The Side Door to Your Production Environment: How to discover access paths hidden behind IAM policies
Speaker
Viola Lykova
Agenda
18:00 - Networking in BCS London over refreshments
18:30 - Event start with resentation and Q&A either ad hoc or at the end
20:00 - Presentation closes and networking for venue attendees in BCS London (pizza & refreshments)
20:45 - Event close and adjourn to The Old Doctor Butler's Head to continue discussion if desired (or Mason's Arms next door to it, if too noisy)
Synopsis
You locked the front door. You checked the keys. You reviewed the access list. So production should be secure, right? Not necessarily. In modern systems, access rarely follows a single, obvious route. A developer may have no direct permission to reach a sensitive resource, yet still be able to get there indirectly through a deployment pipeline, a service role, a workload, a delegated identity, or a chain of individually legitimate permissions.
This talk looks at those side doors. We’ll explore how privilege escalation paths emerge across cloud identities, CI/CD systems, workloads and services, why a perfectly reasonable IAM policy can still leave unexpected routes into production, and how access can drift as systems evolve. Rather than asking only, “What permissions does this user have?”, we’ll ask a more useful question: “What can this identity eventually cause to happen?” The goal is to move from reviewing permissions as isolated rules to understanding access as a connected system of paths, dependencies and delegated authority, and to show why closing one door does not always mean the risk is gone.
About the speaker
Viola Lykova (https://www.linkedin.com/in/violaly/) is the Founder of Viola Security and CTO at nuclecode, working at the intersection of security, cloud infrastructure and production engineering.
Over the past nine years, she has built and led engineering teams, designed and operated highly available systems, and worked across fintech, cloud platforms and regulated technology environments. Her experience spans technical leadership, platform engineering, SRE, identity and access management, and the architecture of production systems.
Her current work focuses on a deceptively simple security question: who can actually reach, influence or control a production system, regardless of what the IAM policy appears to say? Through Viola Security, she researches effective access, privilege escalation paths, access drift and revocation verification, with a particular interest in turning complex authority relationships into systems that can be measured, tested and continuously verified.
Viola is also a technical speaker, presenting on cloud security, IAM, production access and the engineering problems that emerge when systems grow beyond the assumptions they were originally designed around.
Our events are for adults aged 16 years and over.
This meeting is conducted in accordance with the BCS Code of Conduct for Meetings.
BCS is a membership organisation. If you enjoy this event, please consider joining BCS. You’ll be very welcome. You’ll receive access to many exclusive career development tools, an introduction to a thriving professional community and also help us Make IT Good For Society. Join BCS today
If you are attending in person, please familiarise yourself with the Visitor Instructions for the BCS London Office.
Please note, if you have any accessibility needs, please let us know via groups@bcs.uk, and we’ll work with you to make suitable arrangements.
BCS privacy notice: your data will be processed by BCS in accordance with our data privacy notice.
Photography: by attending this event, you may be photographed or filmed. Please speak to a member of staff if you do not wish to be included.
For overseas delegates who wish to attend the event, please note that BCS does not issue invitation letters.
This event is brought to you by: Software Practice Advancement (SPA) SG