<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1490657597953240&amp;ev=PageView&amp;noscript=1">
What's Going On In Banking · Episode 4

Can Banks Gain Cloud Leverage With AWS, GCP and Azure?

with Barb MacLean · 18:04

Transcript

Hi, and welcome to another episode of the What's Going On in Banking podcast. I'm Ron Shevlin, chief research officer at Cornerstone Advisors and a senior contributor at Forbes, where I write the Fintech Snark Tank blog.

 

The U.S. Department of the Treasury recently released a report examining cloud adoption in the financial services industry. The report did a good job of explaining how cloud adoption has evolved in banking over the past several years and outlined some of the challenges financial institutions are facing. But it doesn't take long to uncover the political angle behind the report, particularly its criticism of the three dominant cloud providers: Google, Amazon, and Microsoft.

 

Treasury identified several concerns involving the major cloud service providers, or CSPs. Among them was the idea that the information shared by CSPs may be insufficient for financial institutions to properly identify and assess risk. The report specifically cited areas such as internal software dependencies, operational incidents, real-time updates, and after-action reports.

 

Treasury also criticized some CSP tools as being difficult to use and potentially inadequate for security configuration and monitoring. It noted that cloud services remain vulnerable to operational incidents and acknowledged that many of the alternatives available to financial institutions could increase their costs.

 

The report then gets to what I think is the heart of the matter: Is too much cloud power concentrated in too few providers? Treasury raised concerns about Big Tech's market share in financial-services cloud infrastructure and wrote that concentration could expose financial-services clients to physical or cyber risks, potentially requiring action from those institutions.

 

The report also discussed the implications of having three dominant providers when banks negotiate contracts, particularly for smaller institutions that may have relatively little leverage.

 

So what does Treasury intend to do about that concentration? Let me read part of what they wrote, because I found the language pretty difficult to interpret. Treasury said it would prioritize its focus on the concentration of cloud services that are most important to the financial sector. If Treasury determines that cloud services critical to the financial sector do not have appropriate resilience and security, it will take action consistent with its authority and in consultation with other government agencies.

 

If that means something other than trying to limit the power of the large providers, or potentially forcing some sort of structural change, I'm not sure what else it means.

 

I look at this and wonder whether the government is focusing on the wrong problem. Banking regulation already feels like playing football with your hands tied behind your back. If Treasury were to limit or dismantle portions of the large cloud providers' businesses, that could amount to turning the banks' helmets around backward too.

 

The report seems to reflect a broader consensus in Washington that Big Tech has too much power and should be constrained. The risk argument becomes part of the justification for doing that.

 

I find some of this frustrating because most bankers will tell you they simply don't have the internal resources to provide these capabilities themselves. They often receive services from the large cloud providers indirectly through other technology vendors, where they may actually have more contractual leverage.

 

I also thought the comments about negotiating leverage were a little misguided when you consider that the core-banking systems market is itself dominated by a small number of large providers. That concentration was largely ignored in this report and has received relatively little attention from Treasury.

 

To help us understand the real implications and what is happening operationally in the cloud market, I've asked Barb MacLean, senior vice president and head of technology operations and implementation at Coastal Community Bank, to join me. Barb has deep experience in this space.

 

Barb, thanks a lot for joining me today.

 

Thanks, Ron. I'm really happy to be here. It's great to see you.

 

Same here. We talk a lot through Twitter and LinkedIn, but I can't remember the last time we actually spoke live, so I appreciate you doing this.

 

I asked you to join because of your deep experience on the technology and operations side. From your perspective, what are the real challenges financial institutions face when working with the large cloud providers?

 

I think the fundamental challenge is simply getting started. You rightly pointed out in your post that there is a lot of activity happening in this area. Adoption itself is not necessarily the problem. The conversation gets more interesting when you start asking what kind of cloud adoption we're actually talking about.

 

I think we'd be surprised to find a financial institution that isn't already using some form of cloud service for everyday technology, whether that's Microsoft 365, Google Workspace, or another hosted platform. There has been a lot of progress in moving day-to-day applications and collaboration tools into commodity cloud services.

 

We can certainly call that cloud adoption. But financial services gets much more complicated when you start talking about core and mission-critical workloads.

 

I also found the report's language around leverage and contract negotiations interesting. Smaller institutions often have very little leverage with large core providers, and one of the characteristics of that traditional business model is that it can be very difficult to exit those contracts. That's the paradigm financial institutions have been living with for decades.

 

But do you care about that in exactly the same way when cloud-provider business models are largely consumption-based? You're moving from a capital-expenditure model to more of an operating-expense model. Some of the anxiety about getting started may come from financial institutions thinking, "I don't even know how to negotiate directly with Microsoft or Amazon."

 

My question is: Why would you necessarily want to take on all of that responsibility yourself?

 

Aren't there plenty of providers sitting in the middle? When I first started researching cloud adoption a few years ago, I would hear CIOs say, "We're not in the cloud and we'll never be in the cloud," even though one of their vendors was already hosting their systems in the cloud. They were in the cloud without necessarily realizing it.

 

So isn't some of this concern overblown? Even midsize institutions, say those below $50 billion in assets, rely heavily on vendors that are likely handling much of this for them. And if they aren't, there are still a lot of service providers in the middle that can negotiate and manage those relationships on behalf of clients.

 

I think that's probably true. Those providers are capturing a position in the value chain by saying, "We'll interact with the big, scary cloud providers for you. You don't know where to begin, so let us help you."

 

There is a legitimate need for that. It helps institutions get past the fear of getting started. The good news is that there is a healthy ecosystem of providers that can help.

