CIEM finds cloud identities holding more access than they use, and the permission chains that lead to admin. How it works, and how it differs from IAM.

Fundamentals · 3 September 2026 · 7 min read

Blast radius: measuring what falls with a single asset

Blast radius is what an attacker can reach after taking one cloud resource. How it is computed, how it differs from attack paths, and where it misleads.

Prioritisation · 2 September 2026 · 6 min read

Why a CVSS score cannot prioritise your cloud risk

CVSS rates a flaw before anyone has seen your account. Attack paths rank risk by what an attacker can reach. Where each fits, with a side-by-side table.

Fundamentals · 1 September 2026 · 7 min read

What is Cloud Security Posture Management?

CSPM checks cloud configuration against a secure baseline using read-only APIs. What it covers, what it misses, and how it differs from CWPP and CNAPP.

Stop prioritising by guesswork.