Unlocking Cloud Potential: Architectural Strategies and Security Paradigms
CIOREVIEW >> Microsoft >> NEWS

Microsoft

Carlos Fernández, Cloud Solutions Architect, Fernando Fierro, Cloud Solutions Architect and Adriana Gomes, Director of Cloud Architectures Data & AI

Unlocking Cloud Potential: Architectural Strategies and Security Paradigms

Carlos Fernández, Cloud Solutions Architect, Fernando Fierro, Cloud Solutions Architect and Adriana Gomes, Director of Cloud Architectures Data & AI
Carlos Fernández, Cloud Solutions Architect, Fernando Fierro, Cloud Solutions Architect and Adriana Gomes, Director of Cloud Architectures Data & AI, Microsoft

Organizations around the world are aiming to improve efficiency, disrupt customer experience with innovative, tailored, personalized, and relevant offers to end users, customers, and citizens, and build new business models for revenue growth in their industries.  

Cloud technologies are the foundation to enable digital capabilities and to fasten value realization of business goals while moving forward in the digital transformation journey. AI is shaping the future of every single industry, accelerating the pace of that journey. 

One of the frequent challenges while adopting cloud services is the lack of or not completely defined technology strategy, on which many questions should be addressed to decide on technologies, architecture, and evolution plans for applications, data platform architecture, infrastructure, security, and operational frameworks. These definitions are inevitably linked to cultural changes and how to democratize data-driven decision-making processes within organizations. 

For organizations with on-premises infrastructure, migrating to the cloud has different approaches: 

● Hybrid cloud (mixed at least one on-premises, connected to only one cloud provider, and (optional) bare-metal or virtual environment connected to these on-premises or the cloud Provider). 

● Multi-cloud (similar to hybrid but adding connection to more than one cloud provider). 

Designing landing zone architecture that includes network connectivity, reliability according to workload requirements, security, identity and resource management is part of the early stage of migration to the cloud and has several considerations in architecture (on-premises infrastructure and cloud-design considerations, the transformation of traditional operating model to a new one which requires reskilling and processes) to evaluate according to different scenarios. 

Network Topology 

When connecting on-premises to the cloud, network connectivity topology Hub-and-Spoke or SD-WAN options are the two more commonly used.  

Both approaches provide a central point of connectivity, security, and traffic management. However, SD-WAN provide increased flexibility, operational simplicity, and greater scalability; being more suited for globally distributed large scale deployments.    

  ​When considering the broader perspective, accessing cloud services within your virtual network from on-premises is achievable through a dedicated connection, ensuring privacy and security.  

Public clouds were initially conceived to offer services such as computing power or storage to the general public over the Internet. However, as cloud technology matured and organizations became more comfortable with it, public cloud providers started to offer options for hosting private workloads as well, thus becoming an extension of any organization. While traditional cross-premises connectivity methods like VPNs remain effective, many organizations today foster enduring partnerships with one or multiple carriers, availing dedicated links or internet services. These existing relationships can be seamlessly harnessed to establish dedicated connections with cloud infrastructure while ensuring predictable network performance, low latency access, higher reliability, and enhanced security by bypassing the public Internet. Because of these benefits, dedicated connections are predominantly the primary means of connecting public clouds to on-premises infrastructure and can be leveraged in Hub-and-Spoke or SD-WAN topologies.  

Hosting private workloads on public clouds entails organizations having the opportunity to bring their own addressing space when constructing their virtual networks, an often-overlooked aspect that sparks controversy. This means organizations can define and manage their own IP addressing scheme using public and private (RFC 1918) addresses within the cloud environment, aligning it with their existing network infrastructure. Upon provisioning, a compute resource, for example, is assigned an IP address belonging to the IP range defined by the organization in a virtual network. In major public clouds, this is also possible for all cloud services. Special interfaces can also be allocated for cloud services, such as storage repositories or web apps within a virtual network. This assigns IP addresses belonging to the organization's defined IP range to the cloud services, ensuring a private and secure connection between clients and the cloud services. 

When considering the broader perspective, accessing cloud services within your virtual network from on-premises is achievable through a dedicated connection, ensuring privacy and security. 

Now, as the adoption of IPv6 continues to grow globally, IPv6 support in public clouds has become increasingly important. Major public cloud providers offer comprehensive IPv6 support, allowing users to deploy dual-stack (IPv4/IPv6) or, in some cases, IPv6 only resources within their cloud environments. Therefore, organizations can leverage the benefits of IPv6, such as a larger addressing space, more efficient routing and enhanced security features, among others. 

Security Approach  

In this new digital era, the concept of perimeter has changed. The traditional perimeter was conceived as a single corporate network protected by security solutions like firewalls, proxies and more; however, the new perimeter is beyond that. Now users work from a variety of locations, personal and enterprise devices, on-premises, and cloud platforms.   

To shift into this new reality, organizations can have support from security frameworks, IT regulations, industry trends and other security controls that aim to enhance cybersecurity. The zero trust methodology adopts the principle ‘never trust, always verify’ which means that every access from every identity needs to be verified from the authentication perspective to the level of access.  

During the pandemic, organizations had to implement infrastructure that they had never imagined; I remember some customers buying expensive devices and applications to provide access to users working from home, and other customers realized they did not have the basic requirements to enable the workforce to work remotely. Others had to work on-site despite the health crisis. Zero trust methodology helps organizations to protect their entire digital state against threats coming from a single corporate network or micro perimeters like single identities in front of devices.  

In this new digital era is critical to develop a strong strategy that allows every organization to work from anywhere, from any device, any platform without compromising the security and not only the security for the user but the applications and other pillars as well. Some organizations started to implement a security strategy for identities and devices, as well as plan to protect data, applications, and infrastructure. Other organizations have invested several hours in modernizing applications that support cloud protocols and get all the benefits of cloud security.  

The reality is that traditional corporate network perimeter has evolved; the new global perimeter requires technical experts to implement reliable connectivity, good performance and strong security controls.   

 

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.