Shifting the Risk of CSP Lock-in

Opinion
Jan 7, 20102 mins

Not just an economic issue—it’s a security issue

Cloud vendor lock-in is a significant concern for cloud consumers. This is not just an economic issue, it’s a security issue. As an example, the European Network and Information Security Agency (ENISA) lists vendor lock-in as a top security risk having both high probability and high business impact. Unfortunately, in today’s market there is little incentive for cloud service providers (CSP) to address this risk. Lock-in is a competitive move but at the same time it’s limiting cloud adoption. For adoption to increase we need to reduce the enterprise risk burden by shifting it back toward the CSP.

One way to shift risk is to use a third-party solution. There is an emerging ecosystem of third-party providers such as Cast Iron Systems, Elastra, RightScale and Sesame Software offering services and products that make movement to the cloud, from the cloud and between clouds easier. These portability providers assume the risk of lock-in from the enterprise: They take on the responsibility of dealing with CSP APIs, data structures and SLAs while providing a consistent and uniform experience to the enterprise; an interface that melds to the enterprise requirements. If the CSP changes their API or runtime environment it’s the portability solution provider’s responsibility, not the enterprise.

The price of these third-party solutions becomes the cost of risk shifting. For some this is necessary to reduce the risk profile to an acceptable level. For others the cost is too high leaving the choice of either accepting the risk directly or avoiding the cloud entirely.