I manage IT for a small team and we’re moving more services to AWS / Google Cloud. I’ve read a bunch of generic cloud security tips (MFA, encryption, least privilege), but I don’t know which ones I should prioritize given a tight budget and no full-time security person. We’ve already enabled MFA and basic backups, but I’m worried about misconfigured storage (S3/GCS), IAM role sprawl, and logging gaps. Looking for a prioritized, practical checklist (including low-cost tools and quick wins) that will actually reduce the biggest risks for a business of 15 people.