Cloud Strategy for Australian Businesses: Where Security Fits In
Most businesses moving to the cloud are chasing the same thing: how a business moves workloads to the cloud without quietly handing attackers an easier path in. REDD sat down with Arctic Wolf’s security executives for a conversation on global cyber security trends, and the practical takeaway for an Australian business is this: cloud is a change in where your risk sits, not a reduction in how much of it you own.
This article covers the decisions that actually matter when you are planning or reviewing a cloud strategy, in the order you need to make them.
Decide what “cloud” means for your business first
Most businesses do not do one cloud thing. They do three or four at once, and each carries a different security burden.
| Model | What you run | What the provider secures | What you still own |
|---|---|---|---|
| SaaS (Microsoft 365, Xero, CRM) | Nothing. You use the app | The app, the servers, the patching | Identities, permissions, data sharing, logging, backup of your data |
| PaaS (managed databases, app platforms) | Your code and data | The platform and OS | App config, secrets, access control, network exposure |
| IaaS (virtual machines in Azure or AWS) | Servers, in someone else’s data centre | Physical hardware and hypervisor | OS patching, firewalls, backups, monitoring, everything you used to own on-prem |
| On-prem or colocated | Everything | Nothing (or power and cooling only) | Everything |
The trap is assuming the provider covers more than they do. Microsoft keeps Microsoft 365 running. It does not stop a staff member from being phished, a mailbox rule being added by an attacker, or a SharePoint folder being shared with the world. That is the shared responsibility model, and it is where most cloud incidents live.
Identity is the new perimeter, and it is where attacks start
When your systems sat in a server room, the firewall was the front door. Once your data is in SaaS, the front door is a username and password that works from anywhere on earth.
What that means in practice:
- Multi-factor authentication on every account, including service accounts, admin accounts and anything with a licence. Partial MFA is the same as no MFA to the person testing your credentials.
- Conditional access rules so logins from unusual countries or unmanaged devices are blocked or challenged rather than trusted.
- Least privilege. Global admin should be a small, named list, not a convenience for the IT-savvy person in accounts.
- Offboarding that actually happens. Departed staff with live accounts are one of the most common findings in a cloud review.
If you are weighing up how much of this you can handle internally, our cyber security services page sets out what a managed approach covers.
Visibility: can you tell when something goes wrong?
The uncomfortable question in any cloud strategy discussion is not “are we secure” but “how would we know”. Cloud platforms generate enormous volumes of log data. Very few businesses have anyone reading it.
Three things need an answer before you sign off on a cloud plan:
- Are logs turned on and retained? Some platforms default to short retention. If an intrusion is found eight weeks later, short logs mean you cannot tell what was taken.
- Is anyone watching outside business hours? Attacks are scheduled for Friday evenings and long weekends on purpose.
- Who acts on an alert at 2am? An alert nobody responds to is a record of an incident, not a defence against one.
This is the gap that monitored detection and response services exist to fill, and it is the single biggest difference between a cloud environment that is genuinely defended and one that only looks tidy on a diagram.
Backup is still your responsibility
Cloud providers protect themselves against hardware failure. They are not your backup. If a user deletes a folder, or ransomware encrypts synced files, or an account is compromised and data is wiped, recovery depends on a backup you arranged.
Check three things: what is covered, how far back you can go, and whether anyone has ever tested a restore. A backup that has never been restored is an assumption.
Cost is a strategy question, not an invoice question
Cloud spend has a habit of drifting. Oversized virtual machines, test environments nobody turned off, duplicate licences, storage tiers that were right two years ago. A cloud strategy that only considers security and ignores cost tends to get overruled at budget time, which then undermines the security work as well.
Build in a quarterly review of what you are paying for and whether it is still doing a job. Our managed technology services page explains how that ongoing management works alongside the security side.
Map it to a recognised baseline
Rather than inventing your own checklist, line your cloud strategy up against the Australian Signals Directorate’s Essential Eight. It is the baseline most Australian insurers, auditors and larger customers will ask about, and it translates directly to cloud workloads: application control, patching, MFA, restricting admin privileges, and backups. Knowing which maturity level you are at, and which one your industry expects, gives a cloud plan a defensible shape.
A sensible order of work
If you are starting from a messy position, this sequence causes the least disruption:
- Inventory what you actually have. Every SaaS app, every cloud account, every admin.
- Fix identity. MFA everywhere, trim admin rights, close dormant accounts.
- Turn on and retain logging across the major platforms.
- Put monitoring and a response path in place, including after hours.
- Verify backups by doing a test restore.
- Then look at migration, consolidation and cost optimisation.
Moving more workloads to the cloud before steps two through five are done just increases the surface area you cannot see.
FAQ
Does moving to the cloud make us more secure or less?
Neither by default. Cloud platforms are generally better patched and more resilient than a small business server room, but they expose your data to anyone with valid credentials, from anywhere. Whether it is a net gain depends entirely on how you handle identity, monitoring and backup.
We are already in Microsoft 365. Do we need a separate cloud strategy?
Yes, and it is usually more urgent than businesses expect. Microsoft 365 holds your email, files and often your identity directory. A strategy for that one platform, covering permissions, external sharing, retention and backup, is worth more than a migration plan for anything else.
How do we know if our current setup is missing something?
Start with a review that lists your cloud services, admin accounts and current logging and backup coverage. If you would like someone to walk through it with you, get in touch with the REDD team.
If anything in this post interests you, or you'd like to have a chat with someone about your technology challenges, we would love to hear from you!