Gartner: Five actions for CISOs to manage cloud concentration risks

Cloud concentration risks are becoming increasingly pervasive, driven by evolving regulatory requirements and heightened geopolitical uncertainties. As organizations deepen their reliance on cloud services, these risks demand greater attention —particularly from chief information security officers (CISOs), who are now more involved in business continuity planning than ever before.

Charlie Winckless at Gartner
Charlie Winckless at Gartner

There are four primary facets of cloud concentration risk, each presenting distinct challenges. Vendor risk arises when heavy reliance on a single provider reduces negotiation leverage, potentially resulting in unfavourable pricing or contract terms. Availability risk occurs if a major outage at a cloud provider disrupts critical business operations. Business continuity risk is present when multiple applications or functions become unavailable for an extended period due to issues with a cloud provider, threatening the organization’s ability to operate. Regulatory risk emerges as organizations face differing and sometimes conflicting expectations from various regulatory bodies.

It is essential for CISOs to clearly communicate these potential downsides, as well as the challenges in addressing them, to internal stakeholders involved in cloud acquisition decisions, ensuring everyone understands the inherent uncertainties and is prepared to make informed, explicit choices in this complex environment.

Understanding the Challenges of Cloud Substitutability

Organizations are often encouraged to pursue cloud portability, or “substitutability,” for their cloud applications, especially in response to regulatory expectations. However, substitutability is not a one-time initiative—it requires ongoing maintenance for the entire lifespan of each application, which increases both complexity and recurring costs. Additionally, maintaining substitutability can diminish the advantages of cloud adoption by reducing agility and limiting access to innovative cloud features.

Switching providers, whether under planned or unplanned circumstances, is inherently difficult, time-consuming and expensive. For example, moving from one SaaS provider to another almost always necessitates a complete solution replacement due to unique customizations and integrations. Transitioning between PaaS providers frequently requires refactoring some or all applications, while switching IaaS providers is challenging even for basic infrastructure, given the differences in management, operations and security. Despite market claims, technologies such as containers and orchestration platforms like Kubernetes or Red Hat OpenShift do not significantly ease these portability and switching challenges. Because substitutability imposes ongoing costs and operational burdens — not just at the point of switching but throughout the lifetime of the solution — Gartner recommends considering it only when other methods for managing concentration risk are insufficient.

Implement 5 Immediate Actions Until Concentration Risks Are Addressed

To balance concentration risk concerns, CISOs can take five core actions outlined below to appropriately protect your organizations.

#1 Actively Manage Cloud Provider Relationships

To effectively mitigate concentration risks, CISOs should start by identifying and documenting both third-party and fourth-party risks, with a focus on the most critical cloud providers. It is important to recognize that some non-cloud products may also have cloud dependencies, such as management consoles or reporting engines. Collaborating closely with strategic procurement and vendor management (SPVM) leaders ensures that each cloud provider has a clearly documented owner who understands their responsibilities. Additionally, partnering with business stakeholders is essential when making changes to cloud provider relationships, such as adopting new services or adjusting the criticality of existing applications delivered from a cloud provider.

#2 Maximize Single-Cloud Resilience

Before considering more complex multi-cloud strategies, organizations should prioritize building resilience within their existing single-cloud environments. This involves understanding the costs associated with resilience measures and balancing them against the potential impact of a cloud outage. CISOs should not rely solely on service level agreements (SLAs) to mitigate financial losses from outages, as SLA payouts are often insufficient. Instead, focus on designing applications to gracefully handle limited failures and use cloud-native resilience patterns. In IaaS and PaaS, focus on short-term failure of some cloud services first, rather than catastrophic failure of a large provider and use cloud-native resilience patterns in your architecture. In addition, special attention should be given to cloud identity providersdue to their position as a large single point of failure.

#3 Focus on Business Continuity for Critical Processes

Conducting a business impact analysis (BIA) helps organizations identify their most critical services and determine the necessary steps to meet continuity standards. For applications where the cost of maintaining high availability is prohibitive, consider designing lightweight alternatives—such as backup SaaS solutions or even manual processes — to keep essential business functions running. Prioritize cloud availability for the most impactful processes to ensure that resources are allocated where they are needed most.

#4 Partition Your Cloud-Based Application Portfolio

To reduce the risk associated with single-vendor dependency, organizations should intentionally distribute applications and workloads across at least two cloud providers. While single-vendor solutions can simplify integration and sourcing, a multi-cloud approach limits the potential impact of an issue affecting any one provider. This strategy requires careful planning, as it introduces additional complexity and demands greater skill and staffing to manage multiple environments. Security teams should be trained on multiple platforms, and cross-cloud tools should be validated to ensure seamless operation.

#5 Build a Cloud Exit Plan to Satisfy Regulators

Regulatory compliance may require organizations to develop a concrete and actionable plan for exiting a cloud provider and transitioning to another solution. The speed at which an exit must be executed should be weighed against the upfront investment and ongoing resources needed to maintain readiness.It should be noted that these plans are not trivial to build and must be maintained and updated over the lifetime of the applications in scope.

Establishing a continuous exit planning program allows organizations to adapt to evolving business and cloud requirements. Where possible, consider outsourcing aspects of exit planning and execution to streamline the process and ensure compliance with regulatory expectations.

By Charlie Winckless, VP Analyst at Gartner

Baburajan Kizhakedath
Baburajan Kizhakedath
Baburajan Kizhakedath is the editor of InfotechLead.com. He has three decades of experience in tech media.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest

More like this
Related

Intel Accelerates AI Innovation with Domestic Chip Manufacturing, AI PCs, and Workforce Development

Intel is reinforcing its leadership in the artificial intelligence...

Amazon to Invest Additional $13 bn in India AI and Cloud Infrastructure by 2030

Amazon has announced an additional investment of $13 billion...

Oracle Cuts 21,000 Jobs as AI Reshapes Workforce and Cloud Expansion Accelerates

Oracle has reduced its global workforce by approximately 13...