Focus

Cloud security depends on how responsibility is distributed across the stack

Exposure emerges through configuration, identity, workloads, networks and unclear boundaries between teams and providers.

2 min read Author: KeynesMoore

Cloud security depends on how responsibility is distributed across the stack

Cloud transfers operation of some infrastructure; not service accountability. Responsibility changes across infrastructure, platform and software offerings, and varies by control. Exposure appears in the seams�when provider, central platform, product team and security each assume another party owns identity, configuration, logging or recovery.

Create a control map for the actual service, not a generic cloud diagram. For data, identity, keys, workloads, logs, backup and response, name who designs, configures, operates, monitors and assures. CISA�s cloud architecture makes the distinction explicit: vendors secure underlying SaaS platforms while customers remain responsible for correct configuration, with some monitoring shared.

Identity is the primary control plane. Remove implicit trust based on network location, use phishing-resistant authentication, short-lived workload identities and least privilege, and govern privileged and machine accounts. NIST�s zero-trust guidance emphasizes user, device, application and service identities across hybrid and multi-cloud environments. Review paths that bypass federation or central policy.

Reduce drift through governed landing zones, infrastructure as code, policy checks and continuous inventory. Central teams should provide secure defaults and reusable controls; product teams retain ownership of data classification, workload behavior and exceptions. Logs must reach an independent plane able to connect cloud changes, identity events and application activity.

Test the shared model under failure. Rehearse compromised administrator access, provider outage, destructive action and recovery when the tenant is unavailable. Verify export, backup integrity, support escalation and contractual evidence. Cloud security works when every boundary has an owner, controls are observable and recovery does not depend on the same identity or service that failed.

Registered access

Access exclusive content and member services

Register or log in to read the full content and access exclusive insights and services reserved for registered users.

Related macro

Digital

Connect digital strategy, technology, products, operations and customer experience to enterprise priorities.

Discover the macro

Editorial overview

Articles

Focus

Strategic challenges

POV

Strategic impact

What we observe

Get in touch

Get in touch with our experts to discuss your priorities, explore potential opportunities, and understand how our capabilities can support your organization.

Contact us
The content on this website is provided for general information only and does not constitute financial, legal, tax, or professional advice. KeynesMoore makes no representations regarding the accuracy or completeness of the information provided. Users are solely responsible for any decisions made based on this material. For comprehensive analysis and tailored strategic guidance, please schedule a consultation with our expert team. All content is proprietary to KeynesMoore and protected by copyright. Any unauthorized reproduction, distribution, or use is strictly prohibited.
®2026 KeynesMoore. All Rights Reserved.