{"id":118,"date":"2025-08-14T12:03:09","date_gmt":"2025-08-14T09:03:09","guid":{"rendered":"https:\/\/upcloud.com\/global\/us\/2025\/08\/14\/is-your-cloud-security-proactive-or-reactive\/"},"modified":"2026-05-12T22:13:33","modified_gmt":"2026-05-12T21:13:33","slug":"is-your-cloud-security-proactive-or-reactive","status":"publish","type":"post","link":"https:\/\/upcloud.com\/global\/blog\/is-your-cloud-security-proactive-or-reactive\/","title":{"rendered":"Is Your Cloud Security Proactive or Reactive?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">When we think about Cloud Security, we often think about defenses. People picture strong passwords, <a href=\"https:\/\/upcloud.com\/global\/docs\/products\/networking\/firewall\/\" target=\"_blank\" rel=\"noreferrer noopener\">firewalls<\/a>, and locked doors. This is a good start, but it\u2019s solely a defensive, or \u201creactive\u201d, mindset.<br><br>Keeping a reactive only approach focuses on building a wall and waiting to see if anyone tries to climb it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The problem with this approach?<\/strong> You only find out you have a weak spot when someone is already taking advantage of it.<br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>A better approach: Shifting left<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In today&#8217;s world, a reactive stance is not enough. A better way is an approach that fully embraces proactive security throughout a product&#8217;s entire lifecycle. This is often called the <em>&#8220;shift left&#8221;<\/em> movement in software security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It means building security in from the very beginning, starting at the design phase before any code is written. It is far more effective and less costly to design secure systems from the start than to fix vulnerabilities in a live product. This creates a culture of continuous improvement, a different philosophy built on the idea that the best way to stay safe is to always be looking for ways to be safer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>From Words to Action<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This proactive mindset is the standard modern businesses should look for in any partner, especially a cloud provider. It\u2019s the standard we hold ourselves to at <a href=\"https:\/\/upcloud.com\/global\/security-privacy\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>UpCloud<\/strong><\/a>. For us, putting these principles into action is the only way to build a platform our customers can truly trust.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While security starts at the design phase, it is critical to continue testing during the operations phase. For live systems, tools like bug bounty programs and Penetration Testing as a Service (PTaaS) are very cost effective ways to discover real issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why we partner with a leader in the ethical hacking space, <a href=\"https:\/\/www.intigriti.com\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Intigriti<\/strong><\/a>.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Their platform connects us with thousands of security researchers from around the world who help us put our proactive philosophy into practice<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cIntigriti\u2019s Penetration Testing as a Service (PTaaS) gave us the flexibility to fulfill strict regulatory requirements while still working with top-tier researchers. The combination of a results-driven bug bounty model and focused, time-boxed testing was exactly what we needed. Intigriti quickly matched us with the right experts and the findings helped us improve security where it mattered most.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Jukka Sepp\u00e4nen, CISO at UpCloud<\/strong><\/p>\n<\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Real world example<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">To see a real world example of proactive security in detail, we encourage you to <strong><a href=\"https:\/\/www.intigriti.com\/customer-story\/upcloud\" target=\"_blank\" rel=\"noreferrer noopener\">read the full customer story on Intigriti&#8217;s site<\/a>.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Intigriti Customer Story: Upcloud\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/Jf_Dlkzix_s?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When we think about Cloud Security, we often think about defenses. People picture strong passwords, firewalls, and locked doors. This is a good start, but [&hellip;]<\/p>\n","protected":false},"author":77,"featured_media":6790,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"235,550,328,4487,868,52","_relevanssi_noindex_reason":"","footnotes":""},"categories":[10],"tags":[37,97,100],"class_list":["post-118","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-security","tag-cloud-servers","tag-data-security","tag-upcloud-bug-bounty"],"acf":[],"_links":{"self":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/users\/77"}],"replies":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/comments?post=118"}],"version-history":[{"count":1,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/118\/revisions"}],"predecessor-version":[{"id":6793,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/118\/revisions\/6793"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/media\/6790"}],"wp:attachment":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/media?parent=118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/categories?post=118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/tags?post=118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}