In Practical Cloud Security, Chris Dotson, an IBM Distinguished Engineer and Executive Security Architect, writes about practical approaches to securing cloud environments, covering data and cloud assets, identity and access management, vulnerability management, network security, and incident detection and response.
The book focuses on understanding when and why particular security controls are needed.
Security has to fight for time and funding, and it often takes a back seat to implementing features and functions.
The Question This Book Helps Answer
Where should an organization focus first when trying to secure its cloud environment?
Security teams rarely have unlimited time, people, or budgets. Dotson notes: the objective is to get the most important controls protecting the most important assets in place quickly and correctly, and then continue maturing the environment from that foundation.
Practical Lessons from the Book
1. Start with the assets and risks, not the security products.
Before choosing controls, organizations need to understand what they are protecting.
Data vs Cloud Assets
Data Asset
Data assets are important information you have, such as customer names and addresses, credit card information, bank account information, or credentials for accessing such data.
Cloud Asset
Cloud assets are the resources you use to store and process your data—compute resources such as servers or containers, storage such as object stores or block storage, and platform services such as databases or queues.
What data matters most, where is it, and what systems can access or process it?
2. Shared responsibility must be understood at the service level.
Shared responsibility means security duties are split between the cloud provider and the customer, and that split changes depending on the type of cloud service being used.
Responsibility changes depending on the service being consumed. Physical infrastructure may belong to the provider, while access to data, identities, application configuration, network controls, or operating systems may remain partly or entirely the customer’s responsibility.
What matters is not whether something fits perfectly into an IaaS, PaaS, or SaaS label; it is understanding what the provider supplies and what remains your responsibility.
3. Least privilege applies to machines as much as people
The principle of least privilege states that people or automated tools should be able to access only what they need to do their jobs, and no more.
As cloud environments become increasingly automated, machine identities deserve the same scrutiny as human identities.
4. Assume individual controls can fail.
Defense in depth is an acknowledgment that almost any security control can fail, either because an attacker is sufficiently determined and skilled or because of a problem with the way that security control is implemented.
If this control failed tomorrow, what would stop the attacker next?
If the answer is “nothing,” there may not be sufficient defense in depth.
5. Zero Trust is about eliminating implicit trust.
The core principle is that trust from a user or another system should be earned, rather than given simply because the user is able to reach you on the network, or has a company-owned device, or some other criterion that’s not well controlled.
Trust should be earned through evidence, rather than granted simply because a user is on the corporate network, has a company device, or possesses an existing session.
6. Design security around likely threats and trust boundaries.
Security architecture becomes much more useful when teams understand:
Who might attack us?
What would they want?
What are we trying to protect?
Where does one system have to trust another?
The author recommends mapping system components, users, administrators, data stores, communications, and trust boundaries.
7. Detection and response belong in cloud architecture from the beginning.
The final part of the book focuses on detecting and responding to incidents using cloud service logs, privileged user activity, defensive tool logs, SIEM, threat hunting, incident plans, cloud forensics, containment, and recovery.
A secure cloud architecture should assume that something will eventually go wrong and be designed so the organization can detect, contain, investigate, and recover from it.
Questions to Test Your Cloud Security Posture
- Do we know which data and cloud assets matter most?
- Is responsibility for securing each cloud service clearly understood?
- Are both human and workload identities operating with least privilege?
- If one major security control failed, what control would stop the next stage of an attack?
- Where are the trust boundaries within our critical applications?
- Are vulnerabilities being identified and remediated according to risk?
- Can we detect suspicious privileged activity?
- Do we have the logs, tools, people, and procedures necessary to respond to a cloud incident?
- Could we rebuild or recover critical cloud workloads after a compromise?
Key Takeaway
One of the strongest lessons from Practical Cloud Security is that cloud security does not begin with a particular vendor product or security service.
It begins with understanding:
Assets → Threats → Responsibilities → Trust → Controls → Detection → Recovery.
For us at Reputiva, that reinforces an important approach to cloud security:
Technology should follow risk not the other way around.
Before recommending another tool or control, organizations should be able to explain what risk it addresses, what asset it protects, and what happens if it fails.
A Question Worth Asking
If one of your organization’s key cloud security controls failed today, what would stop the next stage of an attack?
That question gets to the heart of defense in depth: security should not depend on a single control working perfectly. Strong cloud security comes from overlapping safeguards across identity, network, data, monitoring, and response.
If the answer is unclear, it may be worth reviewing whether your cloud environment is built around a resilient security architecture or simply a collection of individual security tools.
Need a clearer view of your cloud security posture? Reputiva helps organizations assess cloud environments, identify control gaps, and prioritize practical improvements across AWS, Azure, and Google Cloud.
Book a cloud security assessment or start a conversation with us.
Reputiva
Reputiva is a cloud, cybersecurity, and FinOps advisory firm helping SMEs reduce cyber risk, strengthen cloud environments, and manage technology costs with confidence. We publish practical insights on cloud security, identity, AI risk, compliance, and digital transformation.


