Learning Objectives:
-
Understand the unique security challenges of cloud adoption.
-
Apply cloud security best practices and the shared responsibility model.
-
Implement secure cloud migration strategies.
-
Recognise the regulatory requirements for cloud security.
7.1 Cloud Security Challenges
The financial sector’s full dependency on ICT providers, especially cloud service providers, core banking vendors, and outsourced AI systems, is a key driver of ICT-related risks . The ECB Guide provides good practices on effective outsourcing risk management for banks under ECB supervision that use third-party cloud services, based on observed industry practices .
Key Cloud Security Challenges:
-
Data Sovereignty: The requirement to keep data within specific geographic boundaries
-
Vendor Lock-in: Difficulty migrating from one cloud provider to another
-
Shared Responsibility Model: Understanding which security responsibilities are the cloud provider’s and which are the organisation’s
-
Misconfiguration: Cloud misconfigurations are a leading cause of data breaches
-
Multi-tenancy Risks: Risks associated with sharing infrastructure with other tenants
7.2 The Shared Responsibility Model
In cloud computing, security is a shared responsibility between the cloud provider and the customer. The ECB Guide emphasises that institutions must apply the same level of diligence as if services were performed in-house .
Cloud Provider Responsibilities:
-
Security of the cloud infrastructure
-
Physical security of data centres
-
Network and storage security (depending on the service model)
Customer Responsibilities:
-
Identity and access management
-
Data protection (encryption)
-
Security configuration
-
Vulnerability management
-
Incident response
7.3 Secure Cloud Migration
The MAS TPRM Guidelines require financial institutions to conduct a risk assessment before entering into a third-party arrangement, when there are major changes impacting the arrangement, and periodically . The ECB Guide provides detailed guidance on governance and risk management for cloud outsourcing .
Key Cloud Migration Considerations:
Risk Assessment: Comprehensive ex-ante risk assessment covering lock-in and concentration risks, multi-tenancy risks, data protection and geopolitical risks, long and complex sub-outsourcing chains, and vendor dependence across the institution’s entire provider landscape .
Contractual Requirements: Contracts must include:
-
Service level objectives
-
Incident response expectations
-
Data access rights
-
Location of data processing
-
Exit strategies
Data Protection: Data must be encrypted in transit, at rest and, where feasible, in use, with sound key-management and audit procedures .
Exit Strategies: Exit plans must be tested periodically, demonstrate realistic costs, and be subject to independent review .
7.4 Regulatory Requirements for Cloud Security
DORA establishes structured, enforceable rules for managing outsourcing and external dependencies, including cloud services . The ECB Guide clarifies the expectations the ECB has for banks to comply with DORA requirements .
Key Regulatory Requirements:
-
Risk Assessment: Financial institutions must continuously assess the risk level of all ICT service providers
-
Contractual Requirements: Outsourcing contracts must clearly specify service level objectives, incident response expectations, data access rights, location of data processing, and exit strategies
-
Access Rights: Institutions and regulators must retain the right to access, audit, and inspect the ICT systems and premises of third-party providers
-
Exit Strategies: Exit strategies must be established for all critical or important cloud services before go-live