Cyber Enablement

Cybersecurity strategy, architecture, and enablement for business leaders

Cloud Migration Security: Modernize the Architecture, Not Just the Hosting

A legacy monolith transformed during cloud migration into segmented, observable, and resilient services.

A lift-and-shift migration can move applications quickly, but it also carries forward weak identity models, flat trust, unsupported software, fragile recovery, and opaque dependencies. Cloud adoption creates value when the operating and security architecture changes with the workload.

Executive takeaway

Use rehosting selectively as a transition state with an explicit modernization deadline. Before migration, define the target identity, network, data, logging, recovery, and ownership patterns. Do not recreate the data center inside a cloud account and call the program complete.

Architecture priorities

  • Identity first: federation, strong authentication, least privilege, workload identities, short-lived credentials, and emergency access.
  • Account and subscription structure: separate environments and business boundaries; centralize policy, logging, and billing without creating a single administrative blast radius.
  • Network design: minimize public exposure, control egress, segment by service and consequence, and treat private connectivity as transport—not trust.
  • Data governance: know where regulated and sensitive data can be stored, replicated, backed up, and accessed.
  • Observability: enable platform, identity, control-plane, network, and workload telemetry before production migration.
  • Resilience: design and test recovery across regions, accounts, identity failures, destructive administration, and provider-service dependencies.

Prioritized actions

  1. Classify workloads as retire, retain, rehost, replatform, refactor, or replace.
  2. Create paved-road landing zones and reusable deployment patterns.
  3. Remove embedded credentials and unsupported dependencies before or during migration.
  4. Define shared-responsibility ownership for every control.
  5. Time-box rehosting exceptions and fund the second phase of modernization.

Shawn’s perspective

Cloud does not automatically produce modern security. Its advantage is programmability: identity, policy, deployment, evidence, and recovery can become repeatable engineering systems. A migration that fails to use that advantage changes location more than risk.

Source

CISA Cloud Security Technical Reference Architecture v2

Shawn Maschino

Cybersecurity architect and independent analyst translating emerging technology, risk, and regulation into practical business decisions.


Browse the analysis library →