While the need to secure public cloud-resident data is critical, organizations’ confidence in the tools and controls provided by cloud service providers (CSPs) is lukewarm. To alleviate these concerns, organizations are using a combination of CSP-native and third-party controls to secure cloud-resident sensitive data. This defense-in-depth strategy provides a multi-layered approach to address multiple dimensions of data security.