Why Your Cloud Provider Is Only Half the Security Story

Cloud providers secure their platforms, but your organisation still controls access, configuration and data. This article explains where security responsibility really sits.

KANJ Advisory Team
Explore
Why Your Cloud Provider Is Only Half the Security Story

There are few industries where responsibility has become more misunderstood than in cloud computing.

Speak to most business leaders and there is a reasonable assumption that moving systems into Microsoft Azure, Microsoft 365, Amazon Web Services or Google Cloud has also transferred much of the responsibility for protecting those systems. After all, these organisations operate some of the most secure datacentres ever built. They employ thousands of cyber security specialists, invest billions of pounds each year in protecting their platforms and defend against attacks on a scale that few organisations could ever hope to match.

All of that is true.

It is also the reason many organisations misunderstand where their own responsibilities begin.

The cloud has transformed the way businesses consume technology, but it has not transformed accountability. Instead, it has quietly shifted it. Your cloud provider is responsible for securing the platform it delivers. Your organisation remains responsible for how that platform is configured, who has access to it, how information is shared, how identities are protected and how unusual activity is detected.

That distinction may appear technical, yet it sits behind many of the security weaknesses we encounter during cloud assessments.

The organisations we work with are rarely using poor technology. Microsoft, Amazon and Google provide exceptionally secure platforms. The vulnerabilities are far more likely to emerge through the way those platforms have been configured and governed over time. In many cases, the technology is performing exactly as it was instructed to. The problem is that those instructions often reflect decisions made years earlier by a business that has since changed considerably.

That is why cloud security is ultimately less about technology than it is about governance.

The cloud did not remove responsibility. It redistributed it.

One of the most significant changes brought about by cloud computing is that organisations no longer spend their time worrying about physical servers, power supplies, cooling systems or the resilience of a datacentre. Those responsibilities now sit with organisations that specialise in delivering cloud platforms at extraordinary scale.

What has not changed is the responsibility for protecting the business itself.

Someone still decides who can access sensitive information. Someone still determines whether external suppliers should be able to view company data. Someone chooses how administrator accounts are managed, whether Multi Factor Authentication is enforced consistently and whether employees can access company information from unmanaged devices.

The cloud provider cannot make those decisions because they belong to the organisation using the platform.

This is why two businesses running identical Microsoft 365 environments can have completely different levels of cyber resilience. The technology is the same. The decisions surrounding it are not.

Cloud computing has removed much of the operational burden of running infrastructure. It has not removed the need for good governance.

Most cloud security weaknesses are not technical failures

There is a tendency to imagine cyber security failures as sophisticated attacks against complex systems.

In reality, many begin with something remarkably ordinary.

A former employee whose account was never removed. A Global Administrator account that was created during an urgent project and quietly forgotten. External sharing enabled for a collaboration exercise that ended months ago. Conditional Access policies that have accumulated exceptions over several years. Third party applications retaining access to company information long after they are no longer required.

None of these situations usually exists because somebody has made a poor decision.

They exist because organisations evolve.

People join and leave. Projects begin and finish. Departments change. Acquisitions take place. New offices open. Remote working becomes permanent. Every one of those changes introduces small adjustments to the technology environment. Individually they make perfect sense. Collectively they can create an environment that no longer reflects the way the organisation actually operates.

One of the biggest surprises for business leaders is that cloud security reviews rarely uncover dramatic failures.

More often, they reveal hundreds of small decisions that have quietly accumulated over time.

Identity has become more important than infrastructure

A decade ago, most cyber security strategies focused on protecting networks.

That made sense because most employees worked from a single office, applications lived inside the organisation and the network formed a relatively clear boundary between trusted and untrusted environments.

Today that boundary has almost disappeared.

Employees work from homes, airports, customer sites and shared workspaces. Applications are delivered through cloud services. Information moves constantly between Microsoft 365, third party SaaS platforms and mobile devices. Business data no longer sits neatly behind a firewall.

The perimeter has not vanished.

It has moved.

Increasingly, it follows the identity of the individual rather than the location of the organisation.

This is why technologies such as Multi Factor Authentication, Conditional Access, Privileged Identity Management and strong identity governance have become some of the most valuable security controls available. They are not simply Microsoft features. They are business controls that determine who is allowed to access the organisation's most valuable information and under what circumstances.

We have yet to encounter an organisation whose greatest cloud security weakness was Microsoft's infrastructure.

We have encountered many where identity had quietly become the weakest point in an otherwise excellent platform.

Complexity is often a greater risk than capability

One observation appears repeatedly across cloud environments of every size.

The least secure organisations are not always those with the oldest technology.

More often, they are those that have gradually become the most complicated.

Every new project introduces another exception. Every acquisition brings another way of managing users. Every department adopts another application because it solved an immediate operational need. Security policies become increasingly difficult to understand because they have evolved organically rather than through deliberate design.

Complexity has a habit of disguising risk.

When an environment becomes difficult to understand, it also becomes difficult to govern. Security reviews take longer. Changes become more cautious. Documentation struggles to keep pace with reality. Eventually, nobody is entirely certain whether removing an old configuration might inadvertently break something important.

At that point, technology begins dictating how the business operates instead of supporting it.

The strongest cloud environments are rarely the most sophisticated.

They are usually the simplest.

Not because they lack capability, but because every element has a clear purpose, every policy has an owner and every significant decision has been made deliberately rather than inherited accidentally.

