Understanding the Shared Responsibility Model: Who Is Responsible for Your Cloud Security? 

When you hire someone to join your business, you usually provide a job description that clearly outlines their responsibilities. Doing so helps manage expectations, prevents misunderstandings, and ensures important tasks don’t get overlooked.

You do this because a misunderstanding of their role can lead to them doing things they’re not supposed to do, while important tasks may be neglected. Ultimately, this can cost your business time, money and trust.

Now, here is the thing.

When you sign up for a cloud service like Microsoft 365 or Google Workspace, there is also a “job description” that outlines a clear division of responsibilities between you and your cloud provider.

The problem is that most business owners never read it, and that’s understandable. The terms and conditions that come with cloud services can be long, technical and difficult to navigate.

However, not taking the time to understand these details can lead to assumptions about what your cloud provider is responsible for and what your business is responsible for. Those assumptions can then leave your business exposed to unnecessary security risks.

This relationship between your business and your cloud provider is known as the shared responsibility model, and understanding how it works is one of the most important steps you can take to protect your business in the cloud.

So, let’s get into it.

What Is the Shared Responsibility Model?

The shared responsibility model is a security framework that defines how security responsibilities are divided between a cloud service provider and the customer using its services.

In simple terms, it answers a very important question: Who is responsible for what?

When your business uses Microsoft 365 or Google Workspace, Microsoft and Google are responsible for securing the cloud infrastructure that runs their services. Your business, however, remains responsible for how your organisation uses those services and how you configure and protect your accounts and data.

Think of it like renting an office in a secure commercial building. The building owner may be responsible for securing the building, maintaining the structure, managing the electricity and protecting the physical premises, but they are not necessarily responsible for deciding who in your company has the keys to your office.

They don’t decide which employees can enter specific rooms, which documents you leave on your desk or whether you lock the door when you leave; those responsibilities belong to you.

The same principle applies to cloud services; your provider secures the cloud while your business is responsible for securing how you use the cloud.

What Is Your Cloud Provider Responsible For?

Microsoft and Google invest heavily in securing the infrastructure behind their cloud services, and while the exact responsibilities can vary depending on the service and configuration, the cloud provider is generally responsible for the security of the underlying infrastructure.

This can include areas such as:

  • Physical security of data centres
  • Physical infrastructure and hardware
  • Core networking infrastructure
  • The underlying cloud platform
  • Protection of the infrastructure supporting the service
  • Maintaining the availability and resilience of the platform
  • Applying security controls to the services they operate

This is a significant responsibility, and covers core security needs. However, it is important to understand that a secure cloud platform does not automatically make every business using it secure, and this is where the other half of the shared responsibility model comes in.

What Is Your Business Responsible For?

Your business is responsible for the security decisions and configurations that sit within your control.

For example, if your organisation has a Microsoft 365 or Google Workspace account, your organisation is generally responsible for deciding:

  • Who gets access to the account
  • What information they can access
  • Whether they use multi-factor authentication
  • How strong your password policies are
  • What happens when an employee leaves the company
  • Who has administrator privileges
  • How files and information are shared
  • Whether devices accessing company data are secure
  • How suspicious activity is detected and handled

In other words, your cloud provider can give you the tools to protect your environment, but your business has to configure and use those tools correctly.

Imagine that your organisation has an employee whose password is stolen through a phishing attack. If the employee’s account does not have multi-factor authentication enabled, an attacker may be able to log in to your organization’s virtual workspace using the stolen password.

The fact that your business uses a highly secure cloud platform does not necessarily prevent this from happening. The cloud platform may be secure, but the business registered on their platform didn’t perform their own share of responsibility to stay protected.

This is the difference between security of the cloud and security in the cloud, which is why it’s wrong to think that just because you’re using Microsoft 365 or Google Workspace, you’re secure.

One of the most dangerous assumptions a business can make is that subscribing to a reputable cloud service means its cybersecurity responsibilities have been taken care of; it definitely hasn’t, and it is the responsibility of the business to protect themselves from cybercrime.

Microsoft 365 and Google Workspace provide powerful security features, but your organisation still needs to configure those features and establish appropriate security policies, which is a core way of ensuring cybersecurity.

Another common misconception I’ll like to address is that storing information in the cloud automatically means your business has a complete backup strategy. It’s important for you to understand that cloud storage and backup are not necessarily the same thing.

You still need to learn  how data recovery, retention and restoration work within the cloud service you’re using and then determine whether additional backup measures are necessary for your business.

A Simple Shared Responsibility Checklist

To ensure you are taking your share of responsibility seriously, answer the following questions as it relates to your business: 

  1. Do all users have multi-factor authentication enabled?
  2. Who has administrator access?
  3. Are former employees’ accounts disabled immediately?
  4. Do employees have more access than they actually need?
  5. Can sensitive files be shared publicly or externally?
  6. Are we monitoring suspicious login activity?
  7. Are our employees trained to recognise phishing attacks?
  8. Are our company devices properly secured?
  9. Do we have a clear backup and recovery strategy?

If you cannot confidently answer some of these questions, that may be a sign that your organisation needs to take a closer look at its security.

Always remember that while  Microsoft and Google have responsibilities for securing the infrastructure and services they provide your business, you are ultimately responsible for the people, accounts, devices, configurations and data within your control. 

So, take the time to understand your responsibilities, configure the security tools available to you and work with a professional to work with your organization to get the right systems in place.

The bottom line is that your cloud provider can secure the cloud, but your business still has a role to play in keeping your data and users safe. At StonePoint Technology Partners, we help businesses understand their role and make sure their cloud environments aren’t leaving them exposed to unnecessary risk. If you’re unsure whether you’ve got your side of the shared responsibility model covered, contact us at Info@stonepointtech.com or call (727) 478-7355, we’d be happy to help.

Leave a Reply

Your email address will not be published. Required fields are marked *

Skip to content