Skip to Content

Reconsidering the Cloud

Are cloud services still more secure than hosting on premises?
13 May 2026 by
Reconsidering the Cloud
Mark Ferraretto

I have been a big advocate for cloud systems in the past, but some recent events have given me pause. While I'll keep my cloud subscriptions for now, it's an area I intend to watch more closely.

Using the Cloud

There are simply too many advantages with cloud usage. Aside from the convenience of accessing information cloud also brings with it redundancy and security that is difficult to achieve with on-premises solutions. Cloud providers encrypt your data on their servers and also in transit to your computer, they keep multiple versions, they enforce enterprise document retention policies, and they have the cybersecurity expertise to monitor and combat against cyber attacks - expertise most of us simply don't have.

However it is becoming apparent that the move to cloud has shifted the risk profile. Centralisation itself now brings its own risks, and the impact of a social engineering-based risk becomes significantly increased.

Most recently, Instructure's Canvas service was breached, affecting nearly 9,000 educational institutions across the world, and exposing the data of approximately 230 million students. The cause of the breach is not yet known

On 19 April 2026 the same hacker gang infiltrated Vercel, a well-known provider of application hosting services (and a service used by the author), stealing application 'secrets' (essentially passwords for web applications). It is unclear how many were stolen.

In both cases, centralisation had a big part to play in the impact of the breaches.

This gives me pause. Personally, I migrated to cloud services, including Vercel, for cybersecurity reasons. I don't want to be the cybersecurity administrator for my own infrastructure in addition to my day job. I outsourced this to providers who should, and do, know better than me.

That said, it's becoming apparent that cloud services bring with them their own risks. There's an inherent risk that comes from centralisation, as the Instructure breach shows. Centralisation also magnifies the risk from a social engineering attack, as the Vercel breach appears to have been. In the Vercel example, it appears the compromise arose through a third party provider and not a direct breach of Vercel's systems.

We Are the Weakest Link

We live very much in an era where social engineering is the easiest way into technology infrsatructure. So much so, that sophisticated actors will sometimes spend years in establishing and maintaining fake personas in an effort to compromise systems. Social engineering combined with centralised cloud infrastructure has ultimately increased the impact of cybersecurity breaches.

Time to Move Away from Cloud?

Had I hosted my web application on my own servers, instead of Vercel, I would not have been vulnerable to that breach. I may not have had as good cyber protections in place, but I would have been a much smaller and less attractive target.

Likewise, if I was to host my files and my email on my own servers instead of in the cloud as I currently do, I would not be vulnerable to a social engineering attack on my cloud provider or, as was the case with the Vercel breach, on one of my provider's partners. This in addition to being a smaller target.

So, is it time to reconsider cloud usage? 

The short answer is 'no' - at least for now. But what we do need to do is move away from a 'set and forget' mentality when it comes to cloud systems and treat them as vulnerable systems that need monitoring - not by our providers, but by us.

Practices such as regular monitoring of audit logs, keeping backups off the cloud systems are increasingly important. A regular monthly or quarterly audit check of your business' Microsoft 365 tenancy or Google Workspace is really a must.

Conclusion

Cloud systems remain valuable for their cost-effectivness and, despite this article, their security. Some of us more nerdy types may have the skills to move back to on-premises hosting, but doing so is more likely to shift the risk profile than mitigate against it.

Again, and as always with cybersecurity, it comes down to us. We need to take our cloud systems seriously - check them, monitor them and generally keep a close eye on them.

We need to be aware that people now are the weakest link in the cybersecurity context. We need to ensure our practices maintain strict security policies and procedures to guard against social engineering attacks.

In short, we need to place a bit less trust in our cloud providers and a bit more diligence in our own cybsesecurity practices.


Reconsidering the Cloud
Mark Ferraretto 13 May 2026
Share this post
Tags
Archive
Linux for Lawyers 2
The Good, The Bad and the Ugly