Lower risk, greater return: Public sector organizations are focusing on multicloud adoption

3000
Of your peers have already read this article.
4 Minutes
The most insightful time you'll spend today!
Government organizations are starting to realize that no single cloud can meet their wide range of needs. According to the Nutanix 2022 Enterprise Cloud Index1, 75% of public sector organizations agree that multicloud is ideal, and more public sector organizations than average have adopted multicloud as a primary IT operating model (outpacing the global average). Furthermore, global public sector multicloud adoption is expected to nearly double from 39% to 67% in the next three years.
Some leaders worry about the perceived complexity of multicloud —as well as cost, security, and overall compliance requirements. But the right strategy, tools, and partners can help alleviate these concerns and help create a path to new levels of efficiency, service delivery effectiveness, and security.
Multicloud math: Greater return at lower risk
Modern financial theory asserts that a diversified portfolio is an effective hedge that yields greater return at lower risk. Similarly, multicloud, a diversified portfolio of clouds, has the potential to yield a stronger return on IT investment, provide a lower risk, and deliver greater overall efficacy. While this may seem counterintuitive, the “Anything as a service” (XaaS) nature of cloud can be even more potent across a portfolio of trusted Cloud Service Providers (CSPs).
Each cloud brings unique strengths and capabilities in terms of costs, services, footprint, support, and innovation. Moreover, each cloud continues to evolve. Implementing a multicloud portfolio has the potential to optimize the power of these clouds while reducing overall risk.
It’s fair to say that considerations should go beyond just a diversification and cost strategy. Multicloud gives public sector organizations the power to select best-of-breed capabilities and match the right workload to the optimal cloud. In addition, multicloud helps empower government leaders to protect themselves against vendor lock-in, fluctuating costs, and potential external risks. It also broadens access to an ecosystem of strategic partners.
Accelerating the cloud adoption curve
Once you get started with your first CSP, it can be easier to incorporate additional CSPs. Many aspects of the processes, knowledge base, and efficiencies created during the first rollout can serve as a playbook for future cloud engagements.
For instance, technical training can be easier and more iterative. When an organization first embraces cloud, it can make significant investments in training engineers and security staff, in addition to general education for the broader workforce. Subsequent cloud training with additional CSPs is then generally easier for teams to learn and adopt. Furthermore, key concepts are transferable, and some APIs and services are exact duplicates—all of which helps make learning new CSPs easier and cost-effective.
Cloud management efficiency at scale
Standardizing processes at scale across providers is essential to avoiding cumulative overhead costs and complexity. Agnostic partner tools play an important role. For example Kion and Prisma Cloud by Palo Alto standardize and automate security, compliance, and financial processes across CSPs. And, Terraform by Hashicorp has an infrastructure-as-code software tool that provides a consistent command-line interface workflow to manage CSPs (even on-premises).
Public sector organizations can use these options to create and maintain cloud environments that have uniform configurations and security postures and can provide real-time security monitoring—reducing costs, boosting overall security, and optimizing resource availability. For instance, in partnership with Palo Alto Networks, Google Cloud built a secure cloud access solution that allows the Defense Innovation Unit (DIU) users to access services in any commercial cloud environment, while performing the required security actions of logging, threat analysis, and session control (read more here).
The right partners for your mission
A successful multicloud strategy starts with finding the right CSPs for your mission. Google’s multicloud solutions can help kick-start the journey with open source collaboration and the ability to build and scale. Beyond core capabilities, it’s essential to find a cloud partner that can help serve the core needs of your mission: simplicity and rapid time to value. For example, Google Cloud’s Anthos helps public sector organizations ensure multicloud security, allowing them to manage containerized applications across multiple cloud and on-premises environments from a single management plane.
The key to multicloud success is managing and optimizing multicloud using proven portfolio techniques to maximize return and reduce risk. Ready to elevate your multicloud strategy? Download our whitepaper, 5 ways Google can help you succeed in a hybrid and multicloud world, to learn more about how diversifying your cloud portfolio can help you meet the needs of your agency and its mission.
References:
Lower risk, greater return: Public sector organizations are focusing on multicloud adoption

