Cyber Security All-in-One · Volume 2

Identity and Cloud Security by Kai London

Attackers stopped breaking in some time ago. They sign in, to an estate that now lives across three clouds, a hundred SaaS tenants and a build pipeline nobody has fully inventoried. Volume 2 covers the two disciplines that now carry most of the load: identity, and the cloud it governs.

Available on Amazon.

What is inside

Identity and access management

Lifecycle, federation, conditional access, phishing-resistant authentication and joiner-mover-leaver done properly.

Privileged access

Vaulting, just-in-time elevation, break-glass, and removing the standing admin rights nobody remembers granting.

Multi-cloud security

AWS, Azure and Google Cloud — shared responsibility in practice, plus the control equivalents across all three.

SaaS and shadow estate

Tenant configuration, OAuth grants, data residency and the applications procurement never saw.

Application and API security

Secure development, authorisation flaws, secrets management and API exposure at the edge.

Kubernetes and the supply chain

Workload identity, admission control, image provenance, SBOMs and the dependencies you inherit.

Who it is for: security engineers and cloud platform teams, identity architects, DevSecOps practitioners, and security leaders assuring a multi-cloud estate.

Zero TrustNIST CSF 2.0ISO/IEC 27001CIS BenchmarksOWASP

Identity is the control plane. If it is weak, everything downstream is decoration.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.