Cloud Providers Are Not All The Same

Oct 1, 2015 | Cloud, Inside the Briefcase

Shoretel

Featured article By Julian Box, CEO of Calligo Limited

With the maturing cloud now a de facto technology choice for most businesses, especially start-ups, the choice of which cloud solution providers (CSP) to trust is the next big decision. With so many options to choose from, and so many providers, big and small, vying for your attention, it’s important to understand what critical aspects of a CSP to look for. What makes one cloud company better than the next?

Data Protection   

The area of data protection is critical when selecting a cloud provider. There are four areas that really differentiate between providers:

1)     Where is your data stored? Best practice now points to keeping data within a jurisdiction that meets the highest levels of transparency and alignment to the soon to be seen gold standard, that of the EU new data protection law. This should include the ultimate owner of the provider.

2)     Your data should be encrypted from point of access through to where it’s stored and your backups.  This should also include multiple keys, when possible.

3)     An Escrow service in the event that your service provider is no longer operating.

4)     Guarantees of data residence, to ensure you continually meet your legal obligations.

Performance guarantees

When moving business critical systems to the cloud, select a provider that will underwrite their performance metrics, thus giving you a level of comfort that your systems will perform at least as good as they currently do, if not better.

Contracts and Service Level Agreements

This again is a critical area of the selection process when choosing your provider.  The contract should cover areas including:

·         Guarantees and proof of data residency

·         Understanding of your local data protection laws and residency requirements. Assess your provider’s ability to meet these requirements and ensure they are covered fully within the contract

·         High availability and disaster recovery capabilities of the service provider, as well as the service itself

·         How easy is it to move your data to another provider/service? The service and the contract underpinning it should include the ability to off board your data in a format of your choice

·         Interdependencies between services run by multiple providers need to be included within both the contract and service level agreement

·         Ensure an escrow-like contract covering access to a copy of your data in the event of a supplier failure and is covered contractually

Service

Service is an area that has held back cloud – many cloud service providers don’t give you access to a true helpdesk or even a helpdesk person. Instead they give you email only or access to a chat service. Cloud-based services should be an extension to your existing IT service/team. This is more akin to IT as a Service.  This leverages cloud-based technologies to truly create an agile infrastructure that’s able to meet an organisation’s IT demands. At the same time allowing the business to focus on its core areas.  Cloud through IT as a Service can, and is likely to, be made up of several different suppliers and it is here that an organisation needs to focus to ensure it gets a coherent and overarching solution from providers that are able to work together.

Organisations should be focusing on the IT service that will be delivered, rather than the underpinning cloud technology. It is a vital and very important step and one that many organisations will struggle with, yet it’s where many progressive businesses have already moved to.

In your selection of the right cloud provider, focus on data protection, performance guarantees, contracts and SLAs and Service, as outlined above to find the partner that is truly capable of freeing your business to focus on your core capabilities. Ultimately, it comes down to trust. Without a trusted cloud partner delivering true business agility, you will end up with just another “cool” piece of technology devoid of any material benefits or true value.

 

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more
Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

July 24, 2026 | ITBriefcase.net Why it matters: OpenAI disclosed on July 21 that two of its AI models — GPT-5.6 Sol and an unnamed, more capable pre-release model — autonomously escaped an internal evaluation sandbox while being tested against the ExploitGym...

read more