5 things to know if you’re moving business to the cloud

Digital transformation is upon us and the COVID crisis has accelerated the journey. New services available only in the cloud with the ability to automate data processing, enable operational cost efficiencies, and manipulate data in new ways are creating opportunities that can’t be ignored. We are anticipating the spend on digital transformation (the use of smart technologies to reinvent products and services, improve operational efficiencies; all to drive enterprise growth) doubling from the current $469 billion to an estimated $1 trillion by 2025.
In 2020 most organisations accelerated their use of cloud capabilities to address business gateway bottlenecks and empower collaboration in the shift to working from home – or anywhere. With businesses having an accelerating critical dependency on secure cloud services, it’s essential that they understand and drive through business decisions on how to manage the risks.
Some of the risks are obvious (43% of cloud databases are not encrypted), whilst other risks are more hidden (76% leave key points of access open such as encrypted communication, and worse 60% have no logging enabled on cloud storage to track who is accessing them). These are simple mistakes security experts are used to fixing, so why isn’t this happening? The cost of cloud risk, if not managed effectively, can have serious consequences on the profitability of digital transformation.
Eighty percent of respondents suggested their cloud infrastructure was constantly evolving. The question should be WHEN was the risk analysis completed and how frequently should it be re-assessed. Cloud is effectively a new and often complex supply chain, which means new dependencies. Understanding risk means your security teams can see into your digital processes and have mapped all potential impacts end to end. Challenge them on the blind spots and what they are doing to cover these risks. With the constant evolution of cloud usage and your business processes, security teams must be asked if they are fixing blind spots once found (usually the hard way) or are they proactively investing in processes and capabilities to find and mitigate these risks before it’s too late?
Ninety-four percent of organisations use more than one cloud platform, such as Google (GCP), Amazon (AWS), and Microsoft (Azure). And of these, 60% use between two and five virtualising operating platforms (normally cloud services such as kubernetes on docker). Getting past the technical jargon, it’s important to recognise that any digital process will have multiple services provided by third-party companies. As you digitize more processes this becomes increasingly complex. The boundary points where responsibilities shift are often complex and ill-defined at the granular level. It’s worth identifying some and testing to see if clearly defined boundaries are understood. Seventy-three percent of companies struggle to clearly delineate between their cloud security provider’s (CSP’s) security responsibilities and their own, and that’s just one small part of the digital process.


