IT Briefcase Exclusive Interview: State of the Cloud 2023

Mar 8, 2023 | App Modernization, Cloud, Data, Fresh Ink, Mobile, Privacy, Security, Social Media

Cloud

In this interview, Brian Adler, senior director of cloud market strategy at Flexera, highlights how businesses can keep pace with cloud trends.

Q. How is cloud usage evolving in 2022?

The post-pandemic world is coming into focus, as are the implications for cloud usage. Flexera just released its 11th annual report on cloud usage—the Flexera 2022 State of the Cloud Report—with insights into how global cloud decision-makers and users are relying on cloud. A few trends in particular stood out:

Cloud costs are continuing to grow. Wasted cloud spend remains high. This is driving the need for FinOps—cloud financial management—teams to help keep costs downs. As organizations refocus their efforts on usage and cost management, more are embracing FinOps approaches, even if they don’t yet call it “FinOps.”

When it comes to reliance on public clouds, Amazon Web Services (AWS), Azure, and Google Cloud Platform are the top three cloud providers. But a noteworthy shift is taking place; in several instances in the 2022 survey, Microsoft Azure usage met or exceeded that of AWS, while other cloud providers haven’t shown much growth.

Another shift this year is in tooling. Third-party tools (used for orchestration and container management, for example) appear to be losing ground to native tooling—tooling available from the cloud providers themselves. This might be an indication that provider-specific tools are enticing, thanks to their available features and their relative ease of use.

The final major finding this year is in the growth of cloud usage by small-to-midsized businesses (SMBs). Cloud spend by SMBs has grown significantly over the past year (with 53% of SMBs spending more than $1.2 million/annually, up from 38% reported last year).

Q. What are currently some of the biggest challenges in cloud?

We’re seeing a cross-section of cloud challenges. Across all organizations, security, the lack of resources or expertise, and how to manage cloud spend are the top three challenges. There are underlying and evolving issues that perpetually make these issues demanding.

Perhaps it isn’t surprising that security has been the #1 challenge for 10 out of the 11 Flexera State of the Cloud reports. Yet, while security is a major concern, it isn’t preventing new approaches to reliance on public cloud. Something interesting we found this year is that organizations are showing increasing confidence in cloud providers’ security tools and processes. Specifically, in the past, some organizations were hesitant to put certain types of data in public clouds. This year’s report shows that more than half of respondents are considering moving at least some of their sensitive consumer data—such as personally identifiable information (PII) and protected health information (PHI)—or corporate financial data to the cloud.

The issue of lack of resources/expertise is particularly acute in a few areas. This is the case for organizations that currently have light usage of cloud. Also, containers are moving into the mainstream, but the lack of internal staff with expertise in containers is the top impediment to implementation.

When it comes to managing cloud spend, there’s clearly plenty of room for improvement and better cloud cost optimization. Almost a third (32%) of cloud spend is estimated to be wasted. Meanwhile, organizations are over their budgets for cloud by an average of 13%—all while cloud spend is predicted to grow by 29% in the coming 12 months. Getting control of this is essential not only for the budget, but to support reinvestment in innovation.

Other common challenges include governance, managing software licenses, compliance, how to balance responsibilities between central cloud teams and business units, cloud migration, and how to manage multi-cloud.

Q. What’s missing from many cloud strategies these days?

A few things.One way that organizations can accelerate cloud adoption is by centralizing expertise, such as through a central cloud team or a cloud center of excellence (CCOE). The purpose of these teams is to accelerate cloud adoption by centralizing expertise while reducing costs and risk. The need for centralization is particularly acute in enterprises (public or private sector organizations with 1,000 or more employees); due to their larger size and extensive application portfolios, enterprises have a greater need for centralization than do SMBs. Organizations can also rely on software asset management (SAM) and vendor management teams. We’re seeing that reliance on CCOEs and central cloud teams is growing (for 74% of enterprises and 64% of SMBs), but the presence of one isn’t yet a given.

A closer eye on cloud cost management is necessary. FinOps teams can help move these efforts forward, whether by implementing automated policies for cloud governance, finding savings opportunities with cloud provider discounts, and by combining processes (including the unit economics model, the preferred way to perform a cost analysis) to analyze and reduce cloud costs.

Finally, I’d say that training is an important and necessary part of cloud strategy. Knowing how cloud technologies work is the best way of accurately aligning business needs with the technologies themselves. As technologies gain traction, as was the case with containerization technologies this year, appropriate training is necessary to be able to deploy them effectively. Yet we’re seeing that lack of internal resources with expertise is a top impediment to actually expanding the use of containers.

Overall, it’s important for organizations to understand current cloud computing trends in order to guide the digital business decision-making processes, vendor and technology selection, cost forecasting, and investment strategies.

 

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more