Cloud Providers Are Not All The Same

Oct 1, 2015 | Cloud, Inside the Briefcase

Shoretel

Featured article By Julian Box, CEO of Calligo Limited

With the maturing cloud now a de facto technology choice for most businesses, especially start-ups, the choice of which cloud solution providers (CSP) to trust is the next big decision. With so many options to choose from, and so many providers, big and small, vying for your attention, it’s important to understand what critical aspects of a CSP to look for. What makes one cloud company better than the next?

Data Protection   

The area of data protection is critical when selecting a cloud provider. There are four areas that really differentiate between providers:

1)     Where is your data stored? Best practice now points to keeping data within a jurisdiction that meets the highest levels of transparency and alignment to the soon to be seen gold standard, that of the EU new data protection law. This should include the ultimate owner of the provider.

2)     Your data should be encrypted from point of access through to where it’s stored and your backups.  This should also include multiple keys, when possible.

3)     An Escrow service in the event that your service provider is no longer operating.

4)     Guarantees of data residence, to ensure you continually meet your legal obligations.

Performance guarantees

When moving business critical systems to the cloud, select a provider that will underwrite their performance metrics, thus giving you a level of comfort that your systems will perform at least as good as they currently do, if not better.

Contracts and Service Level Agreements

This again is a critical area of the selection process when choosing your provider.  The contract should cover areas including:

·         Guarantees and proof of data residency

·         Understanding of your local data protection laws and residency requirements. Assess your provider’s ability to meet these requirements and ensure they are covered fully within the contract

·         High availability and disaster recovery capabilities of the service provider, as well as the service itself

·         How easy is it to move your data to another provider/service? The service and the contract underpinning it should include the ability to off board your data in a format of your choice

·         Interdependencies between services run by multiple providers need to be included within both the contract and service level agreement

·         Ensure an escrow-like contract covering access to a copy of your data in the event of a supplier failure and is covered contractually

Service

Service is an area that has held back cloud – many cloud service providers don’t give you access to a true helpdesk or even a helpdesk person. Instead they give you email only or access to a chat service. Cloud-based services should be an extension to your existing IT service/team. This is more akin to IT as a Service.  This leverages cloud-based technologies to truly create an agile infrastructure that’s able to meet an organisation’s IT demands. At the same time allowing the business to focus on its core areas.  Cloud through IT as a Service can, and is likely to, be made up of several different suppliers and it is here that an organisation needs to focus to ensure it gets a coherent and overarching solution from providers that are able to work together.

Organisations should be focusing on the IT service that will be delivered, rather than the underpinning cloud technology. It is a vital and very important step and one that many organisations will struggle with, yet it’s where many progressive businesses have already moved to.

In your selection of the right cloud provider, focus on data protection, performance guarantees, contracts and SLAs and Service, as outlined above to find the partner that is truly capable of freeing your business to focus on your core capabilities. Ultimately, it comes down to trust. Without a trusted cloud partner delivering true business agility, you will end up with just another “cool” piece of technology devoid of any material benefits or true value.

 

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more