
- 01Virtually every enterprise is multi-cloud — through acquisitions, line-of-business choices, SaaS dependencies, the occasional CTO change of heart. Pretending otherwise produces a security strategy that does not match the estate.
- 02Cross-cloud common controls: one IdP federated to every cloud, one ingest pipeline to one SIEM with normalized schema, one CNAPP covering all clouds equally, one secrets management plane with federated trust, consistent egress policy (even if implementation differs).
- 03Native primitives are usually better than third-party portability layers: Security Hub for AWS, Defender for Cloud for Azure, Security Command Center for GCP. Feed them all into the common pipeline. Use the natives without being trapped by them.
- 04Real multi-cloud requires three sets of expert knowledge or three sets of generalist 'good enough.' Do not pretend one team can be deep on all three; specialize within the team and rotate juniors across to build breadth.
After a decade of cloud adoption, virtually every enterprise is multi-cloud — through acquisitions, line-of-business choices, SaaS dependencies, and the occasional CTO change of heart. Pretending otherwise leads to a security strategy that does not match the estate.
The cross-cloud common controls
- 01Identity — one identity provider, federated to every cloud
- 02Logging — one ingest pipeline to one SIEM, normalized schema
- 03Posture — one CNAPP that covers all clouds equally
- 04Secrets — one secrets management plane, federated trust
- 05Network — consistent egress policy, even if implementation differs
Where to allow per-cloud divergence
Native primitives are usually better than third-party portability layers. Use AWS Security Hub for AWS-native correlation, Defender for Cloud for Azure-native, Security Command Center for GCP — but feed them all into the common pipeline. The trick is using the natives without being trapped by them.
Skill burden
Real multi-cloud requires three sets of expert knowledge or three sets of generalist 'good enough.' Do not pretend one team can be deep on all three; specialize within the team and rotate juniors across to build breadth.


