Securing Cloud Computing-Moiz Khan-MDS

Cloud computing refers to the accessibility of a wide range of ‘resources including applications, servers, data storage, development tools, and networking capabilities.’ These resources remain stored at off-site data centres managed by Cloud Service Providers (CSPs), allowing users to easily access them over the Internet without users needing them physically on their devices. It differs from the traditional computing by utilising third-party vendors’ remote data centres for scalable resources online. Additionally, it operates on a need-based payment, in contrast, the third parties require regular payment arrangements.  The advantages of cloud computing include its cost-effectiveness, scalability, accessibility, and shared maintenance tasks. It is becoming increasingly prominent as a potent technology allowing individuals and organisations to optimise their performance, adaptability, and effectiveness.

Nevertheless, advancement in cloud computing is not without security risks that can undermine the integrity, confidentiality, and availability of data. Security threats have been emerging as a significant challenge to both CSPs and cloud users. The security threats to cloud computing are a cause for concern for the storage and processing of data in the Cloud. These risks have the potential to compromise data confidentiality, accuracy, and accessibility. Data leakage, Distributed Denial-of-Service (DDoS) attack, client-to-client attacks, malware infections, phishing attempts and data remanence are a few significant concerns. Additionally, insecure Application Programming Interface (APIs) create opportunities for unauthorised access and data manipulation by attackers. Inadequate resource management in cloud environments may lead to exploitation of resources, impacting performance and potentially creating opportunities for attackers to exploit vulnerabilities.

In this regard, security measures need to be coupled with advanced measures aimed at safeguarding the data. Security measures include regular data backups, Virtual Private Network usage for data encryption, network monitoring with tools like firewalls and intrusion detection systems, two-factor authentication for login security enhancement, and antivirus software downloads to help improve overall data and network security by mitigating potential threats. There is also need of implementing various protocols and frameworks ‘including identity and access management (IAM), role-based access control (RBAC), or attribute-based access control (ABAC)’ to regulate data access. Additionally, it is essential to secure interfaces and APIs through encryption and authentication methods. To enhance visibility into cloud usage patterns, Cloud Management Platforms, along with Cloud Access Security Brokers, should be utilised.

Moreover, virtualisation also serves to be effective for safeguarding cloud computing. Virtualisation helps entities to optimise their applications by creating a simulated or virtual machine (VM) that exist in software mode and operates with the physical machine. It offers improved resource allocation and stronger isolation of software resources. While virtualisation enables the sharing of physical resources among multiple tenants and ensuring a level of security and isolation that cannot be easily achieved, CSPs could be helped to evaluate and manage the security and risk aspects efficiently.

A stable and secure cloud computing could represents a paradigm shift in leveraging computing resources for multitude of benefits and economic growth. A study conducted by the London School of Economics and Political Science examined how cloud computing impacted various industries in the United States, the United Kingdom, Italy and Germany between 2010 and 2014. The findings revealed that cloud computing was not only enabling both sectors to innovate faster and reduce costs, but also helped in creating new jobs and skills. Moreover, the market for Public Cloud Services in the Asia-Pacific, excluding Japan (APeJ), is expected to experience substantial growth. It is projected that there will be a Compound Annual Growth Rate (CAGR) of 25.5% and could reach an estimated USD 124 billion by 2024.

Pakistan is also embracing cloud computing; and the field is gradually evolving. There are four CSPs locally including Jazz Garaj, Multinet, PTCL, and RapidCompute by Cybernet. Reports suggest that Pakistan’s cloud computing market is projected to reach USD 1.5 billion this year, exhibiting a CAGR of 19.1% from 2017. The government has taken some positive steps to promote cloud adoption, such as launching the Pakistan Cloud First Policy (PCFP) in 2022, which aims to provide a framework and guidelines for public sector entities to use cloud services in a secure, efficient and cost-effective manner. The creation of digital ecosystem will also complement the emerging technologies which remain inevitable for indigenous industrialisation.

However, Pakistan’s cloud computing infrastructure will not be immune from cyber security threats. While adopting numerous security measures for securing the technology and data, Pakistan needs to introduce specific regulations and compliance standards for CSPs to ensure data privacy and security. Such regulations can include data protection laws, encryption standards, and guidelines for incident response and reporting. Clear regulatory frameworks will encourage cloud providers to prioritise security and protect user data. Hence, strengthening the security, integrity and confidentiality of data would not only help in expanding domestic cloud services but also remain significant for digitalisation and economic growth.  

Moiz Khan is a Research Assistant at the Centre for Aerospace & Security Studies (CASS), Islamabad, Pakistan. He can be reached at [email protected]

Design Credit: Mysha Dua Salman


Share this article

Facebook
Twitter
LinkedIn

Recent Publications

Browse through the list of recent publications.

The US-Israel War on Iran: Objectives, Strategy, and Escalation Management

Zahra Niazi
‘States tend to overestimate themselves or the benefits and swiftness of war, and to underestimate their opponents’ capabilities, intentions, or the costs and duration of war.’ If anything, the 2026 war initiated by the United States and Israel against Iran shall be remembered in the annals of warfare among the most visible manifestations of this dynamic.
The war, immediately preceded by the January mass protests in Iran, did not represent a sudden rupture but rather the continuation of a 47-year-long confrontation and a more intense phase of the June 2025 war.
The US Secretary of War, Pete Hegseth, defined the war’s objectives as being laser-focused: to destroy Iran’s missile capabilities and its security infrastructure, while ensuring that it could never develop nuclear weapons. Beyond these stated objectives, among the priorities on the continuum also lay the objective of regime change, with both President Trump and Prime Minister Netanyahu explicitly calling on the Iranian population to take over the government at the outset of the war.

Read More »

Marka-e-Haq to the Peace Talks: Pakistan’s Middle Power Status

On 7th May 2025, Pakistan’s military forces took the international security community by surprise when it demonstrated operational superiority against its larger belligerent adversary India with its rapid and coordinated response. The Four-Day conflict proved to be a watershed moment for Pakistan, marking its rapid emergence as an important player in the region. In recent years, amidst the ongoing global competition between the United States and China, Islamabad has adopted a position of ’Strategic Balancing,’ where it maintains ties of cooperation with both Beijing and Washington. Deft diplomacy, emphasis on geo-economics, and credible conventional and strategic deterrence have remained the foundational pillars for Pakistan’s ambition as a rising middle power

Read More »

Debunking the S-400 Shield: Lessons from the India-Pakistan Conflict

Air defense has always been a central aspect of warfare. In South Asia, the phenomenon carries immense significance due to compressed reaction times. In this context, one of the most-hyped systems is the Russian-made S-400, touted by New Delhi as a one-stop solution to counter aerial threats from both Pakistan and China.
The 2025 conflict between India and Pakistan marked an important chapter in testing the S-400 technology. The conflict began on May 7, when India attacked what it alleged were terrorist targets in both Pakistani-held Kashmir and Pakistan proper, using drone and missile strikes. The conflict lasted for four days, culminating in a U.S-facilitated ceasefire. However, the brief conflict debunked a lot of the myths regarding the S-400 technology.
First, India claimed that the mobile S-400 would be able to control Pakistan’s airspace. In contrast, Pakistani aircraft continued to operate freely, according to official briefings by the Pakistani military. Although the Pakistan Air Force (PAF) aircraft were in their own airspace, they were still within the air defense range.

Read More »