So, you’ve upgraded to the cloud…now what?

Any experienced sailor knows it’s easy to launch a vessel – the hard part is keeping it afloat once you’re out at sea. The same can apply to chief information officers (CIOs) who’ve successfully upgraded their business to the cloud.
Finding your sea legs quickly as wave after wave of problems hit – including creaking legacy technology, belligerent employees and the ever-present threat of cyberattacks – is key to post-cloud survival.
Helen Ashton helped power fashion giant ASOS through several technological shifts, moves which ultimately made them the market leader in online shopping, earning £3.26bn last year. Now founder of Shape Beyond, a business transformation consultancy, Ashton says the key to success at ASOS was full migration to the cloud.
However, new technology only brings the expected benefits when people are kept on board with the processes needed for success.
“Businesses either plan for months in minute detail or they jump straight in to work on the sexy stuff, such as analytics or digital CX,” says Ashton. “But success comes from winning hearts and aligning incentives. It is amazing how easily focus can shift through overzealous project management to ticking off activities on the plan rather than keeping sight of delivery of the outcomes identified as indicators of success.”
You can use some of the cloud’s metrics and data to demonstrate quick wins and progress. However, the key to ongoing cloud success is to share data in a way that empowers staff to problem solve within the business, creating a sense of shared responsibility that allows all parties to see bottlenecks and show who needs help and why, says Ashton.
Before you share all your data internally, make sure a hole in your S3 bucket isn’t sharing it everywhere else.
A simple S3 bucket exposure from an unknown public source leaked personal details of 120 million Brazilians– including banks, credit details and voting history – partly because an administrator had renamed the index.html by accident. In separate examples, a mobile app developer exposed 500,000 documents from a finance app and a cannabis retailer leaked 30,000 of its customers’ details, which all led to considerable fallout and organisations falling foul of data privacy regulations.
“We’ve seen incidents on a frequent basis where cloud databases have been set to be publicly accessible, when they needed to be private,” says Javvad Malik, lead security awareness advocate at KnowBe4. “Similarly, having the appropriate authentication controls in place is vital to prevent account takeovers which exploit weak credentials.”
To prevent leaks, look for gaps where cloud migration shifts data centre responsibility from the traditional sysadmin to site reliability engineers and DevOps teams, says Tim Mackey, principal security strategist at Synopsys Cybersecurity Research Center. “This shift creates a potential gap between those familiar with the application security requirements and those versed in cloud security topics.


