Skip to main content

Cloud Network Security

Cloud network security protects data, workloads, identities, and communication paths in cloud environments. It follows a shared responsibility model.

What is Cloud Network Security?

Cloud network security protects data, workloads, identities, and communication paths in cloud environments. It follows a shared responsibility model. The provider and customer responsibilities vary by service model, but the customer still controls important settings such as identities, network paths, access policy, encryption, monitoring, and workload configuration. A secure provider platform does not correct an exposed service or an overly broad customer policy.

Why it matters

Cloud networks change through APIs and automation. A broad identity rule, exposed service, or incorrect route can create risk across many workloads quickly.

How it works

  1. The organization maps provider and customer responsibilities, assets, identities, and required communication paths.
  2. It applies identity policy, network controls, workload controls, and encryption at the responsible layers.
  3. It monitors changes and traffic, then reviews policy as workloads and risk change.

Example

A cloud-hosted administration service has no direct public path. A gateway checks user identity and device context, while cloud security groups allow only the gateway to reach the service.

Pomerium boundary

Pomerium can place identity-aware route policy before cloud-hosted HTTP, TCP, and UDP services. It protects the routed access path but does not replace cloud IAM, security groups, workload hardening, or provider controls.

Limits and non-claims

  • Provider responsibility and available controls differ across service and deployment models.
  • Configuration drift and stolen cloud credentials can bypass an intended design.
  • Network controls do not repair a vulnerable or compromised workload.

Evaluation checklist

  • Are public, private, peered, service, metadata, management, and control-plane paths mapped?
  • Which workload identity and application authorization checks remain after the network permits traffic?
  • Can an Internet endpoint, cloud control plane, alternate account, or failover path bypass policy?

Sources and further reading

Keep learning

Zero TrustNetwork and Infrastructure

Micro-segmentation

The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo