Moving your business into the cloud — email, files, accounting, CRM — shifts where your data lives, but it doesn't hand off responsibility for keeping it safe. Cloud providers secure the platform; you're still on the hook for who can get in, what they can reach, and what happens when a laptop goes missing. Here's how to think about that split and what to actually do about it.
Understand the shared responsibility model
Every major cloud service — Microsoft 365, Google Workspace, Xero, AWS — runs on a shared responsibility model. The provider guarantees the infrastructure: physical data centres, network hardware, the uptime of the platform itself. You are responsible for everything you configure on top of it: user accounts, passwords, permissions, which files get shared with whom, and whether a departing employee's access is actually switched off. The overwhelming majority of cloud breaches for small businesses don't come from the provider being hacked. They come from a weak or reused password, a phishing email that harvested a login, or an account that was never deactivated. That's the part you control.
Get identity and access right first
Identity is the front door, so start there. Multi-factor authentication (MFA) on every account is the single highest-value control you can put in place — it's the one that turns a stolen password into a dead end. Turn it on for everyone, not just admins, and prefer an authenticator app or a physical security key over SMS codes where you can.
- Enforce MFA across the board, and make it non-optional in your provider's admin settings rather than leaving it to each person.
- Apply least privilege — people should have access to the files and systems their role needs, and no more. Admin rights in particular should be rare and deliberate.
- Run a proper offboarding process. The day someone leaves, their accounts should be disabled and their sessions revoked. A forgotten ex-employee login is a classic way for data to walk out the door.
- Review sharing links periodically. "Anyone with the link can edit" is convenient and quietly dangerous. Audit what's been shared externally.
The Australian Signals Directorate's Essential Eight is a sensible baseline here — MFA, restricting admin privileges and keeping software patched all feature in it, and it's written for organisations of every size.
Protect the data itself, not just the login
Assume a device will eventually be lost or stolen and design so that it doesn't matter. Enable full-disk encryption on laptops and phones (BitLocker on Windows, FileVault on Mac are built in and free). Most cloud platforms let you enforce a device policy — a screen lock, a passcode, the ability to remote-wipe a lost phone — through mobile device management. Turn that on. And be deliberate about where genuinely sensitive material lives; not every document belongs in a folder that's synced to everyone's machine.
Have a backup that isn't in the same place
This is the point owners most often get wrong: your cloud provider is not your backup. Microsoft and Google keep the service running, but if a staff member deletes a folder, a ransomware infection encrypts your synced files, or an account is compromised and data is destroyed, the provider's own recovery windows are limited and not designed to save you. Use a dedicated third-party backup for your cloud data, or at minimum understand exactly how far back your provider's recycle bin and version history reach. Test that you can actually restore something — a backup you've never restored from is a hope, not a plan.
Make security a habit, not a one-off
The technical controls matter, but people are where most incidents start. A short, plain-English rule set — how to spot a phishing email, why you never re-enter your password on a link from a message, who to tell the moment something looks wrong — does more than any single tool. Keep software and browsers on automatic updates so patches actually land. And write down, in advance, what you'd do if an account were compromised: change passwords, revoke sessions, check what was accessed, notify anyone affected. Under Australia's Notifiable Data Breaches scheme, a breach involving personal information that's likely to cause serious harm carries reporting obligations to the OAIC and to the people affected, so knowing your steps ahead of time genuinely helps.
None of this requires an IT department. It requires a few decisions made once and reviewed occasionally. If you want to see where cloud security fits alongside the rest of your systems, our guide to the modern SME back office puts it in context. This is general information, not tailored security or legal advice — for anything specific to your setup, talk to a qualified IT security professional.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →