Three Security Questions to ask Cloud Vendors

Three Security Questions to ask Cloud Vendors

Your company is looking to dramatically change the way they are saving large amounts of data and they are thinking about moving to the “cloud.” There are many concerns when transferring to the cloud and security is one of the biggest, followed closely by concerns about complying with regulations and losing control of data according to a recent study by 451 Research.

While these are valid fears based on the recent news about breaches in data, loss of information and general doubt of cloud security at both the company and government level. Jack Sepple and Daniel Mellen tend to disagree, stating that “most public clouds are infinitely more secure than most companies’ current internal data centers and security functions,” in a column on Forbes.com.

Does this cloud meet my business’s specific needs?

There are major differences among cloud providers in their approach to security and their use of security technologies, processes, and personnel. These differences can have a major impact on the availability, integrity, accessibility, privacy, and compliance of your data. These cloud components can directly impact your company. Figure out exactly what your business needs, ask yourself questions such as: how many people will be using the cloud, how much storage will it need and how much will it cost? First research the needs of your company and then study available vendors to eliminate the ones that don’t work best for you and when you’ve narrowed down the options, dive deeper into questions about data protection, regulations and isolation of databases.

How can you isolate customer data?

“Some cloud providers will promote the fact that they provide data isolation or tenant isolation, but often that isolation mechanism is just one bad keystroke away from potentially comingling customer data,” Ben Nelson, vice president of security and regulatory compliance for Oracle Cloud said in an article on Forbes.com.

It is all too easy for a cloud provider who segregates customer data on one database and relies on application-level tools to accidentally update information for the wrong customer or multiple customers. If there is proper isolation between customers, meaning each cloud database is separate (although on running on the same hardware) and has proper authentication credentials it could dramatically reduce the chance of a data breach. The provider could even have a unique schema associated with your database instance to keep it even more secure. If all these proper tools are applied, it is less likely for data to be changed, manipulated or lost.

Who can access my data?

When trying to avoid a breach in data, it is crucial to know who can access the data in which you’ve stored on the cloud. You’ll want to know how the cloud provider controls and manages access to your database, from cloud vendor employees to your own staff, and which data they can access and any given time.

In the cloud model, data is transmitted between and among connected data centers and a diverse array of clients: mobile phones, desktops, laptops, tablets, etc. While the cloud service provider has no control over the security mechanisms put in place by the vendors of these devices, they can ensure that no client ever opens a hole in your firewall with any externally accessible port, communicates with any non-authenticated source, or stores cached credential information in an unencrypted format. This will stop three of the most common attack vectors and the people who could be behind the potential breach.

When evaluating prospective vendors, be sure to get a detailed description of their use of the cloud, from their customer isolation process to their protection of your data. Don’t be afraid to ask questions and if you’re not conversant in the technology yourself, consider having it appraised by an expert.

Featured

  • Security Industry Association Announces the 2026 Security Megatrends

    The Security Industry Association (SIA) has identified and forecasted the 2026 Security Megatrends, which form the basis of SIA’s signature annual Security Megatrends report defining the top 10 factors influencing both near- and long-term change in the global security industry. Read Now

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.