* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* How to Migrate to the Cloud---and Strengthen Cybersecurity

# How to Migrate to the Cloud---and Strengthen Cybersecurity

![How to Migrate to the Cloud—and Strengthen Cybersecurity](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2020/02/how-to-migrate-to-the-cloud-and-strengthen-cybersecurity.jpg)  
**By [Steffen Siguda](https://www.paloaltonetworks.com/perspectives/author/steffen-siguda/ "Posts by Steffen Siguda")** | **7 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=How to Migrate to the Cloud—and Strengthen Cybersecurity\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fhow-to-migrate-to-the-cloud-and-strengthen-cybersecurity%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/how-to-migrate-to-the-cloud-and-strengthen-cybersecurity/?pdf=download&lg=en&_wpnonce=b83f8e29b4 "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/panw_master-twitter-profile-pic-400x400-1.png)  
  Steffen is the Corporate Information Security Officer at OSRAM group and Data Protection Officer for OSRAM GmbH...

[Learn more](https://www.paloaltonetworks.com/perspectives/author/steffen-siguda/)

## IN THIS ARTICLE

Organizations are putting more workloads into public cloud, including business-critical applications. The worldwide public cloud services market is projected to grow at a compound annual rate of nearly 22%, reaching $277 billion by 2021, and 41% of enterprise workloads are expected to be running on public cloud platforms.

But what about the idea of an organization outsourcing *all* of its applications---together with the confidential data stored in them---to one or more cloud providers?

The mere suggestion of such a possibility may cause IT security and data protection experts to hyperventilate. Even now, 90% of cybersecurity professionals say they are concerned about cloud security, particularly data loss and leakage, threats to data privacy and breaches of confidentiality.

The reality is that a wholesale migration to the public cloud is not only feasible; it can be accomplished without sacrificing security. Moreover, switching to a cloud environment can mean a security *improvement* in some areas.

## Getting Prepared

The key, as it is with any important IT initiative, is [highly intensive preparation](https://www.paloaltonetworks.com/cybersecurity-perspectives/4-proven-steps-for-successful-cloud-transformation/?doing_wp_cron=1588625478.0181429386138916015625&ts=markdown), with an acute awareness of the potential stumbling blocks. A successful cloud migration revolves around understanding two points:

1. Which services is the company operating itself today, and in what form?
2. How can these functions and applications be covered securely in a future cloud environment?

Answering these questions early in the process is vital to any cloud migration, whether you are moving specific workloads and applications, or completely giving up your own data center operations and moving everything to the cloud.

## Negotiating the SLA

A critical step is negotiating the service level agreement (SLA) with the cloud provider. The SLA should guarantee availability (as confidentiality and integrity are mainly in focus of the company's application setup). In fact, a cloud provider should be able to ensure a level of availability that is better than you would likely be able to achieve in your own data center.

Why better? Because it is almost impossible---from a cost perspective---for any individual company to operate at the same level as a highly specialized cloud infrastructure-as-a-service provider. The same goes for physical security, emergency power supply, fire extinguisher systems, monitoring cameras, fences, access control systems.

These components are typically state-of-the-art for cloud providers and are continuously being updated. Very few individual companies can afford this. The missing element is the scale effect from which a cloud provider benefits.

## Defining Control

Another vital aspect of preparation is taking the proper inventory ahead of the cloud migration. In addition to IT infrastructure and security teams, it is necessary to involve the teams responsible for running individual applications, such as SAP or Microsoft Exchange. Their security needs should be combined with the requirements of the other IT teams.

Make sure your teams are not viewing key functions, such as data encryption, as a mere matter of course simply because they were treated that way in the company's own data center. Proper coordination and planning across IT and security disciplines demand that every aspect of the migration feeds into the contractual documents with the cloud provider.

During this process, applications managers need to accept that they will have less control but, in return, greater reliability. By the same token, your teams need to build confidence in the provider's management of updates and changes, with the knowledge that, if there is an issue, the previous operating status can be quickly recovered by installing a snapshot.

Time to recovery is another point that should be captured in the SLA, along with the nature and timing of the notification by the cloud provider, in terms of drawing attention to a potential problem and simultaneously offering a proposed solution.

