Cloud services have become a core enabler of digital transformation, with the events of 2020 accelerating shifts such as retail moving online, manufacturers reorganizing operations, and widespread remote work. As cloud usage becomes business-critical, security and compliance become central concerns, especially in hybrid IT environments where consistent governance across delivery models is essential. The report emphasizes that security and compliance responsibilities are shared: cloud service providers (CSPs) secure the underlying infrastructure, while cloud clients (tenants) are responsible for securing how services are configured and used, and for meeting legal and regulatory obligations. Many reported cloud security incidents stem from tenant misconfigurations and failures to apply established internal controls to cloud environments.
Key business risks include loss of business continuity from outages, cyber-attacks (including ransomware and denial of service), data breaches from leakage or unauthorized access, and regulatory compliance failures under frameworks such as GDPR, CCPA, PCI-DSS, and others. Mitigation requires governance that sets measurable objectives, verifies provider assurances, and integrates cloud controls into enterprise processes. Foundational practices include strong identity and access governance for privileged administrators, least-privilege access with segregation of duties, regular entitlement reviews, strong authentication, logging, and anomaly detection.
Data protection must cover encryption in transit (TLS 1.2/1.3 or IPsec), encryption at rest with tenant-controlled keys, and—where required—confidential computing approaches such as trusted execution environments, pseudonymization, or homomorphic encryption. Tenants must also implement backup and restore plans for resilience. Security hygiene further depends on automated vulnerability scanning, secure configuration templates, remediation of misconfigurations (including preventing public access to sensitive storage), and zero-trust network segmentation with private subnets and web application firewalls. The report highlights AWS examples (e.g., Control Tower, S3 public access controls, Artifact, Audit Manager, Outposts, GuardDuty, Detective) and stresses “trust but verify” through independent compliance evidence (ISO, SOC, CSA STAR, and related standards).
See All Locations
See All Locations