News
13 min read

Cloud Security: Understanding the Shared Responsibility Model

Learn how the shared responsibility model works and why you are on the hook for your own cloud security. Close your protection gaps today.

A German mid-sized team discusses security questions in front of a monitor showing a schematic view of the shared responsibility model in the cloud.
A German mid-sized team discusses security questions in front of a monitor showing a schematic view of the shared responsibility model in the cloud.

The big illusion: who is really liable for your data in the cloud?

If your mid-sized company relies on cloud services like Microsoft 365, Google Workspace or Salesforce, you probably feel safe at first. It is tempting to believe that, once you move to the cloud, all of your IT security and data backup automatically become the provider's job. But that convenience is a dangerous illusion. A recent study shows, for example, that 64 percent of respondents wrongly assume that data backup rests solely with the provider[1]. In reality, you share responsibility for your business data with the cloud provider from day one.

The myth of the all-inclusive package

Cloud providers like Microsoft, Amazon Web Services or Google primarily secure their own infrastructure. They guarantee the physical protection of their data centers, the failover resilience of the hardware, the power supply and the virtualization layers. In other words: they make sure the cloud platform runs. What happens on that platform, which data is stored there, how user rights are managed and whether the data is backed up correctly is entirely your job[2]. This is what people call the shared responsibility model.

  • The cloud provider's responsibility: physical security of the data centers, protection of the global infrastructure (networks, servers, virtualization) and basic system availability.
  • Your company's responsibility: protecting identities and access rights, classifying and securing all data, running regular backups, and complying with legal requirements.

Your legal duty as the data owner under the GDPR

From a legal standpoint, your business remains the responsible data owner at all times. Under the General Data Protection Regulation (GDPR), you as managing director are personally liable for ensuring that personal customer and employee data is processed securely and protected against loss. If sensitive data is encrypted or stolen through a cyberattack, you cannot shift the responsibility onto the cloud provider. The legal and financial consequences hit your company directly. That is why professional, proactive protection like CAVRIX cybersecurity is essential to close critical security gaps and stay compliant with legal requirements.

The shared responsibility model explained: who takes on which part?

When your mid-sized company uses cloud services from providers like Microsoft, AWS or Google, you quickly run into the shared responsibility model. Many managing directors and IT leads, however, fall for the fatal misconception that moving to the cloud outsources all IT security to the provider. That is a dangerous fallacy. The reality is different: cloud security is a team sport in which responsibilities are clearly divided. While the cloud provider is liable for the security of the cloud, meaning the physical data centers and servers, you are responsible for security in the cloud. That applies in particular to your own data, user accounts and access rights[3].

Physical versus logical security: the subtle difference

To understand shared responsibility, it helps to distinguish between physical and logical security. The cloud provider protects the physical infrastructure: it makes sure no one enters the data centers without authorization, secures the server hardware against failures, and operates the physical network cabling. Logical security, on the other hand, is your domain. That includes configuring firewalls, managing passwords and securing digital identities. If you neglect these logical safeguards, even the most secure data center in the world is useless. A solid, multi-layered security concept is therefore essential to fend off attacks at this logical level.

IaaS and SaaS: your concrete duties compared

Depending on which cloud services you use, the line of your responsibilities shifts. With Infrastructure as a Service (IaaS), such as renting virtual servers, you carry almost the entire responsibility yourself: you have to patch the operating system, secure your applications and configure the network controls. With Software as a Service (SaaS), such as Microsoft 365, the provider handles maintenance of the software and the underlying operating systems, but control over the data and user identities stays one hundred percent with you[3].

Area of responsibilityIaaS (e.g. virtual servers)SaaS (e.g. Microsoft 365)
Data & classificationCustomer (you)Customer (you)
Identities & accountsCustomer (you)Customer (you)
Operating system & patchesCustomer (you)Cloud provider
Physical infrastructureCloud providerCloud provider

Typical false assumptions and how you close security gaps

A widespread mistake in the Mittelstand is the assumption that the cloud provider automatically handles backups and protection against ransomware. If an employee falls for a phishing email and lets malware into the cloud infrastructure, the provider often cannot prevent the incident, because the access happens through a legitimate but compromised user account. To close such entry points, ongoing security awareness training helps: it sensitizes your employees to the dangers and turns them into an active line of defense.

For managing directors in the German Mittelstand, cloud security is not only about technical protection but also about complying with legal requirements and avoiding management liability. This is where CAVRIX comes in. With our cybersecurity service we offer you comprehensive 24/7 monitoring of your cloud environments, so threats are detected and fended off early. Through our intuitive Command Center you keep an eye on your security status and your open tasks at all times. That way you effectively close every security gap without overloading your internal IT resources.

