I traced a production incident back to a Secrets Manager secret that had rotation enabled. The dashboard showed rotation configured. The schedule said 30 days. The compliance report said compliant.
The rotation Lambda had been deleted four months ago.
The credential hadn't changed in 120 days. The audit said 30. Nobody noticed because every tool we had checked whether rotation was enabled not whether it was working.
The gap between configured and functioning is important for cloud security. The gap is a structural problem with how the entire cloud security tool market thinks about detection.
How every cloud security tool works today






