DE
Discuss your challenge
All insights

Cloud Security

Cloud security starts with people, not tools

The real risk landscape behind most incidents, and why user education comes first, with technology closing the gap around identities, devices and data.

Most security budgets go to tools first. In our experience, that’s backwards. The incidents we’ve seen almost never start with a technology failure. They start with a person: a clicked link, a reused password, a fraudulent MFA prompt approved without thinking, a file shared a little too broadly because it was faster than checking who actually needed access.

That’s not a criticism of the people involved. It’s the honest starting point for what actually needs protecting, and in what order.

The risk landscape is smaller and more repetitive than it sounds

Security marketing makes the threat landscape sound infinite. In practice, what we see repeating across customer environments is a short list:

  • Phishing and credential theft. Still the most common entry point, and still the hardest to fully prevent, because it targets judgment, not infrastructure.
  • Business email compromise. A compromised or spoofed mailbox used to redirect payments or extract information, often with no malware involved at all.
  • Ransomware via a compromised endpoint. One unpatched or unmanaged device is usually all it takes to get a foothold.
  • Oversharing and access sprawl. Years of “just give them access, it’s faster” decisions, quietly building a much larger attack surface than anyone intended.
  • Misconfiguration. A storage container, a guest permission, a Conditional Access exception left in place long after the reason for it was forgotten.

None of these are exotic. What usually happens is a combination of at least two, one human decision and one technical gap that should have contained the damage but didn’t.

Why education has to come first

Technology is a layer on top of judgment. It isn’t a replacement for it. MFA doesn’t help if someone approves a push notification they didn’t request. Conditional Access doesn’t help if someone hands their password to a convincing enough phone call. The strongest technical controls still assume a baseline of user judgment underneath them, and when that baseline isn’t there, the controls end up working around people instead of with them.

That’s why we start security engagements with what people actually understand about the risks in front of them, not with a product list. Training that’s specific to how attacks actually reach that organisation works. Generic annual compliance training mostly doesn’t, and in our experience everyone involved already knows which one they’re running. A simulated phishing campaign tells you more in one send than a training completion report does all year, not because it catches everyone who fails, but because it shows you exactly which team or role needs the next round of attention.

Technology’s job is to compensate at scale, consistently

People have good days and bad days. Technology doesn’t get tired at 4pm on a Friday, which is exactly why it belongs layered on top of education, not instead of it. Once the human layer is addressed, the technical layer has one job: close the gap consistently, across three things.

Identities. A stolen password shouldn’t be enough to get in, and getting in shouldn’t be enough to get everywhere. That’s what Conditional Access, phishing-resistant MFA for anyone with elevated access, and least privilege enforced by default are actually for. Identity is the layer every other control sits behind, which is why it gets the most attention in how we structure a security baseline.

Devices. A device has to prove it’s compliant before it’s trusted with company data, not the other way around. Patching, endpoint protection and enrollment policies exist to make sure a single unmanaged laptop can’t become the entry point for everything else.

Data. Even a fully compromised identity shouldn’t mean unrestricted access to everything. Classification and access governance are what keep a single mistake from becoming a full breach, by making sure the blast radius of any one failure stays contained.

None of these three replace the others, and none of them replace the education that has to come first. They’re what catches what judgment alone can’t, consistently, every time, not just on the days people remember their training.

None of this needs a top-tier licence to start. Phishing-resistant authentication strength and Conditional Access baselines run on Entra ID P1. The risk-based conditions and the data classification and protection layer are usually where a P2 or an E5 add-on gets justified, and only once the P1 baseline is actually enforced everywhere, not before. Buying the higher tier first and rolling out the fundamentals later is a common way to pay for capability that sits unused for a year.

When a security review turns up a gap, the answer usually isn’t another product. It’s almost always one of these three fundamentals not being enforced consistently. Buying something new is rarely the next step. Fixing the gap in identity, devices or data that’s already there usually is.

Security isn’t a project with an end date. It’s people who understand what they’re defending against, and a technical baseline across identity, devices and data that keeps working on the days they don’t.

About the author

Spiros Karampinis

Founder & Lead Cloud Consultant · 17+ years of experience

Cloud strategy, business transformation and clear decisions for Microsoft cloud programmes.

What should change in your Microsoft environment?

In 30 minutes, we'll clarify together:

  • Clarify the current situation and objective
  • Structure possible solution paths
  • Define the most sensible next step

30 minutes · Microsoft Teams · No obligation

Spiros Karampinis
Spiros KarampinisFounder & Lead Cloud Consultant
FIRST CONVERSATION

Book a 30-minute first conversation

Choose a convenient time for a no-obligation conversation.

Control the analytics and third-party features used by this website here. We do not use marketing cookies.

NecessaryAlways active

Stores your theme and cookie choices and temporary language navigation. These functions contain no tracking.

Analytics

Allows Microsoft Clarity to collect pseudonymous usage data such as page views, clicks, scrolling behaviour and session recordings. This helps us identify usability issues and improve the website.

External services

Allows Microsoft Bookings and easyDMARC's Mailflow Guard. These providers may use cookies or browser storage. Alternatively, a service loads only when you explicitly open it.