
Alex Goller at Illumio explains how cloud teams can be the secret weapon in securing networks
Cloud adoption is now undeniably the norm across all industries. Most companies have already migrated to the cloud or are in an advanced stage of their migration.
The majority of network and security teams are familiar with the challenges of securing distributed networks. However, many are still struggling with traditional security practices that are geared towards static, on-premises environments.
Maintaining visibility and control across expanding infrastructure becomes increasingly difficult as these older approaches fail to keep pace with the more dynamic nature of the cloud.
Understandably, most organisations rely on their security operations (SecOps) teams to address these critical challenges. But these teams often lack deep technical knowledge of cloud-specific security features, frameworks, and tools.
On the other hand, cloud operations (CloudOps) teams—who manage these environments daily—are often left to operate with little guidance on security, leading to potential vulnerabilities. The gap between these two groups is dangerous, as security controls can’t be enforced without deep integration into cloud workflows.
With the two teams focused on their own domains, closing this gap requires a careful approach by the most senior IT and security leaders. Opening channels of communication and providing the right tools can bridge the divide and ensure that both teams benefit from each other’s expertise. This collaboration ensures that security doesn’t become an afterthought or a roadblock to cloud innovation but is instead an integrated component of cloud operations.
A lack of communication between security and cloud teams is a common hinderance to effective cloud security due to both teams operating in silos. This can lead to a ‘us vs. them’ mentality between the two departments.
Negative sentiment evolves when security may view the cloud teams as a reckless group that moves too quickly, while cloud teams may see security as obstructive and overly cautious. Operationally, this can cause friction whenever new assets are deployed or new security policies are introduced.
According to research from Vanson Bourne, three-quarters of IT and security decision-makers (74 percent) think their organisation’s security function slows down cloud adoption. Nearly half (47 percent) also said they are seeking to improve collaboration between security teams and application developers.
Breaking this cycle requires fostering a culture of collaboration. Establish regular meetings where security and cloud teams openly discuss challenges and share knowledge. Cloud teams need to be involved in security discussions from the outset rather than being treated as an afterthought.
Establishing a culture of open dialogue helps both sides understand each other’s priorities and limitations. Security teams must grasp the technical nuances of the cloud environment, while cloud teams need to understand the broader security strategy. This mutual understanding will enable more effective collaboration.
It’s crucial that security doesn’t disrupt business operations or interfere with cloud teams’ workflows. Such disruptions often lead to significant pushback from cloud teams. Instead, security teams should aim to integrate their measures in a way that complements operations, becoming an integral part of cloud management rather than a hindrance.
Cloud security can also be strengthened by giving cloud teams more ownership over security. Historically, central security teams held all responsibility, but with the cloud’s distributed nature, this model is no longer effective. Cloud teams need direct access to the security tools that allow them to protect their environments in real-time.
Providing self-service security tools empowers cloud teams to identify and respond to threats swiftly without waiting for intervention from a central security team. These tools should include features like automated policy enforcement, logging, and real-time anomaly detection. By decentralising security tasks, cloud teams can integrate security more fluidly into their daily workflows.
Expanding ownership doesn’t mean security is compromised. Central teams still retain oversight through governance and visibility, but cloud teams become active participants in the security process. This distributes responsibility while ensuring cloud experts have the resources to secure their domain effectively.
As cloud adoption continues, the need for advanced security strategies becomes increasingly apparent. A key approach to securing cloud environments is the Zero Trust strategy.
Zero Trust operates on the principle of "never trust, always verify." This means continuously verifying the identity and permissions of every user, device, and application accessing network resources. This is especially important in the cloud, where multiple teams operate with a high degree of autonomy.
Microsegmentation is a fundamental starting point on this journey and serves as the true foundation of Zero Trust. It involves dividing the network into smaller, isolated segments or "micro-perimeters." This minimises lateral movement in the event of a breach, containing threats to a small portion of the network rather than allowing them to spread freely.
As the frequency and pervasiveness of cyber-attacks increases, microsegmentation has also become an essential part of a defense-in-depth strategy. The Forrester Wave™: Microsegmentation Solutions, Q3 2024 report suggests that we are now “living in the golden age of microsegmentation” with adoption spreading to “microservices architecture, public cloud, operational technology (OT) environments, and even layer seven.”
Cloud-native solutions such as Zero Trust Segmentation (ZTS) provide robust support for segmentation through virtual network firewalls, microservices security policies, and automated rule enforcement.
These tools integrate seamlessly with the cloud, enabling businesses to implement Zero Trust and segmentation without disrupting operations. Additionally, cloud-native identity and access management (IAM) tools, such as those from AWS and Azure, can enforce strict identity verification protocols. These tools ensure that only authorised entities access specific cloud resources, thereby limiting exposure to threats.
Because they were designed for the dynamic nature of the cloud rather than adapted from traditional static controls, cloud-native approaches like ZTS also deliver a high-level of flexibility and scalability. Almost all (95%) respondents in the Vanson Bourne research highlighted the need for security to match the speed of cloud adoption as a key requirement.
With the latest advancements in AI, APIs, and third-party integration, cloud environments will only continue to grow more complex. To keep pace with these developments, organisations must deliver better alignment between their cloud and security teams to reduce friction that can slow down innovation or introduce security gaps.
The challenge for IT and security leaders is to provide the control and visibility that the security team requires, while simultaneously providing cloud teams the automation, speed, simplicity, and independence that they need to do their job well. Achieving this requires a two-pronged approach that includes both establishing clear lines of communication and a collaborative culture, backed with security tools like ZTS that enable cross-team collaboration.
Alex Goller is Cloud Security Solutions Architect at Illumio
Main image courtesy of iStockPhoto.com and Vitalii Gulenok
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543