Most SMB cloud deployments are missing baseline security controls — not because the controls are exotic or expensive, but because the deployment was scoped to "get the workloads running" and security was deferred to a later phase that never arrived. The auditor's first question always finds these gaps. The cyber insurance underwriter's questionnaire always surfaces them. The breach response runbook discovers them on the worst possible day.
Five baseline controls every cloud deployment needs from day one.
Control one — identity and MFA discipline. Every administrative account uses MFA. Every user account uses MFA. Service accounts are scoped to least privilege and rotated. Shared credentials are eliminated. Conditional access policies are applied based on role and risk profile. The single most impactful control and the most frequently skipped.
Control two — structured logging across the environment. Every API call, every administrative action, every authentication event writes to a centralized log retained at least one year (longer for regulated industries). Logs are queryable. Retention is automated. Without structured logging, the breach investigation that surfaces in year two cannot determine what happened.
Control three — network segmentation. Production workloads, development environments, and shared services are isolated in separate VPCs or subscriptions. Traffic between them flows through controlled gateways. The lateral movement that defines most cloud breaches is structurally prevented by segmentation configured at deployment, not retrofitted later.
Control four — encryption posture. Encryption at rest for every data store. Encryption in transit for every service-to-service connection. Key management through the platform's managed service rather than user-managed keys for most workloads. A configuration choice at deployment, not an engineering project later.
Control five — backup and recovery procedures with tested restores. Backups exist. Backups run on schedule. The restore procedure is documented and tested at least quarterly. The number of businesses with backups that have never been tested is meaningfully higher than the number that have actually tested them.
Across the cloud deployments I have advised on — from multi-entity finance environments running M365 and Azure AD-integrated identity, to AWS RDS-hosted infrastructure supporting AI workloads — these five controls were configured at deployment. Adding them later runs three to five times the cost.
If your deployment is in flight and any of these five is not explicitly in the configuration plan, the security debt is being booked silently.
Filed under





