Rows of servers in a data center aisle

Cloud SolutionsComplianceCybersecurity

How to Choose the Right Cloud Services Provider for Your Business

Most cloud contracts get signed after a good demo and a reasonable quote. The questions that decide whether the move goes well tend to come up later: who is responsible when an account gets hacked, where the data actually lives, whether the provider will sign the agreement your regulator requires, and how you would get everything back out. If you are working out how to choose a cloud provider, ask those questions before you sign, while the answers can still shape the contract.

Key takeaways

  • Decide what you are moving and why before comparing providers, because the right choice depends on the workload.
  • Your data, user accounts, access controls and devices stay your responsibility in every cloud model.
  • Ask for independent evidence such as a SOC 2 Type II report, and expect it to arrive quickly.
  • Healthcare and financial firms need specific contract terms, such as a HIPAA business associate agreement.
  • Confirm backup, outage history and exit terms, since getting your data back out is part of the deal.

Start with the workload

“The cloud” covers very different services, and a provider that is great for one may be a poor fit for another. List the systems you want to move, who uses them, what data they hold and what you hope to gain: remote access, less hardware, better resilience or easier growth.

  • Software as a service (SaaS) is a finished application you sign in to, such as Microsoft 365 or a cloud practice management system.
  • Platform as a service (PaaS) gives you managed databases and app hosting without managing servers.
  • Infrastructure as a service (IaaS) is virtual servers and storage, often used to move an existing server application with few changes.

Most organizations with 10 to several hundred staff end up with a mix: Microsoft 365 for email and files, one or two specialty SaaS apps, and perhaps a hosted server for software that won’t run anywhere else. Map each system, including which ones depend on each other, before you shop.

Know which half of security stays with you

Signing up with a cloud provider moves some security work to them and leaves the rest with you. Microsoft’s documentation says the split shifts by service type, but some things stay with you whatever you buy.

Laptop showing charts on a desk
  • Your data, including how it is classified, protected and retained.
  • The laptops, desktops and phones that connect to the service.
  • User accounts, including adding and removing people.
  • Access controls such as MFA, role-based permissions and conditional access.

With IaaS you also manage the operating system, applications and network controls. With SaaS the provider handles most of that. Either way, many cloud incidents at small organizations start on the customer’s side of the line: a reused password, an account nobody removed, or a setting left wide open. Our post on preventing cloud misconfiguration covers the common ones, and our cloud security best practices cover the rest.

How to choose a cloud provider: questions to ask

AskWhat a good answer looks like
Can you share a current SOC 2 Type II report or ISO 27001 certificate for the service we would use?A report covering that specific service, sent from a trust center or standard security packet
Is our data encrypted in transit and at rest, and who holds the keys?A clear answer for both, in writing
Can we enforce MFA and single sign-on with our Microsoft 365 accounts?Yes, configurable by your administrator
What logs can we see, how long are they kept, and can we export them?Sign-in and activity logs you can export
How and how fast will you tell us about an incident affecting our data?A defined notification process in the contract
Which subcontractors handle our data, and where?A published list, with notice when it changes
What is your real outage history?The uptime commitment in writing, plus actual history and a public status page
Which regions host our data, and is it copied to a second site?Named regions and a description of redundancy
How long can deleted or overwritten data be recovered?A recovery window that covers ransomware and a rogue admin
How do we get our data out if we leave?Full export in a usable format, a stated retention period afterward, and a deletion process

A provider that hesitates on these is telling you something. Ask for references from organizations your size, ideally in your field, and ask them about the worst outage they had and how the provider handled it.

48%

Share of breaches in Verizon’s 2026 Data Breach Investigations Report that involved a third party, up 60% from the year before

That is why it pays to vet a cloud provider the way you would vet any vendor with access to your data. Our post on securing your supply chain goes further.

Contract terms regulated firms need

Healthcare and HIPAA

HHS says a cloud provider that creates, receives, maintains or transmits electronic protected health information for you is a business associate, even if it only stores encrypted data it can’t read. You need a signed business associate agreement before any patient data goes in. HHS also allows data stored overseas with a BAA in place, but expects you to weigh that location in your risk analysis. See how we support healthcare practices.

Accounting, tax and financial firms

The FTC Safeguards Rule requires covered firms to pick service providers that can maintain appropriate safeguards, put security expectations in the contract, monitor the provider’s work and reassess periodically. A cloud provider holding client tax or financial records falls squarely under that. File the security evidence you collect in your written information security program.

Law firms, nonprofits and everyone else

Client confidentiality duties, NDAs, donor privacy promises and state breach laws all follow your data into the cloud. Read the provider’s terms on data ownership, how it may use your data, and what happens to it when you cancel.

Plan the bill and the move

Cloud pricing swaps a large hardware purchase for an ongoing bill, which helps budgeting but can creep. Ask about storage growth, data transfer fees, minimum terms and which features need a higher tier. Then move in stages:

  1. Inventory systems and map dependencies.
  2. Set up security first: MFA, admin accounts, logging and backup.
  3. Pilot with a low-risk workload and a few users.
  4. Move the remaining workloads in phases, with a rollback plan for each.
  5. Review costs and access after 30 to 90 days and right-size.

As a Microsoft CSP partner, we set up Microsoft 365 for our clients, and on the security step our standard is phishing-resistant sign-in such as security keys or passkeys for admin accounts, and app approval with number matching for everyone else. We also keep separate backups outside the provider. Server backups run hourly, are copied off-site daily and are immutable. Microsoft 365 and Google Workspace data is backed up three times a day and is immutable too. All of it is stored in the US, so recovery never depends on a single vendor having a good day.

If you are comparing providers now, or already signed and wondering what you missed, book a 20-minute call. We will tell you plainly what should move and what should stay. Our hosted and cloud services and Microsoft 365 pages have more.

FAQ

Frequently asked questions

What is a SOC 2 report?

An independent auditor’s review of a service provider’s controls over security and related areas. A Type II report covers how those controls worked over a period of time, which makes it more useful than a Type I.

Is the cloud more secure than an on-site server?

It can be, because large providers secure their data centers and platforms well. You still control accounts, access and data, and that is where many small business cloud incidents start.

Sources: Microsoft Learn: Shared responsibility in the cloud; HHS: Guidance on HIPAA and cloud computing; FTC: Safeguards Rule, what your business needs to know; Verizon: 2026 Data Breach Investigations Report; AICPA: SOC 2 reporting on controls relevant to security, availability, processing integrity, confidentiality or privacy.

Talk to an advisor

Questions about your own environment?

Our team can walk through how this applies to your organization, with honest recommendations and no pressure.