VOOZH about

URL: https://thenewstack.io/why-cloud-migrations-fail/

⇱ Why Cloud Migrations Fail - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2024-09-13 11:05:43
Why Cloud Migrations Fail
contributed,
Cloud Services / DevOps

Why Cloud Migrations Fail

Here are the top three reasons cloud migrations can fail — plus some critical guidance that may help right the ship.
Sep 13th, 2024 11:05am by Shai Morag
👁 Featued image for: Why Cloud Migrations Fail
Featured image by Jason Briscoe on Unsplash.
As more businesses embark on their digital transformations, enterprise teams increasingly turn to the cloud to reap its benefits. Nearly 60% of IT leaders plan to migrate more workloads to the cloud this year.

Understandably, the promise of scalability, cost savings and enhanced collaboration make this a compelling proposition. However, it’s a nuanced and sizable undertaking that admittedly requires time, attention and a commitment to safe and effective use.

Occasionally, cloud migrations become so complex or unwieldy that they fail to deliver the anticipated benefits, leading to cost overruns and delays or an overreliance on third parties. Ultimately, copying and pasting a roadmap derived from a handful of well-intentioned but perhaps overhyped case studies simply doesn’t work.

Here, I’ll review the top three reasons cloud migrations can fail and offer some critical guidance that may help enterprise security teams and decision-makers right the ship.

The Shared Responsibility Model

One stumbling block on the cloud journey is misunderstanding or confusion around the shared responsibility model. This framework delineates the security obligations of cloud service providers, or CSPs (which comes down to securing the underlying infrastructure), and customers (that is, safeguarding data, access, applications and configurations). The model necessitates a clear understanding of end-user obligations and highlights the need for collaboration and diligence.

Broad assumptions about the level of security oversight provided by the CSP can lead to security/data breaches that the U.S. National Security Agency (NSA) notes “likely occur more frequently than reported.” It’s also worth noting that 82% of breaches in 2023 involved cloud data.

The confusion is often magnified in cases of a cloud “lift-and-shift,” a method where business-as-usual operations, architectures and practices are simply pushed into the cloud without adaptation to their new environment. In these cases, organizations may be slow to implement proper procedures, monitoring and personnel to match the security limitations of their new cloud environment.

While the level of embedded security can differ depending on the selected cloud model (Software as a Service, Infrastructure as a Service, Platform as a Service), the customer must often enact strict security and identity and access management (IAM) controls to secure their environment. Today, the latter has become increasingly vital, considering that nearly 40% of all ransomware incidents 2023 began with compromised, legitimate credentials.

In its guidance, the NSA also warns: “Customers often assume the CSP’s responsibility to protect customer data is broader than it is, leading to the customer failing to take needed actions.”

As such, cloud users must develop and pressure-test incident response playbooks, actively hunt for intrusions, deploy multifactor authentication, and perhaps most importantly, carefully review the “fine print,” aka their service-level agreements (SLAs) with the provider.

Data Sovereignty Hurdles

I’d be remiss not to mention another elephant in the room: compliance. According to a 2024 Cloud Security Alliance report, 61% of IT and security leaders recently cited alignment on compliance standards as a top challenge in SaaS environments. Regulations add layers of complexity, particularly regarding timely considerations like “data sovereignty”—or when data is subject to the laws and regulations of the country in which it is stored or processed.

Enforcement around data localization laws has ticked up globally, partly due to stipulations in more sweeping regulations like the European Union’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Each imposes strict guidelines on data privacy and protection for its constituents, including mandates on how the data should be handled, stored, and transferred.

This can present new challenges for enterprise teams, which in turn must develop comprehensive governance frameworks that include, for instance:

  • Encryption practices
  • Strict CSP selection criteria (including choosing those with local data centers)
  • Mandatory, ongoing audits and more

Overall, embarking on a cloud migration without first considering the regulatory implications can increase costs, slow progress, and potentially necessitate a complete redesign as controls are retrofitted.

Post-Migration Oversight

The cloud journey continues once data and applications have shifted. Proper management demands an effective cloud operations team for vital support functions, including:

  • Performance monitoring to detect and resolve issues
  • Ongoing security assessments to protect against known and zero-day vulnerabilities
  • Identity controls to manage access to cloud apps
  • Cost management to prevent budget overruns
  • A process for decommissioning resources to reduce the risk of cloud sprawl or spiraling costs

As the tech-training platform, InfoSec Institute warns, “[Cloud] is more complex [than on-premises] and requires knowing…fundamentals and principles.” It adds: “Ignoring the new paradigms…creates substantial risk.” I couldn’t agree more.

Organizations must plan for permanent oversight and broach the subject at project inception.

Ensuring a Smooth Journey

Despite its challenges, the cloud holds immense promise and offers measurable cost savings as teams ditch significant, upfront investments in physical infrastructure.

With bespoke design, proven controls and effective management, businesses can ensure a smoother cloud journey and unlock its full benefits. Experienced and/or open-minded leadership and core technical staff will also smooth the transition.

Every organization will have a unique path. Still, with proper guidance, teams can avoid clunky, expensive or risky processes, and flourish in the cloud.

TRENDING STORIES
Shai Morag, Chief Product Officer at Tenable and its former SVP and GM of Cloud Security, has over 25 years of experience in product management, technology leadership and senior executive roles. He joined Tenable upon its acquisition of Ermetic in...
Read more from Shai Morag
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.