Cloud Computing

Is the cloud vulnerable? Understand the AWS Shared Responsibility Model

Learn how the clear division of responsibilities between AWS and the customer eliminates vulnerabilities and strengthens protection in the cloud

09/12/2025

Leonardo Fróes

One of the biggest concerns for managers when considering migrating to the cloud is security. After all, if your company's data is no longer "inside the house," how can you ensure it won't be exposed? This concern is legitimate, but it usually stems from a myth: that the cloud is, by nature, more vulnerable than traditional data centers.

The reality is quite the opposite. Amazon Web Services (AWS), the global leader in cloud computing, adopts a Shared Responsibility Model that clearly defines who takes care of what when it comes to security. This approach not only eliminates noise but also increases the level of protection and compliance.

In this article, we will show how this model works in practice, what the roles of AWS and the customer are, and why understanding it is essential to transforming the cloud into a secure, scalable, and reliable strategic asset.

Deconstructing the myth of cloud vulnerability

When someone asks if "the cloud is vulnerable," they start from the premise that internal servers are, by definition, more secure. In practice, most cloud incidents stem from human error or improper configuration, not from flaws in the AWS infrastructure.

AWS operates with rigid layers of protection that most companies could not replicate on-premises: physical security of data centers, network segmentation, isolated virtualization, continuous monitoring, and independent audits. This is what is called defense in depth and security by design.

An operation without good practices can be vulnerable. It is precisely to eliminate these gray areas that the AWS Shared Responsibility Model exists.

What is the AWS Shared Responsibility Model

The Shared Responsibility Model is one of the pillars of AWS security and clearly defines where Amazon's responsibility ends and where the customer's begins. It works as a transparent security contract that avoids doubts and critical management failures.

In practice, AWS is responsible for the security of the cloud: everything involving physical infrastructure, data centers, hardware, network, virtualization, and basic services. On the other hand, the user company is responsible for security in the cloud: operating systems, configurations, access management, data, and applications.

This division organizes roles and also gives companies the flexibility to adopt the controls most suitable for their business. Understanding this model is essential to reducing risks, making better use of cloud resources, and avoiding the most common mistakes that lead to security incidents.

AWS Responsibilities

AWS takes care of the most critical security foundation so that the customer does not have to worry about the physical and structural basis of the cloud. Among its responsibilities are:

  • Physical security of data centers: facilities monitored 24/7, with multiple access barriers, power redundancy, and disaster protection.

  • Hardware, software, and network infrastructure: maintenance, updates, and resilience of servers, devices, and global connectivity.

  • Virtualization layer and basic services: systems that allow running virtual machines, containers, and other resources in an isolated and secure manner.

  • International compliance certifications: external audits and stamps such as ISO, SOC, PCI DSS, which prove adherence to global standards.

In summary, the customer does not need to worry about physical attacks, hardware failures, or global availability: all of this is already delivered by AWS as part of the contracted service.

Customer Responsibilities

On the customer side, responsibility varies depending on the type of service consumed, and this is where many companies make mistakes by not properly configuring their environments.

In infrastructure services (IaaS), such as Amazon EC2, it is up to the customer to:

  • Update and apply security patches to the operating system.

  • Configure firewalls and access rules.

  • Install, monitor, and manage software and applications.

In more managed services, such as Amazon S3 or DynamoDB, AWS takes care of the foundation, and the customer focuses on:

  • Defining access policies using IAM (Identity and Access Management).

  • Choosing and managing encryption strategies.

  • Properly classifying and protecting their data.

This flexibility allows each organization to maintain the level of control suitable for its business, without unnecessary overhead. However, this is precisely where the biggest challenge arises: aligning governance, best practices, and security culture to avoid gaps.

Inherited, shared, and customer-specific controls

In the Shared Responsibility Model, security is organized into three layers of control that define who does what:

1. Inherited controls: fully managed by AWS, such as the physical security of data centers and the protection of global infrastructure.

2. Shared controls: require joint action. For example, AWS applies security patches to its services, while the customer must update operating systems and applications. The same goes for configurations: the cloud guarantees the network, but the customer defines rules in databases and applications.

3. Customer-specific controls: focus on what is under the sole management of the user company, such as access policies, environment segregation, data classification and protection, and regulatory compliance.

This division reduces ambiguity, ensuring that there are no gray areas of responsibility, which is precisely where most incidents occur in traditional environments.

From theory to practice: applying the model

Understanding the Shared Responsibility Model is essential, but it only generates results when put into practice consistently. To do this, AWS recommends some pillars of action:

  • Adopt recognized frameworks, such as NIST CSF and ISO 27001, to align security and governance.

  • Apply the AWS Well-Architected Framework in the continuous evaluation of workloads.

  • Explore native security, identity, and compliance services in the AWS cloud.

  • Analyze audit reports and certifications already made available by AWS.

  • Invest in training the internal team, reinforcing cloud security best practices.

Following these steps transforms the model from a theoretical concept into an operational routine, strengthening resilience and raising the organization's digital maturity.

The cloud as an ally of compliance

Regulatory compliance is one of the biggest challenges for organizations dealing with sensitive data, especially in sectors such as finance, healthcare, and government. Standards such as LGPD, GDPR, HIPAA, and PCI DSS require strict security, traceability, and governance controls.

In the Shared Responsibility Model, AWS ensures the compliance of the foundation infrastructure, covering aspects such as physical security, encryption in transit, international certifications, and independent audits. Meanwhile, the customer is responsible for applying controls in cloud usage, such as access policies, data classification, log monitoring, and environment segregation.

This balance allows companies to reduce the complexity of regulatory compliance, leveraging frameworks already validated by AWS and directing efforts to the most critical layer: data protection and proper use. In many cases, migrating to the cloud not only facilitates compliance with regulations but also offers more transparency and agility in auditing and governance processes.

Security is a partnership, not a barrier

The cloud is not vulnerable by nature. A company that does not understand its responsibilities can be vulnerable. The AWS Shared Responsibility Model shows that security is built in partnership: AWS ensures the global foundation, and the customer configures and protects their operation.

In practice, this means that migrating to the cloud does not increase risks. On the contrary, it reduces them. The question is not whether the cloud is secure, but whether your company is already prepared to take advantage of the available resources.

At CodeBit, as an official AWS partner, we help companies understand and apply this model day-to-day, ensuring that each workload is protected from end to end. If your company still has doubts about cloud security, this is the time to talk to our specialists. 

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546