DE
Discuss your challenge
All insights

Cloud Security

Cloud security starts with people, not tools

The real risk landscape behind most incidents, and why user education comes first, with technology closing the gap around identities, devices and data.

Picture fitting the best lock money can buy, then handing a spare key to anyone who asks nicely enough. That’s roughly what most environments we get called into actually look like: phishing-resistant this, conditional that, sitting on top of years of “just give them access, it’s faster” decisions nobody ever revisited. The lock was never the weak point. The keys were.

Most security budgets still go to the product first. Buying one is easy, it has a price, a demo, a rollout plan, someone signs off on it in an afternoon. Managing who has access and why is harder. It doesn’t show up on an invoice, and nobody puts “better judgement” on a budget line. So the money defaults to what’s easy to approve, and that’s not a technology failure, it’s an ownership one.

In customer environments, the incidents rarely start with a technology failure either. They start with a person: a clicked link, an approved MFA prompt nobody actually requested, a file shared because checking who needed access would have taken longer. What usually makes it worse is a second thing going wrong at the same time, a control that should have caught the first mistake and didn’t. That’s not a criticism of the people involved. It’s the honest starting point for what needs fixing, and in what order, and it’s why I start engagements with what people understand about the risks in front of them, not with a product list.

Training that’s specific to how attacks actually reach that organisation works. Generic annual compliance training mostly doesn’t, and everyone sitting through it already knows which one they’re in. A simulated phishing campaign tells you more in one send than a completion report tells you all year, because it shows exactly which team needs the next round of attention, not just that training happened. Once that human layer is addressed, technology has one job left: close the gap consistently, at scale, on the days people are tired or distracted, at three points.

  • Identities. A stolen password shouldn’t be enough to get in, and getting in shouldn’t be enough to get everywhere. That’s what Conditional Access, phishing-resistant MFA for anyone with elevated access, and least privilege enforced by default are for, not granted once and never reviewed again.
  • Devices. A device should have to prove it’s compliant before it’s trusted with company data, not the other way around, which is what patching, endpoint protection and enrollment policies are actually doing when they work.
  • Data. Even a fully compromised identity shouldn’t mean unrestricted access to everything, which is the job classification and access governance do, keeping one mistake from becoming a full incident by containing the blast radius instead of letting it spread.

None of this needs the most expensive licence to start. Phishing-resistant authentication and Conditional Access baselines run on Entra ID P1. Risk-based conditions and data classification are usually where a P2 or an E5 add-on earns its cost, and only once the P1 baseline is actually enforced everywhere, not before. Buying the higher tier first and rolling out the fundamentals later is a common way to pay for capability that sits unused for a year, and the trade-off runs the other way too: training and governance take longer to show results than a new product does, cost more in the ongoing exceptions and reviews they require, and none of that shows up on a dashboard the week it’s deployed the way a new tool does. Better judgement takes months, and it’s harder to put in a report, which is exactly why it gets skipped even though it’s the part that actually closes the gap.

So when a security review turns up a gap, the answer isn’t another product, and I’d rather say that plainly than hide behind “it depends.” It’s almost always one of these fundamentals, education, identity, devices or data, not being enforced consistently. Fix what’s already there before buying what’s next. Security isn’t a project with an end date. It’s people who understand what they’re defending against, and a technical baseline that keeps working on the days they don’t.

About the author

Spiros Karampinis

Founder & Lead Cloud Consultant · 17+ years of experience

Cloud strategy, business transformation and clear decisions for Microsoft cloud programmes.

What should change in your Microsoft environment?

In 30 minutes, we'll clarify together:

  • Clarify the current situation and objective
  • Structure possible solution paths
  • Define the most sensible next step

30 minutes · Microsoft Teams · No obligation

Spiros Karampinis
Spiros KarampinisFounder & Lead Cloud Consultant
FIRST CONVERSATION

Book a 30-minute first conversation

Choose a convenient time for a no-obligation conversation.

Control the analytics and third-party features used by this website here. We do not use marketing cookies.

NecessaryAlways active

Stores your theme and cookie choices and temporary language navigation. These functions contain no tracking.

Analytics

Allows Microsoft Clarity to collect pseudonymous usage data such as page views, clicks, scrolling behaviour and session recordings. This helps us identify usability issues and improve the website.

External services

Allows Microsoft Bookings and easyDMARC's Mailflow Guard. These providers may use cookies or browser storage. Alternatively, a service loads only when you explicitly open it.