The report Cartographie des risques dans le Cloud (“Cloud Risk Mapping”), produced by the Campus Cyber working group of the same name (part of the “Détection dans le Cloud” Community of Interest), was presented at Forum InCyber 2026 in Lille.

The document addresses the detection of potential or confirmed attacks on digital production environments hosted on public, private, or hybrid Cloud platforms. It proposes a multi-step approach:

  • Risk identification, tied to Cloud-specific features: access from the Internet, shared virtualized environments, outsourced administration and hosting
  • From risks to detection rules, illustrated with examples of major incidents and a summary of the risk analysis
  • Detection rule coverage, with a deployment prioritization strategy for monitoring tools and platforms

The Cloud risk list is organized by business value and by stakeholder — whether the end user or the service provider — so that each party can rethink its security event detection strategy according to its level of Cloud usage.

The report was co-written with Nadège Lesage (Hexatrust), Timothé Penisson (Bouygues Télécom), and Baptiste Cianchi (Wavestone).