YES
The hardest part is getting past people's perception. We've had beaten into our brains that anything "online" is forever in the public space and we can't ever keep that stuff safe or private - but the reality of modern computing systems doesn't jive with old PSAs about MySpace.
This is how we (Innovation Forge) position it when the conversation arises...
Locks keep honest people honest: Data theft cannot be prevented. If a "hacker" is dead set on gaining information, they will do it. Whether you are running a closed ecosystem (e.g. Vault) or a cloud data tool, your information is protected to the same degree. The vast majority of IP theft occurs not by malicious 3rd parties, but by poor behavioral practices by employees. There is a greater chance of social engineering that results in unwittingly handing your data over than some forcible attack. The same can be said for upset employees who outright steal and leave the company.
Obfuscation/Encryption: Data that lives in a Vault is obfuscated. The data itself is largely useless without the database to correctly piece the information back together. Furthermore, the system can be encrypted to further prevent unauthorized access. Cloud based systems employ the exact same techniques but also include end-to-end transmission encryption as well (so someone with a packet sniffer would be very hard pressed to do much of anything with what they intercept).
Your data has lived on the cloud for years anyway: Your personal financial and health records have lived in cloudland for a long time. Odds are your company uses Outlook 365 or IBM SmartCloud for your email... so all of that "sensitive business information" is living out there already. Even if you had an old Exchange or Domino server, you still have a webmail hook that is accessible from outside. While you certainly hear of nefarious plots to steal these types of information - the reality is that those heists typically can't be stopped anyway (see point number 1).
Data center employees don't want your stuff: Yes, a data center admin has both physical and virtual access to your data... but they don't want it! They manage thousands of customers' data and have a hard enough time managing the infrastructure to keep things afloat. There is no Amazon employee somewhere just browsing their servers for gold nuggets of IP to sell off. They would need to know very specific information about how and where data is stored to retrieve it - and due to that previously mentioned obfuscation, they would have to spend forever just trying to find all the associated data that goes with something.
I'm not suggesting we put our nuclear secrets on the cloud. What I am suggesting is that the data integrity of the cloud is the same as the data integrity of a private network - despite a few more moving pieces. Your (and your company's) approach to data security in the modern world should be much more in-line with proper behavior and personal responsibilities over a poka-yoke nanny approach.
Your mileage may vary.
K. Cornett
Generative Design Consultant / Trainer