Cybersecurity and the cloud: who is responsible for what?

Published on June 15, 20267 min read
A split scene: a data centre tended by the provider on one side, a manager securing her own accounts on the other, a dividing line between them

Two years ago, Daniel A. moved his machining workshop's email and shared folders to the cloud. "At least it's with a big provider now — they handle security," he told himself, relieved to be rid of the ageing server humming away in a cupboard. That held until the morning a sharing link left open exposed a technical drawing to anyone who had the address — and Marc K., his part-time IT contact, had to explain that no, closing that link was not the provider's job.

Cloud shared responsibility, in plain terms

The cloud isn't magic: it's simply servers hosted by a provider — Microsoft, Google, a Swiss host — that you reach over the internet instead of keeping your own machine on site. When a small business puts its email, its files or its production software "in the cloud", it does not hand all security over to the provider. It enters a division of roles the industry calls shared responsibility: the provider secures the infrastructure, and you secure your access and your data.

The easiest picture is a safe-deposit box at a bank. The bank guarantees the walls, the reinforced door, the alarms, the surveillance of the building. But you choose the code, you decide who gets a key, and you decide what goes inside. If you leave the key on the counter, that's not on the bank. The cloud works exactly the same way.

The provider takes care of everything "underneath": the data centres, the power, the hardware, server maintenance, the physical protection of the premises. That is a huge amount, and no SME could match it on its own. But everything "on top" stays with you: who has an account, with which password, who can see which folder, what you share with the outside world, and what you do with your own backup copies.

That dividing line shifts a little depending on the service. When you rent only raw computing power — what the industry calls IaaS, "infrastructure as a service" — you manage almost everything running on top of it. When you use ready-made software, such as an email or office suite — SaaS, "software as a service" — the provider manages more of it. But one thing never moves: your accounts, your access rights and your data are, in every case, never the provider's responsibility.

Daniel A.'s misunderstanding is the most common of all cloud misunderstandings. "It's with a big provider" reassures you about how solid the safe is — not about the key left lying on the counter. And in practice, the vast majority of cloud incidents don't come from someone breaking into the provider's servers, but from a setting left unattended: a share that's too open, a forgotten account, a second check never switched on.

The Federal Office for Cybersecurity (OFCS, also known by the label NCSC) publishes practical recommendations for SMEs that point in exactly this direction: the cloud is a sound decision, as long as you know what falls to you. Recognised frameworks such as ISO 27001:2022 — the standard large clients often cite, watchmaking included — likewise describe these access and data-protection measures as the customer's responsibility, never the provider's alone. Put differently: the day a client asks how you protect their drawings in the cloud, the right answer won't be "the provider handles it", but the list of what you have put in place yourself.

What to keep in mind

  • The provider secures the infrastructure, you secure your access and your data. That's the sentence to pin above the screen. The cloud doesn't remove your share of security; it moves it toward what you control directly — the accounts, the rights, the sharing.
  • Most cloud incidents come from a setting, not an exploit. A share that's too open, an account with no second check, a former employee still active: those are your settings, so your responsibility. The good news is that they are also the easiest and cheapest to fix.
  • In Switzerland, the law holds you responsible. The nFADP — the new Federal Act on Data Protection, in force since September 2023 — holds a company responsible for the data it holds, even when that data is hosted elsewhere. Entrusting your data to a provider does not transfer that responsibility. Your business data can be hosted in Switzerland if you ask for it, but it's up to you to check that in the contract, not up to the provider to guess.

Steps to put in place this week

1. List who has access to what

Open your main cloud space — email and shared files — and look, without any special tool, at who has an account and who can reach the sensitive folders: for Daniel A., those are the machining drawings entrusted by clients. You'll almost always find a former employee's account still active, or a folder "visible to the whole company" that shouldn't be. Close whatever has no reason to be open. It's free, it needs no IT specialist, and it's the step that removes the most risk in a single morning.

2. Turn on two-factor authentication on the accounts

Two-factor authentication (MFA) adds, on top of the password, a second proof — usually a code or a confirmation on your phone. A stolen password is then no longer enough to get in. Turn it on first for management accounts and for those that touch payments and client data. It's the single setting that blocks the vast majority of stolen-password intrusions, and most cloud providers offer it at no extra cost.

3. Take back control of your shares and backups

Review the sharing links set to "anyone with the link can access": replace them with named shares, with an expiry date where possible. Then ask yourself the question Marc K. always asks too late: if a cloud folder is deleted or encrypted by mistake, can it be recovered? The provider guarantees that its servers run properly, not necessarily a copy of your deleted files beyond a few days. A backup that belongs to you — a copy of your data that you control — remains your safety net.

Where do you really stand?

Shared responsibility isn't one more constraint: it's a clarification. Once you know where the line runs — the provider for the infrastructure, you for the access and the data — an SME's cloud security becomes a list of manageable settings again, not a topic reserved for large groups with a whole IT department.

One honest question remains: on that dividing line, where do you really stand? The Cyber Passport self-assessment certifies nothing and promises no compliance: it shows you, point by point, what falls to you in your cloud, what's already in place, and what still rests on an "I thought that was handled". It's the starting point for taking back control — without jargon, and without spending your evenings on it.

Topics

  • cloud
  • shared responsibility
  • MFA
  • SME
  • Switzerland

Read next