Cloud Security is still the biggest concern for adoption. But, is it valid?

As the hype about the benefits of cloud computing continues to flow, an obvious question relates to why the adoption rate isn’t higher than it is projected to be over the next couple of years.

As the hype about the benefits of cloud computing continues to flow, an obvious question relates to why the adoption rate isn’t higher than it is projected to be over the next couple of years. There is a widely accepted view that the lack of control that is inherent in cloud computing creates security challenges and is a primary factor in the modest cloud adoption rate. This trend appears to be consistent across industries, including the public sector – here’s some results relating to the Federal government adoption of cloud. And, some surveys have quantified more specifically what these specific security concerns generally are. 

On our website (, we often conduct simple, quick surveys to measure the views of our visitors, generally knowledgeable decision-makers. A recent survey measured the reasons that prevented a more widespread adoption of cloud models, and the results were not only consistent with what we expected, but were also very strongly supportive of the primacy of security as the primary cloud inhibitor. This graphic summarizes the results from 606 responses taken in March 2012:



 But, although this view that “security is the problem” is the common wisdom, a growing body of experience and analyst opinion points to the fact that one might even be able to achieve greater security as cloud adoption increases. Here is one example, and another one, of pundits who make convincing arguments that security does not need to be sacrificed as some IT functions are moved to the cloud.

I think it boils down to control. IT security managers feel that they can’t control what they don’t manage – and there is certainly some truth to that. But, organizations have been outsourcing key functions for years (e.g. ADP, SalesForce, etc) without having any crippling security concerns or issues, at least for the most part. The symmetric capability to control is transparency. If you don’t have control, then you must have transparency into the operations of the people or groups that do have control – specifically, your cloud service provider. If you have sufficient visibility into the security controls that your provider has deployed, and if these controls are equivalent to what you would have in your own on-premise environment ( and cloud service providers often offer better controls than what many organizations provide), then most security concerns that are inhibiting cloud adoption might be overstated.

What’s your view? 


Written by

Sumner Blount

Sumner is a director in the security business unit at CA. Previously, he managed the…

Published in

View this topic
  • James Holland

    This is great. Hooray for Disney’s imagineers!


    become a new brand in the share market research with its accurate research. Proven
    itself always right whether market is bull or bear. Last week all paid clients
    booked handsome profit in NIFTY, BANKINIFTY & STOCKS. Now for the coming
    week we expect more correction can come in NIFTY as the IRAQ issue is getting
    more tense, If it happens more then you will see a sharp fall in all world marketNSE BSE, STOCK TIPSbecause as we know all world run on
    crude & most of the crude comes from IRAQ. So be ready for a sharp fall so
    sell will be the best strategy for next week also. Traders can make a sell
    position in NIFTY around 7600-7650 with stoploss 7750 for the target of
    7300-7200.One can also make a sell call NIFTY 50 stocks as per NIFTY levels. You
    can also take our two days free trial to check our accuracy. For further updates
    you can visit our website.



  • king lear

    testing comment functionality, please do not publish this

  • Rachel Macik

    Love the personal pic :)

    • CAHighlight

      Thank you!

  • Plutora Inc

    This is a good case study. 2.3 sec’s off a login transaction is big.

  • Michele Hudnall

    While the analysts were hyping DevOps, I posted the oversight of not including security as part of that discussion as you are highlighting here. Instead of just talking DevOps, it should be DOS (what’s old is new again :-) – DevOpsSec. As a previous AppDev person, it’s the app, who’s using it, why and where rather than the device and having the service available.

    As you rightly point, out Security should be baked into the solution.

    Nice Post and Timely!


    • CAHighlight

      Thank you for your feedback Michele. Agreed – security cannot be overlooked. Appreciate your input!

  • Mitesh

    I would love a printed copy

  • Lars Johansson

    I love the idea of BYOID! This makes me choose if I am almost anonymous (with my Hotmail Nicname) or official with identity from an official organisation. My Identity Provider will attach identity with right level of LoA according to the need of the Service provider.

    • CAHighlight

      Thank you for your comment. BYOID has tangible benefits for end users and relying parties but it also has to be weighed in the balance with potential risks and liability concerns. It will be interesting to see how BYOID plays out in the enterprise.