Five Worst Practices to Avoid in the Cloud

May 20, 2014 | Cloud, Security, Social Media

Source: Hostway

Businesses of all sizes are moving to the cloud in droves, looking for flexible, cost-effective solutions that enable their operations to run more efficiently. This move by businesses to migrate their IT services, applications and infrastructure to a cloud-based architecture will cause market revenue to reach an estimated $174.2 billion this year, up 20 percent from $145.2 billion in 2013, according to new research from IHS Research. By 2017, enterprise spending on the cloud will amount to a projected $235.1 billion, IHS predicts.

But just as there are best practices to adopt when embracing cloud computing, there are also worst practices to avoid. Let’s take a look at some of the cloud-based decisions by businesses that simply do not pay off in the long run:

1.     Jumping in too soon. It’s easy to get started in the cloud; in many cases it’s as simple as entering your credit card info. That’s great for experimenting, or even offloading some researching and development processes, but anything else requires homework – and sometimes a lot of it, especially if you’re planning to build enterprise-ready solutions in the cloud. Doing your research includes due diligence on security and regulatory requirements, understanding your company’s priorities, and knowing what you should and shouldn’t expect in terms of benefits.

2.     Failing to plan for the unexpected. Yes, that’s an oxymoron, but how many disasters are really expected events? Clearly if your business is on the coast of Florida, you have a plan that involves hurricanes. But what about everyday events that can just as easily put you out of business for a day, a week, or a month? Cloud-based solutions should be incorporated immediately into your company’s overall disaster recovery plan.

3.     Not understanding business needs before picking a vendor or hosting partner. Before selecting a partner, figure out what type of cloud makes sense for both the business problem you are trying to solve and your architectural standards. Potential questions might include the following:

– Are you looking for infrastructure-as-a-service (IaaS)? Do you want to be free to code your applications in any language?

– Does platform-as-a-service (PaaS) make sense, and can you live with writing only in the code mandated by the platform?

– Do simple software-as-a-service (SaaS) solutions adequately meet your needs? Maybe it’s a combination of these that best suits your business?

– What kind of redundancy will you need?

– Do you need virtual datacenters around the globe?

– Do you need a public cloud, private cloud or a combination of the two?

There are a lot of questions to answer before you choose a hosting partner or vendor.

4.     Not evaluating skill sets. The cloud changes everything, or at least it might seem that way if you’re counting on the same employees to deploy, monitor and maintain your cloud-based applications and infrastructure. For some, the change will be easy; however, for others there will be a big adjustment period. IT staff will not only need to understand networking and security, but also distributed computing models and SOA Web architectures. Failure to recognize these changing needs in skill set is a recipe for disaster.

5.     Using cost savings as your only justification. Moving applications to the cloud can result in significant cost savings for many companies, but cost should never be the only factor. Since it shifts IT from capital expenses to monthly subscription payments, the cloud may appear to be far more inexpensive up front. However, primary IT costs tend to remain constant, and companies that build software in the cloud may find it just as expensive or even more so to develop applications in a cloud-based environment.

The bottom line: Adopting bad cloud practices can be incredibly costly to your business. By understanding your requirements and doing your homework before signing on the dotted line, you’ll be well-positioned for success in the cloud.

 

 

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more