 

At this point, I would almost describe parts of that market as a commodity service. You can choose a partner that understands the cloud platform you're using. That's one recommendation I would make to listeners: Look for a provider with real expertise in your cloud of choice.

 

There are plenty of vendors that will tell you they can do everything for everyone. But you may be better served by a partner with deep expertise in the cloud environment that actually fits your strategy, rather than a general-purpose provider. And yes, there are many vendors you can lean on when you don't have the internal skill set yourself.

 

I'm going to ask a two-part question even though I probably shouldn't. Treasury criticized CSPs for providing insufficient information for banks to identify risk, including information about software dependencies and real-time operational updates. It also criticized the providers for remaining vulnerable to operational incidents.

 

First, is that a fair criticism? I would think every cloud provider is vulnerable to some level of operational incident. Second, are the large providers really failing to give financial institutions enough information to manage the risk?

 

Let's take the second part first. There is no system that is impenetrable. It doesn't matter if you're Microsoft and can spend $20 billion a year on cybersecurity while gathering trillions of signals to help monitor and flag potential problems. That level of investment is well beyond what most financial institutions could ever contemplate doing themselves.

 

Security is always a cat-and-mouse game. The question is what the next vulnerability will be, who recognizes it first, and how effectively you have protected your systems using multiple layers of defense.

 

The large cloud providers are doing that at a scale most financial institutions simply cannot match in their own on-premise environments. So when the report suggests cloud security may only equal what institutions can do themselves, my view would be that the cloud providers often exceed it.

 

That doesn't mean they will never have an incident. Even an organization spending billions of dollars on cybersecurity is going to experience problems. Expecting otherwise is unrealistic. If an institution approaches cloud computing as though it is a silver bullet that eliminates all security risk, they're starting with the wrong mindset.

 

So I do think that portion of the report was somewhat unfair.

 

On the information question, I wonder whether some of the feedback Treasury received came from institutions that simply don't have a mature understanding of where to look. If you have experience working with the large cloud platforms, you can find regulatory and compliance reports that are freely available to subscribers and users, whether that's ISO certifications, PCI validation, or other documentation.

 

The amount of responsibility you carry depends on where you are in your cloud-adoption journey. If you've done more of a lift-and-shift model, the financial institution may still own a great deal of responsibility for the infrastructure. If you've moved further into managed cloud services, more responsibility sits with the provider.

 

Regardless, I would argue there is a significant amount of information available showing that these providers go through the same types of validations and standards, including NIST-related frameworks, that financial institutions themselves use.

 

One of the things that drove me a little nuts about the Treasury report was that it acknowledged some of the alternatives being discussed could increase banks' costs. Then, in Washington, increasing costs often triggers another round of concerns about pricing and regulation.

 

I also can't picture how shifting cloud market share away from Google Cloud, AWS, or Microsoft Azure would necessarily help banks. I'm not even sure where Treasury thinks that business would go.

 

Can you envision a scenario where breaking up or limiting those providers would actually benefit financial institutions?

 

I can't. I think we currently benefit from having roughly enough competition among the major providers. If you pay attention to the capabilities and features all three continue to add, they're clearly competing aggressively with one another, and that benefits customers.

 

Their pricing has also generally continued to come down over time. So I don't buy the argument that they're too large, have too much cloud market share, and therefore automatically make everything more expensive.

 

The capabilities they can provide are far beyond what an individual financial institution, or even many consortiums, could realistically assemble on their own. To me, that's a worthwhile trade-off. From a security perspective, I would still rather rely on organizations that can gather global signals and invest at enormous scale than on something I could assemble myself.

 

That's exactly what struck me as contradictory. The report seems to say, "We're going to take regulatory action to reduce your costs because you're locked into contracts," while also acknowledging that the alternatives could raise operational costs. What Treasury giveth, Treasury taketh away.

 

Let's look at this more positively. Are there regulatory changes that could reduce cloud-related technology risk while also helping banks?

 

When I think about that, I don't necessarily think the answer is more regulation directed at the cloud providers. I'd rather see changes in the regulatory environment that reduce the fear, uncertainty, and doubt around using cloud services.

 

The other piece is encouraging, or when necessary requiring, modernization of the fundamental infrastructure that still supports day-to-day banking. One example we're wrestling with is the continued requirement for certain physical network devices to connect to essential banking infrastructure.

 

To me, those can actually be some of the riskiest things a technology leader has to manage. I would much rather rely on the strength of a major cloud provider and its security frameworks than have to assemble the same capabilities in-house.

 

That's where I would rather see regulators focus their attention: helping essential banking infrastructure modernize, using both incentives and requirements where appropriate.

 

Spot on. I think what Treasury may be missing is that, because they're so focused on the risks of cloud deployment, they aren't adequately considering the risk of not moving to the cloud. In many cases, the risk of staying off the cloud may actually be greater than the risks associated with using it.

 

Barb MacLean, senior vice president and head of technology operations and implementation at Coastal Community Bank, thank you very much for being on What's Going On in Banking.

 

And for everybody listening, if you aren't checking out Barb's Fintech Playlist on Saturdays, you're missing a great roundup of what happened in fintech during the week, paired with some excellent music choices. I'm always thrilled when I make the list and get to see what song she pairs with my work.

 

Barb, thanks a lot for joining me. And thanks, everybody, for checking out another episode of What's Going On in Banking.

Enjoying What's Going On In Banking?

Subscribe on your favorite platform

← Back to all What's Going On In Banking episodes