Why “is this cloud platform secure” is the wrong question — and what the shared responsibility model actually demands of you.

Cloud changed one thing a lot of security teams still struggle to accept. You no longer own most of the infrastructure. You still own all of the business risk.

That’s where cloud security conversations tend to go wrong. People ask: is AWS secure, is Azure secure, is Microsoft 365 secure? Wrong question. The one that matters is: which part is the provider securing, and which part is still mine?

Where the breaches actually happen

The big cloud breaches rarely happen because a hyperscaler forgot to secure a data center. They happen because someone exposed a storage bucket, disabled MFA, over-permissioned an identity, left an API open — or simply assumed the provider must be handling that. That one assumption has probably caused more cloud incidents than most sophisticated attack techniques combined.

This is exactly why the Cloud Security Alliance’s Cloud Controls Matrix exists, built around the shared responsibility model. There’s no running cloud security without it. The provider secures the building; you still have to lock your own apartment. Where the line falls shifts with what you buy — with infrastructure, you own most of the stack; with SaaS, the provider owns nearly everything except your data and who you let near it, which is always yours.

The pattern I’ve seen too many times

An organization moves fast onto a genuinely excellent cloud platform — a provider with a security team bigger than the whole customer company. A comfortable assumption settles in: we’re top-tier now, the security’s handled. Then a bucket full of sensitive data is left open to the internet. Not by the provider — by a hurried internal change nobody reviewed.

When someone asks how a world-class provider let this happen, the honest answer points, correctly, to the shared responsibility model. That bucket was always the customer’s. The split existed. It just lived in a document nobody had turned into an owned, operational reality.

One control, many frameworks

This is also where the Cloud Controls Matrix stops looking like a rival to your other frameworks and starts looking like a layer on top of them. STAR Certification is built on ISO 27001. STAR Attestation is built on SOC 2. CCM didn’t replace either — it sits on top and adds the cloud-specific piece they were missing. A single control, mapped once, can answer CCM, ISO, PCI DSS, and SOC 2 at the same time. Do the work once; present it many ways.

Plenty of organizations are proudly cloud-first. Very few are genuinely cloud-governed.


Vikas Khandelwal is the Founder & Principal Consultant at Secalyx Technologies, advising organizations on cloud security governance and shared responsibility.

Leave a Reply

Your email address will not be published. Required fields are marked *