Cyber AssessValydex™by iFeelTech
Implementation Guide

Cloud Security Guide (2026)

Implementation playbook for SMB and mid-market cloud operations

Source-backed cloud security guide covering shared responsibility, identity controls, workload hardening, telemetry, and governance.

Last updated: September 25, 2026
3 minute read

Cloud controls to verify

  • Know which cloud apps hold business data and who administers each tenant.
  • Enforce MFA and review privileged, external and dormant accounts.
  • Test sharing rules, audit signals, retention and data recovery—not just license ownership.
  • Use the platform's included controls and documented configuration guidance before adding a tool.

Last updated: September 25, 2026

A cloud provider secures its service infrastructure, while the customer still makes decisions about users, access, data and configuration. The exact boundary differs by service and contract; a generic “the provider handles security” statement is not enough. CISA's SCuBA material gives Microsoft 365 and Google Workspace configuration baselines that organizations can evaluate and adapt. The baselines were developed for federal use, so an SMB should select applicable controls rather than claim blanket compliance.

Start with a tenant inventory

List business-critical cloud services, exact subscription editions, tenant administrators, integrations, external guests, data owners and support contacts. Include marketing and finance apps that staff bought directly. Mark the systems needed for customer service, payroll and payments. Ask whether any single employee owns a critical tenant with no second administrator or documented recovery route.

ControlTestEvidence
Administrator MFAAttempt a controlled admin sign-inEnrollment and exception export
User and guest lifecycleRemove a pilot account or expired guestAccess review and revocation result
SharingOpen a test external link from an unauthorized accountPolicy and observed access
Audit/alertsTrigger an approved test eventEvent reaches a named responder
RecoveryRestore a deleted item or critical workflowDated restore result and data age

Fix the configuration you own

Require named administrator accounts and MFA. Use least privilege for integrations and suppliers; review delegated app consent and external sharing. Set retention, deletion and data-export rules that match the business purpose and any applicable obligations. Turn on the available audit logs and agree who will review high-priority events. Run a test rather than relying on a default-settings screenshot. The privacy-first guide helps map sensitive data before changing sharing or retention.

For email and collaboration, check the email-security guide. For recovery, the backup strategy distinguishes version history and sync from an independent restore. The incident-response guide names who can revoke sessions, isolate a tenant or approve communications.

When a cloud security product is justified

Write the control the native platform cannot deliver in your exact edition, then test a product against it. Common reasons may include cross-tenant visibility, required retention, external sharing governance or monitoring capacity. Compare administration effort, data access granted to the add-on, supported apps, alert quality, data export and renewal terms. A tool that requires broad app permissions can create a new exposure; document that tradeoff. A managed service needs service hours and an escalation agreement, not just a dashboard.

A 30/60/90-day rollout

In the first 30 days, inventory tenants, administrators and MFA gaps. By day 60, review sharing and integrations, test a leaver and confirm alert ownership. By day 90, restore a representative item, run an account-compromise exercise and close or fund remaining exceptions. Use the 90-day roadmap to preserve evidence and ownership.

No-purchase first step

Choose your most important cloud tenant and test one administrator login, one leaver, one external share and one restore. Those results make the product requirement specific.

Sources checked September 25, 2026: CISA SCuBA overview, CISA SMB resources, and NIST SP 1300. This is source-based guidance, not a tenant audit.