CISOs are rethinking security in a fragmented cloud world

CISOs are rethinking security in a fragmented cloud world

Skip to main content

Tech Radar Pro

Tech Radar Gaming

Tech Radar Pro

TechRadar the business technology experts

Search TechRadar

View Profile

België (Nederlands)

Deutschland

North America

US (English)

Australasia

New Zealand

Expert Insights

Website builders

Web hosting

Best website builder
Best web hosting
Best office chairs
Best antivirus
Expert Insights

Recommended reading

How the hybrid work boom reshapes corporate security

The complexity trap: why cybersecurity must be simplified

Keeping your cloud secure with the Finops edge

How to defend your cloud environments: 7 major rules

The digital bedrock of a business holds the key to innovation with intelligence

Palo Alto firewall hack: network security policy management is no longer optional

AI powered cloud creates AI powered risks

CISOs are rethinking security in a fragmented cloud world

James Sturrock

27 June 2025

How CISOs can be secure in a fragmented cloud world

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

(Image credit: Shutterstock / Blackboard)

It was supposed to be the answer to IT’s flexibility dilemma. Hybrid cloud, with its blend of on-premises control and public cloud scalability, gave businesses the agility to respond to new demands without overhauling infrastructure. But what started as a strategic advantage has, for many CISOs, evolved into a patchwork of fragmented tools, siloed teams and visibility gaps.

The result is an increasingly difficult environment to secure. And the solution isn’t just more technology. It’s a rethink of how CISOs lead in a hybrid world.

James Sturrock
Social Links Navigation

Director of Systems Engineering at Nutanix.
Why the old playbook no longer works
In traditional data centers, security was built around well-defined perimeters. The rise of cloud computing forced a shift to more distributed security models. But hybrid cloud has created something altogether more complex — an environment where workloads move between clouds, teams manage different platforms, and security responsibilities blur across IT, DevOps and compliance.

You may like

How the hybrid work boom reshapes corporate security

The complexity trap: why cybersecurity must be simplified

Keeping your cloud secure with the Finops edge

This complexity undermines many of the assumptions baked into earlier security strategies. Tools that worked well in isolated environments struggle to deliver unified protection across platforms. Policies become inconsistent. Incident response slows down. Most concerning of all, blind spots develop — not out of negligence, but out of an inability to see and manage everything at once.

