Highmark & Google’s Secure-by-design Technique to Bring the Living Health Solution to Life

6550
Of your peers have already read this article.
3:30 Minutes
The most insightful time you'll spend today!
In an industry as highly regulated as healthcare, building a single secure and compliant application that tracks patient care and appointments at a clinic requires a great deal of planning from development and security teams. So, imagine what it would be like to build a solution that includes almost everything related to a patient’s healthcare, including insurance and billing. That’s what Highmark Health (Highmark)—a U.S. health and wellness organization that provides millions of customers with health insurance plans, a physician and hospital network, and a diverse portfolio of businesses–decided to do.
Highmark is developing a solution called Living Health to re-imagine healthcare delivery, and it is using Google Cloud and the Google Cloud Professional Services Organization (PSO) to build and maintain the innovation platform supporting this forward thinking experience. Considering all the personal information that different parties like insurers, specialists, billers and coders, clinics, and hospitals share, Highmark must build security and compliance into every part of the solution.
In this blog, we look at how Highmark Health and Google are using a technique called “secure-by-design” to address the security, privacy, and compliance aspects of bringing Living Health to life.
Secure-by-design: Preventive care for development
In healthcare, preventing an illness or condition is the ideal outcome. Preventive care often involves early intervention—a course of ideas and actions to ward off illness, permanent injury, and so on. Interestingly, when developing a groundbreaking delivery model like Living Health, it’s a good idea to take the same approach to security, privacy, and compliance.
That’s why Highmark’s security and technology teams worked with their Google Cloud PSO team to implement secure-by-design for every step of design, development, and operations. Security is built into the entire development process rather than waiting until after implementation to reactively secure the platform or remediate security gaps.
It’s analogous to choosing the right brakes for a car before it rolls off the assembly line instead of having an inspector shut down production because the car failed its safety tests. The key aspect of secure-by-design is an underlying application architecture created from foundational building blocks that sit on top of a secure cloud infrastructure. Secure-by-design works to ensure that these building blocks are secure and compliant before moving on to development.
The entire approach requires security, development, and cloud teams to work together with other stakeholders. Most importantly, it requires a cloud partner, cloud services, and a cloud infrastructure that can support it.
Finding the right cloud and services for secure-by-design
Highmark chose Google Cloud because of its leadership in analytics, infrastructure services, and platform as a service. In addition, Google Cloud has made strategic investments in healthcare interoperability and innovation, which was another key reason Highmark decided to work with Google. As a result, Highmark felt that Google Cloud and the Google Cloud PSO were best suited for delivering on the vision of Living Health—its security and its outcomes.
“Google takes security more seriously than the other providers we considered, which is very important to an organization like us. Cloud applications and infrastructure for healthcare must be secure and compliant,” explains Highmark Vice President and Chief Information Security Officer, Omar Khawaja.
Forming a foundation for security and compliance
How does security-by-design with services work? It starts with the creation and securing of the foundational platform, allowing teams to harden and enforce specified security controls. It’s a collaborative process that starts with input from cross-functional teams—not just technology teams—using terms they understand, so that everyone has a stake in the design.
A strong data governance and protection program classifies and segments workloads based on risk and sensitivity. Teams build multiple layers of defense into the foundational layers to mitigate against key industry risks. Google managed services such as VPC Service Controls help prevent unauthorized access. Automated controls such as those in Data Loss Prevention help teams quickly classify data and identify and respond to potential sources of data risk. Automation capabilities help ensure that security policies are enforced.
After the foundational work is done, it’s time to assess and apply security controls to the different building blocks, which are Google Cloud services such as Google Kubernetes Engine, Google Compute Engine, and Google Cloud Storage. The goal is to make sure that these and similar building blocks, or any combination of them, do not introduce additional risks and to ensure any identified risks are remediated or mitigated.
Enabling use cases, step by step
After the foundational security is established, the security-by-design program enables the Google Cloud services that developers then use to build use cases that form Living Health. The service enablement approach allows Highmark to address complexity by providing the controls most relevant for each individual service.
For each service, the teams begin by determining the risks and the controls that can reduce them. The next step is enforcing preventive and detective controls across various tools. After validation, technical teams can be granted an authorization to operate, also called an ATO. An ATO authorizes the service for development in a use case.
