The decline in cloud computing privacy and security protections has gradually picked up pace over the last two years. With the advent of the novel coronavirus, COVID-19, the early months of this year have accelerated that pace. Businesses are now learning hard lessons about the reliability and responsibility of their cloud providers when it comes to privacy and security protections.
Dont get me wrong. Almost every cloud provider can produce truly impressive marketing materials and, even, contractual commitments with regard to privacy and security. But when the rubber meets the road, very few providers are actually willing to assume any real liability if they fail to comply with those commitments. During audits, regulators in financial services and healthcare have made clear security/privacy protections without material liability results in illusory protection and is not consistent with exercising reasonable care in the protection of sensitive data.
A recent example will highlight the problem. A well-known cloud provider, through its own gross negligence, wiped out the data, both production and backup, for a number of their customers. The entire database for each customer was rendered unrecoverable. The customers were left having to engage in the laborious, time-consuming, and extremely expensive task of having to reconstruct those records by hand. In wiping out the data, the cloud provider breached its customer contract in several ways, but, as the provider was quick to point out, its liability for resulting damages was strictly limited in its standard agreement, leaving the customer with no real remedy.
The foregoing example points up one of the most substantial problems and trends we are seeing in cloud engagements: vendors who appear to offer outstanding security and privacy protections, but then limit their liability for violation of those protections, even if by gross negligence, to a trivial amount. In fact, two very well-known cloud providers attempt to limit their liability for every breach of contract, including data breach, to zero damages in their form agreements. They accept no responsibility whatsoever for their failures.
Another alarming trend is the very recent approach used by some cloud providers to absolve themselves of all liability (i.e., zero damages) for their third party hosting vendors. That is, the cloud provider can subcontract the entire operation of its data center to a third party and thereby avoid any liability if that third party suffers a data breach, incurs substantial down-time, fails to have adequate disaster recovery/business continuity procedures and plans, etc. Worse yet, if that happens, the customer is not permitted to terminate its contract with the original cloud provider. The customer, having had its data compromised, must continue to pay for a faulty service through the entire remainder of the term of its contract with the original cloud provider.
To complement their refusal to assume material liability for their obligations, a growing number of cloud providers are taking the unprecedented step of offering their services, even those involving hundreds of thousands of dollars in fees, as entirely as-is, with no warranties or performance obligations at all. The customer is, in essence, signing on to pay for a service that need never work, never be available, be entirely insecure, etc. If pressed on this point, the providers seem genuinely shocked that a customer might want or need actual performance obligations.
Yet another change in cloud contracting is the multi-national nature of many providers. This means a business highly sensitive data may, without its knowledge or consent, be transmitted, stored, and accessed anywhere in the world, including locations that have little or no laws respecting the protection of data. This creates a very substantial concern for regulated entities like healthcare providers and financial institutions.
Finally, there are the most recent risks created by COVID. These include the use of minimal, skeleton onsite staffing at hosting locations and the authorization of remaining vendor personnel to work remotely, frequently from unsecure locations or using public Wi-Fi. It is not uncommon for remote workers to access sensitive systems and data using shared home computers or computers in rooms with other individuals present who can view the workers screen. In some instances, sensitive information is printed via unsecure printers and the hardcopies not disposed of in a secure manner.
COVID also creates the perfect storm of businesses under duress because of the limited resources available to them to continue to conduct business and the siren song of cloud providers. Under these circumstances, many businesses are choosing to take the plunge and move more operations to the cloud. Unfortunately, moving those operations, particularly if they are critical or involve highly sensitive information, could present very substantial risk. If something goes wrong, the business may be left with little or no real remedy.
What, then, is a business to do to protect themselves? The key is in truly understanding the risks presented by a potential cloud engagement, including how those risk are (or are not) mitigated in the proposed contract. In some cases, the risks simply cannot be mitigated, but must be accepted. Better, however, to accept those risks knowingly, than to discover them only after an adverse event has occurred (e.g., performance failure, security breach, misuse of data, etc.). In other cases, identifying the risks early and having a clear conversation with the vendor about them, may result in at least some ability to mitigate those risks. The earlier in the potential engagement to have that discussion, the better. Waiting until the sale is done, will leave the vendor with little or no interest in negotiating. If, however, they believe they may lose a sale, they will be more inclined to negotiate.
