Skip to main content
Tech Radar Pro
Tech Radar Gaming
Tech Radar Pro
TechRadar the business technology experts
Search TechRadar
View Profile
België (Nederlands)
Deutschland
North America
US (English)
Australasia
New Zealand
Expert Insights
Website builders
Web hosting
Best website builder
Best web hosting
Best office chairs
Best antivirus
Expert Insights
Recommended reading
How the hybrid work boom reshapes corporate security
The complexity trap: why cybersecurity must be simplified
Keeping your cloud secure with the Finops edge
How to defend your cloud environments: 7 major rules
The digital bedrock of a business holds the key to innovation with intelligence
Palo Alto firewall hack: network security policy management is no longer optional
AI powered cloud creates AI powered risks
CISOs are rethinking security in a fragmented cloud world
James Sturrock
27 June 2025
How CISOs can be secure in a fragmented cloud world
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
(Image credit: Shutterstock / Blackboard)
It was supposed to be the answer to IT’s flexibility dilemma. Hybrid cloud, with its blend of on-premises control and public cloud scalability, gave businesses the agility to respond to new demands without overhauling infrastructure. But what started as a strategic advantage has, for many CISOs, evolved into a patchwork of fragmented tools, siloed teams and visibility gaps.
The result is an increasingly difficult environment to secure. And the solution isn’t just more technology. It’s a rethink of how CISOs lead in a hybrid world.
James Sturrock
Social Links Navigation
Director of Systems Engineering at Nutanix.
Why the old playbook no longer works
In traditional data centers, security was built around well-defined perimeters. The rise of cloud computing forced a shift to more distributed security models. But hybrid cloud has created something altogether more complex — an environment where workloads move between clouds, teams manage different platforms, and security responsibilities blur across IT, DevOps and compliance.
You may like
How the hybrid work boom reshapes corporate security
The complexity trap: why cybersecurity must be simplified
Keeping your cloud secure with the Finops edge
This complexity undermines many of the assumptions baked into earlier security strategies. Tools that worked well in isolated environments struggle to deliver unified protection across platforms. Policies become inconsistent. Incident response slows down. Most concerning of all, blind spots develop — not out of negligence, but out of an inability to see and manage everything at once.
The challenge isn’t visibility. It’s integration
Many security leaders have responded by investing in more observability tools. But even with best-in-class dashboards and alerts, visibility alone doesn’t equal security. It’s not what you can see that protects your environment, but how quickly and intelligently you can act.
That’s where integration becomes essential. Security needs to be embedded into the fabric of hybrid infrastructure, not added on after deployment. This means consolidating policy controls, enabling workload portability without security drift, and ensuring that response actions can be automated and orchestrated across environments.
It also means designing security to work with the business, not against it. Hybrid strategies are often driven by performance or cost optimization goals. When security becomes a bottleneck, teams find workarounds, and that’s when risk increases.
Leadership starts with simplification
The most effective CISOs today are not simply technologists. They are architects of simplification. Instead of trying to manage complexity through sheer effort, they look for ways to reduce it at the source.
This might mean consolidating infrastructure platforms to reduce the number of control points. It could involve standardizing security policies across cloud and on-prem environments. It often requires working more closely with enterprise architects and business leaders to design security in from the beginning, rather than retrofitting it later.
Partnerships that bring infrastructure and security closer together can play a pivotal role here. For example, when hybrid cloud platforms are tightly integrated with next-generation firewall capabilities, CISOs gain more than visibility. They gain a consistent, policy-driven approach to security that travels with workloads, automates enforcement, and simplifies day-to-day operations.
Bringing security closer to the workload
Rather than layering security tools on top of an existing environment, an integrated approach embeds protection directly into the virtual network fabric, enabling precise control over how applications and data communicate across both public and private clouds.
Through virtual private cloud (VPC) capabilities, organizations can isolate and secure multitenant environments with greater confidence. This alignment offers a practical path forward for CISOs aiming to implement zero-trust principles.
