Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Blog Artikel
01.06.2026
2 min read

Cloud Misconfigurations Explained & Secured | Baggenstos Cloud Security

Symbolic image: glowing digital cloud with an orange padlock against a dark, networked data background

Das Wichtigste in Kürze

  • 80% of all cloud attacks exploit misconfigurations, with human error behind 82% of them. According to Microsoft, weak identity control (IAM) is the leading cause of all compromises
  • Baggenstos continuously checks cloud configurations against baselines using the Microsoft Defender Suite and Darktrace / Cloud. Privileged access only via approval workflow

Ever watched Tom Cruise in Mission: Impossible? Villains and secret agents wear masks, impersonate others and blend in seamlessly. For Baggenstos, a very real mission is securing cloud infrastructures — provided configurations are reviewed on a regular basis.

You don’t need to be a secret agent. At Baggenstos, alarm bells start ringing figuratively speaking when a customer’s database suddenly becomes publicly accessible on the internet. What may seem practical from a developer’s home-office perspective quickly turns into a nightmare for cybersecurity teams — and an open attack surface for digital crime.

Dormant Attack Surface

One incorrect tick here, one faulty entry there: according to Microsoft, over 80 per cent of all attacks are caused by cloud infrastructure misconfigurations. A silent epidemic, so to speak. Security misconfigurations rank second in the OWASP Top Ten 2025. The figures are alarming: 23% of all cloud security incidents result from misconfigurations, with human error being the root cause in 82% of cases.

Hackers are logging in — increasingly targeting Identity and Access Management (IAM) to take over legitimate accounts. According to Microsoft’s own Digital Defense Report, weak or missing identity controls are now the leading cause of compromises.

Depending on the service provider agreement, customers often retain partial responsibility for secure operations. In day-to-day practice, however, security concerns are frequently sacrificed for convenience, resulting in configurations that should never be permitted from a security standpoint. In his daily work, Baggenstos CTO Eckhard Neuhaus repeatedly encounters the same issues: publicly exposed endpoints, over-privileged roles and incorrect permission assignments.

Close to the Customer, Precise in Analysis

«A problem that must be addressed consistently through clear processes», says the CTO. Baggenstos’ strategy is built on two pillars «secure configuration» and continuous monitoring. Automation and clear policies reduce the risk of human error. Permissions, for example, should be granted and revoked dynamically rather than assigned permanently. Highly privileged access requires an approval workflow.

Baselines or reference values based on established frameworks define the target state, while deviations are continuously monitored. Baggenstos uses several tools for this purpose, including the Microsoft Defender Suite with Secure Score as a core component, as well as Darktrace / Cloud for real-time alerts in case of policy violations. «Cloud misconfigurations are not purely a technical issue», Eckhard Neuhaus emphasises. This is where the Baggenstos team’s close relationship with customers proves invaluable.

Through in-depth workshops, organisations are assessed for weaknesses across their IT infrastructure and underlying processes. Understanding how people work and how processes function enables the right decisions when designing a cloud security architecture. «Security has to be lived», says Eckhard Neuhaus. «It can be uncomfortable at times — but with the wrong configuration, a seemingly productive solution can quickly turn into a cybersecurity nightmare.»

No items found.

Share article

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund

Deine IT läuft im Modus “Sicherheit”?

Du bist unsicher? Gerne zeigen wir dir unsere Säulen der Cloud-Security