Cloud

What to Know Before Moving Business Systems to the Cloud

Cloud services can improve access and flexibility, but organizations should understand ownership, security, costs, connectivity, and recovery before migrating important systems.

Moving to the cloud can mean replacing an on-site server, adopting a hosted application, storing files online or building an environment with rented computing resources.

Those are different decisions.

The word “cloud” describes how technology is delivered. It does not mean that every service is automatically secure, affordable or appropriate for the business.

The main point

Begin with the business need, then evaluate the service, responsibilities and migration plan.

NIST defines cloud computing as on-demand access to a shared pool of configurable computing resources that can be provided and released with limited management effort.

In practical terms, an organization can use applications, storage, platforms and infrastructure without owning every underlying component.

The business still has responsibilities.

The provider may operate the underlying service while the customer remains responsible for some combination of:

  • Users and access
  • Account configuration
  • Data handling
  • Sharing permissions
  • Connected devices
  • Recovery planning
  • Legal and contractual obligations

The exact division depends on the service model, configuration and contract.

Start with the reason for moving

Do not begin with the assumption that everything should move.

Define the problem first.

A cloud project may be intended to:

  • Improve access for remote employees or multiple locations
  • Replace aging infrastructure
  • Support growth without a large equipment purchase
  • Improve collaboration
  • Adopt an application available only as a hosted service
  • Reduce local maintenance
  • Improve availability or recovery options

A clear goal makes it easier to determine whether the proposed service actually solves the problem.

Understand the service model

Cloud services generally fall into three broad models.

Software as a service

The provider delivers a complete application, such as email, file sharing, accounting or customer management.

The customer still manages users, permissions, information and many configuration choices.

Platform as a service

The provider supplies a platform on which an organization develops or runs applications.

Responsibilities vary based on the platform and how it is configured.

Infrastructure as a service

The provider supplies computing, networking or storage resources. The customer may remain responsible for operating systems, applications, configurations and much of the security environment.

The contract and technical documentation should explain the division of responsibilities.

Questions to answer before migrating

What information will the service hold?

Identify:

  • The information being moved
  • Its sensitivity
  • Legal or contractual requirements
  • Retention requirements
  • Geographic storage restrictions
  • Who should have access

Do not move information before understanding how it must be protected.

Who owns the accounts and data?

Create business services under organization-controlled accounts.

Do not use an employee’s personal email address or personal account as the permanent owner of company files, subscriptions, domains or administrator access.

Document the primary owner, backup administrators and recovery methods.

How will access be protected?

Plan:

  • Individual user accounts
  • MFA
  • Administrator roles
  • Least-privilege access
  • Employee onboarding and offboarding
  • Guest access
  • Account recovery
  • Access reviews

Access planning should happen before data is moved, not after the service is already in use.

What does the provider protect or retain?

Availability, version history, retention and backup are not necessarily the same.

Understand:

  • What the provider can restore
  • How long deleted information is retained
  • Whether entire accounts can be recovered
  • What the customer must back up separately
  • How long a recovery may take
  • Which restoration options cost extra

Test important recovery functions where possible.

What happens when internet access is unavailable?

Cloud services depend on connectivity.

Review:

  • Internet reliability
  • Backup connectivity
  • Local or offline work options
  • Mobile access
  • Which functions must continue during an outage

A highly available service does not help an office that cannot reach it.

What will the service really cost?

Include:

  • Licenses
  • Storage
  • Data transfer
  • Security features
  • Backup and retention
  • Support
  • Migration work
  • Integration
  • Training
  • Future growth

A low entry price may not represent the long-term operating cost.

How will the organization leave?

Confirm:

  • How information can be exported
  • Which formats are available
  • Whether metadata and permissions are preserved
  • How long an export takes
  • What assistance is available
  • When information is deleted after cancellation

Portability and interoperability should be considered before the organization becomes dependent on the service.

Plan the migration

Inventory the current system, including:

  • Users
  • Information
  • Applications
  • Integrations
  • Permissions
  • Workflows
  • Dependencies

Use a representative pilot group when practical.

Test:

  • Access
  • Security settings
  • Sharing
  • Business workflows
  • Recovery
  • Reporting
  • Support procedures

Create a written migration and rollback plan. Explain what will change, when it will change and where employees can get help.

Review the environment after launch

After migration, review:

  • Administrator access
  • External sharing
  • Recovery methods
  • Unused accounts
  • License assignments
  • Security alerts
  • Data retention
  • Backup coverage

Cloud environments still require ongoing management even when the physical infrastructure belongs to another organization.

What to avoid

Do not:

  • Move systems without understanding ownership and recovery.
  • Use personal accounts to own business services.
  • Share administrator credentials.
  • Leave external sharing open-ended.
  • Assume the provider backs up everything in the expected way.
  • Ignore export and cancellation options.
  • Move an inefficient process without reviewing the process itself.

Migration is an opportunity to simplify ownership, access and workflow.

When to involve IT

Involve IT before moving:

  • Email
  • Shared files
  • Identity services
  • Business applications
  • Regulated information
  • Servers or infrastructure
  • Systems with multiple integrations

Professional review is especially important when downtime would interrupt operations.

Cloud services can be an effective part of a modern environment. The strongest results come from treating the move as an operational change, not simply a new subscription.

Considering a cloud migration or reviewing an existing environment? Book a consultation.

Sources and further reading

On this page
More Insights

Related Posts

Explore more from The Infrastructure Journal.

Protection

A Backup Is Not Complete Until It Has Been Tested

Having backup software is not the same…
Strategy

When Your Business Needs a Technology Roadmap

A technology roadmap helps organizations plan upgrades,…
Risk

What to Do When You Receive a Suspicious Email

A suspicious message does not automatically mean…
Get Started

Start with a solid foundation

Build systems that support your business without constant fixes or workarounds.