39:51The Cloud: Security Threat or opportunity? (Spoiler, it’s both!)
Download resourcesAbout this session
Jon Rohrich, security and compliance specialist at Microsoft Canada, argues that the cloud is both a new attack surface and the best chance most organisations have to improve their security. He opens with the attacks seen in cloud tenants: password spray, malicious Exchange forwarding rules, internal phishing aimed at privilege escalation, OneDrive exfiltration, supply-chain tampering and consent abuse by rogue applications. With the perimeter gone, he frames the answer around SASE and zero trust, where identity is the front door and every access request is judged on user, device health, location and data classification. The core of the talk is the shared responsibility model: the provider covers the physical data centre, network and host, while accounts, endpoints and data governance always stay with the customer, which is why unprotected admin accounts and open storage buckets still cause breaches. He walks through how a hyperscaler secures its side (unmarked data centres, background checks, just-in-time access, secure development lifecycle, bug bounties, audit reports, threat telemetry) and closes on the customer toolset: single sign-on, MFA, endpoint detection, cloud SIEM, CASB, data labelling and DLP, noting that MFA alone blocks the vast majority of identity-based attacks.
As more and more organizations move to the cloud for their essential information services, users are equipped to be more productive than ever. But does this productivity introduce additional risk to your organization? How can you ensure security for information that sits outside your datacenter? In this session, you’ll learn about the benefits that modern cloud computing provides, the additional threat vectors that are exposed and how cloud providers can help you mitigate these risks and more.
Key takeaways
- Know which layers the shared responsibility model leaves to you: identities, endpoints and data governance never move to the provider, whatever the service model.
- Turn on multi-factor authentication for every account, admins first; most breaches start with stolen or weak credentials and MFA blocks the vast majority of them.
- Treat identity as the control plane: single sign-on plus per-request evaluation of user, device health, location and data sensitivity is the practical start of zero trust.
- Use a cloud access security broker to discover which SaaS apps staff actually use, then sanction or block them rather than guessing.
- Ask your provider for its audit reports (ISO 27001 and sector certifications) and for just-in-time, approval-gated support access instead of standing access to your data.
Speakers

As Technical Specialist – Modern Workplace Security and Compliance, Jon Rohrich helps enterprise organizations in central Canada understand and respond to the modern threat landscape with up-to-date security and compliance solutions. As an expert in… Read moreRead less
As Technical Specialist – Modern Workplace Security and Compliance, Jon Rohrich helps enterprise organizations in central Canada understand and respond to the modern threat landscape with up-to-date security and compliance solutions.
As an expert in current workplace security with a military background, Jon collaborates with financial services, healthcare, legal, and government clients to identify and thwart increasingly sophisticated cyberattacks.
Jon is a strong leader and analyst. During his 10+ year career, his passion for security and compliance translated into impressive sales of Microsoft enterprise products and compelling training sessions and presentations to diverse audiences.
Before joining Microsoft, Jon worked as a Senior Consultant focused on professional services delivery for New Signature Canada and served five years in the Canadian Armed Forces. Jon earned a Network Engineer Honours diploma from triOS College as he transitioned out of the military. He holds over 15 Microsoft Certifications, and is a Certified Information Systems Security Professional and Certified Ethical Hacker.
“I believe that knowledge is power. The more I can help Canadian individuals and organizations understand and adapt to the modern threat landscape, the better.”
