Newsletter Subscribe
Enter your email address below and subscribe to our newsletter


Enterprises of all sizes and across sectors are steadily embracing cloud computing and its various applications and benefits. Some companies are still more comfortable using the private cloud, others have embraced the public cloud, while a growing number are adopting a hybrid solution. While concerns around security, ownership and accessibility of data persist, there are indications that CIOs and business leaders worldwide are becoming more confident in the cloud and trusting of third party providers of cloud services. Gartner has forecasted that by the end of 2016, more than 50 percent of Global 1000 companies will have stored customer-sensitive data in the public cloud.
Murky Waters
Yet as adoption increases, new questions, concerns and conflicts arise. For many local enterprises, one of the most critical questions is around the ownership of data: in cases where a company’s data is stored on the servers of a third party cloud provider, for example, does the data still belong to the company that is outsourcing the storage function?
The answer is undoubtedly yes – that data still belongs to the company, and the third party provider is merely the custodian of that data for a specified time. The third party provider is simply there to store the data and provide a specific service, and has no legal claim to – or authority over – the data.
Held to Ransom
Unfortunately, it can be extremely difficult to reclaim the data that is being stored by the third party provider in the event of a termination of contract. Not only can it be difficult, but it can also prove to be a hugely expensive exercise.
In some instances, companies are literally ‘held to ransom’ by third party providers, and can find themselves locked into lengthy contracts that they simply cannot afford to terminate. By way of example, SYNAQ recently had a prospective client who wanted to switch to its services. This client received a staggering bill of R790,000 from their existing third party provider to export the company’s 7.5TB of data! To put this into context, R790 000 for R7.5TB of data translates into R102 per GB – which is many multiples more than you’d pay for the associated Internet traffic or the cost of storage.
Smart Choices
While this is a very real and serious risk associated with cloud computing, it can be mitigated. Firstly, the most obvious and important step is to be extremely careful and diligent when selecting a third party provider to store and manage your data.
For example, companies should be checking what the potential supplier’s policy is around returning data, the associated charges, and what format it is provided in. In addition, best practices should be verified and ensured, including the following: that charge is based on time and material and not the amount of data stored; data is provided in open standards format that can be easily imported into other platforms, and finally, the service provider can’t retain or withhold your data for any reason.
Watertight Agreement
The other element to consider is the service level agreement (SLA). According to the purpose for which the data is processed, it is essential, for example, to agree on binding service levels for availability and data recovery. If necessary, this can be safeguarded by attaching fixed penalties in the event of non-compliance with the agreed service levels. Critically, upon termination of the contract, the orderly return of data to the company/user should be ensured.
This requires periods of notice for the company to be able to take the necessary measures to ensure the availability and further processing of data – and the form in which the data is to be delivered to the company must also be ascertained.
Ultimately, it is the company’s responsibility to ensure that the right third party service provider is selected, because responsibility for the protection of information lies with the company itself. Once data has been moved off to the servers – and the control of – a third party, the company in question needs to be 100% sure not only of the ability of that provider/operator to provide a secure service, but also to act with integrity and honour all agreements and contracts. Companies therefore need to ensure that any contracts entered into with third party providers are fair and agreeable to both parties before any service commences.
By Yossi Hasson, CEO of SYNAQ