Cloud security
Cloud security: protecting your business in the digital sky
The migration business case is usually written in terms of cost and speed. The security assumptions underneath it are rarely written down at all.
Cloud migration is generally justified on elasticity and operating cost. Both are real. What often goes unexamined is the implicit assumption that security comes with the platform, that because the provider is demonstrably better at physical and hypervisor security than you were, the overall posture must have improved.
It may have. But the controls you lost in the move are rarely inventoried, and they are usually the ones nobody thought of as controls: the network that was simply not reachable, the change process that was simply slow.
The four things to get right first
Identity, because it is the new perimeter and the most common root cause. Logging, because an incident you cannot reconstruct is an incident you cannot bound. Data classification, because encryption decisions and residency obligations both depend on it. And segmentation, because flat cloud networks fail in exactly the way flat corporate networks did.
None of these are advanced. All of them are much cheaper to establish before the estate grows than after.
Assume you will need to prove it
At some point a customer, an auditor or a regulator will ask you to demonstrate a control rather than assert it. Design for that from the start: retention long enough to investigate, access records that show who did what, and a documented process for the questions you know are coming.
It is the same work either way. Doing it early just means doing it once.
Want this looked at in your environment?
We run scoping calls with practitioners, not salespeople. Half an hour is usually enough to tell you whether there is a real problem here and what it would take to close it.

