The cloud and cloud computing have become an essential part of IT infrastructures -- but could your employees use a Cloud 101 primer? Put another way: Do they really know where they're putting sensitive data? Credit: Thinkstock Popular culture has exposed a fundamental knowledge gap in the ordinary consumer. Even though our smartphones are set up to auto-save pics to our online accounts, we enjoy hours of streaming videos and music, and we regularly use online email, a lot of people don’t know where all this information is stored. They just know it’s “in the cloud.”Helping a typical employee understand the cloud can go a long way toward protecting sensitive data and keeping files in house, where they belong. This article discusses the cloud in plain-speak and may be a good tool for your next security awareness training session.What Is the Cloud?You probably hear about “the cloud” frequently and think of a single, huge computer that holds trillions of files. Actually, the cloud refers to some company’s network of data center servers that’s accessible to consumers and organizations via the Internet. Amazon has its own cloud; so do Apple, Google and a lot of other companies. “The cloud” is a generic term to describe whichever company’s network of servers to which you connect. A company can also create its own cloud by leasing space on another company’s cloud. For example, Company A wants a cloud for its customers, so it pays a monthly fee to Company B, a cloud provider. Company A’s customers use the cloud, unaware that their files are actually stored on a different company’s server. It’s a common practice nowadays, and both Company A and Company B put measures in place to protect that data. (More on that later.)What Is the Cloud Used For? The cloud makes sharing documents, photos and pretty much any type of file easy, using any device running any operating system. All you need is an Internet or cellular connection. But the power behind the cloud is storage and Everything as a Service.Special servers in a company’s cloud do nothing but hold data. Lots of data. Think of your own computer, which probably holds upwards of 500 gigabytes (GB) of data. Compare that to Microsoft’s cloud servers, which hold a combined total of more than 400 petabytes. That’s like 100,000 hard drives – and that’s just one company’s cloud resources.[ Analyses: Business Agility Drives Cloud Adoption and The Real Cloud Computing Revolution ]Whereas some clouds are built mainly for storage and sharing, such as Box and Instagram, other clouds deliver services. The services are typically sold on a monthly or annual subscription basis; others are free. Three common services are Software as a Service (SaaS), Infrastructure as a Service (IaaS) and Platform as a Service (PaaS).SaaS covers a lot of territory, such as online email, word processing, customer relationship management (CRM) software, software development management, content management and much more. Google Gmail is one example.With IaaS, you get a virtual server in the cloud, on which you can install and run applications just like you would on a physical server in your office. It has everything an ordinary server has: Network connections, storage and so on. The cloud provider owns the server, which runs within the provider’s IT infrastructure, and is responsible for making sure it runs properly. This eases the administrative burden for companies and saves them money. [ Counterpoint: The Truth About Enterprises and the Public Cloud ]PaaS is the most complicated, and provides an entire platform on which a company can build and test applications, manage huge databases or run a very large website.Why Is Storing Documents All Over the Cloud Bad for Business?With services such as Microsoft OneDrive and Dropbox only a click away and offering up to 15 GB of free storage space, it seems reasonable to use them for holding work files, especially if the company’s server is frequently down or not accessible. However, storing files in any location other than company-sanctioned servers makes those files difficult for IT to find and track. It poses a big security risk, too. Remember, IT is responsible for the protection of all company files. If you save the only copy of certain files offsite, IT can’t do its job. If the files are lost or stolen, and contain sensitive or confidential information, you could very well be held responsible and face disciplinary action (at the least). Unwanted disclosure could also cause a major catastrophe for your company, and you don’t want to be the person with that weight on your shoulders.It’s also difficult for coworkers to access offsite files when and if they’re needed in a pinch, which is likely to occur when you’re on vacation or otherwise unavailable. It’s just not a smart practice – and it’s bad for business.The level of security offered from one cloud provider to another differs as well. Not every provider has the best track record as far as keeping out bad guys who find new and interesting ways to breach servers every day.A Word About Products Disguised As ‘The Cloud’Now that we’ve covered the cloud proper, you might also explain to employees that the cloud is a great selling point for some companies that manufacture local storage. These are typically external drives that connect to a computer or router and let you access files whether you’re home, at work or across the world. With up to 2 TB of space, such drives are popular for storing videos and music, then streaming those files to a home entertainment system or other home computers. They’re often pitched as a “personal cloud,” too.Well, yes and no. They’re local storage that’s accessible over the Internet, with some bells and whistles to make them fun to use, but they don’t offer anywhere near the huge capacity and gamut of services that a real cloud does. They’re called “personal” for a very good reason and should be used as such. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe