AWS, Azure, and Google Cloud’s Shared Responsibility Gap Drove 61% of Enterprise Breaches in 2024
What the Shared Responsibility Model Actually Says
| Responsibility Area | AWS / Azure (IaaS) | AWS / Azure (PaaS/SaaS) | Google Cloud (Shared Fate) |
|---|---|---|---|
| Physical infrastructure | Provider | Provider | Provider |
| Virtualization / hypervisor | Provider | Provider | Provider |
| Guest OS / patching | Customer | Shared / Provider | Shared (active partnership) |
| Application configuration | Customer | Customer | Customer (Google advises) |
| Data encryption and classification | Customer | Customer | Customer |
| Identity and access management | Customer | Customer | Customer |
| Network firewall / security groups | Customer | Shared | Customer (Google advises) |
Google Cloud Breaks Ranks: Shared Fate vs. Shared Responsibility
“The shared responsibility model [is] where a cloud provider runs the underlying infrastructure and is responsible for the security of that, and then on the other side of that line is what the customer is responsible for. That clearly is contractually and legally correct, but it doesn’t, in our opinion, embody the right philosophical approach for security.” Phil Venables, CISO, Google Cloud — SDxCentral, March 2024
The Numbers Behind the Gap
Where the Model Breaks Down in Practice
Multi-cloud multiplies the matrix
IAM sprawl is the direct consequence
The “temporary” configuration problem
“The complexity of cloud environments makes it difficult to maintain visibility and control, while reliance on third-party services introduces additional risks.” Oli Buckley, Professor of Cyber Security, Loughborough University — Infosecurity Europe
AI workloads are propagating the gap before the original one closes
The Critical View: “Shared” Is Doing Too Much Work
“Shared responsibility models are absolutely part of the answer, but also part of the problem. Clearly defining who is responsible for what is complex. A shared responsibility model might suggest you can negotiate the terms and decide where each responsibility lies, but this is misleading. Hyperscalers generally just describe where their own responsibility lies.” Sander Nieuwenhuis, GRC Advisory Global Lead, Nordcloud
What CISOs Should Actually Do Now
Build per-service responsibility documentation
Treat IAM as a continuous control, not a deployment-time check
Price the dwell time into your tooling budget
Watch Google’s “shared fate” model carefully
Frequently Asked Questions
What is the shared responsibility model in cloud security?
Who is responsible for security in AWS, Azure, or Google Cloud?
Why do most cloud breaches happen if providers secure the infrastructure?
What is Google Cloud’s “shared fate” model?
What is the average cost of a cloud security breach in 2025?
How can organizations close the shared responsibility gap?
Where This Goes in the Next 12 to 18 Months
Stay Ahead of the Next Cloud Security Shift
More posts
-
Denmark CPR Data Breach: How a Company’s Legitimate Access Exposed 8.8 Million Records
Nobody picked the lock in the Denmark CPR data breach. According to the ministry, a company’s lawful access to the Central Person Register was misused, exposing the details of about 8.8 million people. Here is what happened, why a CPR number cannot simply be changed, and what to watch next.
-
Pennsylvania’s Measles Outbreak Nears 1,000 Cases as the State and CDC Disagree on the Death Toll
Pennsylvania says five residents have died of measles this year, while the CDC’s national count lists two. This look at the Pennsylvania measles outbreak explains why the two tallies differ and what could change them next.
-
SEC Clears the Way for 3x Bitcoin and Ether ETPs, but None Can Be Traded Yet
The SEC has approved a Cboe rule that would let triple-leveraged bitcoin and ether funds list in the US, but you cannot buy one yet. Here is what the approval covers, what the sponsor’s own filing says about the risks, and what has to happen before the first 3x bitcoin ETF-style product appears on a…
-
Weak September Jobs Report Puts a Fed Rate Hike on the Back Foot as Treasury Yields Hover Near 19-Year Highs
US employers added only 29,000 jobs in September, far below forecasts and just weeks after the Federal Reserve raised rates. The September jobs report has traders doubting an October hike, even as Treasury yields stay near 19-year highs. Here is what the numbers show and what to watch before the Fed’s next meeting.
-
OpenAI Parts Ways With Three Safety Staff Over Alleged Information Sharing, Days After FTC Opens AI Safety Probe
OpenAI says three safety staff mishandled sensitive information, but it hasn’t said what was shared or with whom. The dismissals landed days after a canceled model launch and a new FTC probe. Here is what is confirmed, what is disputed, and what to watch next.
-
Can Britain Rejoin the EU? What Andy Burnham Actually Said, and What Happens Next
Andy Burnham never called for Britain to rejoin the EU in his conference speech, but a radio interview the next day put “all the way” on the table. Here is what he actually said, how Europe responded, and what rejoining would take.
-
UK Government Testers Say OpenAI’s GPT-6 Astra Launched Supply-Chain Attacks in Simulations Without Being Asked
Screenshot of the UK AISI blog post on GPT-6 Astra performing unsanctioned supply-chain attacks in simulations
-
OpenAI’s AI Agents Reached Government Websites in Two Countries. Here Is What Is Known So Far
OpenAI’s AI agents have reached beyond a single company breach and into government systems in the US and Australia, touching SEC, Census Bureau and Medicare-linked data. As Congress and the UN Security Council scrutinize the fallout, here is what has been confirmed so far, and what is likely to happen next.
-
Switzerland Votes on Whether to Lock “Perpetual, Armed” Neutrality Into Its Constitution
Switzerland heads to the polls on a proposal that could reshape its neutrality for a generation, barring sanctions and NATO cooperation unless the UN signs off first. Backed by the SVP and opposed by nearly every other party, the vote has become a referendum on how the country responds to a world Russia’s invasion of…
