With so many companies joining the cloud market, it can be pretty daunting selecting a supplier. You’ll need to make sure your chosen partner provides the services you’re looking for, and has the kind of technology capability you’re looking for – but how do you know who you can trust? Happily for us UK types, the National Cyber Security Centre (NCSC) have provided some guidance. I have taken that guidance and given it a bit of a plain English make-over.
Choosing a Cloud Supplier
Once you’ve established your chosen cloud supplier can support your organisation’s objectives, and that they have the technology capability you need, you’re going to want to spend some time ensuring they are a safe bet from a cyber security perspective. This is even more important if you’re looking toward Cyber Essentials, ISO27001 for information security.

The following questions can be shared with any potential supplier to establish their credentials as a ‘fit an proper’ partner.
Supplier Cyber Onboarding Questions
- Do you have people and processes in place that are responsible for cyber security?
- Are the people occupying security roles suitably skilled and experienced? Please provide examples.
- Are senior decision makers aware of their cyber security responsibilities?
- Do you have plans and processes in place to cope with an incident and recover from it? Please provide summary information.
- Have you suffered any material security breaches or compromises which you need to declare?
- What business continuity / disaster recovery plan do you have for maintaining minimum service levels to you, should you suffer an incident (e.g. a ransomware attack)?
- Do you agree to meet any necessary obligations for managing and reporting incidents, including reporting timescales, who to report to, and expected actions?
- How do you protect your network from the Internet or other untrusted networks?
- How have you configured and protected your Cloud services (if used)?
- Do you know what devices connect to their network and who has access to them?
- Do you have processes in place to control which users have privileged access to your networks?
- Do your users have the minimum level of access to data and networks required to do their job and no more?
- Do you secure remote connections to its network, with a robust process for identifying and authenticating remote users?
- Are all users properly authenticated before being given access to networks or services?
- If you use bespoke or in-house developed software applications in your service to us, how are these secured?
- If you allow Bring-Your-Own-Device (BYOD), how do you protect your networks from potential harms on BYOD devices?
- Do you encrypt data on portable devices such as laptops, mobile phones, tablets and removable media, in case of loss or theft?
- Do you securely wipe or destroy all storage media prior to disposal or re-use?
- If you allow BYOD, how do you protect data on BYOD devices?
- Do you have processes in place to detect and prevent unauthorised or unusual (e.g. very large) data transfers from your network?
- Do you use secure email and secure data connections to their network, to protect data in transit?
- How do you constrain access to sensitive data?
- Do you offshore any components of your service to us, such as data storage, data processing, support, development or maintenance of services?
- If so, in which locations and what security controls are in place around those offshore components?
- Will you notify us if any of the locations change, or if you change any of your offshore subcontractors?
- Will any of our personal data be subject to offshore storage or processing?
- Do you handle or process any personal data as part of your service to us, and if so, does it meet the GDPR security principles?
- Is your use of personal data lawful, fair and transparent?
- Is it only used for the purposes it was collected for and nothing else?
- Do you only collect the minimal amount of personal data required?
- Is the personal data accurate, up to date, protected and deleted when no longer required?
- Do you carry out suitable background checks on employees and have processes in place for in-house personnel security controls?
- Do you have security awareness training, covering common attacks on users, such as phishing and other means of enticing users to disclose sensitive information, or download unauthorised code?
- Do you supplier encourage a positive security culture? For example, do you encourage users to report suspected or actual incidents promptly in a no-blame environment?
- Have you performed a risk assessment to understand your insider threat?
- Do you have suitable physical controls in place to protect data, networks and premises?
- Do you securely dispose of sensitive printed information?
- Do you conduct any independent security tests, such as penetration tests of their internal and external IT infrastructure and remediate any findings?
- Are there any specific risk mitigations or controls in your contracts with us which must be passed down to your subcontractors?
- Would you inform us if subcontractors change?
- Do you hold any cyber security certifications, such as Cyber Essentials, Cyber Essentials Plus or ISO27001?
- If so, does the scope of the certifications cover the parts of the service we are consuming, and the way in which we are consuming it?
- Will you (or any subcontractors employed by you) connect, or have access to, our data, IT network or premises?
- If so, how will this be limited, controlled, and monitored?
- For any remote access to our data or IT network, we require acceptance of a separate remote access support agreement.
- All remote connections are logged and audited.
- Contract exit – what provisions are there for secure deletion or return of your data/assets at contract exit, including transfer of services, data or assets to another supplier?
- This assessment is subject to repetition in the event of material change, for example, when the volume of data being processed by the significantly increases, when different types of data are introduced (e.g. personal data or commercially sensitive data), or when new technology is introduced (e.g. mobile access platforms).
- We require the “right to audit” and/or regular reporting on security. You agree to respond to any audit request in a timely fashion.
Your Perfect Cloud Partner
There is no one size fits all answer for a perfect cloud partner, every business is different and technology needs unique. This is why the search should be for a partner rather than a supplier – you need a partner who can start where your organisation stops, filling all the gaps and enabling your cloud journey.
I can help you get there. No blinding anyone with science – we’ll talk through the options, and help you figure out what works best for you. My fees are very competitive for initial design and build, as well as for the monthly feeding and watering. I have established relationships with the vendors, and other players in the sector – I know what I’m good at, and I know what other people are good at too. I’ll advise you accordingly.