The Shared Responsibility Model & Microsoft 365

Shared Responsibility Model MS 365 Security

The shared responsibility model. You may have heard of it, but do you know what it is or what it means for your business? Before we jump in, there are a few things that you need to understand about your cyber security. 

With more and more businesses using cloud services like Microsoft 365 (MS 365), they are starting to become the standard. And though we do recommend the use of the cloud, you must also assess your risks when using these platforms. Take a minute to think about what could happen, even if you think there is little to no chance a breach or cyber attack could happen to you, they need to be considered.

We often hear businesses say that they don’t need to worry about cyber security because they’ve never been breached or hit with ransomware. Former IBM Ginni Rometty said cybercrime “the greatest threat to every profession, every industry, every company in the world.”  and Former FBI Director James Comey said “There are two kinds of companies in the United States. There are those who’ve been hacked … and those who don’t know they’ve been hacked.” 

At this point, the discussion about cyber attacks should be based on the assumption that every business will eventually by affected. It’s time make cybersecurity a priority and to protect your organization, employees and clients.

Not sure if your 365 is secure? Download this free checklist.

What Is the Shared Responsibility Model?

In an on-premises datacenter you are responsible for everything including security.  As you move workloads to the cloud, some responsibilities transfer to the Cloud Service Provide (CSP), hence the concept Shared Responsibility model.

When moving workloads to the cloud  it’s critical to understand the shared responsibility model including which security tasks the CSP is responsible for and and which tasks your organization is responsible for.  They will vary depending on whether the workload is hosted on Software as a Service (SaaS), Platform as a Service (PaaS), Infrastructure as a Service (IaaS), or in an on-premises datacenter

With cloud services improving and evolving, people often use them with blind trust and a lack of understanding of who is responsible for what. They assume that because the technology is advancing, they are going to be kept safe when using the cloud. But that is typically not the case when you are running with the default settings.

It’s On YOU: Cloud Security

Cloud services are not responsible for protecting your information. That bears repeating. It is your responsibility to keep your business safe. Understanding your risks is critical, because breaches, ransomware and other attacks are not scary hypotheticals, they actually happen with increasing regularity and impact. You need to understand what the cloud will do to assist you in protecting yourself, and what you need to take upon yourself.

Microsoft 365 Shared Responsibility Model

With Microsoft 365, there are a variety of aspects to the shared responsibility model. Here are the most critical to take into your own hands:

  • Microsoft 365 is NOT obligated to protect the loss of your data in the instance of an app outage. Though Microsoft takes many measures to keep service up and running, in the instance of an outage, there may be a loss of your data. You need to know that Microsoft is not liable for this. Microsoft makes it clear that in order to keep your data safe, you should back it up with a third-party application
  • Microsoft is NOT liable for data loss due to a deprovisioned user account. Their policy states that information is kept for 90 days after the termination of an account. If you terminate your MS 365 account and do not retrieve or back up your information with a third party, it will be permanently lost after the 90-day period is up. 
  • Microsoft is NOT liable for data loss as a result of data that was inadvertently or maliciously deleted.  If a user accidentally or maliciously deletes data and it is not discovered for more than 90 days, it is lost forever.

Backups aren’t the only security concern. Microsoft 365 comes with a variety of security features, but it is up to you to configure them for your business. Check out the 21 critical controls we recommend in our Microsoft 365 Security Checklist.

Now What?

After hearing about what actions you need to take, you might be wondering where to start. We recommend Datto SaaS Protection, which is  a powerful and secure backup solution for your MS 365 tenant. If you want to learn more, feel free to contact us or book a no-obligation consultation so we can help. 

We’ve also created the Microsoft 365 Security Checklist to help you make sure your MS 365 Security is configured correctly. It’s a free resource that could save you time, money and damage from a cyber attack.

Download the Checklist

Intrust IT Intrustimonials

Intrust Man

Intrust Man may be small, but he is mighty smart. You can trust this clever cartoon hero to provide news you can use.

Share this Blog

Get This Free Resource to Protect Your Business

Checklist: "14 Non-Technical Things You Can Do Today to Protect Your Business from Cyber Crime"

Trending Now: Read More From Intrust IT

2022 Inc. 5000's List

Intrust IT on 2022 Inc. 5000’s List of Fastest Growing Companies

By Tim Rettig | August 18, 2022

CINCINNATI – Intrust IT, a cyber security and IT support company, has been named on the 2022 Inc. 5000’s prestigious annual list of fastest growing companies. For the fourth time, Intrust has ranked among America’s most successful and rapidly growing private businesses. Since its establishment in 1992, the IT company has been putting the “service”…

Microsoft Office Auditing Case Study

How One Client Saved 28K with Microsoft Office 365 Auditing

By Intrust Man | June 16, 2022

We saved one client over $28,000 per year on Microsoft Office 365 licenses through our Office 365 auditing process.  Here at Intrust, almost all of our clients use Microsoft Office 365 licensing for some combination of email hosting, Office software, and Dynamics CRM. Sometimes clients who had Microsoft 365 prior to their relationship with Intrust…

Managed Microsoft 365 featured image

Managed Microsoft 365: 9 Benefits of Managed IT Services

By Tim Rettig | June 16, 2022

If you are using or considering Microsoft 365 for your business? Consider this: Managed Microsoft 365 is even better. Managed 365 means that a managed service provider (MSP) correctly configures, optimizes and provides ongoing support for your Microsoft 365 installation. Here are nine reasons why your company should partner with an MSP for your Microsoft…