Unfortunately, all too often, businesses become fixated on a particular cloud provider and leave themselves no room to find an alternate if appropriate protections cannot be negotiated. This is the single greatest errors we see in negotiating cloud agreements. It is not unusual for an initial negotiation call to begin with the customers business person stating that we need to get this solution in place by next month or we will be in great trouble. Saying something like that will leave the customer with virtually no negotiating ability. As noted above, the vendor must believe they can lose the sale before reasonable terms may be capable of negotiation. Dont give up that leverage.
It bears point out that not all cloud providers are created equal. While, as noted above, a growing number offer little more than illusory protection to their customers, there remain a large number of providers that truly get it. They value their customers, listen to their concerns, and offer solutions and contract terms to address those concerns. A case in point: while many cloud providers are scrambling to find ways to absolve themselves of any real responsibility in their contracts, one of the most well-known providers offers unlimited liability for data breaches in their standard, unmodified customer agreement. Why do they do that? Because they know it distinguishes them from the rest of the pack. They know data is one of the most important assets of their customers and want to show they take their obligation to protect that data seriously.
COVID-19 has forced many businesses to move their operations including those with highly sensitive information to the #cloud. #cybersecurity #respectdata Click to Tweet
In summary, cloud computing can be cost-effective and of tremendous benefit to most businesses. Know the risks, however, before entering into a new engagement. Ask what liability the vendor really has, particularly for critical performance failures and data breaches. Check disclaimers of liabilities and warranties carefully to determine if they undermine or, as likely, render largely useless security and privacy protections. Nail down where your data will be hosted and accessed. Try to identify vendors that truly do appreciate their customers and make a real commitment to stand behind the contractual protections they offer. Finally, never buy into the common vendor ploy of saying trust us, weve never had a failure or a breach of security, you dont need those contract protections.
See the article here:
COVID and Cloud Computing: The Perfect Storm - CPO Magazine
- Roundup Of Cloud Computing Forecasts, 2017 - Forbes [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- RCom arm in tie-up for cloud computing - Moneycontrol.com [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- How Do You Define Cloud Computing? - Data Center Knowledge [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- 5 Cloud Computing Stocks to Buy - TheStreet.com [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Cloud Computing Continues to Influence HPC - insideHPC [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Red Hat's New Products Centered Around Cloud Computing, Containers - Virtualization Review [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Adobe bets big on cloud computing for marketing, creative professionals - Livemint [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Verizon sells cloud services to IBM in 'unique cooperation between ... - Cloud Tech [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- How Cloud Computing Is Turning the Tide on Heart Attacks - Fortune [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Hospital CIOs see benefits of healthcare cloud computing - TechTarget [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Trends In Cloud Computing - Business Solutions Magazine [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- A deeper dive into cloud security as a service: Advantages and issues - Cloud Tech [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- OpenText buys cloud computing firm for US$103 million - TheRecord.com [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Belfast IT firm celebrates cloud computing success in 57 countries ... - Belfast Telegraph [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Meet The Cloud Wars Top 10: The World's Most-Powerful Cloud-Computing Vendors - Forbes [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- How to approach cloud computing and cyber security in 2017 - Information Age [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- CFOs have discovered the big stick of cloud computing - InfoWorld [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Belmont Stakes Odds 2017: Latest Vegas Betting Lines Before Post Positions Draw - Bleacher Report [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Cloudistics Announces New Cloud Computing Program That Enables High Margin Reoccurring Revenue Models for ... - Marketwired (press release) [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- CloudCheckr, cloud computing company expects rapid growth in Rochester - WXXI News [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- IBM Losing Facebook's WhatsApp as Cloud Customer, says CNBC - Barron's [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- What My Father Taught Me About Cloud Computing - Virtualization Review [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Workday Phenomenon Goes Global As Cloud Computing Goes Mainstream - Forbes [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - JD Supra (press release) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- 3 Things You Should Know About Cloud Computing Right Now - Fortune [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Learning in the Sky: Collaborative Robots Embrace Cloud Computing - Machine Design [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Best Practices To Manage Your Hybrid Cloud - Forbes [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Here's how venture capitalists are thinking about cloud computing companies and technologies - GeekWire [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Amazon is helping veterans find jobs in cloud computing - Marketplace - Marketplace.org [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - Lexology (registration) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Growing Patent Claim Risks in Cloud Computing - Lexology (registration) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- The benefits of cloud computing, Rust 1.18, and intelligent tracking prevention in WebKit SD Times news digest ... - SDTimes.com [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Edge Computing Is New Cloud Computing Tech Investors Should Track - GuruFocus.com [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Real Estate Weekly: Digital Realty Becomes A Cloud Computing Giant - Seeking Alpha [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Virtualization admin? Pivot -- pivot now -- to a cloud computing career - TechTarget [Last Updated On: June 10th, 2017] [Originally Added On: June 10th, 2017]
