How to Hold Your Cloud Providers Accountable With Security Contract Terms
Retrospective: this article looks back at events from April 2024, written in 2026 with the benefit of hindsight.
Cloud provider security failures can affect your data — but your contract often gives you little recourse. Here are security terms to negotiate or verify with your cloud and major SaaS providers.
Step 1: Know what you've already agreed to
Read the provider's data protection addendum (DPA), service terms, and security documentation. Microsoft, AWS and Google publish standard terms; enterprise agreements may allow negotiation.
Step 2: Key terms to look for or request
- Incident notification: a specific timeframe (for example, within 72 hours of confirming an incident affecting your data) and content requirements.
- Logging availability: access to security-relevant logs at no extra charge, with defined retention.
- Independent audits: current SOC 2 Type II, ISO 27001/27017/27018 and relevant certifications (FedRAMP, C5, etc.).
- Root cause reports after significant incidents.
- Subprocessor transparency and notification of changes.
- Data location and residency commitments.
- Encryption key options (customer-managed keys where needed).
- Termination and data return terms.
Step 3: Use shared responsibility documentation
Map which controls belong to the provider and which to you. Make sure you're implementing your half.
Step 4: Ask for transparency programs
Providers offer service trust portals (Microsoft Service Trust Portal, AWS Artifact) with audit reports and documentation. Review them annually.
Step 5: Track provider security commitments
Follow initiatives such as Microsoft's Secure Future Initiative and AWS security bulletins. Ask your account team for updates relevant to your services.
Step 6: Build independent verification
Don't rely only on the provider: keep your own logs, monitoring and backups so you can see and recover from provider-side issues.
- The CSRB Report on Storm-0558 (Apr 2024): A 'Cascade of Security Failures' at Microsoft Platform Changes
- Annual Cloud Provider Security Review Checklist How-To & Hardening
- CIO Brief: What the CSRB Findings Mean for Microsoft Customers CIO Briefings