For use cases with greater data sensitivity, the Highmark teams validate the recommended security controls with an external trust assessor, who uses the HITRUST Common Security Framework, which maps to certifications and compliance such as HIPAA, NIST, GDPR, and more. A certification process follows that can take anywhere from a few weeks to a few months. In addition to certification, there is ongoing monitoring of the environment for events, behavior, control effectiveness, and control lapses or any deviation from the controls.
The approach simplifies compliance for developers by abstracting compliance requirements away. The process provides developers a set of security requirements written in the language of the cloud, rather than in the language of compliance, providing more prescriptive guidance as they build solutions. Through the secure-by-design program, the Highmark technology and security teams, Google, the business, and the third-party trust assessor all contribute to a secure foundation for any architectural design with enabled Google Cloud services as building blocks.
Beating the learning curve
Thanks to the Living Health project, the Highmark technology and security teams are trying new methods. They are exploring new tools for building secure applications in the cloud. They are paying close attention to processes and the use case steps and, when necessary, aligning different teams to execute. Because everyone is working together collaboratively toward a shared goal, teams are delivering more things on time and with predictability, which has reduced volatility and surprises.
The secrets to success: Bringing everyone to the table early and with humility
Together, Highmark and Google Cloud PSO have created over 24 secure-by-design building blocks by bringing everyone to the table early and relying on thoughtful, honest communication. Input for the architecture design produced for Highmark came from privacy teams, legal teams, security teams, and the teams that are building the applications. And that degree of collaboration ultimately leads to a much better product because everyone has a shared sense of responsibility and ownership of what was built.
Delivering a highly complex solution like Living Health takes significant, more purposeful communication and execution. It is also important to be honest and humble. The security, technology, and Google teams have learned to admit when something isn’t working and to ask for help or ideas for a solution. The teams are also able to accept that they don’t have all the answers, and that they need to figure out solutions by experimenting. Khawaja puts it simply, “That level of humility has been really important and enabled us to have the successes that we’ve had. And hopefully that’ll be something that we continue to retain in our DNA.”

Why Indian Enterprises Need to Embrace The Cloud-First Imperative to Accelerate Digital Transformation
DOWNLOAD WHITEPAPER3792
Of your peers have already downloaded this article
3:30 Minutes
The most insightful time you'll spend today!
Digital transformation is rewriting the rules of business both in India and worldwide. Digital customer experiences deliver easy, effective, and emotional touchpoints that focus operations on what the customers value. Around half of Indian decision makers prioritize the improvement of CX and the simplification of operations, as top priorities in their business agenda, according to a Forrester Consulting study of 360 business and technology decision makers of Indian enterprises.
According to the study, forward-thinking enterprises are increasingly turning to cloud to support their business as they attempt to keep pace with evolving customer needs. As a result, cloud has become a strategic priority, and ensuring its support in the marketplace will only enable digital business and accelerate innovation.
The study reveals that:
- Public cloud is a key enabler for the transformation of digital business.
- Security, inconsistent monitoring tools, and legacy applications are top barriers to public cloud expansion.
- Enterprises are expanding their adoption of the public cloud and want to gain a competitive edge.
Download this study to understand why more and more organizations are moving applications to the cloud in order to take advantage of scalability, lower capital costs, ease of operations, and the resilience offered by the public cloud.
Why Moving SAP Workloads to Google Cloud is Beneficial for the Consumer Goods Industry

3641
Of your peers have already read this article.
3:00 Minutes
The most insightful time you'll spend today!
Even before the COVID-19 pandemic struck, the consumer packaged goods (CPG) industry was facing disruption. Consumers have come to expect personalized and seamless experiences at every point in their relationship with a brand. Additionally, consumers are expecting CPG brands to meet rising standards for sustainability, social responsibility, and transparency. Business models are shifting as well. Direct-to-consumer and subscription models have been gaining ground on traditional business models. Add in the CPG industry’s ever-present pressure for wider profit margins and the effects of the global pandemic, and you get a perfect storm of disruption.
Leading CPG companies are responding to these changes by capitalizing on the potential of emerging technologies and leveraging the power of the cloud to create digital enterprises. In doing so, they can unlock value through reduced operational costs, faster innovation, improved marketing ROI, and greater transparency and sustainability—among other benefits. For businesses that run on SAP, accessing these benefits requires creating a digital enterprise with SAP at its heart.
