Driven by the need to collaborate across remote work environments, COVID-19 has sped up the adoption of cloud services by many government agencies. Yet, questions about security remain.
For a variety of reasons, government agencies often lag years behind their private sector counterparts in cloud adoption. A common talking point among program managers is that agency figures have previously been tentative about moving to the cloud because they don’t understand cybersecurity, are not cloud experts, and don’t want to have to deal with it themselves. Their trepidation may be well founded however, as even private sector security leaders struggle with the intricacies of cloud migration. When surveyed, only 10% of CISOs reported that they fully understood the shared responsibility model, a common security framework used by cloud providers, while 82% have experienced security events due to confusion in the model.
But with cloud adoption taking on a new imperative, how comfortable an agency feels about that migration has become irrelevant. They must adjust and adapt. The question is, how can they do so securely and in a manageable way? Let’s take a look.
Assess cloud provider risk
When migrating to the cloud, government agencies must understand the risk associated with the vendors they come to rely on to enable their cloud journey. In the past, gaining visibility into these risks has been a challenge.
Before signing a contract, many agencies have traditionally relied on point-in-time security assessment practices that don’t account for evolving risk. These assessments also use a “one-size-fits-all” mentality that fails to consider the variances between different vendors. Security teams end up spending the same amount of time and money assessing every third-party vendor — using the same boilerplate questionnaires — no matter their size or risk potential. It’s a vigorous and lengthy process that can undercut cloud adoption.
But agencies can streamline their assessments and optimize the cloud vendor onboarding process by using Bitsight for Third-Party Risk Management. Unlike cumbersome and cookie-cutter assessment practices that fail to scale to each third-party and only provide a snapshot, time-bound view of a cloud provider’s security posture, this solution offers immediate visibility into cyber risks within a potential vendor’s ecosystem. With these data-driven insights, agencies can reduce onboarding time and costs — and accelerate their cloud migration process.