A Cloud Provider Decision Guide: How to Choose the Right Provider to Reduce Your Risk of a Data Breach

Nov 23, 2015 | Cloud, Data

By Kathy Killingsworth, senior director, Governance, Risk and Compliance at Concerto Cloud Services

Choosing the optimal cloud solution for your organization—and the right cloud provider to help you secure your sensitive and mission-critical data and applications—is no easy task. Public cloud offerings can’t provide the levels of security and regulatory compliance needed to protect sensitive or mission-critical information. While private clouds managed on an individual company basis can provide the necessary security and compliance, they require significant expense, staffing with specialized skill sets, certifications and attestations that few organizations can afford. For most businesses, the most secure and cost-effective approach is a private hosted cloud.

It’s important to choose a cloud provider that will collaborate with you to design, build and support a tailored solution that meets your business requirements for security, compliance, reliability and customization. But how do you determine which provider is right for your business? Half the battle is knowing what to look for and the right questions to ask.

Here are seven key criteria to help you choose the right cloud provider for your business.

1. Ability to service all your business and audit requirements. Look for a provider with a standards-based cloud environment and a security program that meet the regulatory policies and procedures with which your business must comply.

– Compliance and attestations: Data security and compliance is a formal methodology that applies the right physical, technical and administrative processes to properly ensure confidentiality, integrity and availability (CIA) of mission-critical applications. Some cloud providers claim to be compliant when just the physical data center they reside in is compliant. They may offer the components to build a compliant solution, but it’s up to you to know how to assemble them. Choose a provider that not only is up-to-date on its data center and service attestations but also can meet your regulatory compliance needs including SOC1, SOC 2, SOX, HIPAA, FIPS 140-20, PCI, CJIS, ITAR, Sarbanes-Oxley and the same capabilities as Safe Harbor (which the EU has ruled is no longer valid).

– Policies and procedures: Does the provider follow ITIL best practices for aligning IT services with the needs of your business? Do they have an Architectural Review Board and Customer Advisory Board (CAB) for changes? Make sure you understand the process to update and make maintenance changes to your solution.

2. Comprehensive contract and offering. Find out which services are part of the standard offering and which are considered add-ons that cost extra. Ideally a standard configuration should include multiple site redundancy and automatic failover to an alternate data center in the event of a disaster. Make sure to look for a provider whose standard service level agreement (SLA) guarantees 99.99% (versus 99.9%) uptime, a non-differentiated uptime agreement (i.e., an all-inclusive guarantee), and automatic notification and refunds for downtime. Also consider how each provider charges for traffic and look for one that offers pre-sales design resources (versus just a quote) and gives you visibility into usage numbers and costs.

3. Reputation and experience. What is the provider’s reputation? How long have they been in business? How much experience do they have with clients in your industry and how well do they understand your industry-specific requirements? Are they staying on top of technology and security trends and investing in new technologies?

4. Relationship and day-to-day support. It’s essential to choose a cloud provider with whom you feel comfortable working as a partner, one with a collaborative, flexible approach and whom you trust to have your best interests at heart. Private cloud providers that get involved in the initial design usually understand business goals better and find more efficient ways of deploying your cloud.

Responsive day-to-day support is another key requirement. Look for a cloud provider that offers unlimited technical resolution for operating system, SQL Server or Cloud Platform with 24/7 support, as well as integration of support plans with your current application support provider/partner. The ideal provider will have a 24/7 toll-free phone support and an online customer portal that provides a convenient, central gateway for submitting requests, reporting incidents and getting status updates and compliance documentation.

5. Expertise, training and screening of the cloud specialists. Ask about the skill set matrix and certifications of each member of the team that will be working on your cloud solution. Also, several of the key attestations require criminal, credit and other types of personnel screening. Ask each provider about its screening process for cloud specialists.

6. Flexibility and customization. How flexible is the cloud provider in providing “your cloud” the way you need it? Look for a provider that can tailor a true hybrid cloud if you need it by creating high-speed, low-latency private connections between public cloud platforms and infrastructure that resides on premise or in a co-location facility.

7. Ability to limit access by geography or provide international support. The ability to limit access just to U.S. citizens is a critical requirement for any company that does business with the Department of Defense and other Federal government agencies. And if you are operating a global company with remote sites in multiple countries, make sure the company you choose can provide international support.

On-premise data centers are not necessarily more secure than hosted private clouds. If you do choose to focus your efforts and investment in your core business and put your trust in a cloud provider to handle some or all of your business’ data, app hosting and security, be absolutely certain you entrust them to the right provider.

Kathy Killingsworth has more than 25 years of consulting and private industry experience, including IT strategy and business process management, software development, systems implementation and quality assurance. Kathy oversees operational policies and procedures for Concerto Cloud Services. She is responsible for maintaining industry best practices and ensuring adherence to all governance, regulatory and compliance protocols and certifications.

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more
Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

July 24, 2026 | ITBriefcase.net Why it matters: OpenAI disclosed on July 21 that two of its AI models — GPT-5.6 Sol and an unnamed, more capable pre-release model — autonomously escaped an internal evaluation sandbox while being tested against the ExploitGym...

read more