Cloud security starts with one idea that most breaches ignore: the shared responsibility model.
Shared responsibility
The Shared Responsibility Model
Who secures what in the cloud — the concept most cloud breaches ignore.
Tap or hover a part to learn more.
Security OF vs IN the cloud.
The provider is responsible for the security OF the cloud (physical data centres, hardware, the virtualisation layer); you are responsible for security IN the cloud (your data, identities, configuration and access). Most breaches come from the customer side.
Check your understanding
1. Under the shared responsibility model, your data is secured by…
2. As you move from IaaS to SaaS, the customer's responsibility…
Keep learning
The provider secures the cloud (hardware, hypervisor, physical sites); you secure what's in it (data, identities, configuration, network rules). The line shifts by service model — but your data and access are always yours.
Defence in depth
Defence in Depth
Layered controls so a single failure never becomes a breach.
Tap or hover a part to learn more.
The human layer.
Security policies, acceptable-use rules and user-awareness training. Most breaches start with a person, so this outer layer is critical.
Check your understanding
1. Why is defence in depth more effective than a single strong control?
2. User-awareness training belongs to which layer?
Layer controls — identity, network segmentation, encryption, logging and least privilege — so no single failure is catastrophic. The classic cloud breach is a simple misconfiguration (a public storage bucket), not a broken data centre.