What CPG can expect from SAP on Google Cloud
SAP drives core business processes across most enterprise functions in CPG companies, and modernizing these operations is step one in unlocking next-level data and analytics capabilities. Creating a digital enterprise with SAP at the core requires establishing a digital foundation on a cloud platform capable of supporting and optimizing SAP workloads well into the future. From there, CPG companies can leverage the combination of SAP data and additional data signals to support high-value use cases utilizing the advanced analytics capabilities of the cloud
For CPG companies, running a successful digital enterprise in this climate depends on the power of the cloud because of the unmatched agility, security, scale, and flexibility offered by cloud technologies. More and more, consumer brands are turning to Google Cloud to host their applications—including core enterprise applications such as SAP—to drive business agility and maximize the value of data through smart analytics and machine learning. Google Cloud establishes a digital foundation for SAP customers by simplifying SAP deployments and offering a suite of applications that integrates with and enhances SAP functionality. A Forrester study on the total economic value of Google Cloud for SAP customers found an average payback of less than six months and a total ROI of over 160%. By turning to Google Cloud to run their SAP systems, companies are able to:
- Maximize insights
CPG enterprise data is often fragmented across disparate systems. Google’s analytics tools including BigQuery and Looker allow businesses to connect customer, operational and business data at scale by unifying data from SAP systems with other Google data signals such as Ads, Maps, Shopping or Google Marketing Platform. This precious data is fully democratized, allowing for complex queries to be completed rapidly so companies can uncover and analyze insights and create an end-to-end view of the consumer and the business. - Create an intelligent organization
Google’s AI and machine learning capabilities allow businesses to create built-in intelligence. Instead of reacting to trends, they can accurately predict them. For marketing teams, this could be the ability to evaluate promotions and effectiveness of marketing spend. For forecasting, product quantities and restock timing can be better planned. Supply chain optimization can include external data sources to closely monitor inventory and eliminate stock outs. - Future-proof your business
Running SAP systems on Google Cloud creates an agile, secure and highly available environment that scales quickly as a business grows and as the CPG market evolves. A recent study conducted by IDC showed that SAP on Google Cloud deployments resulted in a 46% lower three-year cost of operations with 83% less frequent unplanned downtime and 56% more efficient IT teams. This frees IT resources to drive innovation and customer centricity. - Deliver on sustainability
Around the globe, consumers are becoming more and more demanding regarding sustainability. The impact of climate change and the abundance of plastic waste is only fueling this trend. Consumers are leaning into social signalling, and CPG companies are taking note. Sustainable IT is step #1, significantly advanced by moving applications to Google Cloud, the cleanest cloud in the industry. We’ve neutralized all of our carbon emissions since our founding in 1998 and matched 100% of our electricity consumption with renewable energy purchases since 2017. Google Cloud allows SAP enterprises to further drive sustainability compliance and business objectives with AI and ML tools that can drive down waste and provide real-time decision making power to support proactive green initiatives.
Rémy Cointreau is in high spirits after deploying SAP in the Google Cloud
Rémy Cointreau, a family-owned international maker of fine spirits, has products that can take up to one-hundred years to produce. But this long production cycle presents some unique challenges in today’s hyper-competitive premium beverage brands market. Since 1724, the company has been consumed with putting its customers first. In 2020, the company realized it was failing to capitalize on the benefits that the cloud can provide and began searching for a business partner that could help with this transformation.
Rémy Cointreau made the move to Google Cloud for many reasons. First, the company could connect its SAP backbone to key SaaS applications like Salesforce. This enabled the creation of a 360-view of data among its ecommerce platform, SAP, and Salesforce to deliver sophisticated customer experiences that reflect the heart of the brand. The Rémy Cointreau team quickly realized they now had the ability to be more agile in their finance, manufacturing, and supply chain functions with easy access to valuable SAP system data that drives decision-making. Sebastien Huet, the company’s CTO, explains: “Now that we’re fully deployed on Google Cloud Platform, anything is possible. We can pull data in from multiple sources via integration and analyze it in a matter of days. We don’t need a three-month project to see value.”
