top of page

NIST Warns Multi-Cloud Adoption is Creating New Security and Compliance Challenges

  • 15 hours ago
  • 2 min read


As organisations continue to adopt multi-cloud strategies to improve resilience and reduce reliance on a single provider, the US National Institute of Standards and Technology (NIST) has warned that managing security across multiple cloud platforms introduces significant operational and compliance risks.


In a recent report, NIST identified 23 cyber security challenges unique to multi-cloud environments, highlighting concerns around identity management, vulnerability management, incident response, disaster recovery and regulatory compliance. While using multiple cloud service providers (CSPs) can improve availability and business continuity, it also increases complexity by requiring organisations to manage different security models, tools and shared responsibility frameworks simultaneously.


One of the biggest challenges is maintaining consistent identity and access management across different cloud platforms. Each provider uses its own authentication and authorisation mechanisms, making it difficult to enforce standardised access controls, verify multi-factor authentication (MFA) settings and maintain visibility of privileged accounts across the entire environment. NIST also highlighted concerns around vulnerability management. Cloud providers often use different reporting formats, severity ratings and remediation processes, making it harder for security teams to maintain a unified patching and risk management strategy. In some cases, customers have limited ability to perform independent vulnerability assessments because direct access to underlying cloud infrastructure is restricted by the provider.


Incident response and recovery become equally challenging in multi-cloud environments. Security teams frequently have to work with different logging formats, monitoring tools and notification processes, slowing investigations and complicating threat detection. Disaster recovery planning can also be difficult when providers offer limited visibility into their internal resilience testing, recovery processes and contingency arrangements. Data protection and regulatory compliance present additional risks. Organisations operating across multiple cloud providers must ensure that encryption, retention policies and security controls are applied consistently. Variations in how providers manage and store data can make it more difficult to demonstrate compliance with regulations such as GDPR and industry-specific security requirements. The challenge is often compounded by the need to gather assurance evidence and security documentation from multiple providers.


The findings reflect a growing industry trend. As organisations increasingly adopt cloud-first strategies, security teams are discovering that resilience gained through provider diversity can be offset by greater management complexity. Without effective governance and visibility, organisations risk creating fragmented security controls across their cloud estate.


The UK National Cyber Security Centre (NCSC) advises organisations to approach cloud security through strong governance, clear accountability and a thorough understanding of the shared responsibility model between the customer and cloud provider.

Key NCSC recommendations include:

  • Implement strong identity and access management controls, including MFA for all cloud services.

  • Clearly define security responsibilities between the organisation and each cloud provider.

  • Maintain visibility of cloud assets, configurations and security controls across all environments.

  • Assess providers against the NCSC Cloud Security Principles, including audit, governance, resilience and operational security requirements.

  • Protect data in transit and at rest using appropriate encryption and access controls.

  • Regularly test business continuity and disaster recovery plans to ensure critical services remain available during outages or cyber incidents.


As multi-cloud adoption continues to grow, organisations must balance the benefits of resilience and flexibility against the added security complexity. Effective governance, centralised visibility, strong identity management and consistent security controls across all cloud providers will be critical to managing risk and maintaining compliance.

bottom of page