Visibility is just as important as protection

There is a natural tendency in cyber security to focus on prevention. Organisations invest in firewalls, endpoint protection, email security and identity controls because the objective is to stop attackers gaining access in the first place. Prevention is undoubtedly important, but it tells only part of the story.

A more useful question is this: if somebody gained access today, how quickly would you know?

Many organisations struggle to answer.

Cloud platforms generate an extraordinary amount of information. Every authentication request, administrator action, file share, configuration change and security event leaves a trail. The challenge is rarely the availability of data. It is knowing which events matter, who is reviewing them and how quickly unusual activity would be investigated.

Good monitoring is therefore not about collecting more alerts. It is about reducing uncertainty. It should provide confidence that unusual behaviour will be identified before it becomes a business problem rather than after it has developed into a major incident.

One of the most revealing questions we ask during cloud security reviews is not what monitoring tools an organisation owns. It is who is responsible for reviewing them, how frequently that happens and what would trigger an investigation. Those answers often tell us far more about an organisation's security maturity than the technology itself.

The risks that rarely appear on the board agenda

When business leaders think about cyber security, conversations naturally gravitate towards ransomware, phishing attacks and organised cyber crime. Those threats are real and deserve attention, but they are not always the risks that concern us most.

The quieter risks often prove more persistent.

An administrator account that has not been reviewed for years. Third party applications retaining unnecessary permissions long after a project has finished. Sensitive information shared externally because a temporary collaboration site quietly became permanent. Cloud storage that has grown steadily without anyone questioning what is actually being retained or why.

None of these issues is dramatic. None would normally justify an emergency meeting.

Yet they all represent examples of governance gradually falling behind the way the organisation now operates.

One of the most common observations we make is that organisations rarely become vulnerable because of one catastrophic decision. More often, risk accumulates through hundreds of entirely reasonable decisions that nobody ever pauses to review.

Good governance is simply the discipline of asking whether yesterday's decisions still make sense today.

What a secure cloud environment actually looks like

Business leaders often ask what a mature cloud environment should look like. They expect the answer to involve advanced technologies or sophisticated security products.

It rarely does.

A mature cloud environment is one where the fundamentals are consistently managed. Identity is treated as the primary security boundary. Devices are trusted before they are granted access. Privileged accounts are tightly controlled and regularly reviewed. Security policies are applied consistently across the organisation rather than negotiated for individual users or departments. Monitoring provides meaningful visibility and backup procedures are tested often enough to provide genuine confidence rather than simple reassurance.

Perhaps most importantly, security evolves alongside the organisation.

As the business grows, enters new markets, acquires other companies or adopts new ways of working, the cloud environment changes with it. Policies are reviewed, architectures are challenged and assumptions are revisited. The platform remains aligned with the business because somebody is continually asking whether it still reflects the organisation's current reality rather than its past.

That process is never finished.

The strongest organisations rarely describe themselves as secure.

They describe themselves as continually improving.

The question every board should be asking

If there is one question capable of changing the quality of a conversation between business leaders and their IT provider, it is remarkably simple.

How do we know our cloud environment still reflects the way our business operates today?

Notice what that question does not ask.

It does not ask whether Microsoft is secure.

It does not ask whether Azure is resilient.

It does not ask whether Amazon Web Services has experienced an outage.

Those are important questions, but they are largely the responsibility of the platform provider.

The more valuable question is whether the organisation has kept pace with its own change.

Have identities been reviewed?

Have permissions evolved as employees changed roles?

Have acquisitions introduced inconsistent security standards?

Have temporary exceptions become permanent configurations?

Has anyone challenged whether the current architecture still reflects the business rather than simply accepting that "it has always been done this way"?

Those are governance questions.

Increasingly, they are also board questions.

The cloud has changed technology. It has not changed accountability.

Cloud computing has transformed business technology in ways few organisations could have imagined twenty years ago. It has improved resilience, accelerated innovation and given businesses access to capabilities that were once available only to the world's largest enterprises.

What it has not changed is accountability.

Organisations still decide who can access information. They still determine how identities are protected, how sensitive data is shared, how unusual behaviour is investigated and how quickly they can recover when something goes wrong.

Those responsibilities have not disappeared.

They have simply become easier to overlook because the infrastructure itself feels somebody else's responsibility.

The organisations that build the strongest cloud environments understand this distinction. They stop asking whether Microsoft, Amazon or Google are secure and begin asking whether their own use of those platforms reflects the ambitions, governance and risk appetite of the organisation they are trying to support.

That shift in thinking changes almost every subsequent decision.

How Kanj Technologies helps

Many organisations assume they have a cloud security challenge when, in reality, they have a governance challenge.

The underlying platforms are often highly capable, but years of business change, acquisitions, hybrid working and evolving operational requirements have gradually taken the environment in a different direction to the one originally intended. Our role is not simply to recommend new technology. It is to understand how the organisation has evolved, identify where cloud architecture, identity management and security controls no longer reflect that reality, and help leadership teams regain confidence that their technology is supporting the business rather than quietly introducing unnecessary risk.

Whether that involves reviewing Microsoft 365, Microsoft Azure or other cloud platforms, strengthening identity management, improving monitoring, preparing for Cyber Essentials or ISO 27001, or providing independent assurance alongside an existing IT provider, the objective remains the same.

Cloud security should never be judged by the reputation of the platform you have chosen.

It should be judged by how confidently your organisation is using it.

 

Keep exploring

Related blogs

let's collaborate

Contact our India or global teams to discuss IT infrastructure, security, and operational requirements across your organisation.

Let's strengthen reliability and optimise your IT for efficiency.