The challenge isn’t visibility. It’s integration
Many security leaders have responded by investing in more observability tools. But even with best-in-class dashboards and alerts, visibility alone doesn’t equal security. It’s not what you can see that protects your environment, but how quickly and intelligently you can act.
That’s where integration becomes essential. Security needs to be embedded into the fabric of hybrid infrastructure, not added on after deployment. This means consolidating policy controls, enabling workload portability without security drift, and ensuring that response actions can be automated and orchestrated across environments.
It also means designing security to work with the business, not against it. Hybrid strategies are often driven by performance or cost optimization goals. When security becomes a bottleneck, teams find workarounds, and that’s when risk increases.
Leadership starts with simplification
The most effective CISOs today are not simply technologists. They are architects of simplification. Instead of trying to manage complexity through sheer effort, they look for ways to reduce it at the source.
This might mean consolidating infrastructure platforms to reduce the number of control points. It could involve standardizing security policies across cloud and on-prem environments. It often requires working more closely with enterprise architects and business leaders to design security in from the beginning, rather than retrofitting it later.
Partnerships that bring infrastructure and security closer together can play a pivotal role here. For example, when hybrid cloud platforms are tightly integrated with next-generation firewall capabilities, CISOs gain more than visibility. They gain a consistent, policy-driven approach to security that travels with workloads, automates enforcement, and simplifies day-to-day operations.
Bringing security closer to the workload
Rather than layering security tools on top of an existing environment, an integrated approach embeds protection directly into the virtual network fabric, enabling precise control over how applications and data communicate across both public and private clouds.
Through virtual private cloud (VPC) capabilities, organizations can isolate and secure multitenant environments with greater confidence. This alignment offers a practical path forward for CISOs aiming to implement zero-trust principles.
Policies based on user identity, application behavior and contextual risk can be applied consistently, regardless of whether workloads reside in a data center or a hybrid multicloud setup. Continuous verification, least-privileged access, and deep threat inspection all become easier to manage when security is embedded at the infrastructure layer.
Importantly, this model supports automation. Using policy tags and centralized tools such as Palo Alto Networks Panorama, teams can manage firewall deployments across environments and streamline security operations within CI/CD pipelines. It’s a significant step toward security that adapts as the business scales and a compelling example of how simplification and strategic integration can go hand in hand.
From silos to synergy. A new operating model
What begins with tighter integration at the infrastructure level is now evolving into broader operational change. Organizations are starting to move away from fragmented roles and responsibilities. Instead of separate cloud and data center teams, some are creating platform teams that manage hybrid environments as a whole. And rather than relying on a patchwork of point security products, they are turning to solutions that bring networking, security and operations into a cohesive, centrally managed layer.
This improves efficiency and makes it possible to apply zero trust principles more effectively. When identities, workloads and data flows are managed consistently, the attack surface shrinks — not because there are fewer threats, but because there are fewer gaps to exploit.
Crucially, these organizations are moving from reactive security to proactive resilience. That’s the real goal in a hybrid world. You cannot prevent every breach, but you can design systems to detect, contain and recover more effectively. That’s what gives the business confidence to move faster without sacrificing safety.
Rethinking the role of the CISO
Hybrid cloud is becoming more entrenched as organizations balance cost, performance and regulatory demands. For CISOs, the new burning question is how to lead with hybrid cloud in a way that makes it secure by design.
This starts by embracing simplification, fostering collaboration, and embedding security into every layer of hybrid operations. It’s not easy. But it’s also not optional. Because in today’s environment, complexity is the greatest vulnerability, and clarity is the most powerful defense.
We’ve featured the best productivity.
This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsorsBy submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

James Sturrock

Social Links Navigation

Director of Systems Engineering at Nutanix.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

How the hybrid work boom reshapes corporate security

The complexity trap: why cybersecurity must be simplified

Keeping your cloud secure with the Finops edge

How to defend your cloud environments: 7 major rules

The digital bedrock of a business holds the key to innovation with intelligence

Palo Alto firewall hack: network security policy management is no longer optional

Latest in Pro

61 million US Verizon customers could be at risk after hacker posts potentially genuine database online – here’s what you need to know

ClickFix fake error message malware spikes over 500%, takes second place as the most abused attack vector

I tested the EnGenius EOC655 bridge, an innovative product that combines Bluetooth and GPS

This new malware has developed a spooky way to tell AI-based detection methods to ignore it

SMBs are being hit by malicious productivity tools – Zoom and ChatGPT spoofed by hackers

British man behind ‘IntelBroker’ hacker group charged with stealing millions

Latest in Opinion

How data conversations unlock the transformative potential of AI

Democratized cybercrime: a new lower bar for hackers and higher stakes for security

DORA: reshaping UK’s financial ecosystem through cyber resilience

I tried a super-bright 83-inch OLED TV and now projectors are ruined for me

Good tech doesn’t have to be boring – from headphones to smart lights, here are my top 6 recommendations for colorful tech that’ll stand out from the crowd

Doctor Who is my #1 Disney+ recommendation – here’s why it’s my TV show of choice across all of time and space

LATEST ARTICLES

I hosted an 8-player Mario Kart World tournament at my office – here’s everything I needed to make it work

NYT Strands hints and answers for Saturday, June 28 (game #482)

Quordle hints and answers for Saturday, June 28 (game #1251)

NYT Connections hints and answers for Saturday, June 28 (game #748)

This tiny sensor will turn your Philips Hue lights into a home security system – and it’s cheap too

TechRadar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

Contact Future’s experts

Terms and conditions

Privacy policy

Cookies policy

Advertise with us

Web notifications

Accessibility Statement

Future US, Inc. Full 7th Floor, 130 West 42nd Street,

Please login or signup to comment

Please wait…

Read More…