Nobody understands server security better, or spends more money and manpower on security, than the big cloud providers.
Who is responsible for configuring customers (i.e. _your_) leased space on a cloud provider? Who was responsible for misconfiguring the 'Tea' app bucket?
If you own your own servers, the answer is obvious. But if the cloud provider just sold your CIO on the cost savings, you'd better make sure they agreed to do so. And they don't come back and point the finger at your staff for checking the incorrect permissions box. Because your corporate cut your budget, figuring it would be the other guy's problem and you don't have the time/resources to take care of those details anymore.