Cloudanix Joins AWS ISV Accelerate Program

The Critical Role of Asset Management and Kubernetes in Modern Cloud Security

Kesten Broughton shares why asset management is the bedrock of cloud security and how to handle ephemeral Kubernetes workloads effectively.

In the rapidly evolving world of cloud-native infrastructure, the traditional security perimeter has dissolved. Organizations now manage hundreds of SaaS vendors and thousands of ephemeral Kubernetes workloads, making “knowing what you have” one of the most daunting challenges in cybersecurity.

We sat down with Kesten Broughton, a member of the security infrastructure team at Crunchyroll and former cloud security specialist at Praetorian and Nuro, to discuss why asset management is the bedrock of a security program. With over 12 years of experience in DevOps and security, Kesten provides a roadmap for building a streaming, enriched, and engineering-friendly asset inventory.

You can read the complete transcript of the epiosde here >

Why is Asset Management the Most Important Component of Security?

Asset management is often cited as the most critical part of a security program because it provides the foundational visibility needed to answer basic questions in seconds rather than days. For example, if a security team identifies a suspicious IP address, a robust asset inventory can immediately determine if it belongs to their AWS or GCP environment, an on-prem system, or a third party.

Without a centralized data lake or warehouse to ingest these feeds, tracking down system owners and permissions can take significant time, leaving the organization vulnerable. Asset inventory is essentially about the ability to query your organization’s entire footprint in a matter of seconds.

How Should Organizations Prioritize Assets in the “Swiss Cheese” Perimeter?

Kesten notes that the concept of a strong perimeter has been replaced by a “Swiss cheese” model, where everything is connected to the web. For startups and enterprises alike, prioritization should follow these steps:

  • Third-Party SaaS Vendors: Most companies use 300 to 500 SaaS tools but cannot list them all. Organizations must track these because if a vendor is compromised, they need to know immediately if they are at risk. This is where a solid third-party risk management program becomes essential.
  • Outside-In Visibility (DNS): DNS is often the primary entry point for attackers. “Dangling subdomains” — records pointing to ephemeral cloud IPs that have been released — allow attackers to claim that IP and launch attacks using the trust of the organization’s domain.
  • Registrar Management: Younger companies often find their domains are still registered in the name of a founder who may not check expiration warnings.

What Makes Kubernetes Asset Management Different from Traditional Cloud Resources?

While daily snapshots are sufficient for slow-moving assets like DNS records or static EC2 instances, they are completely inadequate for Kubernetes. Kubernetes workloads are highly ephemeral and often exist for less than a day.

To avoid being out of touch during a security incident, organizations should:

  1. Avoid “For Loops”: Manually querying 100 clusters and thousands of namespaces via APIs is slow, inefficient, and can potentially DDoS your own system.
  2. Use Cloud-Native Feeds: Leverage services like GCP Cloud Asset Inventory feeds or AWS Config to get real-time state information.
  3. Implement Pub/Sub: Configure the cloud to send continuous updates to a Pub/Sub feed that triggers database updates on the backend, ensuring you have the latest state information.

This event-driven streaming approach is the correct paradigm for Kubernetes — treating asset inventory as a real-time data pipeline rather than a periodic snapshot.

How Can Organizations Enrich Asset Data to Drive Ownership?

A list of IPs is useless if the security team doesn’t know who to contact when a vulnerability is found. The native GUIs provided by cloud providers are often too limited for full SQL queries or data joins.

Kesten recommends dumping asset inventory into BigQuery (GCP) or Athena (AWS) to enable deeper analysis. Key enrichment strategies include:

  • Tagging: This is the most underutilized tool in the cloud. Organizations should use linters to refuse any deployment that lacks an owner tag. A strong tagging strategy is the foundation of asset ownership at scale.
  • Mapping to Code: Enrich data by mapping infrastructure back to GitHub CODEOWNERS files or Terraform modules. This creates a direct line from any asset to the team responsible for it.
  • Graph Layers: Transition from a spreadsheet view to a “spider web” or graph view. This allows security teams to see how an IP is connected to a load balancer, which is connected to Route 53, which is vital for end-to-end tasks like blocking bot traffic.

