← All insights

Cloud security needs named owners

Translate shared responsibility into specific ownership for access, configuration, information, and response.

Moving a service to the cloud changes the distribution of security responsibilities. Leaders still need to know who protects information, controls access, monitors the service, and responds when something goes wrong. A supplier contract is one part of that answer.

Microsoft’s shared-responsibility guidance makes a critical distinction: responsibilities vary across infrastructure, platform, and software services, while customers retain responsibilities for their data, identities, and configuration choices. A SaaS subscription does not transfer every security obligation to the provider. (Microsoft source)

Make responsibility operational

For each critical service, document the relevant responsibilities and the evidence that they are being carried out. Identify the business owner, the internal technical owner, the provider’s obligations, and the escalation path.

Consider an illustrative team adopting a cloud collaboration tool. The provider may secure the underlying infrastructure, while the customer must decide who can join, what information can be shared, how access is reviewed, and what happens when someone leaves. Those decisions need owners before the tool becomes embedded in everyday work.

Examine the boundaries

Distributed services introduce dependencies across providers, applications, identities, and data flows. Map the important boundaries and examine what crosses them. An integration can create access or information exposure that is easy to miss when each application is reviewed separately.

The response plan should cover those boundaries too. Establish how incidents will be detected, who can contain the problem, what assistance the provider supplies, and how affected business teams will be informed. Test recovery arrangements against the service the business actually needs.

Review evidence as the service changes

Access, configuration, integrations, and usage change over time. Assign responsibility for reviewing those changes and for closing the gaps they reveal. Concentrate attention on the services and information whose compromise would materially affect the organisation.

Cloud security becomes more dependable when shared responsibility is translated into named work. Leaders should be able to point to an owner, an operating practice, and evidence of completion for each critical obligation.

Revised from my original essay on The Loop. This edition develops the argument for a leadership audience; the original preserves its coursework context and bibliography.

Original article: The Loop, 23 October 2025.

Bring this topic to your team or event. Connect with David.