* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* The Path to a Successful Cloud Transformation

# The Path to a Successful Cloud Transformation

![The Path to a Successful Cloud Transformation](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2021/06/the-path-to-a-successful-cloud-transformation.jpg)  
**By [Mike Towers](https://www.paloaltonetworks.com/perspectives/author/mike-towers/ "Posts by Mike Towers")** | **8 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=The Path to a Successful Cloud Transformation\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fthe-path-to-a-successful-cloud-transformation%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/the-path-to-a-successful-cloud-transformation/?pdf=download&lg=en&_wpnonce=b83f8e29b4 "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/panw_master-twitter-profile-pic-400x400-1.png)  
  Mike Towers is the former Chief Information Security Officer at Takeda Pharmeceuticals International....

[Learn more](https://www.paloaltonetworks.com/perspectives/author/mike-towers/)

## IN THIS ARTICLE

I first became a Chief Information Security Officer (CISO) in late 2008. Almost immediately, I began to ruffle feathers and raise eyebrows because I was a strong advocate that the cloud was the direction in which we all needed to move. My reasoning was that security in the cloud was more advanced, reliable and resilient than anything we could do internally. The cloud, even at that time, offered the best way to collaborate safely.

Today, more than a decade later, in the midst of a global pandemic that has put enormous pressure on organizations of all types and sizes, I believe more than ever that the cloud is still the best way to go. In fact, I would argue that there are maybe 10 companies in the world that can secure and run their data centers as well as the large hyperscale cloud providers such as Amazon Web Services, Google and Microsoft.

In many organizations, the skills and resources necessary to empower digital transformation and run IT and security on-premises are not aligned with targeted business outcomes.

For example, in the pharmaceutical industry, we are building new channels for direct engagement with healthcare professionals, yet must operate within rapidly changing data privacy and regulatory parameters. Companies that try this with a do-it-yourself approaches at scale are hard-pressed to match the capabilities of the cloud providers. A classic example is encryption-at-rest, which is a constant data center frustration. Yet, cloud providers have shown that they have the scale, platform and resources to do it, and do it well.

The cloud is no longer a choice---it's a destination we have to get to. The question is not whether to embrace the cloud; but how can business and technology leaders choose the right path and timeline for their organizations.

## Security Is About Trust

The most important advice I can share with my fellow CISOs is that we must all challenge ourselves to do a better job of thinking about the business impact of our decisions. For a long time, we've been lobbying for a seat in the boardroom and in the C-suite. Now that we have it, we have to start thinking and acting like business leaders.

Our job is not about just protecting against breaches; it is about making our organizations more successful, responsive and resilient. The cloud journey provides a perfect opportunity to do this. I remember listening to a keynote speaker at a conference a couple of years ago, and her main message resonated strongly with me: "Security used to be about protection," she said. "Now it is about trust."

I take this to heart when I look at the role of cloud transformation in our organization, which is a leader in the pharmaceuticals industry. We are a values-driven company, with the goal of always making decisions based on patient, trust, reputation and business---in that order. Patients have enough to worry about without having to be concerned if their digital experience is safe and secure.

For a long time, pharmaceutical companies only dealt with doctors, and even then it was not a deep relationship. But our model has changed for the better. The entire industry is focused on long-term health management. We want to establish long-term relationships with physicians and patients, and across our entire ecosystem and supply chain. Instead of a work force on the order of 70,000, we are looking at a potential patient population in the millions.

For that level of scale, size and trust, you have to use the cloud. Our business and the overall business climate move too quickly for anything but the cloud. We can't wait a week, or even a day, for a new server. We need cloud agility, scale and resilience. In our organization, we have gone from pockets of cloud to a board-level, CEO-sponsored full-on initiative to move virtually everything to the cloud in the next three years.

## Taking the Cloud Journey

I have been a cloud advocate for a long time in my career as a CISO. Fortunately, I have been in the same industry, which I love, for that entire time, but I have also worked in different companies. I am aware of both the challenges in cloud transformation, as well as the opportunities. Here is some guidance I can offer from my own experience and as an active participant in the broader cybersecurity community.

