
There is a persistent assumption that moving to Microsoft 365, Google Workspace or a cloud server hands your security problem to someone else. It does not. Cloud providers secure the platform. You remain responsible for your accounts, your data and who can reach it.
Start with identity
Most breaches of cloud services are not clever technical attacks. They are someone logging in with a valid password that was phished, reused or guessed. Multi-factor authentication on every account remains the single highest-value control available to a small business, and it costs nothing but a few minutes of setup per user.
Alongside it, remove accounts promptly when people leave, and give administrator rights only to those who genuinely need them.
Assume email is the front door
The overwhelming majority of successful attacks begin with a message. Filtering that inspects links and attachments, flags external senders and catches impersonation attempts stops most of it before a human has to make a judgement call. Pair it with short, regular staff training so people know what a suspicious request looks like.
Back up your cloud data
This is the gap that surprises people most. Microsoft and Google keep your service running. They are not a backup. If a user deletes a mailbox, or ransomware encrypts a synchronized folder, retention policies may not save you. A dedicated backup of your cloud data, with a tested restore, closes that hole.
Control the devices, not just the accounts
Your data is only as secure as the laptop it is opened on. Encrypted drives, current operating systems, endpoint protection and the ability to wipe a lost device remotely turn a stolen laptop into an inconvenience rather than a data breach.
Know what good looks like
Log in to your admin console and check who has administrator rights, whether MFA is genuinely enforced rather than merely available, what happens to a file when a user deletes it, and when a restore was last tested. If any of those answers is uncertain, that is where to start.


