Cyber Governance3-minute read·Marcin Pajdzik·August 2025

Zero Trust and Cloud Security Assurance

Boards approve cloud migrations. They rarely have equivalent visibility into the access governance model that determines who can reach the workloads afterwards, or who is accountable for it.

A director does not need to understand identity providers or network segmentation to ask the right question. The right question is whether access to critical cloud workloads is owned, governed and reviewed.

How cloud changes the access question

Cloud migration changes the security boundary. Network location alone can no longer provide the assurance that traditional perimeter based models assumed, because users, workloads and services increasingly interact across multiple networks, environments and trust boundaries.

NIST, the US National Institute of Standards and Technology, defines Zero Trust as removing implicit trust based solely on physical or network location and shifting the focus of protection towards users, assets and resources. CISA, the US Cybersecurity and Infrastructure Security Agency, adds that Zero Trust builds on existing network protections. Firewalls, segmentation and private connections still matter, but network location alone should no longer determine whether access is trusted.

What Zero Trust asks of the board

Zero Trust provides a set of principles around which access governance can be built, covering who or what can reach a resource, under what conditions, and how that decision is enforced and reviewed.

Translated into board assurance, those principles become three questions for security leadership. Who is accountable for the policy governing access to our critical cloud workloads? Can management demonstrate that privileged and other high risk access to those workloads is limited to what is necessary? How frequently is that access reviewed, and what happens when exceptions or inappropriate access are identified?

A practical test for the board

If security leadership can answer these questions from routine board reporting, the access governance model is visible at board level. If answering them requires special preparation, there is an assurance gap between operational access management and board oversight.

Strong technical access controls do not, on their own, provide board assurance. The board's test is whether management can demonstrate through routine governance and reporting that access to critical cloud workloads is controlled, reviewed and accountable.

How this affects your organisation

If your organisation has completed or is planning a cloud migration, the question of access governance is already live. The board should expect a named owner, a documented policy, and evidence that privileged access is controlled and regularly reviewed.

A board that cannot demonstrate who owns access to its critical cloud workloads, and how that access is reviewed, does not have effective oversight of the migration it approved, regardless of how well the underlying controls are run.

Does your cloud migration have an access governance model the board can account for?

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.