Someone inside a company sets up an Azure/AWS instance, to do sandboxing, and doesn't secure it.
Many of these giant data breaches, are because some Marketing person, set up an AWS instance, dumped their entire user DB into it, and did a bunch of data mining.
I think that most cloud providers are now defaulting to locked-down, but the issue seems to be, that folks are still going outside their org, to do this.
I suspect that having some kind of secure internal cloud setup would be helpful.
However, and this is a biggie: It needs to be easy to use. So many times, security has so many roadblocks, that folks work around it, simply to be productive.
In my opinion, security needs to be the easiest path. If it is not, then that is the fault of the Security folks; not the end user. I worked for a company that had such terrible security policy, that it basically completely stopped all productivity. You could tell who was violating policy, because they accomplished their goals.
Having a policy is worthless, if it is too difficult to follow.