top of page

The Monthly Cyber Resilience Series: The Cloud Is Not Someone Else’s Problem

  • Jun 8
  • 4 min read

Why Moving to the Cloud Does Not Mean Security Is Solved


Over the past decade, cloud services have become an integral part of the way organisations operate. We use them for email, document sharing, video conferencing, project management, data storage, and countless other activities that have become part of everyday business.


For many organisations, moving to the cloud has been a significant step forward. There is no longer a need to maintain physical servers, manage on-premises infrastructure, or invest heavily in hardware. Services are accessible from anywhere, scale more easily, and often provide a higher level of security than smaller organisations could achieve on their own.


However, this is also where one of the most common misconceptions in modern cybersecurity begins. Many organisations assume that once they move to the cloud, responsibility for security automatically shifts to the cloud provider. Unfortunately, that is not the case. The cloud can be highly secure. But only when organisations understand which aspects of security are managed by the provider and which remain their own responsibility.


Why the Cloud Is Not Automatically Secure


When you use a cloud service, it is reasonable to assume that the provider has invested heavily in security. And in most cases, that assumption is correct. Major cloud providers employ thousands of security specialists, invest heavily in data centre protection, operate advanced monitoring capabilities, and continuously improve their platforms.


Yet the majority of serious cloud security incidents do not occur because someone breached the provider’s infrastructure. More often, they occur because of configuration mistakes. An exposed storage bucket. Excessive permissions. An administrator account protected only by a password. A poorly configured cloud database.


In other words, the problem is often not the cloud platform itself, but how it is being used.


An Old Problem in a New Environment


Interestingly, the cloud has not changed the fundamental rules of cybersecurity. People still reuse weak passwords. Administrator accounts still have excessive privileges. Data is still stored without proper classification. Access rights are still granted without regular review.


The difference is that mistakes can now have a much greater impact. A misconfigured server might once have exposed information within a single office or department. Today, a misconfigured cloud service can expose data belonging to an entire organisation. Technology has evolved, but many of the underlying risks remain exactly the same.


Your Data Does Not Stop Being Your Responsibility


One of the most common psychological traps associated with cloud adoption is the feeling that the data is now “somewhere else” and therefore no longer your responsibility. But the data itself has not changed. If your organisation stores:

  • employee information,

  • customer records,

  • financial documentation,

  • contracts,

  • strategic plans,

then your obligations to protect that information remain exactly the same as they were before moving to the cloud.


Regulators do not distinguish between a data breach caused by a compromised server in your office and one caused by a poorly managed cloud environment. Responsibility for protecting information remains with the organisation. The technology may change. The accountability does not.


The Most Common Cloud Security Mistakes


When security professionals investigate cloud-related incidents, they repeatedly encounter the same problems. The first is the absence of Multi-Factor Authentication (MFA). A surprisingly large number of administrative accounts remain protected by nothing more than a password. The second issue is excessive access. Users are granted broad permissions simply because it is more convenient. The third problem is uncontrolled sharing. Links to documents remain active for years and are distributed far beyond their intended audience. The fourth issue is a lack of monitoring. Many organisations cannot clearly answer questions such as: Who is accessing our cloud resources? Where are they connecting from? What are they doing after they log in?


These weaknesses can exist in traditional IT environments as well, but cloud platforms often make them more visible - and potentially far more damaging.


The Cloud Requires a Different Mindset


Traditional security strategies were often built around protecting a network perimeter. The goal was to create a secure boundary around systems and prevent unauthorised access from outside. In cloud environments, that approach is no longer sufficient. Employees work from offices, homes, airports, hotels, and client sites. Applications are accessible from anywhere. Data resides across multiple platforms and services. As a result, security must focus less on the network itself and more on:

  • identity,

  • access,

  • devices,

  • data.


The key question is no longer: "Is this person inside our network?" Instead, it becomes: "Who is requesting access to this information, and should they be allowed to access it?" That shift in thinking lies at the heart of modern cloud security.


What Every Organisation Can Do Today


The good news is that improving cloud security does not always require major investment. Some of the most effective measures are also the simplest.

  • Enable MFA for all users, especially administrators.

  • Review access rights regularly and remove permissions that are no longer required.

  • Audit who is sharing documents and with whom.

  • Enable logging and activity monitoring.

  • Create an inventory of all cloud services used across the organisation.


Many organisations are surprised when they discover how many cloud services employees are already using without formal approval or oversight. This phenomenon, often referred to as "shadow IT", creates risks that cannot be managed if they remain invisible.


Cloud Security Is a Shared Responsibility


One of the most important lessons in modern cybersecurity is that cloud security is not something you purchase and forget about. It is something that must be continuously managed. The cloud provider may be responsible for securing the underlying infrastructure. However, the organisation remains responsible for its users, its information, its access controls, and its business decisions. This is why security professionals often refer to the concept of shared responsibility. Moving to the cloud does not eliminate responsibility for security. It simply changes how that responsibility is exercised.


Conclusion


Cloud technologies have delivered enormous benefits to organisations of all sizes. They have enabled more flexible working practices, reduced infrastructure costs, and improved the availability of services. However, the cloud is not a security strategy in itself. It can be extremely secure, but only when organisations understand their role in protecting systems and information. Today, the greatest cloud security risk is rarely a lack of technology. More often, it is the assumption that security has become someone else’s problem. And it never was.

Comments


Badge.png

t. +387 33 448 280

e. csec_official@csec.ba

a. Gradačačka 114

    Sarajevo, Bosnia and Herzegovina

White BA logo.png

The establishment of CSEC has been supported by the UK Government.

Subscribe to Our Newsletter

Thanks for submitting!

Follow Us On:

  • Facebook
  • LinkedIn
  • Instagram
  • Twitter
bottom of page