1. **Tread lightly**. Cloud transformation is a journey. Don't expect to go home over the weekend and come back on Monday fully formed in the cloud. Start with areas that can deliver immediate and clear benefits, such as backup, recovery and software development. Migrate more directly as you get more experience.
2. **Don't underestimate the challenge of living in both worlds**. Even for early adopters and companies seeking a cloud-first or cloud-only strategy, there will often be a need to reach back into the on-premises world for data. There are likely to be interdependencies with legacy applications, technologies and processes that are not transferable.
3. **Consider the depth and breadth of your ecosystem and supply chains**. Most business models are no longer focused solely on internal operations. We are all dealing with external ecosystems. In the case of pharmaceuticals, it extends to patients, physicians, payers and beyond. The cloud can help you scale as needed, which is essential because your external ecosystem is typically even larger than your workforce.
4. **Embrace security automation.** The cloud is about server builds, capacity extension, elastic infrastructure. In the past, we used to do many of those things manually. The value of the cloud is speed and agility, largely devolved from automation. In the shared security model, make sure you are automating your portion of the security responsibility, and don't just rely on the public cloud provider's automation. In the rush for speed, developers or line of business managers might want to avoid security. Don't let that happen. Build security automation into your processes and models.
5. **Build up new sets of skills and processes.** In the cloud era, software development is also in a period of rapid transformation. With cloud development, microservices, containers, Kubernetes orchestration and API security, many companies and IT/security teams are finding themselves back in the application development business. Organizations must have in-house skills in areas such as API security, DevOps and SecDevOps.
6. **Modernize hiring, training and talent acquisition.** Stop looking for the 10-to-15-year security pro. They barely exist. Change your talent acquisition and retention processes to focus on fresher, more agile talent that has experience in cloud, DevOps, API security and other areas that are likely to hasten your cloud transformation. Manage your teams to keep them at your company, using flexible approaches, high levels of automation, support for remote work and more.
7. **Streamline security with a platform model.** One of the changes in the cybersecurity industry over the past few years has been the emergence of platform models. We have seen many instances where innovative start-ups have come out with solutions to specific cybersecurity challenges. However, a company like ours is hard-pressed to get the support we need from a 30- or 40-person company. There are larger security companies that have been able to stay close to security innovation by acquiring these start-ups and embracing a platform model. This provides a greater level of confidence in dealing with a company that truly understands the challenges of cybersecurity scale, support, service and innovation---particularly in the cloud.

## Reaping the Business Benefits

Cloud transformation has been of particular value to our organization in responding to COVID-19. We are on the front lines, working on treatments and partnering to deliver vaccines. With remote work and digital transformation, cloud transformation is allowing us to embrace new business models that will probably reshape our industry forever.

Why should our field sales teams continue to go door to door to physicians' offices? Why do treatment centers require sick people to come into a facility where they come into contact with other sick people? Why can't we use remote diagnostics for disease identification, research and other functions?

COVID-19 in some ways has been a rallying cry for digital transformation. For modern CISOs, the world has changed. Security has to be viewed through a new lens, not as a technology risk, but as a business risk. One of the ways to think about cloud transformation is an investment in the most critical requirements of the business---resilience, availability, agility and security.

The cloud provides a fundamental and inherent improvement, not just in security, but in your overall business operations and capabilities, much more so than you could ever build internally. As I said earlier: Cloud is no longer a choice, but a destination.

*** ** * ** ***

*Mike Towers is Chief Information Security Officer at Takeda Pharmaceuticals.*

* [Business Transformation](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=business-transformation)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://www.paloaltonetworks.com/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://www.paloaltonetworks.com/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/RFP-Bottleneck-featured.jpg) BLOG

### AI

**From Weeks to Minutes: How We Applied an AI-First Transformation to the RFP Bottleneck**

Understanding why manual efforts burn hundreds of hours and are bottlenecki...

[Sandeep Uttamchandani](https://www.paloaltonetworks.com/perspectives/author/sandeep-uttamchandani/ "Posts by Sandeep Uttamchandani")
[](https://www.paloaltonetworks.com/perspectives/from-weeks-to-minutes-how-we-applied-an-ai-first-transformation-to-the-rfp-bottleneck/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/02/New-Economics-of-Cyber-Resilience-featured.jpg) BLOG

### AI

**From Insurance Policy to Growth Engine: The New Economics of Cyber Resilience**

Security is not a shield. It is a sensor for business velocity....

[Ben Hasskamp](https://www.paloaltonetworks.com/perspectives/author/ben-hasskamp/ "Posts by Ben Hasskamp")
[](https://www.paloaltonetworks.com/perspectives/from-insurance-policy-to-growth-engine-the-new-economics-of-cyber-resilience/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