IaaS, PaaS and SaaS compared: how your duties shift

Many managing directors and IT leads in the Mittelstand wrongly assume that moving to the cloud also transfers all responsibility for IT security to the provider. That is a dangerous misconception. Whether you rent servers from Amazon Web Services or use Microsoft 365, the shared responsibility model always applies. This model spells out precisely which security tasks the cloud provider takes on and which duties rest with you as the customer. As a managing director or technical decision-maker, you ultimately carry the responsibility for keeping sensitive company data protected, which is why a deep understanding of these interfaces matters for your cybersecurity.

The three cloud models and who is liable for what

How the tasks are actually split depends heavily on the chosen service model. In its shared responsibility guidance, Microsoft makes clear that the boundaries shift depending on the type of usage, but one constant always remains: data ownership and responsibility for access always stay with the customer[4].

  • Infrastructure as a Service (IaaS): with models like virtual servers, the provider supplies only the physical infrastructure, the virtualization and the network. You are responsible for the operating system, the security patches, the network configuration and all installed applications.
  • Platform as a Service (PaaS): the provider additionally takes over management of the operating system and the middleware. Your job is to secure the applications running on top and to control the interfaces.
  • Software as a Service (SaaS): with ready-made cloud applications like Microsoft 365 or cloud CRM systems, the provider handles almost all of the infrastructure and software security. Even so, responsibility for the user accounts, the assignment of rights and above all the backup of the data remains entirely in your hands.

Critical security gaps often arise in the Mittelstand precisely with the widely used SaaS model. Many companies rely on the provider handling data backups and protection against internal data loss by default. In reality, however, providers usually offer only high platform availability and a short-term recycle-bin function, while long-term data backup and defense against phishing attacks are your own responsibility[1]. Anyone who takes no additional protective measures here risks the permanent loss of business-critical information in ransomware attacks or accidental deletion.

Closing security gaps in the Mittelstand

To reliably close these gaps in day-to-day operations without overloading their often tightly staffed IT resources, more and more mid-sized companies turn to professional support. With tailored managed IT, your own duties in the shared responsibility model can be systematically organized and automated. This ensures that identities are protected, patches are applied promptly and backups are carried out without gaps. Given the growing regulatory requirements and the personal liability of management for failures in risk management, proactive protection of cloud resources is no longer an optional extra but the foundation of a crisis-proof company.

The three most common security gaps in the Mittelstand and how you close them

Many mid-sized businesses wrongly equate using cloud services with fully outsourcing all IT risks. But the reality is different: responsibility for your data, identities and access rights always stays with you. When that responsibility is neglected, critical attack vectors open up. The consequences are especially severe in an attack with extortion software: a successful ransomware attack now costs a mid-sized company in Germany around 266,000 euros on average. To avert such damage, you should understand exactly how a typical ransomware attack in the Mittelstand unfolds and put targeted protective measures in place.

Security gapRiskSolution
Missing multi-factor authentication (MFA)Criminals take over user accounts through phishing or password leaks.Introduce a strict MFA requirement for all cloud access and admin interfaces.
Misconfigured storage sharesInternal documents and customer data are publicly accessible on the internet through unprotected links.Centrally managed permission concepts and regular automated security audits.
Inadequate external backupsBackup copies are encrypted along with everything else in a ransomware attack, leading to a business shutdown.Daily, isolated and immutable backups outside the main network.

The biggest entry point: missing multi-factor authentication

Securing user accounts with a password alone is grossly negligent in modern working life. Cybercriminals use phishing emails or stolen credentials from data leaks to gain effortless access to your cloud environment. Without multi-factor authentication, the entire company network is open to them after the first login. For managing directors in the Mittelstand the risk is enormous, because they are also legally liable for securing the IT systems. The only remedy here is the consistent enforcement of MFA for every single employee. To sensitize the team to the dangers of phishing and establish employees as an active line of defense, ongoing security awareness and regular training are also recommended.

A creeping danger: misconfigured cloud storage

Another critical risk factor in mid-sized IT infrastructures is faulty configuration of cloud services. Out of convenience or lack of awareness, storage areas in the cloud system are often set up so that anyone with the corresponding link can access them. When employees store sensitive contracts, design plans or customer data in such unprotected folders, that data can be indexed by search engines or deliberately spied out by attackers. This is where the principle of shared responsibility applies: the cloud provider merely supplies the secure platform, but assigning and monitoring the permissions is your own responsibility. A robust identity and access protection concept, as anchored in professional cybersecurity for the Mittelstand, closes these gaps through permanent automated controls.

