Logo
Cybersecurity

Cloud Security Starts Below the Cloud

Knowing where every security setting lives is useful. Understanding what happens underneath those settings is what helps when something behaves unexpectedly.

ITSEC AsiaITSEC Asia
|
Sep 28, 2026
Cloud Security Starts Below the Cloud

A cloud security engineer sees unusual traffic reaching an application. The access policy looks correct. The workload configuration looks normal. Nothing obvious is flashing red.

Now the investigation moves somewhere less convenient.

Where did the request resolve? Which route did it take? What identity did the workload use? Which protocol carried the connection? Did traffic pass through an edge service, private network or another cloud environment?

The cloud console can answer some of those questions. Networking knowledge answers the rest.

An ITU Academy course running through 28 September 2026 offers an interesting picture of how interconnected modern infrastructure has become. Its curriculum combines cloud and edge computing with IPv6, QUIC, DNS, SD-WAN, fixed and mobile broadband, IoT, AI and cybersecurity. ITU Academy

For cybersecurity workforce development, the combination makes sense. Cloud security increasingly requires people who understand what the cloud is built on.

Abstraction Doesn’t Remove the Fundamentals

Cloud services are very good at hiding infrastructure complexity. That’s part of their appeal.

Security teams don’t always have the same luxury.

A DNS configuration can redirect users to the wrong destination. A routing decision can expose a service unexpectedly. Identity controls determine which workloads can communicate. Encryption protects connections, while logging determines whether investigators can reconstruct what happened later.

Useful cloud security skills therefore extend across several layers:

  • Network fundamentals including addressing, routing and segmentation
  • DNS and how applications discover services
  • Identity and permissions for people and workloads
  • Cloud and edge architecture
  • Encryption and secure communications
  • Logging and telemetry across distributed systems
  • Application and API behaviour

Nobody needs to become an expert in every layer. Teams do need enough shared technical language to recognize where a problem may actually live.

Otherwise, “the cloud is broken” becomes a surprisingly durable diagnosis.

Product Knowledge Has a Half-Life

Platform-specific skills still matter. Engineers need to know how to configure the systems their organization actually uses.

The problem comes when product familiarity is mistaken for underlying capability.

Interfaces change. Services are renamed. New architectures appear. A professional who understands why segmentation matters can transfer that reasoning to another environment. Someone who understands DNS can investigate resolution problems whether the application runs in a data centre, public cloud or edge environment.

NIST’s NICE Framework takes a similar task-oriented view. It describes cybersecurity work through Task, Knowledge and Skill statements that can be used across roles and organizations. NIST

That’s useful for cloud security because the technology will keep changing faster than a static curriculum.

Train Across the Boundaries

Cloud security training becomes more realistic when learners have to cross technical layers.

Give participants a cloud-hosted application with an access problem. The obvious security configuration can be correct while the actual issue sits in DNS, workload identity or network routing. Let them trace the path, test assumptions and determine which team needs to act.

The exercise teaches something broader than a configuration procedure. It develops the ability to reason across systems.

That approach fits practical learning at ITSEC Cyber & AI Academy, where hands-on environments can connect cloud, network and cybersecurity concepts through scenarios that behave more like real infrastructure.

Cloud platforms make infrastructure easier to consume.

They don’t make the infrastructure underneath irrelevant.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ITU Academy: Future Fixed and Mobile Broadband Internet, Cloud Computing and IoT/AI, 21–28 September 2026 · NIST: Getting Started With the NICE Framework · NIST: NICE Framework Components v2.2.0

Share this post

You may also like

Cybersecurity Has a People Skills Gap Too
Cybersecurity

Cybersecurity Has a People Skills Gap Too

An analyst has spent two hours investigating suspicious activity. They understand the sequence, know which systems may be affected and have a reasonable hypothesis about what the attacker did. Then the incident manager asks a simple question: “What do we need to do now?” The answer suddenly requires more than technical knowledge. Cybersecurity work is full of moments like this. Findings need to be explained. Assumptions need to be challenged. Teams need to disagree without losing time. Technical specialists have to communicate with executives, engineers, auditors and people who would prefer never to hear the phrase “lateral movement” before their first coffee. NIST’s NICE program treats these capabilities as part of cybersecurity work itself. Its workplace skills resources include communication, collaboration, critical thinking, conflict management, resilience, strategic thinking and relationship building. That matters for how organizations train cybersecurity professionals. COMMUNICATION CHANGES THE VALUE OF TECHNICAL SKILL Consider a penetration tester who discovers a serious vulnerability. Finding it requires technical skill. Explaining why it matters requires another set of abilities. The tester needs to describe

ITSEC AsiaITSEC Asia
|
Sep 25, 2026 — 3 minutes read
Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?
Cybersecurity

Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?

Indonesia is investing more in cybersecurity technology as businesses move deeper into cloud computing, AI and digital services. Security platforms are becoming more sophisticated, but the people operating them have to keep pace. That gap is becoming harder to ignore. The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals reported at least one skills need within their organizations. AI was identified as the top skills gap at 41%, followed by cloud security at 36%. The issue, then, isn't simply a shortage of cybersecurity professionals. It's a shortage of people with the specific skills needed to secure increasingly complex technology. NEW TECHNOLOGY CREATES NEW SECURITY SKILLS A company moving its infrastructure to the cloud needs professionals who understand cloud architecture, identity and access management and cloud-specific vulnerabilities. An organization adopting AI needs people who understand how AI systems can be secured and how attackers can exploit them. A security team deploying more automated tools still needs analysts who can investigate alerts and distinguish a genuine attack from a false positive. The

ITSEC AsiaITSEC Asia
|
Agu 27, 2026 — 4 minutes read
What Is Cloud Security? A First Introduction for Modern Enterprises
Cybersecurity

What Is Cloud Security? A First Introduction for Modern Enterprises

INTRODUCTION: CLOUD ADOPTION IS ACCELERATING, SO ARE THE RISKS Cloud computing has been part of enterprise IT for years, but the risk landscape around it is changing faster than ever. As organizations embrace AI, remote work, and digital transformation, cloud environments have become the backbone of business operations and a prime target for attackers. Today, breaches are no longer limited to traditional data centers. Misconfigured cloud resources, stolen credentials, and unmanaged identities are now among the most common root causes of security incidents. This is why understanding what cloud security is and what it is not matters deeply for enterprises today. At its core, cloud security refers to the policies, technologies, configurations, and responsibilities that protect cloud-based systems, data, and services. This concept is inseparable from how cloud computing itself is defined:an on demand, shared,and externally managed computing model, as outlined in the NIST [https://csrc.nist.gov/pubs/sp/800/145/final]Cloud Computing Definition (SP 800-145), where responsibility is inherently distributed between the provider and the user. WHAT IS CLOUD COMPUTING? A SIMPLE ENTERPRISE PERSPECTIVE Cloud computing is not

ITSEC AsiaITSEC Asia
|
Feb 12, 2026 — 7 minutes read

Receive weekly
updates on new posts

Subscribe