Cloud Security Strategy
Few companies exist in order to be good at cloud security. Yours most likely sells products, provides services or manufactures something, and cloud security is one of the things that has to work for that to continue. A strategy written without that context ends up as a list of controls with no argument for why those controls and not others.
There is also no version of this where the risk reaches zero. You can spend as much money and effort on cloud security as you want and there will still be residual risk, so the question is where the next investment reduces the most risk, and whether the business is comfortable with what is left after it.
We start from your business strategy, your technology goals and your risk appetite, and work forward from there.
What the engagement includes
- Workshops and meetings to understand your business and IT strategy
- A scored baseline of your current maturity, using our Cloud Program Maturity Assessment
- Presenting the findings so far at a high level, so that the direction can be corrected before the strategy is written
- Calculating where risk can be reduced most effectively, looking at cost, complexity and the effort required
- Writing the Cloud Security Strategy
- Presenting the current status and the proposed roadmap to the business
What you get
- A cloud security strategy written against your business strategy, with the reasoning behind each decision
- A prioritized roadmap, ordered by where the reduction in risk is largest for the effort involved
- The maturity baseline the strategy was built on, so that progress can be measured against it later
- An executive presentation and a working session with the teams involved