John Bradshaw, Akamai’s Director of Cloud Computing Technology and Strategy EMEA, explores the critical challenge for CISOs in achieving consistent security across increasingly complex multi-cloud deployments, without compromising agility or becoming tied to specific vendors.
Cloud concentration is becoming one of the most pressing risks facing organisations today. While the adoption of multi-cloud strategies is on the rise, with over 92% of large enterprises now operating in a multi-cloud environment, the security and operational challenges for CISOs are growing in parallel. Chief among these is the issue of vendor lock-in.

Vendor lock-in is no longer a hypothetical threat; it’s a hard commercial reality. Many cloud contracts, especially those with hyperscalers, are complex, opaque, and heavily skewed in favour of the provider. Once signed, businesses often find themselves locked into long-term agreements that are expensive (and technically daunting) to exit. These arrangements are rarely presented as such at the outset of commercial conversations.
Now, consider the implications of being tied into multiple such contracts, each with limited flexibility and punitive exit costs. This is difficult enough for a CFO, not to mention the critical questions it raises for CISOs such as: How do you maintain agility? How do you retain control? How do you manage the commercial risk?
One answer lies in the concept of economic sovereignty, which means having the ability to make independent, cost-efficient decisions about where and how workloads are run. Like national sovereignty in policymaking, this organisational autonomy is becoming essential in avoiding the systemic risks of cloud dependency.
But before we look at how to build this kind of resilience, it’s important to understand what’s at stake and why getting it right is not just a matter of strategy, but, in some cases, company survival.
What are the risks facing CISOs?
For CISOs navigating a multi-cloud landscape, the risks are layered and increasingly complex. One of the most visible threats remains the headline-grabbing cyberattack such as breaches in which sensitive data is compromised due to gaps in security between cloud providers. With such incidents growing in both frequency and prominence, maintaining robust defences against these threats continues to be a top priority.
Yet beyond these high-profile attacks lies a more persistent challenge: achieving consistent security standards across a fragmented cloud environment. The core principles of cybersecurity, often defined by the CIA triad (Confidentiality, Integrity, and Availability) are difficult to uphold when systems are distributed across different vendors. Availability, in particular, becomes vulnerable. Security solutions and protocols can vary significantly between providers, and these mismatches create gaps. These gaps are precisely the weaknesses that attackers look to exploit.
These challenges often emerge well after initial onboarding. By that point, vendor lock-in has taken hold, and for organisations with multiple cloud platforms, the cost of moving away from providers that no longer serve the business can be prohibitive.
For CISOs, the implications are clear. Cloud risk is no longer limited to data breaches or technical resilience. It increasingly encompasses strategic and financial considerations. Cost predictability, contractual flexibility and the freedom to adapt must be core criteria when assessing any multi-cloud ecosystem and not just technical performance alone.
What makes this an issue for CISOs, and not just a business concern?
CISOs are there to ensure the survivability and resilience of the business. Their role requires managing a wider risk profile and supporting the CFO in ensuring the organisation has a plan for commercial risks and threats to operations.
Security isn’t just about preventing attacks – it is about making sure the organisation has visibility to a wide range of threats that may impact operations.
Building resilience into multi-cloud strategies
Given the range of risks outlined above, it’s clear that CISOs must take a far more strategic and forward-looking approach when evaluating their organisation’s multicloud systems. This isn’t just about performance or uptime. It’s about preparing for disruption, especially the kind that arrives without warning.
What happens, for example, if a cloud provider is suddenly subjected to new government tariffs, regulatory scrutiny, or even outright bans? These may seem like distant scenarios, but the geopolitics of technology in today’s world are moving quickly. Cloud infrastructure is increasingly a national security concern, and providers can quickly find themselves caught in the crossfire. For CISOs, that means planning for exits even before a contract is signed.
The principle is simple: never get so entrenched in a provider that leaving becomes impossible. Or, to borrow from the 1995 film Heat, “Don’t let yourself get attached to anything you are not willing to walk out on in 30 seconds flat if you feel the heat around the corner.” It may be a Hollywood line, but the underlying advice holds, particularly when vendor dependencies threaten organisational agility.
The consistency conundrum
However, beyond contracts and costs, there is the more technical (and equally critical) challenge of maintaining security while ensuring efficient data synchronisation across clouds. This is where CISOs must make decisions grounded in the business’s core objectives and risk tolerance.
At the heart of this decision lies the trade-off between strong consistency and eventual consistency. Strong consistency ensures that data is updated immediately and is accessible in real time across the entire system. No gaps, no delays. For highly sensitive or time-critical environments (say, financial services) this is non-negotiable. A bank processing multiple transactions, for instance, cannot afford latency or duplication.
Eventual consistency, on the other hand, allows for a more relaxed approach. Data updates propagate gradually throughout the system, meaning some users may temporarily see outdated or incomplete information. This model may work well in sectors where immediacy is less critical (content delivery or some retail environments) but it introduces delays and uncertainty that security teams must manage.
Choosing between these models isn’t just a matter of technical preference. It’s a strategic decision that must align with the organisation’s core operations, compliance obligations, and appetite for risk. The key task for CISOs is to identify where strong consistency is essential and where eventual consistency may be acceptable, and then architect the multi-cloud environment accordingly.
Ultimately, consistency is fundamental to resilience. Without it, a multi-cloud strategy risks becoming a patchwork of blind spots.
What does the path forward look like?
The answers for CISOs lie in designing for flexibility and portability from the outset. By adopting application platforms that are built to operate seamlessly across multiple cloud environments, organisations can regain control over their infrastructure. These platforms enable consistent security policies, reduce integration complexity, and most critically, ensure that data and workloads remain portable.
Rather than being locked into a single provider’s ecosystem, businesses gain the freedom to shift workloads as needed, whether for cost, performance, regulatory, or strategic reasons. At the core of this strategy is the principle of interoperability.
Platforms that support open standards, and which are designed to function across diverse cloud systems, offer CISOs the ability to enforce a consistent security posture without sacrificing the benefits of a multi-cloud approach. This reduces the risk of misalignment between environments and closes the gaps that attackers so often exploit.
Equally important is ensuring that any platform adopted does not artificially restrict data mobility. Providers that allow customers to retain control over their data and move it freely across environments, are essential partners in building true operational resilience.
The goal is not to avoid complexity, but to manage it intelligently. With the right frameworks in place, CISOs can navigate the challenges of a fragmented cloud landscape, striking a balance between security, agility, and long-term freedom of choice.
Profile photo of John Bradshaw
AdobeStock_1095166637
AdobeStock_1226129412
AdobeStock_1283345270

