So, as I understand it, you have continued to store potentially sensitive information in the cloud.
You say you have updated everything, including your policy. After that, do you follow up to make sure the policy is being enforced across all departments?