Policies based on user identity, application behavior and contextual risk can be applied consistently, regardless of whether workloads reside in a data center or a hybrid multicloud setup. Continuous verification, least-privileged access, and deep threat inspection all become easier to manage when security is embedded at the infrastructure layer.
Importantly, this model supports automation. Using policy tags and centralized tools such as Palo Alto Networks Panorama, teams can manage firewall deployments across environments and streamline security operations within CI/CD pipelines. It’s a significant step toward security that adapts as the business scales and a compelling example of how simplification and strategic integration can go hand in hand.
From silos to synergy. A new operating model
What begins with tighter integration at the infrastructure level is now evolving into broader operational change. Organizations are starting to move away from fragmented roles and responsibilities. Instead of separate cloud and data center teams, some are creating platform teams that manage hybrid environments as a whole. And rather than relying on a patchwork of point security products, they are turning to solutions that bring networking, security and operations into a cohesive, centrally managed layer.
This improves efficiency and makes it possible to apply zero trust principles more effectively. When identities, workloads and data flows are managed consistently, the attack surface shrinks — not because there are fewer threats, but because there are fewer gaps to exploit.
Crucially, these organizations are moving from reactive security to proactive resilience. That’s the real goal in a hybrid world. You cannot prevent every breach, but you can design systems to detect, contain and recover more effectively. That’s what gives the business confidence to move faster without sacrificing safety.
Rethinking the role of the CISO
Hybrid cloud is becoming more entrenched as organizations balance cost, performance and regulatory demands. For CISOs, the new burning question is how to lead with hybrid cloud in a way that makes it secure by design.
This starts by embracing simplification, fostering collaboration, and embedding security into every layer of hybrid operations. It’s not easy. But it’s also not optional. Because in today’s environment, complexity is the greatest vulnerability, and clarity is the most powerful defense.
We’ve featured the best productivity.
This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsorsBy submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
James Sturrock
Social Links Navigation
Director of Systems Engineering at Nutanix.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.
How the hybrid work boom reshapes corporate security
The complexity trap: why cybersecurity must be simplified
Keeping your cloud secure with the Finops edge
How to defend your cloud environments: 7 major rules
The digital bedrock of a business holds the key to innovation with intelligence
Palo Alto firewall hack: network security policy management is no longer optional
Latest in Pro
61 million US Verizon customers could be at risk after hacker posts potentially genuine database online – here’s what you need to know
ClickFix fake error message malware spikes over 500%, takes second place as the most abused attack vector
I tested the EnGenius EOC655 bridge, an innovative product that combines Bluetooth and GPS
This new malware has developed a spooky way to tell AI-based detection methods to ignore it
SMBs are being hit by malicious productivity tools – Zoom and ChatGPT spoofed by hackers
British man behind ‘IntelBroker’ hacker group charged with stealing millions
Latest in Opinion
How data conversations unlock the transformative potential of AI
Democratized cybercrime: a new lower bar for hackers and higher stakes for security
DORA: reshaping UK’s financial ecosystem through cyber resilience
I tried a super-bright 83-inch OLED TV and now projectors are ruined for me
Good tech doesn’t have to be boring – from headphones to smart lights, here are my top 6 recommendations for colorful tech that’ll stand out from the crowd
Doctor Who is my #1 Disney+ recommendation – here’s why it’s my TV show of choice across all of time and space
LATEST ARTICLES
I hosted an 8-player Mario Kart World tournament at my office – here’s everything I needed to make it work
NYT Strands hints and answers for Saturday, June 28 (game #482)
Quordle hints and answers for Saturday, June 28 (game #1251)
NYT Connections hints and answers for Saturday, June 28 (game #748)
This tiny sensor will turn your Philips Hue lights into a home security system – and it’s cheap too
TechRadar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
Contact Future’s experts
Terms and conditions
Privacy policy
Cookies policy
Advertise with us
Web notifications
Accessibility Statement
Future US, Inc. Full 7th Floor, 130 West 42nd Street,
Please login or signup to comment
Please wait…