Quick answer: The shared responsibility model divides cloud security into two parts: your provider secures the cloud itself (hardware, network, physical data centres), and you secure what you put in it (your data, user access, configurations, and applications). Most cloud breaches happen on the customer side, not the provider’s, so assuming the cloud is secure by default is the mistake that gets businesses breached.
Key Takeaways
- The cloud is not secure by default. Providers secure the infrastructure; you remain responsible for your data, identities, and configurations.
- Through 2025, Gartner projected that the vast majority of cloud security failures would be the customer’s fault, not the provider’s, almost always through misconfiguration.
- IBM’s 2025 report puts the global average breach cost at $4.44 million, and misconfigured cloud remains one of the most common entry points.
- The three areas SMBs miss most: identity and access, storage configuration, and visibility into who is doing what.
- Closing your side of the model is a process, not a product: assess, configure, monitor, and repeat.
The Dangerous Assumption
Migrating to AWS, Microsoft 365, or Google Cloud feels like an upgrade in security, and in some ways it is. These providers run physical security, hardware, and network defences that almost no small or mid-sized business could match on its own. The problem is the conclusion many teams draw from that: that once they are in the cloud, security is handled. It is not. The provider secures the cloud. Everything you put inside it is still yours to protect.
This gap between assumption and reality is where breaches live. A misconfigured storage bucket, an over-privileged user account, a former employee whose access was never revoked, none of these are the provider’s responsibility, and none of them are stopped by the provider’s world-class data-centre security. Pairing your cloud move with a cybersecurity posture assessment is how you find these gaps before an attacker does.

What the Shared Responsibility Model Actually Divides
Every major cloud provider publishes a version of the same model. The wording differs, but the split is consistent:
- The provider secures the cloud. Physical data centres, servers, storage hardware, and the core network. You never touch these, and you never have to.
- You secure what is in the cloud. Your data, your user accounts and permissions, your network and firewall configuration, your operating systems and applications, and your encryption choices.
The balance shifts depending on the service. With infrastructure-as-a-service you manage more; with software-as-a-service the provider manages more. But one thing never moves to the provider’s side: your data and who can access it. Managing that access well is why identity and access management sits at the centre of cloud security.
Where SMBs Get Caught
Misconfiguration
The single most common cause of cloud breaches is a setting, not a hacker: a storage bucket left public, logging switched off, a default permission never tightened. These are quiet mistakes that expose data without any alarm going off. A periodic vulnerability assessment catches the misconfigurations your team cannot see from the inside.
Identity sprawl
Cloud makes it trivial to grant access and easy to forget to remove it. Over time you accumulate over-privileged accounts, shared logins, and orphaned credentials, each one a door left unlocked.
No visibility
You cannot secure what you cannot see. Without monitoring, a compromised cloud account can operate for weeks unnoticed. This is where 24/7 managed SOC monitoring earns its place, watching cloud, identity, and endpoint signals together so an anomaly gets caught in hours, not months.
Across the 260+ organizations Armour protects in 52+ industries, the most common cloud security gaps we see are not sophisticated attacks but avoidable misconfigurations and over-permissive access, the customer’s side of the shared responsibility model.
Closing Your Side of the Model
Owning your half of the shared responsibility model is a repeatable loop, not a one-time setup. Assess your current cloud configuration against a recognised baseline. Tighten identity and access so people have only what they need. Turn on logging and monitoring everywhere. And where cloud runs alongside regulated data, align it with your compliance obligations. For teams building in the cloud, the same discipline extends into how software ships, which is where DevSecOps comes in.
The Bottom Line
The cloud gives you a stronger foundation than most businesses could build alone, but a foundation is not a finished building. The organisations that stay secure in the cloud are the ones that understand exactly where the provider’s job ends and theirs begins, and then do their part deliberately. If you are not certain which side of the line your gaps fall on, Armour’s cloud security services map your responsibilities and close them.
Frequently Asked Questions
Does moving to the cloud make my business more secure?
A: Partly. Cloud providers secure the underlying infrastructure far better than most businesses could alone. But you remain responsible for your data, user access, and configurations, which is where most cloud breaches actually happen. The cloud is more secure only if you do your part of the shared responsibility model.
Who is responsible for cloud security, me or the provider?
A: Both, in defined roles. The provider secures the cloud itself, the hardware, network, and physical facilities. You secure what you put in the cloud: your data, identities, permissions, configurations, and applications. The exact split shifts between IaaS, PaaS, and SaaS, but responsibility for your data and access is always yours.
What is the most common cause of cloud breaches?
A: Misconfiguration. Public storage buckets, disabled logging, and over-permissive access settings expose data without any obvious attack. Through 2025, Gartner projected that the overwhelming majority of cloud security failures would trace to customer error rather than provider failure.
How do I know if my cloud is configured securely?
A: A cloud-focused posture or vulnerability assessment checks your configuration against a known baseline and surfaces the misconfigurations and access gaps your team cannot see from the inside. From there, ongoing monitoring keeps new gaps from opening as your environment grows.
About the Author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate.