In today’s on-demand, omnichannel world, it’s not enough for CPG brands to understand their consumers. For companies like Rémy Cointreau, it is mission-critical that they anticipate consumer preferences and deliver personalized experiences. The winners will be the companies that can reduce time to insights by treating all their data as strategic assets, breaking down data silos to enable real-time business intelligence. With SAP on Google Cloud, CPGs are transforming consumer relationships and business outcomes.
Are you ready to change how your CPG brand operates? Check out this video and read the Google Cloud for SAP CPG customer white paper and ebook. Learn more about how your peers are leveraging SAP on Google Cloud to evolve their businesses.
Strategic Consulting, Training & Implementation Guidelines with Public Sector PSO Helps Governments Stay Compliant

4711
Of your peers have already read this article.
3:00 Minutes
The most insightful time you'll spend today!
Did you know that by 2025, enterprise IT spending on public cloud computing will overtake traditional IT spending? In fact, 51% of IT spend in application software, infrastructure software, business process services, and system infrastructure will transition to the public cloud, compared to 41% in 20221.. As enterprises continue to rapidly shift to the cloud, government agencies must prioritize and accelerate security and compliance implementation.
In May 2021, the White House issued an Executive Order requiring US Federal agencies to accelerate cloud adoption, embrace security best practices, develop plans to implement Zero Trust architectures, and map implementation frameworks to FedRAMP. The Administration’s focus on secure cloud adoption marks a critical shift to prioritizing cybersecurity at scale. Google Cloud’s Public Sector Professional Services Organization (PSO) has committed to helping customers meet security and compliance requirements in the cloud through specialized consulting engagements.
Accelerating Authority to Operate (ATO)
The Federal Risk and Authorization Management Program (FedRAMP) was established in 2011 as a government-wide program that promotes the adoption of secure cloud services across the federal government. FedRAMP provides a standardized approach to security and risk assessment for cloud technologies and federal agencies. US Federal agencies are required to utilize and implement FedRAMP cloud service offerings as part of the “Cloud First” federal cloud computing strategy.
While Google Cloud provides a FedRAMP-authorized cloud services platform and a robust catalog of FedRAMP-approved products and services (92 services and counting), customers are still tasked with achieving Agency ATO for the products and services they use, and Google Cloud provides many resources to assist customers with this journey. Google Cloud’s FedRAMP package can be accessed by completing the FedRAMP Package Access Request Form and submitting it to info@fedramp.gov. Additionally, customers can use Google’s NIST 800-53 ATO Accelerator as a starting point for documenting control implementation. Finally, Google Cloud’s Public Sector PSO offers the following strategic consulting engagements to help customers streamline the Agency ATO process.
- Cloud Discover: FedRAMP is a six-week interactive workshop to support customers that are just getting started with the ATO process on Google Cloud. Customers are educated on FedRAMP fundamentals, Google’s security and compliance posture, and how to approach ATO on Google Cloud. Through deep-dive interviews and design sessions, PSO helps customers craft an actionable ATO plan, assess FedRAMP readiness, and develop a conceptual ATO boundary. This engagement helps organizations establish a clear understanding and roadmap for FedRAMP ATO on Google Cloud.
- FedRAMP Security Review is a ten to twelve week engagement that aids customers in FedRAMP operational readiness. PSO consultants perform detailed FedRAMP architecture reviews to identify potential gaps in NIST 800-53 security control implementation and Google Cloud secure architecture best practices. Findings from the security reviews are shared with the customer along with configuration guidance and recommendations. This engagement helps organizations prepare for the third-party or independent security assessment that is required for FedRAMP ATO.
- Cloud Deploy: FedRAMP is a multi-month engagement designed to help customers document the details of their FedRAMP System Security Plan (SSP) and corresponding NIST 800-53 security controls, in preparation for Agency ATO on Google Cloud at FedRAMP Low, Moderate, or High. PSO collaborates with customers to develop a detailed technical infrastructure design document and security control matrix capturing evidence of the FedRAMP system architecture, security control implementation, data flows and system components. PSO can also partner with a third-party assessment organization (3PAO) or an independent assessor (IA) to support customer efforts for FedRAMP security assessment. This engagement helps customer system owners prepare for Agency ATO assessment and package submission.
Developing a Zero Trust Strategy
In addition to providing FedRAMP enablement, Public Sector PSO has partnered with the Google Cloud Chief Information Security Officer (CISO) team to assist organizations with developing a zero trust architecture and strategy.
