What is CIO best practice when it comes to cloud security?

Modern businesses continue to invest more heavily in the cloud than ever before. Global enterprise spending on cloud services is projected to grow by 17.3% in 2019 to total $206.2bn, up from $175.8bn in 2018, according to analyst Gartner.
While the cloud provides a range of business benefits, such as agility, flexibility and scalability, it also brings challenges around implementation, particularly when it comes to information security. Businesses can be reluctant to push data to the cloud, with Gartner reporting that some CIOs continue to inhibit the use of public on-demand services.
However, with more businesses choosing to adopt a cloud-first strategy, it is essential that CIOs prioritise their security strategy. So, what does best-practice cloud security look like? Six experts gave Computer Weekly their take on the best way to establish an information security strategy that is fit for the on-demand era.
Barry Libenson, global CIO at financial data company Experian, said a strong cloud security strategy must be part of the standard working practices of a modern, technology-enabled business. His firm’s personally identifiable information (PII) resides in a datacentre in Dallas; non-PII data is stored in Amazon Web Services (AWS). Libenson said Experian runs different workloads in different places and always allows for dynamic scaling into the cloud. The automated environment means computing power is added and removed on-demand in response to developer requirements. Data is fully encrypted at rest and in transit – and governance is a key priority, said Libenson. “It’s all about recognising the fact that just because something goes to the cloud doesn’t mean you absolve yourself of the security responsibilities,” he said. “While I think AWS and Microsoft do a very good job on the security side of things, the responsibility still lies with us to ensure that customers’ information is kept secure. “Anything that is in the cloud we treat in the same way we would if it was in our own datacentre and it has the same security requirements regardless of where it is located. So, all PII data must be encrypted at rest as well as in transit. That can make compute more challenging because of the incremental overhead that it creates, but the stack has to be built with that in mind – and it hasn’t been an issue for us.”
Richard Orme, CTO of Photobox Group, is another IT leader who says cloud security must remain at the forefront of any modern business, particularly one dealing with large quantities of data. Photobox typically ingests between three and five million photos a day, with that figure rising to a million an hour during peak periods. Orme says Photobox has more than 6.5 billion photos uploaded to its platform. “It is an incredible amount of data and it requires serious upkeep, and so our 9PB migration to AWSlast year was essential,” said Orme, adding that the move to AWS provides a boost in terms of innovation and security credentials. “Amazon is almost unparalleled when it comes to data security – they are at the top of the game in this sector,” he said. “Our security has only become stronger by being a part of that ecosystem and sharing their resources. Today, I think tech leaders are realising we are much stronger building security systems and practices together than we can be going it alone.” Photobox is therefore benefiting from putting more trust in an external technology provider. Yet great cloud security is not something that can be simply outsourced, said Orme – CIOs must also focus on internal processes, particularly around staff. “On the ground, the most important thing is education,” he said. “Regular training for your team, and constant refreshing of best practices and workshops to keep all staff up to date on data security and hygiene, are all essential. This learning process is key to security becoming a part of the cultural fabric of the organisation, rather than a check-box exercise.


