Setting up cloud is easy. Everything that comes after isn’t. That’s the pain point CloudSoul identified and has sought to answer with their cloud infrastructure deployment platform.
Almost two years since Silicon last caught up with this Luxembourg-based startup, much has changed in how we use technology. But CloudSoul’s goal has remained more relevant than ever: to help companies build prioritised security roadmaps based on their industry posture and cloud configuration data.
Collecting data from a company, CloudSoul first sets out to analyse the cloud being used and the security configurations in place. They then develop a tailored roadmap based on the company profile and the resources available.
Navigating the way
“Our goal is to help companies use cloud and general technologies in a secure and compliant way,” said CEO and Founder Daniel Grigorovich.
One challenge companies today are met with is knowing at some level that they need to meet security and compliance benchmarks, but not necessarily understanding how.
Eric Gray, Co-Founder and CISO of CloudSoul said, “They’re concerned about it because they read the news, but they don’t have the information on how to deal with it up front, nor the budget.”
Often, with all the tools that emerge, companies are focused on speeding up production and moving at a fast pace. But that comes at a price. “A lot of the time,” Gray said, “security gets forgotten.”
It is companies in this position that CloudSoul believes they can best help.
Other instances in which CloudSoul’s services are sought include increasing obligations when an SME is acquired by a larger parent company, or simply an internal goal to become more professional.
For companies that don’t have their own dedicated security team, the need to have trusted advisors on board is all the more important – as is understanding what steps need to be taken.
“For many smaller teams, you don’t need enterprise-level security solutions that cost tens of thousands a year,” Grigorovich explained. “You need something more affordable, someone to tell them what they need, and to help implement them.”
Cybersecurity risks
The breakneck speed with which the tech industry is blossoming presents both opportunities and threats. There are three areas the CloudSoul team has identified as risks: the proliferation of IT, the cybercrime market, and a complex regulatory environment.
“How fast people are producing new products, how fast they’re coming to market, how fast they’re deploying new technologies,” Gray emphasised. “And again, security is always chasing that trail. So it’s a continuous game of catch-up.”
The use of AI could also inadvertently open doors to crime.
“The bar for entry into hacking is much lower. Now you can use AI tools to do things faster, the speed at which attacks happen is very high,” said Gray.
Even when used for good, AI can introduce vulnerabilities.
“Many don’t understand that if you create applications using AI technology, you might miss a lot of the security components,” Grigorovich said, “They don’t come hand in hand.”
Compliance in the EU
As regulations like NIS2 and DORA make security resilience non-optional across the
EU, growing companies face a real challenge: finding the right guidance.
“There are a million regulations and a very complex environment,” Gray said. “We can build depending on what they need, but at the moment it’s mainly NIS2, and we’ve also helped with GDPR and a few others.”
“You have to keep your finger on the pulse,” he advised. “Even if things have not been finalised, [to know] what direction they’re going in. Are they going in a positive direction? Have they changed to be more open?”
While keeping things targeted, relevant and affordable for their clients, CloudSoul is committed to building trust while contributing to the ecosystem.
“What we are building right now is the trust in the market, so we try to score and seize as many opportunities as we have right now through our network,” Gray said. “To build this credibility, because that’s something very important in cyber security.”