Cloud Security
Cloud security starts with people, not tools
The real risk landscape behind most incidents, and why user education comes first, with technology closing the gap around identities, devices and data.
Picture fitting the best lock money can buy, then handing a spare key to anyone who asks nicely enough. That’s roughly what most environments we get called into actually look like: phishing-resistant this, conditional that, sitting on top of years of “just give them access, it’s faster” decisions nobody ever revisited. The lock was never the weak point. The keys were.
Most security budgets still go to the product first. Buying one is easy, it has a price, a demo, a rollout plan, someone signs off on it in an afternoon. Managing who has access and why is harder. It doesn’t show up on an invoice, and nobody puts “better judgement” on a budget line. So the money defaults to what’s easy to approve, and that’s not a technology failure, it’s an ownership one.
In customer environments, the incidents rarely start with a technology failure either. They start with a person: a clicked link, an approved MFA prompt nobody actually requested, a file shared because checking who needed access would have taken longer. What usually makes it worse is a second thing going wrong at the same time, a control that should have caught the first mistake and didn’t. That’s not a criticism of the people involved. It’s the honest starting point for what needs fixing, and in what order, and it’s why I start engagements with what people understand about the risks in front of them, not with a product list.
Training that’s specific to how attacks actually reach that organisation works. Generic annual compliance training mostly doesn’t, and everyone sitting through it already knows which one they’re in. A simulated phishing campaign tells you more in one send than a completion report tells you all year, because it shows exactly which team needs the next round of attention, not just that training happened. Once that human layer is addressed, technology has one job left: close the gap consistently, at scale, on the days people are tired or distracted, at three points.
- Identities. A stolen password shouldn’t be enough to get in, and getting in shouldn’t be enough to get everywhere. That’s what Conditional Access, phishing-resistant MFA for anyone with elevated access, and least privilege enforced by default are for, not granted once and never reviewed again.
- Devices. A device should have to prove it’s compliant before it’s trusted with company data, not the other way around, which is what patching, endpoint protection and enrollment policies are actually doing when they work.
- Data. Even a fully compromised identity shouldn’t mean unrestricted access to everything, which is the job classification and access governance do, keeping one mistake from becoming a full incident by containing the blast radius instead of letting it spread.
None of this needs the most expensive licence to start. Phishing-resistant authentication and Conditional Access baselines run on Entra ID P1. Risk-based conditions and data classification are usually where a P2 or an E5 add-on earns its cost, and only once the P1 baseline is actually enforced everywhere, not before. Buying the higher tier first and rolling out the fundamentals later is a common way to pay for capability that sits unused for a year, and the trade-off runs the other way too: training and governance take longer to show results than a new product does, cost more in the ongoing exceptions and reviews they require, and none of that shows up on a dashboard the week it’s deployed the way a new tool does. Better judgement takes months, and it’s harder to put in a report, which is exactly why it gets skipped even though it’s the part that actually closes the gap.
So when a security review turns up a gap, the answer isn’t another product, and I’d rather say that plainly than hide behind “it depends.” It’s almost always one of these fundamentals, education, identity, devices or data, not being enforced consistently. Fix what’s already there before buying what’s next. Security isn’t a project with an end date. It’s people who understand what they’re defending against, and a technical baseline that keeps working on the days they don’t.
What should change in your Microsoft environment?
In 30 minutes, we'll clarify together:
- Clarify the current situation and objective
- Structure possible solution paths
- Define the most sensible next step
Prefer to write? hello@clouddream.team
30 minutes · Microsoft Teams · No obligation


