About
Subscribe
  • Home
  • /
  • TechForum
  • /
  • Cloud security is not measured by what you have deployed. It is measured at 2am

Cloud security is not measured by what you have deployed. It is measured at 2am

Two organisations can hold identical telemetry and reach entirely different Mondays. The variable is not the tooling. By Hendrik Kruger, chief technology officer (CTO) and CISO, Cloud On Demand.
Johannesburg, 23 Sep 2026
Hendrik Krüger, Cloud On Demand
Hendrik Krüger, Cloud On Demand

Ask most organisations how secure their cloud environment is and you get an inventory of acronyms. We have cloud security posture management (CSPM). We have endpoint detection and response (EDR) on every device. We are on Microsoft 365 E5. All of those can be true while genuine detection capability sits close to zero.

A licence grants access to capability. It is not a control. The distance between the two is where incidents live.

It shows up three ways. The capability was never switched on, because enabling it needed design decisions nobody was tasked with making. Or it was switched on and never tuned, so its alerts are ignored within three weeks. Or it is configured accurately and nobody is rostered, and the alert lands at 2:14am on a Saturday in a mailbox next opened at 8:30am on Monday. All three pass a documentation-based audit. None survives an intrusion.

Identity is where this costs most. The dominant intrusion pattern in cloud is not a novel platform flaw. It is authentication with a valid credential, phished, re-used or bought. The adversary rarely breaks in. They sign in. The signals are already being generated in most cloud tenants: risky sign-ins, anomalous consent grants, suspicious inbox rules. The alert fires correctly, then waits for someone who has not been told it is their job to look.

Consider a composite drawn from mid-market patterns rather than any one company. Saturday, 1:40am, a phished finance credential authenticates from another country, the multi-factor authentication (MFA) prompt relayed in real time. At 1:52am, an inbox rule buries anything mentioning invoices. At 2:15am, a consent grant gives a third-party application mail access that survives a password reset. At 3:10am, four customers receive changed banking details on a real invoice thread. Every event produced telemetry, correctly captured, and nobody read it until 9:20am on Monday.

Run the same sequence against an organisation with detection discipline. Severity escalates automatically because the account has finance system access. A contextual alert reaches the on-call engineer by phone, carrying the risk signals and the containment actions already authorised. The account is disabled and its tokens revoked 11 minutes after the first sign-in.

The reporting layer is the easy half. Standing up posture management, identity monitoring and attack surface discovery is largely a procurement and engineering challenge. The harder question is what happens when something real is detected, who is authorised to act without approval and how long it takes. Every containment action worth having needs a named role that can execute it unilaterally, a written procedure and a rehearsal in the past 12 months.

It also means accepting that containment precedes certainty. A reversible action against a false positive costs an inconvenienced user and an apology. A two-hour wait against a true positive costs considerably more.

Governance tells you who owns the risk. Only detection discipline tells you whether anyone is watching it, and that is the half tested at two in the morning.

From detection to response

Deciding in advance what happens at 2am is the difficult part, and few mid-market teams can staff it alone. Cloud On Demand distributes BlueVision's Fusion Cloud, pairing continuous attack surface monitoring with managed detection and response, so a real signal reaches someone rostered to act on it. Visit www.cloudondemand.co.za or e-mail info@cloudondemand.co.za to learn more.

Share

Cloud On Demand (COD)

Cloud On Demand (COD), a part of Alviva Holdings and previously known as Tarsus On Demand, enables managed service providers, independent software vendors, and technology resellers to transition their businesses to the cloud and software-as-a-service seamlessly.

The COD team works closely with channel partners to help their customers architect and deploy cloud solutions that drive growth, efficiency, agility, and innovation.

COD also provides access to aggregated offerings from leading cloud hyperscalers like Microsoft and Amazon Web Services (AWS), along with tools that enable seamless access to cloud products and services.

In the backup and security space, COD partners with top vendors such as Dropsuite, ESET, AvePoint and Mimecast to deliver robust solutions that protect and secure customer data.

Cloud On Demand has consistently demonstrated excellence in cloud distribution, earning numerous prestigious accolades, including Microsoft Indirect Cloud Solution Provider (CSP) of the Year (2018-2021), Microsoft South Africa Partner of the Year (2021), and Cloud Solutions Distributor of the Year at the Intelligent ICT Awards Africa (2024 and 2025).

Additional recognitions include ESET Growth Partner of the Year (2025), Global Innovator of the Year at the CloudBlue Monetization Summit (2025), and multiple honours from Mimecast, such as Technical Excellence Partner of the Year (2022) and Managed Services Partner of the Year (2021).

Notable nominations include the Mimecast 10+ Years Valued Customer Award (2023) and Microsoft South Africa Partner Award (2021).

For more information, visit:

www.cloudondemand.co.za

https://www.linkedin.com/company/cloud-on-demand

https://www.facebook.com/tarsusondemand/

https://www.youtube.com/channel/UCtJ8OEzpgUXpzJ_dAIy2Tww

Editorial contacts