3001
Of your peers have already read this article.
4 Minutes
The most insightful time you'll spend today!
Government organizations are starting to realize that no single cloud can meet their wide range of needs. According to the Nutanix 2022 Enterprise Cloud Index1, 75% of public sector organizations agree that multicloud is ideal, and more public sector organizations than average have adopted multicloud as a primary IT operating model (outpacing the global average). Furthermore, global public sector multicloud adoption is expected to nearly double from 39% to 67% in the next three years.
Some leaders worry about the perceived complexity of multicloud —as well as cost, security, and overall compliance requirements. But the right strategy, tools, and partners can help alleviate these concerns and help create a path to new levels of efficiency, service delivery effectiveness, and security.
Multicloud math: Greater return at lower risk
Modern financial theory asserts that a diversified portfolio is an effective hedge that yields greater return at lower risk. Similarly, multicloud, a diversified portfolio of clouds, has the potential to yield a stronger return on IT investment, provide a lower risk, and deliver greater overall efficacy. While this may seem counterintuitive, the “Anything as a service” (XaaS) nature of cloud can be even more potent across a portfolio of trusted Cloud Service Providers (CSPs).
Each cloud brings unique strengths and capabilities in terms of costs, services, footprint, support, and innovation. Moreover, each cloud continues to evolve. Implementing a multicloud portfolio has the potential to optimize the power of these clouds while reducing overall risk.
It’s fair to say that considerations should go beyond just a diversification and cost strategy. Multicloud gives public sector organizations the power to select best-of-breed capabilities and match the right workload to the optimal cloud. In addition, multicloud helps empower government leaders to protect themselves against vendor lock-in, fluctuating costs, and potential external risks. It also broadens access to an ecosystem of strategic partners.
Accelerating the cloud adoption curve
Once you get started with your first CSP, it can be easier to incorporate additional CSPs. Many aspects of the processes, knowledge base, and efficiencies created during the first rollout can serve as a playbook for future cloud engagements.
For instance, technical training can be easier and more iterative. When an organization first embraces cloud, it can make significant investments in training engineers and security staff, in addition to general education for the broader workforce. Subsequent cloud training with additional CSPs is then generally easier for teams to learn and adopt. Furthermore, key concepts are transferable, and some APIs and services are exact duplicates—all of which helps make learning new CSPs easier and cost-effective.
Cloud management efficiency at scale
Standardizing processes at scale across providers is essential to avoiding cumulative overhead costs and complexity. Agnostic partner tools play an important role. For example Kion and Prisma Cloud by Palo Alto standardize and automate security, compliance, and financial processes across CSPs. And, Terraform by Hashicorp has an infrastructure-as-code software tool that provides a consistent command-line interface workflow to manage CSPs (even on-premises).
Public sector organizations can use these options to create and maintain cloud environments that have uniform configurations and security postures and can provide real-time security monitoring—reducing costs, boosting overall security, and optimizing resource availability. For instance, in partnership with Palo Alto Networks, Google Cloud built a secure cloud access solution that allows the Defense Innovation Unit (DIU) users to access services in any commercial cloud environment, while performing the required security actions of logging, threat analysis, and session control (read more here).
The right partners for your mission
A successful multicloud strategy starts with finding the right CSPs for your mission. Google’s multicloud solutions can help kick-start the journey with open source collaboration and the ability to build and scale. Beyond core capabilities, it’s essential to find a cloud partner that can help serve the core needs of your mission: simplicity and rapid time to value. For example, Google Cloud’s Anthos helps public sector organizations ensure multicloud security, allowing them to manage containerized applications across multiple cloud and on-premises environments from a single management plane.
The key to multicloud success is managing and optimizing multicloud using proven portfolio techniques to maximize return and reduce risk. Ready to elevate your multicloud strategy? Download our whitepaper, 5 ways Google can help you succeed in a hybrid and multicloud world, to learn more about how diversifying your cloud portfolio can help you meet the needs of your agency and its mission.
References:
3123
Of your peers have already watched this video.
12:00 Minutes
The most insightful time you'll spend today!
How Google Cloud Helps Banks and FinTech Create Cutting-edge, Digital Banking Products
Today’s customers demand sophisticated and secure banking platforms to keep up with the digital era. Banking and financial institutions spend time and investments either modernizing traditional banking products and solutions or building new cutting-edge products from the scratch. Money transfer solutions, bill payments and rewards, credit cards facilities, retail payments, loans services and more, banking products have a huge potential for leveraging Banking-as-a-service model which is a modular, cloud-native digital banking architecture that offers financial products and services via APIs and micro services. So, what typically goes under the sheets of a modern banking app that can easily build and adapt features in a matter of days and not months to keep up with the demand?
Watch the video to understand the role played by Google Cloud and its secure and scalable architecture for building digital banking products and services for today’s customers!
5328
Of your peers have already watched this video.
31:30 Minutes
The most insightful time you'll spend today!
Enhancing Collaboration with Sheets, Python, and Google Cloud
See how you can enhance collaboration within your organization using Google Sheets. Watch to learn about a new set of tools to create custom functions that tap into the power of Python and to expose functions in a standardized fashion throughout your organization.

