Microsoft's Cloud Services Leave Customers Exposed in Ransomware Attacks
A critical gap exists between availability and true cyber recovery in cloud-based services, particularly those provided by Microsoft. According to Brent Torre, GM of cyber resilience, many organizations mistakenly believe that their SaaS provider is responsible for restoring data to a specific known good point before a disaster. However, this responsibility falls solely on the customer.
The shared responsibility model used by major SaaS providers like Microsoft means that the burden of recovery splits between the cloud provider and the subscriber. In the event of a cyberattack, the subscriber is responsible for ensuring that their data is protected and recoverable. This can be particularly challenging for managed service providers (MSPs) who must meet stringent SLAs while working with clients' preferred providers or tooling.
Torre emphasizes that Microsoft's native tools are not designed to deliver true cyber resilience and will not protect against ransomware or recover data. Instead, organizations should consider implementing independent backup protection as a dedicated cloud-to-cloud backup solution stored outside the main SaaS tenant.