Zero Trust Foundations is a seven-week engagement co-delivered by Google Cloud’s CISO and PSO teams. CISO and PSO educate customers on zero trust fundamentals, Google’s journey to zero trust through BeyondCorp, and defense in depth best practices. The CISO team walks customers through a Zero Trust Assessment (ZTA) to understand the organization’s current security posture and maturity. Insights from the ZTA enable the CISO team to work with the customer to identify an ideal first-mover workload for zero trust adoption. Following the CISO ZTA, PSO facilitates a deep-dive Zero Trust Workshop (ZTW), collaborating with key customer stakeholders to develop a NIST 800-207 aligned, cloud-agnostic zero trust architecture for the identified first-mover workload. The zero trust architecture is part of a comprehensive zero trust strategy deliverable that is based on focus areas called out in the Office of Management and Budget (OMB) Federal Zero Trust Strategy released January 2022.
Scaling Secure Cloud Adoption with PSO
Public Sector PSO enables customer success by sharing our technical expertise, providing cloud strategy, implementation guidance, training and enablement using our proven methodology. As enterprise IT, operations, and organizational models continue to evolve, our goal is to help government agencies accelerate their security and compliance journeys in the cloud. To learn more about the work we are doing with the federal government, visit cloud.google.com/solutions/federal-government.
Google Migration and BigQuery Brings PedidosYa Closer towards its Goal of Becoming Data-driven

7241
Of your peers have already read this article.
2:00 Minutes
The most insightful time you'll spend today!
Editor’s note: PedidosYa is the market leader for online food ordering in Latin America, serving 15 markets and over 400 cities. It’s also one of the largest brands within the German multinational company Delivery Hero SE. With over 20 million app downloads, PedidosYa provides the best online delivery experience through 71,000+ online partners, including restaurants, shops, drugstores, and specialized markets.
Having constant access to fresh customer data is a key requirement for PedidosYa to improve and innovate our customer’s experience. Our internal stakeholders also require faster insights to drive agile business decisions. Back in early 2020, PedidosYa’s leadership tasked the data team to make the impossible possible. Our team’s mission was to democratize data by providing universal and secure access while creating a comprehensive information ecosystem across PedidosYa. We also had to achieve this goal while keeping costs under control— even during the migration stage and removing operational bottlenecks.
Challenges with legacy cloud infrastructure
PedidosYa first built its data platform on top of AWS. Our data warehouse ran on Redshift, and our data lake was in S3. We used Presto and Hue as the user interfaces for our data analysts. However, maintaining this infrastructure was a daunting task. Our legacy platform couldn’t keep up with the increasing analytics demands. For example, the data stored on S3 complemented by Presto/Hue required high operational overhead. This was because Presto and our IAM (identity access management) didn’t integrate well in our legacy ecosystem. Managing individual users and mapping IAM roles with groups and Kerberos was operationally time-consuming and costly. Further, sharding access on the S3 files was far too complicated to enable seamless ACLs (access control lists).
There were also challenges with workload management. Our data warehouse had batch data loaded overnight. If one analyst scheduled a query to run during the overnight ETL (extract, transform, load) workload, it would disrupt the current ETL task. This could stop the entire data pipeline. We’d have to wait until data engineers intervened with a manual fix.
It was also difficult to understand whether a query error was due to performance issues or platform resource exhaustion. This lack of clarity affected our data analysts’ ability to autonomously improve querying efficiency. Data team members needed to manually inspect personal queries looking for performance issues. Also, the current architecture was prone to a ‘tragedy of the commons’ situation; it was seen as an unlimited and free resource. As a result, it was impossible to disentangle the infrastructure from different stakeholder teams, as all had very different needs.
The decision to modernize our data warehouse
Given the growing challenges from our legacy platform, our tech team decided to transform our analytics environment with a modern data warehouse. They required the following key criteria from their next data platform:
- Scalability – The ability to grow with elastic infrastructure.
- Cost control – Cost management and transparency. These factors promote efficiency and ownership—both key aspects of data democratization.
- Metadata management – Intuitive data platform focusing on users’ previous SQL knowledge. Plus, being able to enrich the informational ecosystem with metadata, to diminish data gatekeepers.
