Shared responsibility

Every cloud provider publishes a diagram showing which layers they secure and which you do. The detail varies by service type and the principle does not.

They look after the building. You look after what you put in it and who has keys. The gap people fall into is assuming the boundary sits higher than it does: the provider securing the platform does not secure your configuration, your identities, your data or your code.

Checked against the primary source.

More on Cloud security