5814
Of your peers have already downloaded this article
1:40 Minutes
The most insightful time you'll spend today!
APIs are the foundation for digital commerce, enabling retailers to evolve from web to mobile.
APIs allow retailers to create services such as price check, compare and review products, get instant product availability, purchase, schedule pickup, and delivery, and improve customer engagement and loyalty–all from users’ mobile devices.
Evolving from traditional retail and web commerce to mobile and omnichannel business models requires APIs that can bridge traditional business processes and modern services for richer user engagement.
The most common API patterns found among the world’s leading digital commerce programs can be mapped to specific use cases that are tied to critical business initiatives for retailers.
While many retail companies have deployed more than 30 different APIs, almost two-thirds of retailers are still in the early stages of digital commerce maturity.
Digital commerce programs typically begin by implementing a core set of API patterns. Growing competition and requirements to increase margins from digital channels to drive the need for advanced API patterns that enable more sophisticated digital solutions.
Download the full report to get crucial insights on how APIs are changing the way digital commerce is being done.
Secret Manager: Keeping Your Organization’s Secrets Safer!

3283
Of your peers have already read this article.
2:00 Minutes
The most insightful time you'll spend today!
Secret Manager is a Google Cloud service that provides a secure and convenient way to store API keys, passwords, certificates, and other sensitive data. It is the central place and single source of truth to manage, access, and audit secrets across Google Cloud. Since its launch, Secret Manager has helped secure millions of workloads and continues to provide industry-first features like replication policies and support for VPC perimeters. This blog post explores new Secret Manager capabilities and integrations that will help keep your secrets safer.
New tier, free of charge
No, you’re not dreaming – Secret Manager now has a tier that is free of charge! With this tier, each month per billing account you can have up to:
- 6 secret versions
- 3 rotation events
- 10,000 API calls
This enables you to experience the value of Secret Manager with minimal financial risk and pairs nicely with existing services that offer a free tier like Cloud Run and Cloud Functions. For existing Secret Manager customers, this change will go into effect next billing cycle. Learn more about the Secret Manager free tier in the documentation.
Increased SLA
To meet the growing availability and reliability requirements of our customers, the Secret Manager SLA is now 99.95%! With this update, Secret Manager guarantees that all valid requests will succeed 99.95% of the time. This means you can depend on Secret Manager for even your most critical workloads. Additional details are available in the updated Secret Manager SLA.
Geo-expansion
In addition to the free tier and increased SLA, Secret Manager is now available in all public Google Cloud regions! With Secret Manager’s replication policies, you can choose the specific regions in which to replicate your secret, which means you can store secret payloads in geographical proximity to your workloads or users to reduce latency. This is also very useful if you have legal or regulatory requirements to store data in a particular locality. For more information, check out the list of Secret Manager locations in the documentation.
Compliance certifications
For customers wishing to use Secret Manager to store and process regulated data, Secret Manager is validated for compliance use cases including ISO 27001, ISO 27017, ISO 27018, SOC 1, SOC 2, SOC 3, PCI DSS, and HIPAA. Combined with the increased SLA and geographical availability, this makes Secret Manager suitable for use with regulated workloads.
Customer-Managed Encryption Keys (CMEK)
Secret Manager has always encrypted payloads in transit with TLS and at rest with AES-256. For customers that want additional control over the keys used to encrypt their secret payloads, Secret Manager now supports Customer-Managed Encryption Keys (CMEK). Secret Manager CMEK supports software-backed keys via Cloud KMS, hardware-backed keys via Cloud HSM, and even externally-managed keys via Cloud EKM. Learn how to enable CMEK support for Secret Manager in our tutorial.
Expiration and TTLs
While it was previously possible to expire access to a secret using IAM conditions, the underlying secret would continue to exist. Secret Manager now supports auto-expiring secrets which permanently deletes a secret at a specified timestamp or TTL. Since it is also possible to update a secret’s TTL, services can “lease” a secret and renew their lease on a periodic basis. If the service does not extend the lease by updating the TTL, the secret is automatically deleted.
Expiring secrets can be used in combination with IAM conditions to more safely expire secrets. For more information on expiring secrets and safety measures, see the guide on creating and managing expiring secrets.
Etags and server-side filtering
