The Coronavirus pandemic forced rapid changes in how organizations operate, accelerating digital transformation by up to five years within months. This shift relied heavily on cloud services and cloud-based applications, enabling business continuity while creating new cybersecurity and compliance challenges. As organizations moved to hybrid IT models spanning cloud, on-premises, edge, and hosting, they lost direct control over much of the infrastructure, and security/compliance responsibilities became shared between cloud service providers (CSPs) and cloud tenants. This shared responsibility can be confusing, leading to security gaps that adversaries can exploit and increasing the risk of compliance failures.
Core cybersecurity objectives remain consistent regardless of delivery model: confidentiality, integrity, availability, and compliance. However, tenants cannot directly control how CSPs deliver and secure services, so assurance must be governance-driven: define clear, measurable requirements and verify they are met. Since individual customer audits are impractical at cloud scale, industry standards and independent assessments become essential tools for assurance, providing accepted benchmarks and measurable objectives.
The document emphasizes Zero Trust—“never trust, always verify”—as highly relevant to cloud use, especially when cloud services deliver security-critical functionality. It describes four trust levels, concluding that independent third-party audits (Level 3) are currently the most practical path for most organizations. A wide landscape of laws, frameworks, and standards applies, particularly in Europe, where the German BSI C5 standard is increasingly adopted and is planned to inform a European Secure Cloud label alongside initiatives like SecNumCloud. Finally, it distinguishes security from compliance: strong security controls are foundational, but do not automatically satisfy legal obligations such as GDPR, even though they support requirements like GDPR Article 32.
See All Locations
See All Locations