Cybersecurity

Cloud security: how to protect company data in the cloud

Cloud can greatly improve availability and collaboration, but it becomes secure only when identities, access, backups, logging and responsibilities are configured correctly.

  • Cybersecurity
  • 6 min read
  • 03. 01. 2025
  • practical recommendations for business IT
Article illustration Cloud security: how to protect company data in the cloud

Cloud is not automatically secure. It must be designed securely

Cloud services are now a normal part of business IT. Companies use them for e-mail, documents, Microsoft 365, SharePoint, OneDrive, backups, servers, databases and internal applications. This brings flexibility and better availability, but it also changes how security must be approached.

With a local server, companies think about the room, disk array, firewall and physical access. In the cloud, identities, permissions, devices, service configuration, logging and the ability to restore data quickly move to the foreground. If an account has no multi-factor authentication or a user has overly broad permissions, even the best provider will not save the cloud environment.

Cloud security is not one product. It is a combination of good design, correctly configured accounts, regular checks, backups and clear rules about who is responsible for what.
Cloud infrastructure with symbols of security and data protection
A secure cloud stands on several layers: identities, access, encryption, monitoring, backups and regular configuration reviews.

Shared responsibility: what the provider handles and what remains with the company

One of the most important things in cloud security is understanding the shared responsibility model. The cloud provider takes care of a large part of the infrastructure, availability and physical security of data centres. But that does not mean the company can switch off its own security.

For Microsoft 365, for example, Microsoft operates the service, but the company is still responsible for user accounts, strong authentication, SharePoint permissions, file sharing, endpoint devices, internal processes and incident response. With Azure virtual servers, the responsibility is even broader because the operating system, applications and part of the network configuration are managed by the customer or their IT partner.

  • The provider handles the platform Physical data centres, core infrastructure, service availability and part of the security mechanisms according to the type of cloud service.
  • The company handles its own usage Accounts, permissions, devices, data, sharing, passwords, MFA, internal rules, information classification and control over who can access what.
  • The IT partner connects both sides It helps configure the cloud so the provider’s technical capabilities make sense in the specific company, not only in a licence table.

The biggest risks are not always created in the cloud, but in configuration

Incidents often do not show that the cloud service itself was weak. More often, configuration, process or everyday user discipline fails. Typical examples are a shared folder with overly broad permissions, an old account of a former employee, missing MFA or unclear rules for external suppliers.

  • Weak or reused passwords An attacker does not need to break the cloud. It is enough to obtain a password from phishing or another leak and try it in the company environment.
  • Missing MFA Multi-factor authentication significantly reduces the risk of a successful sign-in using only a stolen password. For administrators, it should be standard.
  • Excessive permissions Users often have access to data they do not need for their work. During an incident, the damage then spreads faster.
  • Uncontrolled sharing External cloud links are practical, but without rules and regular checks they can become a path to sensitive documents.
  • Backups without a recovery test A backup has value only when you know what you can restore, how quickly and who is responsible for the recovery.

Security minimum for Microsoft 365 and cloud services

Not every company immediately needs a complex security centre. Almost every company, however, needs a foundation that reduces the most common risks and brings order to the IT environment. For Microsoft 365, Azure or hybrid environments, we recommend starting with these steps.

  • Enable MFA and handle conditional access MFA should be enabled at least for administrators and ideally for all users. With higher licences, it makes sense to configure conditional access based on risk, location, device or application type.
  • Separate administrator accounts Everyday work and administration should not run from the same account. This reduces the risk that a compromised user account opens the way to the whole environment administration.
  • Review SharePoint, OneDrive and Teams You need to know which libraries are internal, which are shared externally, who owns them and what rules apply to links outside the company.
  • Set up backup and recovery A cloud service is not the same as a company backup. For critical data, you need your own recovery strategy and regular tests.
  • Collect logs and monitor anomalies Without logs, an incident is investigated blindly. Sign-ins, permission changes and suspicious activities should be visible and checked regularly.

Encryption helps, but it is not enough on its own

Encryption of data in transit and at rest is an important protection layer. It reduces the risk of information misuse during a technical incident or unauthorised access to storage. In most modern cloud services, encryption is standard, but the company must still manage access to data.

If a user has legitimate access to a file and their account is compromised, encryption of the stored file will not stop the attack. That is why encryption must be complemented by MFA, identity management, need-based permissions, device protection and sharing rules.

Cloud security must also account for people

Technical settings are only part of the solution. Employees work with e-mails, attachments, shared links and external applications every day. If they cannot recognise phishing, do not understand sharing rules or use the same passwords across several services, the security risk remains high.

  • short training on phishing and suspicious messages,
  • clear rules for sharing documents outside the company,
  • a procedure for reporting a suspicious e-mail or lost device,
  • regular review of old accounts, external users and unused licences,
  • understandable rules for passwords, MFA and sign-ins from new devices.

What to do if you already use cloud

Many companies moved to the cloud gradually. First e-mail, then Teams, OneDrive, shared documents, later backups or virtual servers. After some time, however, nobody knows exactly who has access, what is shared externally and which settings are still original.

  • Map the tenant and accounts Review administrators, former employees, external users, unused accounts and sign-in methods.
  • Review data permissions Check SharePoint, Teams, OneDrive and public or external links. For sensitive data, assign owners and access rules.
  • Verify backups and recovery It is not enough to know that a backup exists. You need to test whether you can restore a file, mailbox, user data or critical service in a reasonable time.
  • Set up monitoring Watch risky sign-ins, permission changes, new applications, administrator actions and suspicious user behaviour.

When a cloud security audit is worthwhile

An audit makes sense especially when a company is growing, changing its IT supplier, moving to Microsoft 365, dealing with an incident, adding more external collaborators or does not know whether its cloud is configured correctly. It does not have to be a large project. Even a short check can reveal risks that can be fixed quickly.

  • administrator accounts and MFA,
  • external sharing in SharePoint and OneDrive,
  • mail settings and phishing protection,
  • backup and recovery plan,
  • licence status and security features,
  • logging and incident readiness.

How Yenwa can help you

At Yenwa, we help companies look at cloud practically: not through a list of buzzwords, but through real accounts, data, risks and everyday operations. We review settings, recommend priorities and explain what makes sense to solve immediately and what can wait.

We can help with Microsoft 365, Azure, identity management, MFA, document sharing, backup, security rules, monitoring and long-term administration. The goal is not to make work harder for users. The goal is to have a cloud environment that is usable, clear and appropriately protected.

If you are not sure whether your cloud is configured securely, start with a short consultation. We will review your environment and propose concrete steps without unnecessary pressure to buy additional tools.

Do you want to solve a similar topic in your organisation?

The article is a good starting point. If you want a concrete plan for licences, accounts, cloud, security or school IT, send us an enquiry.