- Ease of management – The team needed to reduce operational costs with a serverless solution. Data engineers wanted to focus on their key roles rather than acting as database administrators and infrastructure engineers. The team also wanted much higher availability, and to reduce the impact of maintenance windows and vacuum/analysis.
- Data governance and access rights – With a growing employee base with varying data access requirements, the team needed a simple yet comprehensive solution to understand and track user access to data.
Migrating to Google Cloud
After exploring other alternatives, we concluded Google Cloud had an answer to each of our decision drivers. Google Cloud’s serverless, managed, and integrated data platform, coupled with its seamless integration across open-source solutions, was the perfect answer for our organization. In particular, the natural integration with Airflow as a job orchestrator and Kubernetes for flexible on-demand infrastructure was key.
We used Dataflow together with Pub/Sub and Cloud Functions for our data ingestion requirements, which has made our deployment process with Terraform seamless. Because we set up everything in our environment programmatically, operation time has diminished. Google Cloud reduced the deployment process from about 16 hours in our legacy platform to 4 hours. This is partly due to the friendliness of automating the deployment (such as schema check, load test, table creation, build.) process with Terraform, Cloud Functions, Pub/Sub, Dataflow, and BigQuery on GCP. Input messages processed with Dataflow allow us to abstract and plan the schema changes according to the needs of the functional team. For example, schema changes raise an alarm, and then we can modify the raw layer table schema. By doing this, we ensure that backend modifications that we don’t control do not affect upper layers.
A key reason why we picked Google Cloud was because of its advanced cost and workload management coupled with its transparent log analytics. This information gives us a complete view into any query performance issues to make improvements on the fly. Further, we achieved a significant amount of cost savings by consolidating multiple tools to BigQuery.With BigQuery, we’ve been able to reduce our total cost per query by 5x.
This was due to a number of reasons:
- Automating pipeline deployment made it much simpler to maintain the data processing processes.
- Analysts are conscious about what queries they’re running, resulting in running better, more optimized queries.
- Analysts use a Data Studio dashboard to see their queries and all the associated costs. As a result, there’s a lot more transparency for each persona.
With these changes, we can easily manage and assign costs associated with each workload with their own cost centers using specific Google Cloud projects.
Change management is always challenging. However, BigQuery is intuitive and doesn’t have a steep learning curve from Hue/Hive on SQL basics. BigQuery also allowed the team to expand its capabilities and enabled them to properly work with nested structures, avoiding unnecessary joins and improving query efficiency. Additionally, we now use Data Catalog as our unique point of truth for metadata management. This allows our team to break the data access barriers and enable federation of data across the organization. By using Airflow to orchestrate everything, we keep track of every data stream. With this information, each end user can see their regularly used data entities’ status via the dashboard. This also adds transparency to our everyday data processes.
Finally, with Google Cloud’s IAM rules applied across the different products, data sharing and access is close to a noOps experience. We have programmatically implemented access according to roles and level access within the company. This allows certain pre-validated roles to view more sensitive information. These solutions help drive a more automated data governance experience.
Up next: Google Cloud AI/ML
The new stack based on BigQuery has created significant productivity gains. Freed from the burden of operational management, PedidosYa’s data team can now focus on adding value through data tools and products.
- Our data engineers are better equipped to integrate constantly changing transactional and operational data.
- The dataOps team can automate the infrastructure and provide autonomy to the end user.
- Our data quality team can focus on bringing added value to data stakeholders.
- Data scientists and data analytics can spend more time analyzing data and less time asking data gatekeepers for data access.
PedidosYa can now democratize data access with a well-governed architecture. We are still at the beginning of our journey, but we are closer to achieving our vision of building a data-driven organization. Up next: expanding our artificial intelligence and machine learning capabilities.
Tune in to Google Cloud’s Applied ML Summit on June 10th, 2021, or listen on-demand later, to learn how to apply groundbreaking machine learning technology in your projects.
A Year of Going Carbon-free! Google’s Road to Sustainability Looks Promising

3738
Of your peers have already read this article.
2:00 Minutes
The most insightful time you'll spend today!
Last year, we announced our most ambitious sustainability goal yet: to operate everywhere on 24/7 carbon-free energy by 2030. We’ve set this goal to ensure that Google Cloud continues to be the cleanest cloud in the industry, and to show that full-scale decarbonization of electricity use is possible.
