
Cloud adoption continues to accelerate as organisations embrace the flexibility, scalability and resilience offered by platforms such as Microsoft Azure, Amazon Web Services (AWS) and Google Cloud. But while migrating to the cloud can reduce the burden of managing physical infrastructure, it doesn't eliminate an organisation's cybersecurity responsibilities.
One of the most common misconceptions in cloud security is the belief that cloud providers automatically protect everything hosted on their platforms. In reality, cloud providers are responsible for securing the cloud itself, while customers remain responsible for securing what they put into it.
Understanding this distinction is essential. Misinterpreting the cloud security model can leave organisations exposed to data breaches, ransomware and compliance failures, despite investing in leading cloud platforms.
What is the shared responsibility model in cloud security?
Simply put, it defines which security responsibilities belong to the cloud provider and which remain with the customer. While the exact responsibilities vary slightly between Microsoft Azure, AWS and Google Cloud, the principle remains the same:
The cloud provider is responsible for securing:
- Physical data centres
- Servers and networking infrastructure
- Hypervisors and core cloud services
- Availability of the cloud platform
Customers are responsible for securing:
- Cloud workloads
- Virtual machines
- Applications
- User identities and permissions
- Operating systems
- Data
- Network configurations
- Security policies
In other words, the provider ensures the building is secure, but you're responsible for locking your office door. Understanding who is responsible for cloud security is fundamental to building a resilient cloud environment.
Shared responsibility model explained
Imagine your organisation deploys a virtual machine in Microsoft Azure.
Microsoft ensures the underlying hardware is secure and the Azure platform remains available.
However, Microsoft will not:
- Patch your operating system
- Detect malware inside your VM
- Protect vulnerable applications
- Prevent ransomware encrypting your files
- Correct overly permissive user permissions
- Secure sensitive business data
Those responsibilities remain yours.
This highlights why simply moving workloads to the cloud does not automatically improve security.
Where customer responsibility starts
Many organisations assume that once a workload is deployed in Azure, AWS or Google Cloud, security becomes largely automated. Unfortunately, attackers know otherwise.
Customer responsibilities in cloud security typically include:
Protecting cloud workloads
Every workload running in the cloud, including virtual machines, application servers and databases, requires the same level of protection as an on-premises server.
Without dedicated workload security, cloud-hosted systems remain vulnerable to malware, ransomware, credential theft and zero-day attacks.
Securing virtual machines
One of the biggest gaps in many cloud environments is virtual machine security.
Virtual machines often contain:
- Business applications
- Customer databases
- File servers
- Domain controllers
- Financial systems
These systems require continuous monitoring, malware prevention and vulnerability management.
Securing virtual machines in the cloud should be treated no differently from protecting critical servers inside your own data centre.
Identity and access management
Misconfigured identities remain one of the leading causes of cloud breaches.
Customers must:
- Implement multi-factor authentication
- Apply least-privilege access
- Monitor privileged accounts
- Remove inactive users
- Secure service accounts
Compromised credentials continue to be one of the easiest ways for attackers to gain access to cloud environments.
Protecting business data
Cloud providers offer highly resilient storage, but they don't determine who should have access to your information.
Organisations remain responsible for:
- Data encryption
- Backup policies
- Access permissions
- Retention policies
- Compliance requirements
Why cloud-native security controls aren't enough
Azure, AWS and Google Cloud all provide built-in security features.
These include:
- Security recommendations
- Configuration monitoring
- Identity tools
- Logging
- Native firewalls
These capabilities provide valuable visibility into the cloud platform itself. However, they are not purpose-built endpoint protection solutions.
Native tools often don't provide:
- Advanced malware prevention
- Behaviour-based ransomware detection
- Comprehensive exploit prevention
- Consistent protection across hybrid environments
- Unified security management across multiple cloud platforms
This is why organisations increasingly combine native cloud controls with dedicated cloud workload protection for businesses.
Rather than replacing cloud-native security, workload protection complements it by defending the workloads themselves.
Common misconceptions among IT teams
Several misconceptions continue to create unnecessary risk.
Misconception: "The cloud provider patches everything."
Reality: Cloud providers patch their infrastructure. Customers remain responsible for patching their operating systems and applications.
Misconception: "Our virtual machines are already protected."
Reality: Unless security software has been deployed and managed on those machines, they remain vulnerable to malware and ransomware.
Misconception: "Cloud workloads can't be infected."
Reality: Attackers target cloud-hosted workloads just as aggressively as on-premises servers. If a vulnerable application exists inside a VM, attackers can exploit it regardless of where it is hosted.
Misconception: "Microsoft Defender or native tools are enough."
Reality: Built-in tools provide important security capabilities, but organisations with sensitive workloads often require layered protection that includes advanced threat prevention, workload security and centralised visibility across their entire environment.
How to secure cloud workloads
Security teams should adopt a layered approach that combines cloud platform controls with workload-level protection. Following best practices can help organisations reduce risk while maintaining operational resilience.
Best practices for cloud workload security include:
- Deploy dedicated protection for all cloud workloads and virtual machines.
- Keep operating systems and applications fully patched.
- Use strong identity and access controls with multi-factor authentication.
- Apply least-privilege access across all users and services.
- Continuously monitor workloads for suspicious activity.
- Encrypt sensitive business data at rest and in transit.
- Regularly review cloud configurations for misconfigurations.
- Integrate workload protection into broader security monitoring and incident response processes.
Cloud compliance requires more than infrastructure security
South African organisations are increasingly expected to demonstrate strong cloud compliance under regulations such as POPIA and industry requirements including Joint Standard 2.
Meeting these obligations involves more than storing data in a secure cloud platform.
Organisations must also demonstrate that they are actively protecting:
- Customer information
- Virtual machines
- Business applications
- Sensitive workloads
- User identities
Without adequate workload protection, organisations may still face regulatory scrutiny even if the underlying cloud infrastructure remains secure.
How ESET Cloud Workload Protection strengthens cloud security
Understanding the shared responsibility model for major cloud service providers is only the first step. Organisations also need the right tools to secure the workloads they are responsible for.
As part of the ESET PROTECT Platform, ESET Cloud Workload Protection (CWP) provides advanced protection for cloud-hosted virtual machines across Microsoft Azure and Amazon Web Services (AWS). It helps organisations defend critical workloads against malware, ransomware and other cyber threats while maintaining consistent security across hybrid and multi-cloud environments.
By extending protection directly to cloud workloads, ESET Cloud Workload Protection complements native cloud security controls rather than replacing them. Security teams gain centralised visibility, simplified management and consistent protection for workloads running in the cloud alongside on-premises infrastructure.
Shared responsibility starts with your workloads
Cloud providers deliver highly secure infrastructure, but they cannot secure the workloads, applications, identities and data that belong to your organisation.
Understanding the shared responsibility model helps eliminate dangerous assumptions and close security gaps before attackers can exploit them.
By combining cloud-native capabilities with dedicated cloud workload protection, organisations can strengthen cloud security, improve cloud compliance, and build a more resilient security posture, ensuring that every virtual machine, application and workload receives the protection it deserves