- Why isn't Cloud Computing in the 2017 Belmont Stakes? - FanSided [Last Updated On: June 11th, 2017] [Originally Added On: June 11th, 2017]
- Cloud Computing Companies Move Into Medical Diagnosis (GOOG, IBM) - Investopedia [Last Updated On: June 11th, 2017] [Originally Added On: June 11th, 2017]
- China's cloud industry moving to new era with emergence of unicorns - TechNode (blog) [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Terry Crews Is On Crackdown 3 Trailer, No Cloud Computing For Single Player - EconoTimes [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- The Risks and Perquisites of Cloud Computing - DATAQUEST [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Alibaba Cloud announces launch of data centres in India and Indonesia - Cloud Tech [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Indonesia banks have yet to implement cloud computing - Jakarta Post [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- 'Sweden is heaven for cloud computing': Amazon Nordic chief - The ... - The Local Sweden [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Amazon.com to open second government cloud-computing region ... - The Seattle Times [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Shadow raises $57 million for its cloud computing service for ... - TechCrunch [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Amazon Still Leads Cloud Rankings, But Competition Is Coming On Strong - Fortune [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 | Air ... - Air Cargo World (registration) [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 - Air Cargo World (registration) [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Pressing Tech Issue: Enterprise Software Vs. Cloud Computing? - Credit Union Times [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- 7 Tips for Securely Moving Data to the Cloud - Government Technology (blog) [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Chinese tech giant Alibaba joins key open-source cloud computing foundation - GeekWire [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Microsoft Could Surpass Amazon in Cloud Computing This Year (AMZN, MSFT) - Investopedia [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- GDS Holdings Limited (GDS) Announces Strategic Partnership with Tencent Cloud - StreetInsider.com [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Cloud first - Philippine Star [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Three Considerations for Reducing Risk in Cloud Computing - CIOReview [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Cloud Computing and Digital Divide 2.0 - CircleID - CircleID [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Microsoft will ride artificial intelligence, cloud computing to higher ... - CNBC [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- Update - Fox Business [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Report affirms continued cloud spend for US businesses in 2017 - Cloud Tech [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Catching up with an interconnected federal cloud - GCN.com [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- 2nd Update - Fox Business [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Cisco adapts to the rise of cloud computing - The Economist [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Amazon accuses Walmart of bullying in cloud computing clash - BBC News [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Companies plan to spend more on cloud computing services this year, higher prices among drivers: Clutch - Canadian Underwriter [Last Updated On: June 23rd, 2017] [Originally Added On: June 23rd, 2017]
- Survey: businesses ramp up spending on cloud computing DC ... - DC Velocity [Last Updated On: June 24th, 2017] [Originally Added On: June 24th, 2017]
- Morgan Stanley: Cloud computing is at 'an inflection point' but how big will it get? - GeekWire [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- How the cloud has changed education and training - TNW [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Cloud computing key to 4th industrial revolution - News VietNamNet - VietNamNet Bridge [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Lady Eli, Cloud Computing Among Workers for Brown - BloodHorse.com (press release) (registration) (blog) [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Microsoft signs cloud-computing partnership with Box - The Seattle Times [Last Updated On: June 27th, 2017] [Originally Added On: June 27th, 2017]
- Microsoft Signs Cloud Computing Partnership with Box - CIO Today [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- US action on Microsoft email case could devastate cloud computing - Irish Times [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Cloud computing challenges today: Planning, process and people - TechTarget [Last Updated On: July 2nd, 2017] [Originally Added On: July 2nd, 2017]
- Five podcasts to catch up on the latest trends in cloud computing - TechTarget [Last Updated On: July 2nd, 2017] [Originally Added On: July 2nd, 2017]
- Microsoft reportedly set to lay off thousands as part of massive sales reorganization - GeekWire [Last Updated On: July 3rd, 2017] [Originally Added On: July 3rd, 2017]
- VMware to surge more than 20 percent because the Amazon cloud ... - CNBC [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Google Unveils Custom Hardware Chip for Cloud - Investopedia [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Cloud Computing Confirmed for Travers | TDN | Thoroughbred Daily ... - Thoroughbred Daily News [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Why 2017 Is The Year To Understand Cloud Computing - Nasdaq [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Biz Cloud Computing - Four States Homepage [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]