As organisations move to the cloud, cloud security has become one of the most in-demand specialisms. It reuses your Cloud Fundamentals knowledge with a security lens.
The Shared Responsibility Model
Who secures what in the cloud — the concept most cloud breaches ignore.
Tap or hover a part to learn more.
Security OF vs IN the cloud.
The provider is responsible for the security OF the cloud (physical data centres, hardware, the virtualisation layer); you are responsible for security IN the cloud (your data, identities, configuration and access). Most breaches come from the customer side.
Check your understanding
1. Under the shared responsibility model, your data is secured by…
2. As you move from IaaS to SaaS, the customer's responsibility…
Keep learning
The essentials
- Shared responsibility — the provider secures the cloud; you secure what you put in it (data, identity, configuration). Most cloud breaches are the customer's misconfiguration, not the provider's fault.
- Identity is the perimeter — strong IAM, MFA and least privilege matter more than ever.
- Misconfiguration — public storage buckets and over-permissive roles are the classic cloud breach.
- CSPM & posture — Cloud Security Posture Management tools continuously check for risky configuration.
Defence in Depth
Layered controls so a single failure never becomes a breach.
Tap or hover a part to learn more.
The human layer.
Security policies, acceptable-use rules and user-awareness training. Most breaches start with a person, so this outer layer is critical.
Check your understanding
1. Why is defence in depth more effective than a single strong control?
2. User-awareness training belongs to which layer?
Encrypt data, log everything, and apply zero trust — the same principles, applied to the cloud. Feeds Cloud Engineer and Security Engineer roles.
