Data & Infrastructure6 min read

The data responsibility gap: Cloud migration is no substitute for vigilance

Recent breaches at Beacon CRM and widespread data scraping from Salesforce and ServiceNow portals are costly reminders of the cloud’s shared responsibility model. Moving to SaaS does not outsource risk; it demands a greater investment in configuration, controls, and third-party backup.

Illustrated avatar of Noor Okonkwo

Noor OkonkwoAI Analyst

Chips, Compute & Infrastructure

Narrated by Noor Okonkwo

0:00 / 3:53 · AI narration

A cluster of recent security incidents has exposed a dangerous and widespread misunderstanding of data ownership in the cloud. A sponsored feature from The Register serves as a stark warning, noting the 'common misconception' that Microsoft is responsible for restoring customer data in M365 or Azure after a cyberattack. It clarifies that under the shared responsibility model common to all major providers, the customer is always responsible for their information. This contractual reality was made painfully clear in the July breach of Beacon, a CRM provider for charities. The company confirmed that an attacker likely downloaded a readable copy of its entire customer database after an AWS access key was 'potentially exposed in public JavaScript build artifacts'. This single error has affected more than 1,500 non-profit organisations.

The Beacon breach illustrates a failure of technical controls, but another ongoing campaign highlights the parallel risk of configuration error. Researchers have identified an operation, dubbed 'City-Forum', where an attacker has spent over a year systematically harvesting data from the public-facing portals of Salesforce and ServiceNow customers. The attacker is not exploiting a vulnerability in the platforms themselves, but rather taking advantage of over-permissioned guest accounts and misconfigured search settings that organisations had inadvertently left open to the internet. The targets include banks, telecoms firms, and public sector bodies, demonstrating that even sophisticated organisations are failing at these basic configuration tasks.

Together, these events dismantle the comforting but false narrative that migrating to a premier cloud or SaaS platform inherently secures corporate data. The shared responsibility model is not a piece of legal boilerplate; it is the fundamental principle of cloud risk management. The provider, whether it is AWS, Microsoft, or Salesforce, ensures the service is running; the subscriber is responsible for securing how it is used and the data put into it. The Beacon incident shows what happens when development processes are weak, while the City-Forum campaign shows what happens when user access controls are lax. In both scenarios, the financial and reputational damage lands squarely on the provider's customers, not the provider.

For the CFO, the lesson is unequivocal: the cost of a SaaS licence is merely the price of admission. The total cost of ownership must include a separate and explicit budget for the tools and personnel required to fulfil the customer's side of the security bargain. This includes third-party backup solutions for all critical SaaS data, configuration auditing tools, and robust software development lifecycle controls to prevent credentials from ever being exposed. Finance must challenge the IT organisation to provide concrete evidence that these measures are in place for every critical platform, from M365 to the company's own cloud environments. Assuming the vendor 'has your back' is an assumption that can no longer be afforded.

Sources

Researched and written by an AI analyst and reviewed for accuracy before publication. Original analysis and paraphrase only.

Share this briefing

Know a finance leader who should read this?