CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Risk Management & Compliance
  • CIO Viewpoints

Risk Management for Cloud Computing and Data Services

Ramesh Munamarty, Group CIO, International SOS

Tweet

content-image
Moving to the Cloud for computing is no longer optional for many enterprises and hence many of them have already embarked on this journey. However, several of them do so without a formalized and effective Risk Management strategy which results in them making unintended news headlines due to a breach. Risk Management is key to protecting the shareholder value and includes strategic risks, financial risks, operational risks, and damage risks.

Enterprise Risk Management

As outlined in a paper by North Carolina State University, Enterprise Risk Management is an approach to develop a holistic, portfolio view of the most significant risks to the achievement of the entity’s most important objectives. This is a top down approach driven by the Executive Management and Board of Directors as they are the ones who have the enterprise view of the organization and they are viewed as being ultimately responsible for understanding, managing, and monitoring the most significant risks affecting the enterprise.

Because risks constantly emerge and evolve, it is important to understand that ERM is an ongoing process. The diagram in Figure 1 illustrates the core elements of an ERM process. It is important to focus on the oval shape to the figure and the arrows that connect the individual components that comprise ERM. The circular, clockwise flow of the diagram reinforces the ongoing nature of ERM. Once management begins ERM, they are on a constant journey to regularly identify, assess, respond to, and monitor risks related to the organization’s core business model.

Enterprise Risk Management Approach on Cloud Computing

Risk Management is not a new concept and organizations have been doing this for decades as managing risk is key to succeeding in business. However, the approach that was adopted by many was a siloed approach. Each Business Unit or Functional leader was tasked with managing risk in their own department and over time this led to a lot of issues resulting in the formation of Enterprise Risk Management approach.

Cloud Computing is a classic example of why traditional risk management will not work as it traverses across different areas. Software-as-a-Service solutions are highly appealing as they are primarily OPEX based and offer an on-demand consumption model. Hence, these solutions are highly popular as traditionally the business units would subscribe to them within their P&L without requiring involvement of IT and cumbersome CAPEX approval process. Traditionally, IT was opposing these solutions due to the security and data privacy issues.

Cloud Computing is a classic example of why traditional risk management will not work as it traverses across different areas


Over time, better governance has been implemented in enterprises as Cloud Suppliers have strengthened security and there are proper Cloud Security frameworks that have evolved to manage the risks. The upside and downside risks are articulated, and the risk-based performance management approaches are replacing the traditional risk management.

The frameworks associated with Cloud computing cover requirements of the users, cloud service providers risk assessment, third-party agencies review, and continuous monitoring. Vendor IT Risk Assessment includes items such as:

• Formal Security program adopted by the provider including dedicated security officer, external auditors and senior management oversight
• Third Party Assessments such as SOC2, ISO etc.
• Critical programs such as BCP, DR, Asset destruction, recovery and security operational incident management
• Penetration Test results
• Vendor Security Assessment and oversight

Enterprise Risk Management Approach for Data Services

Risk Management for Data should include:

• Leak of sensitive and confidential information
• Loss of User Data
• Access Control Lists compromised
• Data Classification mismatch
• Data Integrity compromised

Although GDPR imposed by EU has created an upheaval in the enterprises having operations in Europe several of the principles apply to data services in general. The data protection principles stipulated by GDPR include:

• Lawfulness, fairness and transparency – essentially the privacy policy needs to state the type of data being collected and why it is being collected
• Purpose limitation – collect data for a specific purpose and collect it only for as long as you need to complete that purpose
• Data Minimization – process only the personal data that you need to achieve the processing purpose
• Accuracy – every reasonable step must be taken to erase or rectify data that is incomplete or inaccurate
• Storage limitation – delete personal data after a predefined time when it is not necessary. Data retention policies should be set, and compliance ensured
• Integrity and Confidentiality – personal data should be processed in a manner that ensures appropriate security and protection against accidental loss, destruction or damage

In Summary, since enterprises can rarely avoid Cloud Computing or dealing with personal and sensitive data, they should adopt formalized approaches to Risk Management and the sponsorship needs to come from Executive Management and Board of Directors. ISO, PCI, GDPR, and several other certifications mandate compliance but regardless of the need for the enterprise to be certified, shareholders are mandating this to protect their value.

Weekly Brief

loading
cioviewpoint
TOP VENDORS
Top 10 Risk Management Solutions Companies - 2023
  • Adopting And Driving AI Across an...

    Dr. Yves Gorat Stommel, Deputy Head of Function Evonik Digital, Evonik [ETR: EVK]

  • Challenges under the Hood: Cloud...

    Ivan Romero, Global Head Of Public Cloud, Wealth Management & Insurance, Banco Santander(BME: SAN)

  • Evolving Role of the CISO

    Christos Syngelakis, Group Chief Information Security Officer, Motor Oil[Fra: Mhz]

  • EU Cyber Challenges For The Private...

    Paulo Moniz, Director- Information Security and It Risk, EDP [ELI: EDP]

  • Inspiring Extraordinary Customer Success

    Alexander Bender, Global Head of Client and Broker Relationship Management, Allianz

  • Unveiling the Power of Data Visibility

    Muhammad Saleem, Head of Data Architecture, Bae Systems [LON: BA]

  • Transforming The Trucking Industry...

    Jair Ribeiro, Data Analytics and AI Leader, Volvo Group

  • The Transforming Landscape of...

    Cameron Farrar, Vice President - Head Of Software Asset Management, Marsh Mclennan(NYSE: MMC)

RECENT EDITIONS
‹ ›

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://risk-management-and-compliance.cioapplicationseurope.com/cioviewpoint/risk-management-for-cloud-computing-and-data-services-nid-1002.html