Crown jewel GCS bucket is vulnerable to ransomware or deletion via internal access

Description

A Google Cloud Storage bucket tagged as a crown jewel asset is exposed to ransomware or destructive attacks through internal access — an attacker who compromises an internal identity with delete or overwrite permissions could permanently destroy or encrypt the bucket’s contents without the ability to recover previous versions. Because the bucket is a crown jewel, the impact of data loss or a ransom event is significantly higher than for a typical bucket.

Remediation

  1. Enable object versioning to retain previous versions of objects and allow recovery from malicious or accidental deletion/overwrite.
  2. Configure a retention policy on the bucket to prevent objects from being deleted or overwritten before a specified duration.