Cloud security for businesses: practical knowledge from an ECM expert
Trust is undoubtedly the most important factor when introducing a cloud solution to a business. But how can trust in this technology be established? In this interview, Patrick Carl, CSO of Portal Systems, shares his insights on the key issues of security, transparency and compliance.
Question: When companies talk about a trustworthy cloud, what does trust actually mean, and why is it more important today than ever before?
Patrick Carl: For me, trust in the context of the cloud means transparency, control and verifiability above all else. Transparency means being able to track where the data is located at any time, who has access to it, when they have access, and which sub-processors are involved. ‘Control’ means that identities, authorisations, encryption and configuration remain in my hands. This aligns with principles such as zero trust, least privilege, and owning keys and policies. Verifiability and compliance ensure trust through audit trails, documentation, test reports and clear SLAs with guaranteed availability and rectification times. Finally, resilience and reversibility are required in the form of reliable backup and restore procedures, exit scenarios that prevent lock-in, and planable upgrades that ensure long-term operation. As attack surfaces, regulatory requirements and critical business importance continue to increase, trust in the cloud cannot be based on promises alone, but must be based on verifiable mechanisms and reliable practice.
Building trust through ‘transparency, control and verifiability’
Question: Many providers advertise security and compliance. How can companies tell if a cloud partner is trustworthy, and how can they distinguish between marketing promises and actual practice?
Patrick Carl: Yes, that’s correct. While security and compliance are always advertised, verifiable criteria are crucial. This includes data storage and emergency access, integrated user and authorisation management, and regular audits and certifications by independent third parties. Clear SLAs with guaranteed KPIs, as well as the ability to easily export data and switch providers, are also key indicators of a company’s actual practices. References from similar companies can help distinguish marketing promises from genuine trustworthiness.
Question: What role does Portal Systems play in building trust in the cloud? How do you ensure that your customers can rely on your solutions in the long term?
Patrick Carl: Portal Systems plays a central role in building trust in the cloud by consistently relying on Microsoft 365 as a secure IT platform. IT security is our top priority, continuously monitored and now certified according to ISO 27001. We see ourselves as a reliable and trustworthy partner, working alongside our customers to support their cloud strategy without introducing additional risks. Shareflex does not store any customer data itself. Instead, all information is securely stored in the customer’s M365 tenant. This means that, once the decision to use the platform has been made, it can be implemented consistently and for the long term.
Portal Systems: your partner for secure cloud solutions in Microsoft 365
With over 20 years’ experience in ECM, Portal Systems is now focusing exclusively on Microsoft 365. Shareflex ECM Online seamlessly extends the platform with secure functions such as DMS, controlled documents and incoming invoice processing, ensuring security in document and contract management. More than 300 customers, ranging from SMEs to large corporations, already rely on it.
Portal Systems AG is ISO/IEC 27001 certified, meeting the highest security and quality standards. Customers benefit from direct contact with the manufacturer, quick feedback and uncomplicated implementation without any third parties involved. This makes Portal Systems a trustworthy cloud partner.