Industry News
Cloud, compliance, and blind spots
For years, the cloud was presented as a given. Quick to deploy, flexible, cost-effective. For many tech companies, the issue was no longer really up for debate: they had to move fast, deliver, and scale. Compliance would come later.
By 2026, this line of reasoning will reveal its limitations. Not because the cloud is being called into question, but because compliance audits and resilience requirements are highlighting something many organizations had not anticipated: a loss of visibility into their own infrastructure.
What recent audits reveal are not so much flagrant violations as gray areas. Poorly documented dependencies. Data flows that are difficult to trace. Responsibilities shared between suppliers, internal teams, and external service providers, with no real leader at the helm.
The cloud under the scrutiny of regulators
With the implementation of frameworks such as NIS2 and DORA, the nature of audits has changed. It is no longer just a matter of verifying the existence of policies or procedures. The questions are more direct: Where does the data flow? Who is in charge in the event of an incident? How long does it take to restore a critical service?
These questions almost always revolve around the cloud—not just the choice of provider, but also how services are assembled, interconnected, and outsourced. In many companies, the answer isn't always clear.
This is a view widely shared by large companies: the majority of cloud incidents do not result from sophisticated attacks, but from internal structural flaws. In other words, it is not so much external threats as the accumulation of technical decisions made over time—without a big-picture perspective—that weaken architectures and leave organizations vulnerable.
Technical choices that have become compliance decisions
What stands out in 2026 is that decisions made five or six years ago to accelerate development are now at the center of compliance discussions. Third-party APIs integrated without clear governance. Managed services that have become indispensable. Backups spread across multiple regions without precise mapping.
In reality, regulators aren’t asking companies to bring everything back in-house or to abandon the public cloud. They’re trying to determine whether the organization knows what it’s doing—whether it can demonstrate that it has control over its data flows, access, and disaster recovery mechanisms.
As one World Economic Forum expert put it, “Compliance is no longer about intent or good faith, but about demonstrable operational capability.” A capability that, in most cases, depends directly on the cloud architecture.
The Illusion of Shared Control
One of the most common blind spots involves responsibility. The cloud’s shared responsibility model is well understood in theory. In practice, however, it remains a source of confusion. During an audit, who is responsible for misconfigured encryption? For a missing backup? For an incomplete access log? The client company, the cloud provider, or the integrator? The answers vary depending on contracts, usage, and sometimes interpretations.
Resilience: The Test Nobody Liked to Take
Another point highlighted by the audits: true resilience. Not the kind described in a document, but the kind that holds up when a service goes down, when a cloud region becomes unavailable, or when a third-party provider suffers an attack.
Many companies are discovering that their business continuity plans have never been thoroughly tested—or that they are based on assumptions that are no longer valid. Multi-cloud, often presented as a guarantee, sometimes proves to be more complex to implement than it is to promote.
Analyses published by specialized firms and technical media outlets regularly highlight the growing complexity of modern cloud architectures, where the proliferation of interconnected services makes impact analysis particularly challenging in the event of an incident.
According to these experts, many organizations have robust redundancy mechanisms in place but struggle to visualize critical dependencies between applications, services, and providers in real time due to a lack of up-to-date mappings. This disconnect between theoretical resilience and operational understanding frequently emerges in feedback regarding recent major cloud outages: when an incident occurs, it sometimes takes teams several days to accurately determine which components are affected and in what order, illustrating a structural issue of visibility rather than a mere lack of recovery capacity.
Compliance as a revelation, not a problem
What the 2026 audits show is not that companies are negligent or irresponsible. It is that they have optimized for speed, not for readability.
Compliance then acts as a catalyst. It forces us to ask questions that many would prefer to avoid: do we really know how our product works in depth? Who can intervene in the event of a crisis? What happens if a critical supplier disappears overnight?
These issues are nothing new. What has changed is that they are no longer purely theoretical. They determine access to certain markets, the signing of sensitive contracts, and sometimes even the ability to obtain insurance.
When the subject reaches the level of senior management
Unsurprisingly, the cloud and compliance are no longer just matters for CIOs or CISOs. They have moved up to the executive committee level—not out of a passion for regulations, but because the consequences of a technical blind spot are now strategic.
A major incident is no longer viewed as an isolated IT problem. It is seen as a failure of governance. Why didn’t we foresee the risk? Why wasn’t the dependency identified sooner?
This article explains why some executives are beginning to take a close interest in topics that have long been considered too technical. Not to micromanage, but to understand where the vulnerabilities lie.
What 2026 is changing
The cloud remains a key driver for tech companies. There are no signs of a reversal. But the era of the “default” cloud is coming to an end. The 2026 compliance checks impose a new requirement: that of control. Not absolute, unrealistic control, but the ability to explain, to prove, and to take back control when necessary.
For many organizations, this is an uncomfortable process. For others, it’s an opportunity to take a fresh look at technical choices that have become too opaque. In both cases, the message is clear: compliance is no longer a peripheral issue. It speaks directly to how companies design and manage their cloud. And that is precisely why it brings so many blind spots to light.
Cloud & AI Infrastructure
Cloud & Cyber Security
Data & AI Leaders Summit
Data Centre World