Can Security Automation Be “Overdone”?

Contrary to common industry trends, Kesten argues that automation can sometimes be overdone if the maintenance effort exceeds the security value.

  • Infrastructure as Code (IaC) Drift: Terraform models the cloud state, but the cloud is the source of truth. Minor provider updates (e.g., changing a default from an empty string to “none”) can break deployments that haven’t been touched in months. Understanding IaC security trade-offs is critical for making pragmatic decisions.
  • Security Logic vs. IaC: If a one-off security deployment (like a logging sink) will not be touched for a year, building it manually or via CLI commands may be more efficient than maintaining a complex Terraform module.

The key insight is that automation should serve the team, not the other way around. Every automated system carries a maintenance cost that must be weighed against its security value.

How Can Security Teams Help Engineering Move Faster?

Security should focus on removing friction for developers rather than becoming the “department of no.”

  • Identity-Aware Proxy (IAP) “Paved Roads”: Security can create standard, documented ways to implement IAPs for backend admin panels, reducing the number of “permission denied” errors in the logs.
  • Post-Deployment Checks: Instead of a blocking code-scanning gate that interrupts a tight development loop, consider post-deployment checks. While this may leave a vulnerability live for a few hours, it may allow a team to meet several more sprint objectives over a year — a trade-off that is often worth the risk. This philosophy aligns with shifting security culture from friction to flow.

How Does Kesten Rate Common Security Practices?

  • Unrestricted Access (Rating: 3/5): While a “1” for production, Kesten rates this as a “3” for non-prod. Supporting “Wild West” zones — where developers have full ownership but automation “annihilates” all resources weekly — helps them move faster without accumulating risk.
  • Periodic Security Audits: Third-party pentests are often expensive “checkbox exercises.” A better approach is to use Bug Bounty programs to leverage the creativity of niche attackers.
  • Training and Awareness (Rating: 1/5): A one-size-fits-all approach is ineffective. Training must be tailored; for example, Finance needs to know about fake invoice scams, while Legal and Security need better joint workflows.

Conclusion: From Compliance Task to Strategic Asset

Asset management in the cloud and Kubernetes is a dynamic engineering challenge rather than a static compliance task. By shifting toward real-time feeds, enriching data with ownership tags, and maintaining a “paved road” approach that enables engineering velocity, organizations can turn their asset inventory into a strategic defensive asset.

The organizations that treat asset management as a living, streaming data problem — rather than a quarterly spreadsheet exercise — will be the ones best positioned to respond to incidents in seconds rather than days.

Learning Resources Recommended by Kesten Broughton

  1. Darknet Diaries Podcast

Fascinating stories on social engineering and hacking that highlight the human psychology behind many breaches. A must-listen for security professionals who want to understand attacker motivations.

Listen to Darknet Diaries >

People Also Read

What Our Users Are Saying

Customer Reviews

Cloudanix is trusted by security leaders worldwide to deliver proactive, reliable, and cutting-edge cloud security.

One day, I changed the password of a root account, and my CTO called me within less than a minute to confirm if I did so. I was not expecting a reaction this quick. He told me Cloudanix alerted him of this password change and that he wanted to confirm as it was a critical security notification. I couldn't believe it!

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Compliance is one way of staying secure, but what I want is the ability to go deeper and attain 'true security.' Cloudanix provides us the capability to do so.

Vishal Madan
Vishal Madan
Head of Engineering, iMocha

Cloudanix is building for the future of the cloud, which makes the product all the more desirable.

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Cloudanix gave us the visibility we were missing. Being able to move from permanent access to a robust Just-In-Time (JIT) workflow has fundamentally changed our security posture without slowing down our engineering velocity.

