Skip to content

Risk & Reward: Digital Transformation's Impact on Cyber Security

Moving to cloud changes the shape of the attack surface, not just its location. Why third-party sprawl and rushed adoption create the exposure — and what complete visibility across devices, software, SaaS and cloud actually has to include.

What is digital transformation?

Digital transformation is an organisation adopting current technology to improve how it operates and how it competes. The most common example is moving from traditional on-premises systems to cloud platforms.

The security consequence is usually stated too narrowly. It is not that cloud is less secure than a data centre. It is that as workloads move, the security model has to move with them — and for a period, most IT teams are defending both at once, with tooling and habits designed for only one of them.

How does digital transformation affect security?

The exposure created by transformation programmes is rarely exotic. It comes from three ordinary places.

The first is dependency on third parties. Cloud and SaaS adoption pushes a growing share of your data into services you do not operate, and organisations frequently expand faster than their oversight does. Senior leaders often cannot say with confidence which providers hold their information, what those providers’ practices are, or who inside the business agreed to it. Nothing is broken in that picture — it is simply unmapped, and unmapped is the condition attackers rely on.

The second is speed. Transformation programmes are approved on the promise of moving quickly, and security review is the step that gets compressed when the date is fixed. The result is not a single bad decision but a long tail of small ones, none of which is revisited.

The third is the reverse failure, which gets less attention. Some organisations avoid modernising because they judge it too risky, and end up running unsupported software on ageing hardware — a materially worse security position than the one they were trying to avoid.

There is a measurable version of the first problem. Wasted cloud spend runs at 29%, up for the first time in five years. Waste is a cost problem, but it is also a security signal: an unused resource is generally an unowned one, and an unowned resource is not being patched, monitored or decommissioned.

What the pandemic changed

The pandemic accelerated all of this sharply. Remote working infrastructure and cloud-delivered software were deployed in weeks rather than quarters, and the usual controls were bypassed to make that happen.

Much of that was the right call at the time. The problem is that very little of it was revisited afterwards. Organisations that never established tracking of what was adopted during that period still carry the consequences: cloud resources nobody owns, services still being billed for people who have left, accounts outside single sign-on, and no consolidated view of who has access to what.

How to reduce the risk

Two things matter, and only one of them is usually done.

The first is supplier assurance. Ask for the certifications and check they are current. Certero holds ISO 27001:2022 for information security management, Cyber Essentials Plus — the highest level of the UK NCSC scheme — and a SOC 2 Type 1 attestation.

The second, and harder, is complete visibility across everything you run, whatever the delivery model. Security work depends on an accurate answer to questions that sound trivial and usually are not: what software is installed and at which version, which of it is out of support, what is running in cloud, which SaaS applications people are actually using, and what happens to all of that when someone leaves.

That is asset management doing security work, and it is worth naming what it looks like in practice:

  • Version and lifecycle truth. Titles resolved against a normalised recognition database of over 3.5 million entries, carrying release date, end-of-support and extended-support dates — so end-of-life exposure is a standing report rather than a scramble after an advisory.
  • Policy as code. Governance policies expressed as reusable filters and evaluated continuously, covering things like BitLocker enabled, Defender running, and cloud VM tag hygiene, with a violation history you can hand to an auditor.
  • Third-party access, scored. OAuth grants to consented applications discovered and risk-scored from zero to one hundred on data sensitivity, scope, how consent was given and how long the grant has been dormant — with one-click revocation, available as an automated workflow action.
  • The AI you did not sanction. Shadow AI detection classified from application feature tags rather than a fixed list, ranked by how much of the organisation is using each tool, because ten people using a model is a different problem from a thousand.
  • Cloud security signals alongside cost. Inactive IAM users, unused console access and open security groups surfaced by the same engine that finds the abandoned resources.
  • Offboarding you can prove finished. A per-user checklist showing every licence held, the connector status behind each revocation, and whether it is pending, in progress or complete.

Consolidating onto one view of all of it does three things at once. It shrinks the attack surface, because you can finally see and remove what nobody uses. It reduces cost, because the same exercise finds duplicate applications and unused licences. And it puts decisions in one place, informed by evidence rather than by whichever team shouted loudest.

Security and cost optimisation are usually presented as competing priorities. Here they are the same piece of work.

Related reading

Other posts covering the same ground.

  • Top IT Asset Management Trends of 2025 (So Far)

    Eight shifts reshaping ITAM through 2025 — from the gap between MDM and true lifecycle management, to multi-cloud visibility, compliance automation, security convergence and workflow orchestration. What each one means, and what to do about it.

    • ITAM
    • SAM
    • Cloud
    • Security
    • FinOps
    7 min
  • 8 Ways Software Asset Management Benefits Your Business

    SAM is usually justified as audit insurance. It is also cost reduction, a security control, acquisition due diligence, a stronger negotiating position, and the only reliable basis for rationalising applications.

    • ITAM
    • SAM
    • SaaS
    • Cloud
    • Security
    10 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.