| Definition |
Protects an organisation's entire digital ecosystem, including networks, applications, devices, users, and data from cyber threats. |
Focuses specifically on securing cloud-based infrastructure, applications, services, and data hosted on cloud platforms. |
| Scope |
Broad security strategy covering on-premises, cloud, hybrid environments, endpoints, and networks. |
A subset of cybersecurity dedicated to protecting cloud environments such as AWS, Azure, and Google Cloud. |
| Primary Objective |
Prevent cyberattacks, data breaches, unauthorised access, and business disruption across all IT assets. |
Ensure the confidentiality, integrity, and availability of cloud resources while preventing cloud-specific threats and misconfigurations. |
| Protects |
Networks, servers, endpoints, applications, databases, user identities, and sensitive business data. |
Virtual machines, cloud storage, cloud workloads, containers, cloud identities, APIs, and SaaS/PaaS/IaaS services. |
| Common Threats |
Phishing, ransomware, malware, insider threats, DDoS attacks, credential theft, and data breaches. |
Cloud misconfigurations, insecure APIs, excessive permissions, exposed storage buckets, compromised cloud accounts, and container vulnerabilities. |
| Security Controls |
Firewalls, endpoint protection, intrusion detection, identity management, encryption, security monitoring, and vulnerability management. |
Identity and Access Management (IAM), cloud encryption, security groups, cloud workload protection, configuration management, and Cloud Security Posture Management (CSPM). |
| Who Needs It? |
Every organisation that stores, processes, or transmits digital information. |
Organisations using public, private, or hybrid cloud services for applications, infrastructure, or data storage. |
| Relationship |
Umbrella discipline covering all aspects of information and digital security. |
Specialised branch of cybersecurity focused exclusively on cloud environments. |