Lesson 19 — Cloud Security Posture Best Practices
Knowing how Microsoft Defender for Cloud works is only half the battle.
This lesson explains how mature organisations build a repeatable Cloud Security Posture Management programme using Secure Score, risk-based prioritisation, ownership, automation and measurable risk reduction.

What you will learn
This lesson brings the entire Cloud Security Posture Management module together into one repeatable operating model.
A repeatable CSPM operating model
Risk-based prioritisation model
| Priority | Typical characteristics | Example response |
|---|---|---|
| Critical | Internet-facing, exploitable, privileged, sensitive or connected to a realistic attack path. | Investigate immediately, contain exposure and assign an urgent remediation owner. |
| High | Material security weakness affecting important workloads or a large number of resources. | Schedule rapid remediation and track progress through governance reporting. |
| Medium | Meaningful weakness with lower immediate exposure or stronger compensating controls. | Place into a planned remediation queue with a target date. |
| Low | Limited exposure, minor hardening opportunity or low business impact. | Bundle with routine maintenance or automate where practical. |
Agent Foskett investigation: “Nothing was actually broken…”
Operational review cadence
| Cadence | Focus | Typical output |
|---|---|---|
| Daily | Critical recommendations, internet exposure, new attack paths and urgent alerts. | Immediate triage, escalation and ownership. |
| Weekly | Recommendation progress, Secure Score movement, overdue actions and new assets. | Updated remediation queue and owner actions. |
| Monthly | Risk trends, exceptions, plan coverage, compliance posture and recurring weaknesses. | Management report and improvement priorities. |
| Quarterly | Policy effectiveness, maturity, investment needs and long-running accepted risks. | Executive review and roadmap decisions. |
Key takeaways
- Operate Defender for Cloud as a continuous programme rather than a one-time configuration project.
- Prioritise business risk, internet exposure and attack paths before low-impact score improvements.
- Use Secure Score to measure progress, not to replace security judgement.
- Assign every material recommendation to an accountable owner.
- Use governance rules, due dates and escalation to prevent findings from becoming permanent backlog.
- Automate repeatable controls wherever practical.
- Review exemptions and accepted risks regularly.
- Measure risk reduction, remediation time and coverage—not only recommendation counts.
- Report outcomes in language that technical teams and executives can understand.
- Repeat the posture cycle as cloud environments change.
Learning objectives
After completing this lesson, you should be able to build and operate a repeatable cloud security posture programme.
Why programmes fail
Organisations often deploy Defender for Cloud without defining ownership, prioritisation, reporting or remediation processes.
Technology is not enough
The value of Defender for Cloud depends on how consistently teams act on its findings.
Start with business context
Identify critical services, sensitive data, regulatory obligations and operational dependencies before ranking recommendations.
Identify crown jewels
Crown-jewel workloads should receive stronger monitoring, faster remediation and tighter exception controls.
Prioritise exposure
Internet-facing resources and externally reachable attack paths normally require attention before isolated internal assets.
Prioritise exploitability
Give greater urgency to weaknesses that can realistically be exploited with available techniques.
Prioritise privilege
Recommendations involving privileged identities, broad permissions and management access deserve additional scrutiny.
Prioritise data sensitivity
Resources holding personal, financial, health or commercially sensitive information should receive higher priority.
Prioritise attack paths
An individual weakness becomes more urgent when it contributes to a realistic path towards a critical asset.
Secure Score
Secure Score provides a useful measure of posture improvement across assessed controls.
Secure Score is not the goal
A higher score does not automatically mean the organisation has addressed its most important risks.
Avoid score chasing
Do not complete easy low-impact actions simply because they produce quick score gains.
Use score trends
Track Secure Score over time to identify sustained improvement or unexpected deterioration.
Recommendation ownership
Every important recommendation should be assigned to a named team or individual.
Business owner
The business owner explains workload importance and accepts the consequences of delayed remediation.
Technical owner
The technical owner plans and implements the required configuration change.
Security owner
The security owner validates risk, prioritisation and evidence of completion.
Executive sponsor
An executive sponsor removes organisational blockers and supports required investment.
