All briefings
Cloud SecurityResilience

Cloud growth needs a governed foundation

By Marcin Pajdzik ·

Moving business applications to the public cloud, and expanding what already runs there, requires investment, clear ownership and oversight. Much of the risk that follows depends on the foundation those workloads run on. Where business units or countries adopt cloud separately, each environment can develop its own accounts, access model, network paths and logging, which can make a consistent group-wide view of cloud risk difficult to maintain.

What a landing zone provides

A landing zone is a shared foundation that sets rules for who can access cloud services, how activity is monitored, how environments connect and who owns the costs. It provides a governed route for introducing new workloads and bringing existing environments under the organisation's standards. Each major cloud provider publishes landing zone guidance, and the design follows the organisation's structure, regulatory obligations and growth plans.

Why the foundation matters to the business

Visibility and ownership. When cloud environments sit under the common controls with a named owner, leadership can see what the organisation runs in the cloud, who is accountable for it and what it costs. For environments outside the common controls, leadership needs separate evidence of logging, policy enforcement and cost ownership.

Containment. Separating workloads and controlling the paths between them limits how far a failure or compromise in one service can spread. Putting Zero Trust strategy into practice in your cloud estate covers the controls involved.

Recoverability. Recovery arrangements must remain usable if production is compromised. Protected backups, independent recovery access and tested restoration of critical services should demonstrate that the business's recovery objectives can be met.

Scale. The foundation has to keep pace as new accounts and products follow. A consistent process brings new environments under the organisation's current standards, with workload-specific requirements and approved exceptions recorded.

Who maintains it

A named platform owner and an appropriately funded operating team maintain the foundation, with clear responsibilities shared across security, finance and application teams. The owner needs the authority to hold the standard across business units, and the team needs funding as a standing capability, because the platform keeps changing after the migration programme closes. Application teams keep ownership of their own services and build on the foundation beneath them.

Where the estate already exists

An organisation already running workloads in the cloud can establish the foundation afterwards. Where one business unit already operates a well-governed environment, extending it to the rest of the group can avoid rebuilding identity and network integrations that already work. Existing environments are assessed and brought under the common standard in stages, with changes tested to avoid disrupting existing services.

Where a delivery partner builds the landing zone, independent assurance gives the board a view, separate from the builder's, of whether the design meets the organisation's requirements and is ready for the workloads planned for it.

What the board should see

The board should see how much of the cloud estate meets the agreed standard, where significant gaps remain and who owns their resolution. Recovery tests should demonstrate whether critical services can be restored within the business's required timescales. Exceptions should have named owners and review dates.

Questions for the board

  • Who owns the cloud platform, and is its operating team funded to maintain the standard after migration?
  • How much of our cloud estate meets the agreed standard, and how are new environments brought under it?
  • Could we recover critical services if production were compromised, and when was that last tested?
  • How are cloud costs attributed to the business units that incur them?
  • What evidence shows the platform standard is being met?
  • Which gaps require investment or explicit risk acceptance?

Continuous governance at scale shows a shared landing zone established across Bauer Media's UK, German and Polish cloud estate. A Cloud Security Governance Review establishes whether your cloud foundation operates as designed.

References

  • Amazon Web Services, AWS Prescriptive Guidance, Setting up a secure and scalable multi-account AWS environment.
  • Microsoft, Cloud Adoption Framework for Azure, What is an Azure landing zone?
  • Google Cloud, Landing zone design in Google Cloud.
  • Amazon Web Services, AWS Control Tower User Guide, Enroll an existing AWS account.
  • Microsoft, Cloud Adoption Framework for Azure, Transition existing Azure environments to the Azure landing zone conceptual architecture.
  • Amazon Web Services, AWS Backup Developer Guide, Creating backup copies across AWS accounts.
  • Microsoft, Cloud Adoption Framework for Azure, Cloud Center of Excellence.
Start the conversation

Facing this in your organisation?

Talk to us

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.