Cloud Migration Security Checklist: Protecting Data When It Is Most Exposed

A practical checklist for securing an on-premise to cloud migration: identity, landing zones, data classification, encryption, posture management and monitoring.

A cloud migration is the moment your data is most exposed. It is copied, moved, transformed and re-permissioned, often under deadline pressure and often by people who are new to the target platform. Security that is bolted on after the move is always more expensive than security designed into it.

Why the stakes are high

IBM's 2025 Cost of a Data Breach research, conducted by the Ponemon Institute across 600 breached organisations, put the global average cost of a breach at US$4.44 million and the United States average at a record US$10.22 million (IBM newsroom). IBM's 2026 report puts the global average at US$4.99 million, a record high.

Two findings are directly relevant to migrations. Supply-chain and third-party compromise was among the costliest breach types and took the longest to contain. And one in five organisations reported a breach involving shadow AI, often without proper access controls. Migrations involve many third parties and, increasingly, AI tools.

The checklist

Before anything moves

  1. Classify your data. Know which datasets hold personal data, financial records, health data or intellectual property. Classification drives every control that follows.
  2. Map regulatory obligations. Data residency and privacy rules such as India's DPDP Act, GDPR and sector rules decide where data may live and who may access it.
  3. Design identity first. Single sign-on, multi-factor authentication, least-privilege roles and a named owner for every privileged account.
  4. Build a secure landing zone. Separate accounts or subscriptions per environment, network segmentation, guardrail policies and central logging, all in place before the first workload arrives.

During the migration

  1. Encrypt in transit and at rest, with keys you control and rotate.
  2. Use temporary, scoped credentials for migration tools and third parties, and revoke them when each wave completes.
  3. Log every data transfer and reconcile what left the source with what arrived at the target.
  4. Keep production data out of test environments, or mask it first.
  5. Scan infrastructure as code and images before deployment, not after.

After go-live

  1. Turn on posture management. CSPM or CNAPP tooling checks configurations against benchmarks and alerts on drift, such as a storage bucket made public.
  2. Monitor around the clock. Feed cloud logs into your SIEM and define who responds, how fast, to which alerts.
  3. Review access quarterly and remove what is no longer needed.
  4. Decommission the source securely. Old servers and backups hold the same data; wipe and certify them.
  5. Govern AI use. Approve which AI tools may touch which data, and monitor for unapproved use.

Common mistakes we see

Who does what

Security in the cloud is shared between you and the provider, and in a migration a partner adds a third party. Agree responsibilities in writing before the first wave.

AreaCloud providerYour organisationMigration partner
Physical data centres and hardwareResponsible——
Identity, roles and access reviewsProvides toolsOwns and approvesDesigns and implements
Landing zone and guardrailsProvides servicesApprovesBuilds and documents
Data classification—OwnsSupports
Migration credentials and tools—ApprovesUses, scopes and revokes
Monitoring and incident responsePlatform signalsOwns outcomeOperates, if contracted

Zero trust in practice

Zero trust means every request is authenticated, authorised and encrypted, wherever it comes from. In a migration, that translates into three habits: never grant network-level trust to a workload because it is "inside", require identity for service-to-service calls, and assume any credential may leak and limit what it can do.

Key takeaways

Planning something similar? See our Cloud migration, cloud security and Snowflake, or talk to our team about your situation.
MGMJC GlobalTech Editorial Team
Enterprise transformation practitioners
Keep reading

Related insights

Let's build what's next — together.

Whether it's setting up your India GCC, modernizing your enterprise stack, or hiring 50 engineers in 30 days — we'd love to scope it with you.