Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
Tips & Tricks 8 min read

Security in the cloud: How to protect your data in NextCloud and similar services

How to recognise and avoid email phishing

Cloud services are now regarded as one of the most important technologies for businesses, the self-employed and private individuals who wish to access their data from anywhere. Security plays a key role here, particularly when it comes to sensitive information or personal data.

One popular solution for hosting your own cloud storage is NextCloud, for example, which offers a wide range of security options and a high degree of flexibility. In this article, you’ll learn how to effectively protect your data in a hosted NextCloud environment or alternative cloud applications. We’ll cover topics such as secure passwords, two-factor authentication and various encryption options. We’ll also introduce solutions such as Cryptomator and other tools that you can use to provide additional security for your data.

Why cloud security is so important

In today’s digitalised world, data is at the heart of many processes. We store confidential documents, customer data or personal photos in the cloud so that we can access them at any time and from anywhere. However, once data is uploaded to the cloud, it is no longer available solely on a local computer or external storage device. This means you must take greater care to ensure that no unauthorised persons gain access. A data breach can not only lead to business-critical problems or damage to a company’s reputation, but can also result in legal consequences - particularly with regard to the General Data Protection Regulation (GDPR).

Security in the cloud encompasses various aspects: a robust technical foundation, such as professional hosting, is just as important as how you handle your own data. Only when both factors work together can effective protection against unauthorised access be achieved.

Secure passwords as a fundamental safeguard

One of the most important steps in securing any cloud solution - be it NextCloud, Dropbox or another platform - is the use of secure passwords. Simple combinations such as ‘123456’ or ‘password’ are still frequently used. These are easy for attackers to crack and leave the door wide open to potential misuse.

Best practices for secure passwords

  1. Length: Use passwords with at least twelve characters.
  2. Character set: Use a mix of upper- and lower-case letters, numbers and special characters.
  3. Avoid personal information: Names, dates of birth or simple word combinations are easy to guess.
  4. Uniqueness: Use a separate, unique password for each service. Reusing passwords increases the risk that other accounts will also be compromised in the event of a data breach.
  5. Password managers: Tools such as KeePass, 1Password or LastPass make it easier to create and remember complex passwords.

Secure passwords are the first line of defence when it comes to cloud services. If they are handled carelessly, it doesn’t matter how sophisticated the rest of the security systems are - a weak password can undo everything.

Two-factor authentication (2FA)

Even the best passwords do not offer 100 per cent protection. This is where two-factor authentication (2FA) comes into play. With this method, an additional factor is required alongside the password, e.g. an SMS one-time password (TAN), a one-time password generated by an app, or a security key (hardware token).

Advantages of 2FA

  • Significantly makes access more difficult, even if the password is compromised.
  • Provides additional protection against phishing attacks.
  • It is straightforward to set up and use.

NextCloud offers support for common 2FA solutions as standard. You can use apps such as Google Authenticator or FreeOTP to enter a dynamic code every time you log in. This code changes at short intervals, making it much more difficult for attackers to gain unauthorised access to your account.

Encryption solutions in NextCloud

NextCloud’s greatest strength is its flexibility and the wealth of extension options available. This principle also applies to encryption: by default, NextCloud features server-side encryption, which protects data as soon as it is uploaded to the cloud server.

Server-side encryption

  • What is it? With server-side encryption, your data is secured on the server using a key.
  • Advantages and disadvantages: This method is easy to configure and relatively user-friendly. However, in the event of a dispute, the server operator may also have the ability to access the keys.

Client-side encryption

  • What is it? Here, encryption takes place on the user’s device. The data is uploaded in encrypted form and therefore remains secure in the cloud.
  • Advantages and disadvantages: Greater security, as the cloud provider cannot access the raw data. However, this can be slightly more complex to set up and requires the appropriate tools.

Many NextCloud installations support not only server-side encryption but also the option of a client-side solution. With this option, your files are already encrypted before they reach NextCloud. Only you (and, where applicable, authorised users) possess the key. Should files fall into the wrong hands, they are virtually worthless without the correct key.

Discover servers for NextCloud

Additional tools: Cryptomator & Co.

