Back to Field Notes
Cloud & SASE/Field Note

Multi-Cloud Security — The Honest Version

You are multi-cloud whether you planned to be or not. The only choice is whether your security strategy reflects that reality.

Author

Sofia Reyes

Distinguished Architect, Zero Trust Practice

Published

February 24, 2026

Read

9 min

Share
AI-generated illustration of a shipping terminal facility
AI-generated illustration of a shipping terminal facility
Key Takeaways
  • 01Virtually every enterprise is multi-cloud — through acquisitions, line-of-business choices, SaaS dependencies, the occasional CTO change of heart. Pretending otherwise produces a security strategy that does not match the estate.
  • 02Cross-cloud common controls: one IdP federated to every cloud, one ingest pipeline to one SIEM with normalized schema, one CNAPP covering all clouds equally, one secrets management plane with federated trust, consistent egress policy (even if implementation differs).
  • 03Native primitives are usually better than third-party portability layers: Security Hub for AWS, Defender for Cloud for Azure, Security Command Center for GCP. Feed them all into the common pipeline. Use the natives without being trapped by them.
  • 04Real multi-cloud requires three sets of expert knowledge or three sets of generalist 'good enough.' Do not pretend one team can be deep on all three; specialize within the team and rotate juniors across to build breadth.

After a decade of cloud adoption, virtually every enterprise is multi-cloud — through acquisitions, line-of-business choices, SaaS dependencies, and the occasional CTO change of heart. Pretending otherwise leads to a security strategy that does not match the estate.

The cross-cloud common controls

  • 01Identity — one identity provider, federated to every cloud
  • 02Logging — one ingest pipeline to one SIEM, normalized schema
  • 03Posture — one CNAPP that covers all clouds equally
  • 04Secrets — one secrets management plane, federated trust
  • 05Network — consistent egress policy, even if implementation differs

Where to allow per-cloud divergence

Native primitives are usually better than third-party portability layers. Use AWS Security Hub for AWS-native correlation, Defender for Cloud for Azure-native, Security Command Center for GCP — but feed them all into the common pipeline. The trick is using the natives without being trapped by them.

Skill burden

Real multi-cloud requires three sets of expert knowledge or three sets of generalist 'good enough.' Do not pretend one team can be deep on all three; specialize within the team and rotate juniors across to build breadth.

#Multi-Cloud#AWS#Azure#GCP

/WRITTEN_BY

Sofia Reyes

Distinguished Architect, Zero Trust Practice · Alexa Cybersecurity