Earlier quoted context omitted.
The entire underlying layer of possible misconfigurations is absent in the cloud. Yes, the services on top of that can still be misconfigured, but you don't get access to hosts, SANs, switches, firewalls, gateways, there isn't anything for you to mess up. The shared responsibility model allows you to also pick even more robust options. But even if you were to stick to something simple, say, object storage. A bucket o…
My friend some the biggest data leaks happened because of misconfigured S3 buckets which is literally one line of code to get right. Cloud is not an insurance against incompetence.
About two years ago we got an email from AWS associated with a PHD notice. It “apologized” for an issue whereby the EC2 Security Groups in a single AZ were in place but not operative. All traffic was permitted for several hours, irrespective of the SG config.
We deploy and align host-based firewalls alongside whatever the cloud provider gives us, for exactly this reason.
Somewhere along the line “the cloud” seems to have gotten a reputation for some level of infallibility of which I’m not convinced.
See also the recent problem where Entra logs weren’t captured for some tenants, and are just gone.