The missing life insurance: inadequate external backups

Should an attacker break into your systems despite all defensive measures, your backup strategy decides the survival of your company. A serious mistake in the Mittelstand is the belief that data in the cloud is automatically backed up safely. If your local backups are permanently connected to the company network, they are usually the first thing to be encrypted or deleted in a ransomware attack. A secure backup strategy absolutely requires external, isolated copies that are separated from the primary network. Ideally these backups must be immutable, so that in an emergency they enable a fast recovery of the systems and prevent lengthy downtime. With a professional security approach and proactive monitoring, you ensure that your business is quickly operational again even after an incident.

A step-by-step plan for your secure path into the cloud

Moving to the cloud promises flexibility and scalability, yet many mid-sized businesses confuse using cloud services with automatically outsourcing all risks. An unprepared migration, however, quickly leads to dangerous security gaps. According to studies, only around 28 percent of smaller companies start their cloud projects with a clear focus on IT security from the outset. To avoid unpleasant surprises and data loss, you as managing director or IT lead should choose a structured, proactive approach. With this step-by-step plan you make your cloud infrastructure sustainably compliant and secure.

Step 1: inventory and risk analysis

The first step toward more security is a complete inventory of all cloud services used in your company. Unregulated use of Software as a Service (SaaS) often creates a sprawling shadow IT. When employees sign up for tools on their own, the IT department loses control over where sensitive company data ends up. Systematically analyze which applications are in use and which data is processed there. Only once you know where your data lives can you take the corresponding protective measures and apply the shared responsibility model cleanly.

Step 2: implement compliance standards like NIS2

Security and compliance go hand in hand. For many mid-sized businesses, complying with legal requirements such as the GDPR or the new NIS2 directive is no longer a voluntary option but a legal obligation. You should check early on whether your business falls under the stricter cyber requirements. A NIS2 quick check gives you fast orientation to identify any regulatory duties directly. By integrating recognized compliance frameworks, you not only protect your company from steep fines but also strengthen your entire digital resilience against cyberattacks.

  1. Complete inventory of all cloud services used, from IaaS to SaaS, to avoid shadow IT.
  2. Classify data by how much protection it needs and assign restrictive access rights following the zero-trust principle.
  3. Clearly define responsibilities for security patches, backups and configurations between your team and the cloud provider.
  4. Introduce continuous security controls and gap-free monitoring of all cloud access for anomalies.

Relief through managed IT and cybersecurity

Securing modern cloud environments requires deep expertise and resources that smaller IT departments often lack. To ease the burden on your team and close security gaps for good, it is wise to work with an experienced partner. With modular managed IT services you hand over the day-to-day administration, patch management and monitoring of your infrastructure into professional hands. Complemented by specialized cybersecurity services, your company benefits from gap-free threat detection around the clock. That keeps your cloud secure, your compliance intact, and lets you focus fully on your core business.

Frequently asked questions

Who is liable for data loss in the public cloud?

Under the shared responsibility model, the cloud provider is generally not liable for your lost data. While the provider secures the physical IT infrastructure, you as the customer are responsible for backing up and restoring your data. A survey shows that 64 percent of companies wrongly believe the provider would handle this.

What does shared responsibility mean in the cloud?

It is the model of shared responsibility. The cloud service provider is responsible for the security of the global cloud infrastructure (hardware, software, networks). As the user, you are responsible for security within that cloud (data, user accounts, access rights, encryption).

Who is responsible for backups in Microsoft 365?

Primarily you. Microsoft does ensure high availability of the services, but by default it does not offer a full backup of your data. Without your own backups, data is often lost for good after deletion or ransomware attacks, which in the Mittelstand can cost an average of 266,000 euros.

How do the duties differ between IaaS and SaaS?

With Infrastructure as a Service (IaaS) you carry responsibility for almost everything, including the operating system, applications and network traffic. With Software as a Service (SaaS) the provider takes over the operation and protection of the software, but you remain responsible for your data and identity management.

Why is multi-factor authentication (MFA) so important in the cloud?

MFA is one of the most effective measures against unauthorized access. Since 99 percent of cloud security problems stem from mistakes on the customer side (such as weak passwords or misconfigurations), MFA prevents unauthorized access even when credentials have been stolen.

How can small companies improve their cloud security?

To begin with, they should eliminate shadow IT and establish clear compliance policies. Since, according to studies, only 28 percent of smaller firms factor IT security in right at the project start, using managed IT and cybersecurity services helps close gaps efficiently and professionally.

Sources

  1. veeam.com
  2. cloudcomputing-insider.de
  3. learn.microsoft.com
  4. learn.microsoft.com

Where does your company stand?

30 minutes, free, no commitment. We show you where you stand.