{
  "id": 1887380,
  "title": "Being in the cloud does not equate to being secure",
  "url": "https://urgent.news/2026/08/19/being-in-the-cloud-does-not-equate-to-being-secure",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-19T06:29:35.000Z",
  "source": {
    "name": "ITWeb",
    "slug": "itweb",
    "url": "https://www.itweb.co.za/article/being-in-the-cloud-does-not-equate-to-being-secure/dgp45qaBl5gvX9l8"
  },
  "original_language": "en",
  "account": "Many South African businesses are under the impression that moving to the cloud automatically ensures their security. However, the reality is far from this assumption. The infrastructure of cloud providers is secure, but the responsibility for safeguarding data and ensuring safety lies with the customers. This concept, known as the shared responsibility model, is not well understood among local companies. Despite widespread adoption of cloud platforms like Microsoft 365, Azure, and AWS, businesses have not adjusted their approach to security accordingly.\n\nAttackers typically do not need to physically hack into a cloud environment. More commonly, they gain access through stolen credentials, compromised accounts, or by exploiting session tokens through phishing attempts. Once inside, they can stay unnoticed for weeks, exacerbating the damage. This discovery gap is not only an operational issue but also a compliance and reputational problem, particularly in a country like South Africa where the Protection of Personal Information Act mandates companies to safeguard personal data and report breaches.\n\nCompounding this issue is alert fatigue, a result of security tools generating an overwhelming amount of notifications that most internal IT teams cannot manage alongside their regular responsibilities. This leads to too much information, much of it irrelevant, making it difficult to identify real threats. Furthermore, security reports often use technical jargon, which is difficult for executives to comprehend. Under King IV, directors are responsible for technology and information risk, yet they are often presented with reports that they cannot effectively interpret.\n\nThe solution lies not in abandoning the cloud but in ensuring continuous visibility into identity and cloud configurations, applying expert judgment to the data provided by security tools, and translating technical findings into actionable insights for the board of directors. South African businesses, from SMEs to listed enterprises, face daily threats. Those that will fare best are those that have bridged the gap between believing they are secure and actually knowing their true security status, and those that have developed a disciplined approach to ongoing assessment rather than assuming their security status remains constant.",
  "summary": "The shared responsibility model is one of the least understood concepts in South African business today.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}