Apart from NextCloud itself, there are various programmes and services specifically designed to encrypt files before they are uploaded. Cryptomator is a particularly well-known example. This is open-source software that allows you to create a ‘vault’ on your computer. This vault appears as a normal folder into which you can place your files. When synchronising with the cloud, these files are automatically uploaded in encrypted form.

Further advantages of Cryptomator:

  • Ease of use: You set up a vault once and can then store as many files in it as you like.
  • High compatibility: The software works with various cloud services, from NextCloud and Dropbox to Google Drive.
  • Transparency: As an open-source project, the source code and encryption mechanisms are freely available for inspection.
  • Security: Encryption is in the user’s hands; no third party can view the keys, and the data is transferred to the cloud in an encrypted form.
  • Compatibility: Whether on a smartphone, MacBook, tablet or computer - decryption can be carried out on a wide variety of devices.

As well as Cryptomator, other solutions such as Boxcryptor and VeraCrypt offer similar approaches. The advantage of such tools is that they protect your data locally. Even if the cloud provider is compromised, your files remain secure thanks to the additional layer of encryption.

Further best practices for cloud security

To achieve the highest possible level of protection, you should always view cloud security as a holistic concept. In addition to password and encryption strategies, this includes the following points:

  1. Regular updates Both the NextCloud server system and the client applications should always be kept up to date. Updates quickly patch security vulnerabilities, making it much harder for attackers to breach your systems.
  2. Security plugins for NextCloud NextCloud offers a whole range of plugins that can make your installation more secure. These range from firewalls and anti-virus scanners to advanced monitoring tools. Check regularly to see if there are any new, useful extensions available.
  3. Manage access rights Clearly define who is allowed to view or edit which folders. Especially within teams, it makes sense to set up granular access rights, for example to restrict certain folders to read-only mode.
  4. Enable the audit log NextCloud’s audit log allows you to record all important activities (e.g. logins, data access, configuration changes). In the event of a security incident, this enables you to quickly trace what has happened.
  5. Regular backups Even with the best security strategy, not all risks can ever be ruled out. You should therefore create regular backups of your data. This way, you can quickly restore your data in an emergency - whether due to a cyberattack, a hardware fault or accidental deletion.

Discover secure cloud servers

Conclusion: Comprehensive protection for your cloud

Cloud security is a complex topic encompassing many individual aspects. Anyone using a hosted NextCloud solution or similar services should, in addition to strong passwords and two-factor authentication, focus particularly on encryption. NextCloud already provides robust basic features for server-side encryption; those who want even greater control can also rely on client-side tools.

Programmes such as Cryptomator ensure that your data is not only uploaded securely but also remains protected from the prying eyes of third parties. When these measures are combined with ongoing maintenance, regular updates and a well-thought-out permissions management system, you benefit from a robust security strategy that more than meets modern requirements.

If you’re looking for a reliable, professional NextCloud solution or need support in setting up your cloud security strategy, we at SpeedIT are happy to help. Find out how we can support you with high-performance hosting, experienced IT experts and bespoke security solutions.

This ensures your valuable data remains protected at all times, allowing you to focus fully on making the most of the cloud’s benefits - whether that’s for seamless team collaboration, working from home or accessing your most important documents whilst on the move. A reliable security strategy is essential for continuing to work securely and worry-free in the cloud in the future.

Managed Hosting for NextCloud

More posts

All posts
Security 4 min read

How to recognise and avoid email phishing

Email phishing is one of the most common methods used by criminals to try to obtain personal data from internet users. More and more people are using the internet to communicate and exchange data, which makes it…

Tips & Tricks 5 min read

Two-factor authentication - here’s why you should use it!

For many online service providers, two-factor authentication has now become the state-of-the-art login procedure. Instead of simply logging in with your password, you need an additional factor. This differs…

General 3 min read

SpeedIT nominated once again: Web Host of the Year 2026

We are delighted to announce that SpeedIT Solutions has once again been nominated for the prestigious ‘Web Host of the Year’ award in 2026 - in no fewer than three categories: Managed Servers, Shop Hosting and CMS Hosting…