Pavan Kumar Lekkala
Pavan Kumar Lekkala
SRE Lead, HugoHub

We are excited to leverage Cloudanix's comprehensive multi-cloud DevSecOps solution to secure our production workloads on AWS. Cloudanix has demonstrated that it can solve many challenges that DevSecOps teams face while continually adding new features such as SOC2 compliance and drift detection.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Managing third-party partner access was once a major concern for our security posture. With Cloudanix JIT Cloud, we've effectively achieved zero third-party risk. We can now grant access confidently, knowing that it is temporary, audited, and automatically revoked, resulting in a 100% reduction in our privileged access exposure.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

The snooze feature and responsible alerts have helped us save time and prioritize what to tackle first.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Implementing Cloudanix JIT internally allowed us to practice what we preach. By eliminating permanent access to our own clouds and databases, we've neutralized the risk of standing privileges, ensuring our own 'keys to the kingdom' are never left exposed.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

The problem with permissions is a lot of times, the gaps are left open due to oversights from inside the organization itself. With Cloudanix's CIEM, we get a complete view of user permissions and access. This enables us to update the permissions, reducing the attack surface.

Nilesh Pethani
Nilesh Pethani
Application Architect, iMocha

In the world of Fintech, trust is our currency. Cloudanix provided the frictionless visibility we needed to secure our EKS workloads across AWS, ensuring we stay audit-ready for SOC2 and GDPR without slowing down our engineering velocity.

Amol Naik
Amol Naik
Head of Security & Infrastructure, HugoHub

Cloudanix delivered value within 5 minutes of onboarding. Continuous monitoring, timely detection, and excellent documentation helped us attain a great cloud security posture.

Divyanshu Shukla
Senior DevSecOps, Meesho

Technology strategies and business strategies are in a state of constant change which includes centralization and decentralization of responsibilities. Regardless of strategic shift, we still have intellectual property to protect. Cloudanix are critical partners for us in our public cloud security posture across our three cloud providers.

Jerry Locke
Jerry Locke
Senior Director Global Solutions Engineering, Eversana

Cloudanix has been amazing. They opened up a common Slack channel with us — and it feels like we are talking to our own team and getting things done with Cloud security. The support team is always available, friendly, helpful, and ready to go out of their way.

Satish Mohan
Satish Mohan
CTO, Airgap Networks

Beyond just access management, Cloudanix CSPM has given us a unified view of our AWS environment. The real-time alerting and anomaly detection allow us to prevent any untoward activity before it happens, which is critical for a marketplace connecting 50+ financial institutions.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

For a Fintech company, data is our most valuable — and most sensitive — asset. Cloudanix DAM hasn't just improved our visibility; it has given us control. The ability to mask data and prevent unauthorized queries in real-time is a game-changer for our compliance and customer trust.

Jiten Gala
Jiten Gala
President Engineering and Product, Kapittx

Our clients, especially in the Middle East financial sector, demand absolute accountability. Cloudanix JIT Cloud has been a competitive differentiator for us, allowing us to provide secure, governed access to customer accounts that meet their strictest audit and compliance requirements.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

Cloudanix is always on my team's lips because of its exceptional support. Be it a small or big query, Cloudanix has gone above and beyond to resolve them. This one's a keeper for us.

Sujit Karpe
Sujit Karpe
CTO, iMocha

For a long-lasting partnership, great support goes a long way. Cloudanix has delivered exceptional support whenever required. Their edge is their team is always ready to go beyond to solve any issues that we have. This speaks volumes about the culture at Cloudanix.

Akash Maheshwari
Akash Maheshwari
Co-founder, MoveInSync

Beyond the technology, Cloudanix feels like an extension of our own team. Their willingness to stand up a dedicated Middle East tenant for us and provide exceptional support at a sensible price makes them a long-term partner for Hugosave.

Surya Tamada
Surya Tamada
CTO, HugoHub

The real-time notifications that Cloudanix provides are a real lifesaver. Their adaptive notifications ensure that my team stays productive and doesn't get interrupted all the time.

Digvijay Singh
Staff Security Engineer, Meesho

The whole point in technological evolution is to help improve the world we live in. We must protect that and to do so requires an effective and efficient security strategy. The Cloudanix team helped make our public cloud security posture management strategy a reality. The symbiotic relationship we have allows for a continuous feedback loop which is how business should operate.

Larry Wheat
Larry Wheat
Staff Solutions Engineer, Eversana

Ready to see your graph?

Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.

Book a Demo