forumNew topic

We Moved Our Data to the Cloud — What's Left for Us to Handle Regarding Cloud Security?

BBarış C***New member
Job title
Supply chain manager
Sector
Tourism
Organization type
two-branch business
Joined
Jul 2026
Message
249
#1

We are a wholesale company with 35 employees operating in e-commerce and distribution. Until last month, we had an on-premise physical server; accounting records, dealer orders, and our customer database were all kept on local disks. After the old server failed and drive costs kept climbing, we migrated our entire setup to a major, reputable global cloud provider.

The general mood among our board of directors has become quite relaxed. The perception now is that our data sits in the world's largest data centers, there's no longer any risk of physical fire, flood, or cyberattacks, and they protect everything for us. Some have even suggested cutting the security line item from our IT budget.

I, on the other hand, am a bit uneasy about this complacency. It's true that the provider makes massive security investments, but where do our responsibilities as a business begin? When it comes to cloud security, what exactly does the infrastructure provider guarantee, and what fundamental security configurations are on us to implement?

TTuğçe B***MemberCommunity member
Joined
Oct 2025
Message
100
Most Helpful#2

Short answer: Your cloud provider only protects the physical data center, the hardware layer, and the underlying infrastructure; securing the data inside the cloud, user access OS patching, and system configurations is entirely your responsibility. In the industry this is known as the shared responsibility model, and the misconception that "they take care of everything now" is the most common cause of data breaches.

First, you must immediately configure identity and access management. Never use the root admin account for daily operations. Create separate accounts for every employee based on the principle of least privilege, and enforce multi-factor authentication (MFA) across all accounts without exception. If an employee's password gets compromised, an attacker can simply waltz right in like a legitimate user even if your data center is the most secure facility in the world.

The second critical step is tightening your network and storage access rules. Storage buckets left exposed to the internet and publicly open ports are the biggest vulnerabilities. Restrict your database and management ports exclusively to your corporate office's static IP address. Protect your data with encryption keys both at rest and in transit.

Finally, back up your data regularly in an isolated write-protected, and independent environment to safeguard against the provider's own system outages or internal ransomware threats. Enable security logging and set up mechanisms that trigger immediate alerts for unusual login attempts.

PPolat K***MemberCommunity member
Joined
May 2023
Message
329
#3

The line in the shared responsibility model is crystal clear: Security of the cloud belongs to the provider, security in the cloud belongs to you. Review your security groups immediately; never open ports 22 (SSH) and 3389 (RDP) to all IP addresses (0.0.0.0/0). Whitelist only your office's static IP, and block any access to the management console without a VPN.

GGürkan B***MemberCommunity member
Joined
Oct 2024
Message
407
#4

Two months after we migrated, an employee's corporate email was compromised through a phishing attack. Because two-factor authentication wasn't enabled, the attacker penetrated the cloud console and wiped our database backups. The provider rightfully stated that "the login was performed with valid credentials," and we ended up having to pay an 80 thousand TL ransom.

PPınar Ç***Expert
Job title
Call center representative
Sector
Livestock
Organization type
40-person manufacturing company
Joined
Jan 2022
Message
189
#5

Your board wanting to slash the security budget is an absolute recipe for disaster. That's like renting an apartment in a luxury high-rise with a deadbolted steel door and leaving the front door wide open. If you leave the door open, you can't blame building security when a burglar walks in.

İİlker K***Member
Job title
Information Security Specialist
Sector
Glass
Organization type
a company within a holding
Joined
Jul 2025
Message
185
#6

Two things you need to handle first thing tomorrow morning: 1) Log into the management console and enforce app-based 2FA instead of SMS for all users. 2) Purge all unused test accounts and old consultant API keys.

OOkan I***Member
Job title
Front office accounting
Sector
Cosmetics
Organization type
sole proprietorship
Joined
Nov 2023
Message
260
#7

Cloud providers safeguard data integrity against hardware failures, but if an insider deletes the customer table—whether intentionally or by accident—they treat that as a legitimate command, not a cyberattack. That's why having an immutable backup policy stored in a separate account within the cloud is essential.

NNurMember
Job title
Web Designer
Joined
Aug 2024
Message
96
#8

definitely check your storage buckets that's where companies mess up the most. like they leave them public during testing and next thing you know, all customer data is indexed on google.

DDeniz K***MemberCommunity member
Joined
Nov 2025
Message
21
#9

Since you handle wholesale and dealer management, your status as a data controller under KVKK remains entirely unchanged. Keeping your data in the cloud doesn't absolve you of legal liabilities. You are obligated to ensure access logs are stored in a tamper-proof, timestamped format going back at least two years.

TTülay Ç***MemberCommunity member
Joined
Feb 2024
Message
77
#10

You're right.

FFurkan U***MemberCommunity member
Joined
Dec 2024
Message
266
#11

It's rare to find an explanation this clear.

ÜÜlkü T***MemberCommunity member
Joined
Nov 2023
Message
140
#12

I have a question. Trying to do this alone is the most expensive way.

Hope this helps.

SSerkan Ş***Member
Job title
Data entry clerk
Sector
Healthcare services
Organization type
family business
Joined
Dec 2025
Message
3
#13

great work. honestly when making decisions write down the worst-case scenario too not just the best.

if I were you, I'd go this route.

DDoruk U***Member
Job title
Technical service technician
Sector
Cosmetics
Organization type
two-branch business
Joined
Aug 2025
Message
137
#14

There's one point I'm curious about. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Proven by experience.

TTülay D***VeteranCommunity member
Joined
Mar 2024
Message
2
#15

I went through the same thing.

MMelis Ç***Expert
Job title
System support specialist
Sector
Energy
Organization type
two-branch business
Joined
Apr 2025
Message
4
#16

This is exactly what we experienced. The harder it is to reverse a decision the slower you should make it.

If you have questions, write them; I'll answer as best I can.

RReyhan S***Member
Job title
Clinic manager
Sector
Tourism
Organization type
family business
Joined
Apr 2024
Message
242

Doki · Penetration test · 2026

#17

Correct. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

This is my opinion, I'm not claiming it's absolute truth.

GGamze K***Member
Job title
Accounting Manager
Sector
Textile
Organization type
300-person organization
Joined
Jul 2024
Message
350

Doki · E-commerce infrastructure · 2026

#18

This approach has a cost, which isn't discussed. Most time waste accumulates in tasks waiting for approval.

If you have questions, write them; I'll answer as best I can.

PPerihan A***New memberCommunity member
Joined
Sep 2026
Message
7
#19

I agree with this. The biggest time-waster for us was not knowing who had the final say.

Most incidents start with a leaked password not a vulnerability. Correct me if Im wrong.

IIrmak S***MemberCommunity member
Joined
Feb 2024
Message
381
#20

Great work. If you get three different answers on a topic, the question was asked wrong.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic