Digital transformation is an organisation adopting current technology to improve
how it operates and how it competes. The most common example is moving from
traditional on-premises systems to cloud platforms.
The security consequence is usually stated too narrowly. It is not that cloud is
less secure than a data centre. It is that as workloads move, the security model
has to move with them — and for a period, most IT teams are defending both at
once, with tooling and habits designed for only one of them.
The exposure created by transformation programmes is rarely exotic. It comes from
three ordinary places.
The first is dependency on third parties. Cloud and SaaS adoption pushes a growing
share of your data into services you do not operate, and organisations frequently
expand faster than their oversight does. Senior leaders often cannot say with
confidence which providers hold their information, what those providers’
practices are, or who inside the business agreed to it. Nothing is broken in that
picture — it is simply unmapped, and unmapped is the condition attackers rely on.
The second is speed. Transformation programmes are approved on the promise of
moving quickly, and security review is the step that gets compressed when the
date is fixed. The result is not a single bad decision but a long tail of small
ones, none of which is revisited.
The third is the reverse failure, which gets less attention. Some organisations
avoid modernising because they judge it too risky, and end up running unsupported
software on ageing hardware — a materially worse security position than the one
they were trying to avoid.
There is a measurable version of the first problem. Wasted cloud spend runs at
29%, up for the first time in five years. Waste is a cost problem, but it is
also a security signal: an unused resource is generally an unowned one, and an
unowned resource is not being patched, monitored or decommissioned.
What the pandemic changed
The pandemic accelerated all of this sharply. Remote working infrastructure and
cloud-delivered software were deployed in weeks rather than quarters, and the
usual controls were bypassed to make that happen.
Much of that was the right call at the time. The problem is that very little of
it was revisited afterwards. Organisations that never established tracking of what
was adopted during that period still carry the consequences: cloud resources
nobody owns, services still being billed for people who have left, accounts
outside single sign-on, and no consolidated view of who has access to what.
How to reduce the risk
Two things matter, and only one of them is usually done.
The first is supplier assurance. Ask for the certifications and check they are
current. Certero holds ISO 27001:2022 for information security management, Cyber
Essentials Plus — the highest level of the UK NCSC scheme — and a SOC 2 Type 1
attestation.
The second, and harder, is complete visibility across everything you run,
whatever the delivery model. Security work depends on an accurate answer to
questions that sound trivial and usually are not: what software is installed and
at which version, which of it is out of support, what is running in cloud, which
SaaS applications people are actually using, and what happens to all of that when
someone leaves.
That is asset management doing security work, and it is worth naming what it
looks like in practice:
- Version and lifecycle truth. Titles resolved against a normalised
recognition database of over 3.5 million entries, carrying release date,
end-of-support and extended-support dates — so end-of-life exposure is a
standing report rather than a scramble after an advisory.
- Policy as code. Governance policies expressed as reusable filters and
evaluated continuously, covering things like BitLocker enabled, Defender
running, and cloud VM tag hygiene, with a violation history you can hand to an
auditor.
- Third-party access, scored. OAuth grants to consented applications
discovered and risk-scored from zero to one hundred on data sensitivity, scope,
how consent was given and how long the grant has been dormant — with one-click
revocation, available as an automated workflow action.
- The AI you did not sanction. Shadow AI detection classified from
application feature tags rather than a fixed list, ranked by how much of the
organisation is using each tool, because ten people using a model is a
different problem from a thousand.
- Cloud security signals alongside cost. Inactive IAM users, unused console
access and open security groups surfaced by the same engine that finds the
abandoned resources.
- Offboarding you can prove finished. A per-user checklist showing every
licence held, the connector status behind each revocation, and whether it is
pending, in progress or complete.
Consolidating onto one view of all of it does three things at once. It shrinks
the attack surface, because you can finally see and remove what nobody uses. It
reduces cost, because the same exercise finds duplicate applications and unused
licences. And it puts decisions in one place, informed by evidence rather than by
whichever team shouted loudest.
Security and cost optimisation are usually presented as competing priorities.
Here they are the same piece of work.