Cloud Security Starts Below the Cloud
Knowing where every security setting lives is useful. Understanding what happens underneath those settings is what helps when something behaves unexpectedly.

A cloud security engineer sees unusual traffic reaching an application. The access policy looks correct. The workload configuration looks normal. Nothing obvious is flashing red.
Now the investigation moves somewhere less convenient.
Where did the request resolve? Which route did it take? What identity did the workload use? Which protocol carried the connection? Did traffic pass through an edge service, private network or another cloud environment?
The cloud console can answer some of those questions. Networking knowledge answers the rest.
An ITU Academy course running through 28 September 2026 offers an interesting picture of how interconnected modern infrastructure has become. Its curriculum combines cloud and edge computing with IPv6, QUIC, DNS, SD-WAN, fixed and mobile broadband, IoT, AI and cybersecurity. ITU Academy
For cybersecurity workforce development, the combination makes sense. Cloud security increasingly requires people who understand what the cloud is built on.
Abstraction Doesn’t Remove the Fundamentals
Cloud services are very good at hiding infrastructure complexity. That’s part of their appeal.
Security teams don’t always have the same luxury.
A DNS configuration can redirect users to the wrong destination. A routing decision can expose a service unexpectedly. Identity controls determine which workloads can communicate. Encryption protects connections, while logging determines whether investigators can reconstruct what happened later.
Useful cloud security skills therefore extend across several layers:
- Network fundamentals including addressing, routing and segmentation
- DNS and how applications discover services
- Identity and permissions for people and workloads
- Cloud and edge architecture
- Encryption and secure communications
- Logging and telemetry across distributed systems
- Application and API behaviour
Nobody needs to become an expert in every layer. Teams do need enough shared technical language to recognize where a problem may actually live.
Otherwise, “the cloud is broken” becomes a surprisingly durable diagnosis.
Product Knowledge Has a Half-Life
Platform-specific skills still matter. Engineers need to know how to configure the systems their organization actually uses.
The problem comes when product familiarity is mistaken for underlying capability.
Interfaces change. Services are renamed. New architectures appear. A professional who understands why segmentation matters can transfer that reasoning to another environment. Someone who understands DNS can investigate resolution problems whether the application runs in a data centre, public cloud or edge environment.
NIST’s NICE Framework takes a similar task-oriented view. It describes cybersecurity work through Task, Knowledge and Skill statements that can be used across roles and organizations. NIST
That’s useful for cloud security because the technology will keep changing faster than a static curriculum.
Train Across the Boundaries
Cloud security training becomes more realistic when learners have to cross technical layers.
Give participants a cloud-hosted application with an access problem. The obvious security configuration can be correct while the actual issue sits in DNS, workload identity or network routing. Let them trace the path, test assumptions and determine which team needs to act.
The exercise teaches something broader than a configuration procedure. It develops the ability to reason across systems.
That approach fits practical learning at ITSEC Cyber & AI Academy, where hands-on environments can connect cloud, network and cybersecurity concepts through scenarios that behave more like real infrastructure.
Cloud platforms make infrastructure easier to consume.
They don’t make the infrastructure underneath irrelevant.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: ITU Academy: Future Fixed and Mobile Broadband Internet, Cloud Computing and IoT/AI, 21–28 September 2026 · NIST: Getting Started With the NICE Framework · NIST: NICE Framework Components v2.2.0
.png)