## Timing the Migration

Cloud providers typically commission external auditors once a year to carry out an accurate check of vulnerabilities. The results of these audits are relevant for the customer's auditors. These reports are calibrated to the calendar year and are generally available in the winter. If your fiscal year ends in September, the report arrives too late.

For that reason, this is another point to consider in contract negotiations. If the report cycles do not fit with your reporting obligations, then interim reports are required. If these are requested after the contract has been concluded, you can incur costs running into six figures. Cloud providers that supply these audit reports on a quarterly basis are ideal. Otherwise, a compromise should be negotiated before signing the contract.

## Deploying Security Technology

With public cloud environments, the concept of protection alters fundamentally. With on-premises infrastructure, IT might have tried to make data centers as secure as possible with proverbial walls and ditches. This approach is no longer feasible due to access from the outside via mobile endpoint devices by workers, partners, Internet of Things (IoT), etc. Cloud migration is the purest form of this change since practically all access comes from the outside.

Given that paradigm shift, the challenge is to move the security mechanisms closer to the applications. Instead of surrounding the whole network with one wall, there are many small walls around the SAP system, OLTP system, CRM, web server, e-commerce server, etc. Security efforts are focused on the points where the critical data is located. This is all the more relevant given the reality that endpoint devices cannot be armed for complete defense against malware infections.

Especially on cloud services (SaaS), take a close look at which parts of the service are really required and either deactivate or correctly configure these services to avoid having unknown backdoor access through "forgotten" service details.

## Handling Incident Response

The handling of security incidents is critical. Clarification is needed as to how the provider will act in case of a successful attack by criminal hackers. If customer data worthy of protection is flowing to the outside for a number of hours due to the lack of capacity to intervene, that can lead to major problems, not the least of which is running afoul of the European Union's General Data Protection Regulation (GDPR).

In this case, it may be better to purchase a self-administered firewall and run it in the cloud provider's data center (usually as a virtual appliance). All data flows through this firewall to the applications concerned, including traffic from internal networks. If there is a successful attack, the cloud customer can immediately terminate dangerous data flow using this firewall, without a ticket and without any delay.

Since every cloud provider offers its own firewall systems, it is likely that only a few potential customers would have this requirement. However, many companies may find that control, monitoring and insights may be worth an additional expense. Similar insights into data flows can potentially be purchased via the cloud provider or a managed security services provider. These potential costs must be factored into the budget.

## Doing What's Right

Cybersecurity professionals are paid to worry about cybersecurity. So, naturally, they will be concerned about cloud security, now and into the future. As a business leader you should not let these concerns stop you from doing what you think is right for the business.

In fact, you should use their concerns to inspire and incentivize your teams to take the proper precautions and preparations in migrating applications to the cloud. Cybersecurity doesn't have to be a roadblock to the cloud. In fact, when done properly, it can be an on-ramp.

*** ** * ** ***

*Steffen Siguda is Corporate InfoSec Officer and Data Protection Officer at OSRAM Licht AG.*

* [Business Transformation](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=business-transformation)
* [Staying Ahead of Evolving Threats](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=staying-ahead-of-evolving-threats)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**Cybersecurity in 2026: What we predicted, what surprised us, and what's next**

At Palo Alto Networks, we are privileged to sit at the intersection of cybe...

[Haider Pasha](https://www.paloaltonetworks.com/perspectives/author/haider-pasha/ "Posts by Haider Pasha")
[](https://www.paloaltonetworks.com/perspectives/cybersecurity-in-2026-what-we-predicted-what-surprised-us-and-whats-next/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://www.paloaltonetworks.com/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://www.paloaltonetworks.com/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/RFP-Bottleneck-featured.jpg) BLOG

### AI

**From Weeks to Minutes: How We Applied an AI-First Transformation to the RFP Bottleneck**

Understanding why manual efforts burn hundreds of hours and are bottlenecki...

[Sandeep Uttamchandani](https://www.paloaltonetworks.com/perspectives/author/sandeep-uttamchandani/ "Posts by Sandeep Uttamchandani")
[](https://www.paloaltonetworks.com/perspectives/from-weeks-to-minutes-how-we-applied-an-ai-first-transformation-to-the-rfp-bottleneck/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