For customers that create or manage Secret Manager secrets via the API or an SDK, concurrency controls and performance are extremely important. This is why Secret Manager now supports Etags and server-side filtering! Etags help prevent concurrent modifications to the same secret by providing optimistic concurrency controls, while server-side filtering can dramatically reduce payload size and client-side computational overhead. Together, these enable stronger consistency guarantees and performance improvements to your applications. Learn more about Secret Manager Etags and Secret Manager server-side filtering in the documentation.
Code, build, run, deploy, monitor, and orchestrate
Secrets – like API keys, passwords, and certificates – are an integral part of most modern software applications. It is crucial that developers, operators, and security teams are empowered to build, operate, and observe software securely. That is why Secret Manager is now integrated with popular tools and technologies used throughout the application development lifecycle:
- Code – Software engineers can create and access secrets directly from their preferred IDEs with Cloud Code. In VS Code, IntelliJ, or the Cloud Shell Editor, developers can browse secrets and insert code snippets for access secrets, all from the comfort of their local IDE.
- Build – Release engineers can access secrets as part of CI builds using the Cloud Build Secret Manager integration. This could be used, for example, to authenticate to a Docker registry or communicate with the GitHub API. For customers that use other CI systems, there is also a GitHub Action for accessing Secret Manager secrets.
- Run (on serverless) – Developers can mount secrets to be available as environment variables or via the filesystem through the native Cloud Run Secret Manager integration. Since the secrets are resolved in Cloud Run’s control plane, developers can use this integration to avoid a tight coupling between their applications and Secret Manager to enable hybrid cloud deployments or better local development experiences.
- Run (on Kubernetes) – Developers can mount secrets from GKE, Anthos, or any Kubernetes cluster using the Secret Manager CSI driver. This vendor-agnostic driver exposes secrets via environment variables or the filesystem and enables hybrid cloud deployments using the same interface as other public cloud providers and HashiCorp Vault.
- Deploy – To complement the existing Secret Manager Terraform integration, operators can now manage Secret Manager via Kubernetes Config Connector (KCC). KCC allows operators to manage Google Cloud resources through Kubernetes and the familiar Kubernetes APIs.
- Monitor – With the Secret Manager Cloud Asset Inventory (CAIS) integration, security teams can understand secret usage across specific projects, folders, or the entire organization.
- Orchestrate – Secret Manager Event Notifications enable DevOps and security teams to subscribe to Pub/Sub topics for when secrets or secret versions are changed. This enables customers to create deeply-integrated workflows, such as creating a ServiceNow ticket when a new secret version is added. Additionally, Secret Manager Rotation Scheduling enables DevOps teams to build automatic rotation flows like the ones described in the rotation guide.
Best practices
The Secret Manager best practices guide ensures customers get the maximum security benefits from Secret Manager. Security is non-binary, and this guide covers nuanced topics like access controls, coding practices, and secret administration. While not an exhaustive list, the Secret Manager best practices guide answers some of the most common questions and concerns around using Secret Manager in production deployments.
Towards seamless security
Secrets management is an important part of every organization’s security toolkit. With Secret Manager, you can easily manage, audit, and access secrets like API keys and credentials across Google Cloud, Anthos, and on-premises. These new features and integrations make it easy to adopt Secret Manager whether you are a hobbyist working on a side project or a large enterprise with thousands of employees.
To get started, check out the Secret Manager documentation.
More Relevant Stories for Your Company

What’s New in Retail: Bits from Google Cloud’s Retail & Consumer Goods Summit
Today we’re hosting our Retail & Consumer Goods Summit, a digital event dedicated to helping leading retailers and brands digitally transform their business. For me, this is a personally exciting moment, as I see tremendous opportunities for those companies that choose to focus on their customers and leverage technology to elevate

Don’t Just Move to the Cloud, Modernize With Google Cloud
Our customers tell us they don’t just want to migrate their applications from point A to point B, they want to modernize their applications with cloud-native technologies and techniques, wherever those applications may be. Today, we’re excited to tell you about a variety of new customers that are using Anthos to transform

APIs Help Cleveland Clinic Revamp their IT Infrastructure and Deliver High Quality Healthcare
Cleveland Clinic is one of the largest and most respected hospitals in the United States. Its mission is to provide better care of the sick, investigate their problems, and deliver further education of physicians. The clinic deployed electronic medical records (EMR) to help doctors deliver greater quality healthcare. But the

New Map Customization Features for Enhanced User Experiences
A customized map can be key to delivering a frictionless experience that engages users and sets you apart in users’ minds–whether you’re a real estate company fine-tuning points of interest (POIs) on a map to help buyers decide where to live, or a regional pharmacy styling a map to ensure






