Re: Malware and Exploits as a Service
Unfortunately we don't live in this utopic world that you talk of where IT department security functions are well funded and staffed with competent security professionals. After 35 years working in this industry, 25 as a security expert in multiple consultancies and private companies I'm flat out telling you that you couldn't be more misguided.
Cloud is not a magic bullet my any means but Microsoft have literally 1000's of security people working on their systems 24/7. In many companies, especially smaller ones, there's a handful of people in the IT department, none of which are security specialsts. Many want to be secure but have neither the budget or skills to do the work. For literally 1000's of companies going Azure and relying on MS to secure your data will be orders of magnitude more secure than staying on prem.
This ridiculous delusion that "cloud bad, on prem good" just needs to die. As I said, it's not a magic bullet but in this day and age even as a 25 year veteran I think I'd struggle to keep things as secure without a big budget.
Even 10 years ago, the average mean time to exploitation after a vulnerability was published was mostly measured in weeks. That means you had SOME time to work on patching things before you were attacked. These days it's typically measured in hours. That kind of timescale makes on-prem security increasingly difficult to provide. Of course you can do it, but it's likely MS will do it faster and better than I could ever hope to do it.
That ignores the triviality of actually deploying and configuring much of it (single click natively supported for most of Azure) and everything is fully integrated into the entire platform already.
Of course there's still many things to worry about and you can mess up the configuration just as easily with either approach but my experience and knowledge tells me that for the vast majority of the systems I've seen and secured, going cloud is infinitely more secure all things considered.