Since setting our target, we’ve made tremendous progress in how we track, buy, and use electricity; advocate for clean energy policies; and support the development of new technologies to help us reach this goal. And we’ve done it all while maintaining a commitment to transparency that we hope will make it easier for other organizations wishing to fully decarbonize their operations as well.
In the spirit of transparency, today we’re releasing the 2020 carbon-free energy percentages (CFE%) for all Google data centers, as well as overall progress on the road to our 2030 goal: In 2020, Google achieved 67% round-the-clock carbon free energy across all its data centers, up from 61% in 2019. In other words, of all the electricity consumed by Google data centers in 2020, two-thirds of it was matched with local, carbon-free sources on an hourly basis.
Though we saw a significant jump in global CFE% in 2020, we expect the numbers to vary from year to year. Ultimately, CFE% is dependent on the amount of new clean energy that comes online in a given year; we may even occasionally see short-term drops in the numbers. What’s most important is that we continue to maintain a long-term trajectory toward our 2030 goal. With meaningful progress in clean energy policy, technologies, and transactional models, we believe 24/7 carbon-free energy is achievable.
Tracking these numbers also allows us to give Google Cloud customers greater control in their own sustainability efforts. Earlier this year we announced Google Cloud Region Picker, a system that helps our customers assess factors like cost, speed, and CFE% as they choose where to run their applications.
To outline some of the events that have helped us get to 67% CFE%, we’ve developed an animation that shows every hour of electricity use in 2020, at all our Google data centers around the world.
Visualizing clean energy: every hour, every day, everywhere
Imagining what every hour in a year looks like is hard enough (there are 8,760 of them, in case you’re wondering). With 23 data centers and 25 cloud regions around the world, we’re aiming to source clean energy for over 200,000 operational hours each year.
https://youtube.com/watch?v=f9ecEokcFlk%3Fenablejsapi%3D1%26
The “A year in carbon-free energy” animation points out significant projects that came online in 2020 to bring our data centers closer to operating entirely on round-the-clock carbon-free energy. It also reflects an unparalleled level of transparency about our carbon-free energy data, showing hour-by-hour where we need to develop new clean energy projects, advocate for policy changes, and in some cases, look to new technologies that can help fill in the gaps left by variable renewable resources.
In the animation, you’ll notice sites with a lot of green at midday (e.g. in Chile or the U.S. Southeast) – a sign that solar is making a big contribution. Other data centers, such as our facilities in the U.S. Midwest, rely more heavily on wind power and are subject to seasonal fluctuations in wind speed.
Preventing the worst impacts of climate change will require decarbonizing the world’s electric grids, as fast as possible. Google is committed to doing as much as possible to clear a path for others and drive collective action to achieve this goal. We’re thrilled to be in good company as we move, together, toward a carbon-free future.
More Relevant Stories for Your Company

Expanding Google Cloud Ready – Sustainability Program with 12 New Partners
We introduced the Google Cloud Ready – Sustainability designation earlier this year to showcase those partners committed to help global businesses and governments accelerate their sustainability programs. These partners build solutions that enhance the capabilities and ease the adoption of powerful Google Cloud technologies, such as Google Earth Engine and

Learning Should be Your Resolution for 2022: Register for Google Cloud Skills Boost
Start your 2022 New Year’s resolutions by learning at no cost how to use Google Cloud with the following training opportunities: 30 day access to Google Cloud Skills Boost Register by January 31, 2022 and claim 30 days free access to Google Cloud Skills Boost to complete the Getting Started with

AgroStar: Small farms in India getting big help from the cloud
AgroStar has launched a cloud-based mobile app that is helping to boost crop yields and encourage best practices for small farmers in India. Launched as an on-premises ecommerce platform selling farm tools in 2008, the firm turned to Google Cloud Platform (GCP) to expand its offering. It now uses cloud-based analytics and is

Lending DocAI Shortens Borrowers’ Journey on Roostify
The home lending journey entails processing an immense number of documents daily from hundreds of thousands of borrowers. Currently, home lending document processing relies on some outdated digital models and a high dependency on manual labor, resulting in slow processing times and higher origination costs. Scaling a business that sorts