Governance rules
Use governance rules to assign owners, define due dates and monitor remediation progress.
Due dates
Set realistic target dates based on severity, exposure, complexity and business impact.
Escalation
Escalate overdue critical recommendations before they become accepted operational debt.
Automation
Automate repeatable configuration, assignment, notification and remediation tasks wherever practical.
Azure Policy
Use Azure Policy to prevent insecure configurations and deploy required controls consistently.
Logic Apps
Use Logic Apps and automation workflows to route findings, notify owners and create work items.
Infrastructure as code
Embed secure configuration into templates and deployment pipelines rather than fixing the same weakness repeatedly.
Shift left
Identify posture issues during design and deployment instead of waiting until production.
Prevent recurrence
After remediating a recommendation, determine how policy or automation can stop it returning.
Exception management
Use exemptions only when risk has been investigated, justified, approved and assigned an expiry date.
Temporary acceptance
Temporary accepted risk should include compensating controls and a documented remediation plan.
Recommendation backlog
Separate active risk, planned remediation, accepted risk and invalid findings so the backlog remains meaningful.
Daily review
Review new critical recommendations, attack paths and exposed resources every business day.
Weekly review
Review recommendation progress, owners, due dates and Secure Score movement each week.
Monthly reporting
Summarise risk reduction, remaining critical exposure, plan coverage and overdue remediation each month.
Executive reporting
Translate technical findings into business impact, trend, ownership and investment decisions.
Useful metrics
Track critical findings, mean remediation time, attack paths, internet exposure, coverage gaps and exception ageing.
Mean remediation time
Measure how long findings remain open from detection to verified closure.
Coverage metrics
Track subscriptions, servers, storage accounts and other workloads without appropriate Defender plan coverage.
Trend analysis
Look for repeated configuration weaknesses, recurring exceptions and teams with persistent remediation delays.
Evidence of closure
Verify that the resource changed and that Defender for Cloud reassessed the recommendation.
False completion
Closing a ticket without confirming the security state leaves risk hidden behind process.
Multicloud consistency
Apply the same prioritisation, ownership and reporting model across Azure, AWS, Google Cloud and hybrid assets.
Tagging strategy
Use resource tags to identify business owner, criticality, environment, application and data sensitivity.
Resource inventory
Maintain accurate visibility of new, changed and retired cloud resources.
Maturity level 1
Teams react to findings manually with limited ownership or reporting.
Maturity level 2
Recommendations are prioritised, assigned and reviewed on a regular schedule.
Maturity level 3
Policy, automation, metrics and executive governance support continuous improvement.
Common mistake: fixing everything
Trying to remediate every recommendation at once creates noise and delays important action.
Common mistake: no owner
Recommendations without accountable owners remain open indefinitely.
Common mistake: permanent exceptions
Exceptions without expiry dates can hide unresolved exposure for years.
Common mistake: no validation
Remediation should be confirmed through reassessment rather than assumed from implementation.
Common mistake: poor reporting
Recommendation counts alone do not explain business risk or security improvement.
What Agent Foskett checked
Agent Foskett checked exposure, attack paths, resource criticality, ownership, ageing, exceptions and evidence of closure.
Best-practice checklist
- Review Defender for Cloud every business day.
- Prioritise business risk over quick Secure Score gains.
- Assign every material recommendation to an owner.
- Use governance rules and due dates.
- Automate repeatable controls.
- Prevent remediated weaknesses from returning.
- Review exceptions and overdue actions.
- Validate completed remediation.
- Measure risk reduction and remediation time.
- Report clear outcomes to leadership.
Related Agent Foskett resources
Continue learning
What are cloud security posture best practices?
Cloud security posture best practices combine continuous assessment, Secure Score, risk-based prioritisation, accountable ownership, policy, automation, exception governance and measurable remediation across changing cloud environments.
Cloud Security Posture Best Practices Lesson
This Agent Foskett lesson explains how to operate Microsoft Defender for Cloud as a repeatable Cloud Security Posture Management programme that reduces real business risk rather than simply increasing recommendation completion counts.
