The threat of data loss flying into the cloud

A woman's hand underneath a small white cloud with icons representing different types of data raining out of it on a black chalkboard background
(Image credit: Shutterstock)

Compliance in the cloud

Cloud computing may pose serious data security threats to businesses wanting to save on software licensing and support services. This is according to a recent report by City law firm Reynolds Porter Chamberlain (RPC).

In theory, the concept of cloud computing can be more secure than do-it-yourself computing since shared costs allow larger overall investment in security processes and infrastructure. The business benefits to the cloud model are also compelling, creating a centralised method to access shared data, significantly lowering costs and reducing data centre space and power. However, despite the cost saving potential offered by moving data storage and applications online, the use of cloud computing may lead to breaches of the Data Protection Act (DPA) by businesses and their information security obligations to their customers.

For example an organisation, choosing to outsource their data storage, risks claims being made against them by their customers if data held by the host server becomes unavailable during an interruption or outage, or even lost. The likelihood of service interruptions also raises concerns over the use of the cloud for applications that are critical to the day to day running of an organisation, such as database or email. According to a recent report by analyst house Gartner, the cloud computing community has received reports of 14 outages and consequent lost data and security issues throughout 2009, an increase from just one in 2008 (‘Gartner on cloud computing’, 2009).

As most cloud computing service providers will not guarantee the security of the data they store, this may put organisations in breach of their requirements under the DPA to ensure an appropriate level of security. Furthermore, companies regulated by the Financial Services Authority are required to have adequate risk management systems in place, and any failure to comply could result in a considerable fine. In light of this, organisations must realise that accountability for valuable business data cannot be as conveniently outsourced. Therefore, when considering a cloud-based service, organisations should look into various solutions which not only protect them from the well known malicious threats, but enable them to fully comply with applicable regulations to protect their own sensitive data such as credit card details and customer data.

Selecting the correct cloud solution

When selecting a cloud solution, it goes without saying that organisations should look for efficient and customisable offerings that do not compromise data and which also enable savings on their capital and operational costs. The problem is, that there are multiple vendor offerings on the market that address these needs. Organisations need to consider an overall cloud based service that provides data privacy and regulatory compliance by ensuring that confidential data remains in a dedicated cloud with clear security boundaries. Only then will they be able to ensure that confidential data remains within the corporate boundaries and is not stored in the public cloud.

Organisations must also remember that management will always be responsible for protecting company and customer data. It is, therefore, essential when moving applications and data towards the cloud that companies consistently ensure the health of the cloud-provided services. This includes gaining complete confidence that the cloud provider is a viable, stable business with assurances and protections, such as comprehensive risk and security defences in place, to safeguard business data.

Alongside guarantees from the cloud provider, businesses must also ensure that they have an alternative strategy in place in the case of any disruptions or loss of connectivity to the cloud-based service. This includes awareness of the providers’ fallback plans and commitments that may jeopardise valuable information. Businesses also need to bear in mind that any interruptions to cloud computing providers may have to be dealt with on both a short- and long-term basis, depending on the nature of the disturbance.

However, guarantees from your cloud provider are all well and good, but they can’t stop Government enforcing regulation. The current criminal justice and immigration bill states that the UK Information Commissioner has the power to levy fines on companies who recklessly lose confidential or personal information. This means that it is now more important than ever for organisations to protect themselves from the loss of sensitive data in the cloud, particularly as the level of fines could run to millions of pounds.

In summary, it appears that with many organisations moving their business applications online, cloud computing is here to stay. While businesses should always protect themselves from malicious threats such as malware, trojans, botnets and phishing attacks, there are still major concerns about whether organisations can have complete access and control their sensitive data in the cloud. It is therefore imperative that when searching for a cloud solution, companies consider a service that protects them from data loss.

ITPro

ITPro is a global business technology website providing the latest news, analysis, and business insight for IT decision-makers. Whether it's cyber security, cloud computing, IT infrastructure, or business strategy, we aim to equip leaders with the data they need to make informed IT investments.

For regular updates delivered to your inbox and social feeds, be sure to sign up to our daily newsletter and follow on us LinkedIn and Twitter.

Latest in Cloud
AI chatbot text dialogue boxes in difference colours above a digital circuit board with lines of light emanating from it
Enterprise AI is surging, but is security keeping up?
Oracle logo pictured in red lettering against a black background at the company's stall at Mobile World Congress (MWC) 2025 in Barcelona, Spain.
Say goodbye to walled gardens, Oracle is doubling down on multi-cloud
A glowing blue CGI representation of a network solution provided via the IT channel.
Why understanding the customer’s network unlocks its value and your success
Cloud storage concept image showing digitized cloud symbol with data flows.
AI is putting your cloud workloads at risk
A CGI visualization of cloud computing, with an isometric view of a purple and blue cloud linked to seven glowing cube nodes, to represent devirtualization and revirtualization.
Navigating devirtualization as businesses move away from the cloud
Logo of Google Cloud, which recently announced the Wiz acquisition, pictured at Mobile World Congress 2025 in Barcelona, Spain.
The Wiz acquisition stakes Google's claim as the go-to hyperscaler for cloud security – now it’s up to AWS and industry vendors to react
Latest in Feature
A photo of UNSW's Sunswift 7 car pictured in front of Uluru in Australia's Northern Territory.
How UNSW’s Sunswift Racing and Ericsson achieved cross-country connectivity in Australia’s outback
Matt Clifford speaking at Treasury Connect conference in 2023
Who is Matt Clifford?
Open source vulnerabilities concept image showing HTML code on a computer screen.
Open source risks threaten all business users – it’s clear we must get a better understanding of open source software
An abstract CGI image of a large green cuboid being broken in half with yellow, orange, and red cubes to represent ransomware resilience and data encryption.
Building ransomware resilience to avoid paying out
The words "How effective are AI agents?" set against a dark blue background bearing the silhouettes of flowchart rectangles and diamonds to represent the computation and decisions made by AI agents. The words "AI agents" are yellow, while the others are white. The ITPro Podcast logo is in the bottom right-hand corner.
How effective are AI agents?
An illustration showing a mouth with speech bubbles and question marks and a stylized robot alien representing an AI assistant chirping away with symbols and ticks, to represent user annoyance with AI assistants.
On-device AI assistants are meant to be helpful – why do I find them so annoying?