ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

Send in the Clouds

April 27, 2018
Reading Time: 5 mins read

By Monica C. Meinert

In 2015, Capital One announced plans to reduce its number of physical data centers from eight locations down to three by the end of 2018 by leveraging the cloud computing technology provided by Amazon Web Services. Having gone through an experimentation phase with AWS throughout 2013 and 2014, the public announcement marked another significant step in the bank’s ongoing quest to remain on the cutting edge of financial technology.

A year later, the bank officially selected AWS as its predominant cloud infrastructure provider, with the goal of migrating many of its core businesses and customer applications to Amazon’s cloud environment over the next five years. By moving to the cloud, the bank gained the ability to scale products and services even more quickly, realize cost efficiencies, ensure a higher level of cybersecurity and even attract new talent by opening up new tech-oriented positions within the company. Perhaps most importantly, the cloud allowed Capital One to free up resources that would allow it to drive innovation and respond nimbly to customers’ increasing demand for a better digital experience.

Capital One’s journey with Amazon echoes a broader mindset shift that’s occurring across the industry from the nation’s largest institutions to local community banks: in a world of constant technological change, innovation is imperative, and cloud services are becoming increasingly central to banks’ innovation strategies.

Choosing the cloud

It was 2013 when Ben Wallace—a former IT executive at JP Morgan Chase—arrived at Orrstown Bank in Shippensburg, Pa., charged to help engineer an operational and IT revitalization. The $1.5 billion asset institution was, at the time, working to strengthen many aspects of its business—including the foundation upon which it would grow and expand into new markets. Having never worked at a community bank before, Wallace immediately began to assess what it would take to help the bank operate more efficiently and grow.

One possible solution: thinking differently about its infrastructure and in-house systems—including which could be migrated to the cloud.

“Historically, we operated all of our applications and systems within local data centers—carrying all the related overhead and expense,” he explains. “So we said: ‘We’re going to engineer a bank for the future—thinking how we reduce the reliance on our local data centers over time and improve our risk and control environment while also improving our efficiency. From there, it became a question of “which public cloud partners offer the appropriate control and risk environment—Amazon, [Microsoft] Azure and others.”

Wallace and his team began by migrating the bank’s backup framework over to Amazon Glacier—an archival storage solution that helped the bank retire the physical magnetic tapes it had used for years. They also explored additional solutions through other cloud providers, such as Microsoft Office 365, email archival solutions and numerous in-house applications.

Depending on the solution, he notes that the bank has seen cost reductions resulting from using cloud services rather than those hosted on-site. And Orrstown’s move to the cloud has also allowed employees to spend less time focusing on system maintenance and upgrades and more time on customer-facing initiatives. “We’ve been able to realign functions and roles [to spend] more time on applications and with the business users than we do on the infrastructure side,” Wallace says. “That’s a dramatic shift from where we were five years ago.”

Balancing strategy and risk

Cloud-hosted environments—whether public clouds like AWS or Azure, private clouds created for individual institutions or hybrid clouds combining elements of the two—are slowly but surely becoming the standard across many industries for the efficiencies they provide. Even within the heavily regulated financial services industry, which has been slower to adopt new technologies, many bankers are finding that cloud-hosted solutions are beginning to overtake on-premises options.

“As we have evaluated new solutions over the last five to seven years, we’re seeing more and more of [them] delivered as software as a service—or SaaS—solutions, to the point that in some evaluations, we would be lucky to have one or two in-house implementation options,” notes Albert Kendrick, chief information officer at FirstBank in Lakewood, Colo.

That observation, along with the bank’s longstanding customer-focused strategy, prompted Kendrick and other FirstBank executives to begin serious conversations about moving certain systems and platforms to the cloud. Stakeholders from across the organization were pulled in to assist: from IT to security, vendor management to audit; Kendrick emphasizes that it was important to the bank to have a wide range of perspectives looking at the issue from the outset. The bank also engaged a third-party auditing firm to assist with additional reviews.

Now a year and a half into the process, Kendrick says that the bank has identified the various cloud providers that it plans to use for the bulk of its solutions and is beginning to transition solutions one by one to a cloud environment. “Our ultimate goal is to eliminate our in-house data centers and run them as much in the cloud as possible,” he says. “The next six to nine months as we assess different applications and what their cost model is in the cloud versus on-prem, that’s really going to be the decider as far as how far we go down this path.”

Critical to any successful cloud strategy is a strong risk management framework, and banks pursing such a strategy should be carefully evaluating what data is being uploaded to a cloud environment, how it is being used and who can access it.

“You really have to look at: what risk does that data pose should it be compromised?” notes David Kelly, FirstBank’s chief risk officer. “And not just today—you have to determine those potential risks that could exist down the road as well . . . and find the right partner that allows you to configure things appropriately and provide the actual protection that you’re looking for.”

In evaluating a potential third-party cloud service provider, Kelly says the bank’s risk management team examines the extent to which data is shared, the physical and environmental security of the vendor, whether data can be encrypted, how personnel with data access are authenticated and how the company approaches breach management.

“We do make sure we have access to what their third-party audits are, we look at their SOC reviews, do they conduct penetration testing themselves?” Kelly says. “A lot of the large, well-established providers will automatically give that to you. If they’re reluctant, that may be a flag.”

Kelly also tries to include requirements in the vendor service contract for the third-party to have a known trusted incident response provider on retainer that could step in and assist in the event of a breach. “We’ve even talked about: should we have the right to audit built into the contracts?” he adds. “If we find there’s a deterioration in performance, can we negotiate the right to send our own auditors in to assess the situation?”

Cloud on the horizon

The bankers all agree that the key to successful cloud migrations lies in the partnerships banks forge with their providers. “Always think about it as a journey that’s not going to be an overnight, and do it in phases,” Wallace advises. “Involve your regulatory partners, educate your internal staff and methodically evaluate which systems go first, second, third.”

Kelly emphasizes that bankers should feel comfortable with the level of security and controls their cloud provider has in place, noting that while banks may be outsourcing various functions, they still own the risk. “Our customers don’t care that we outsourced it to a poorly run vendor,” he says. “Ultimately, we take responsibility for our customers’ data.”

The advantages of cloud computing are numerous, and with strong third-party risk management controls in place, bankers can reap the rewards of reduced costs and more efficient operations. But beyond the financial statement implications, the cloud model is beginning to fundamentally reshape companies at the organization level as well. “Recognize that it’s not going to be a static environment,” Wallace says. “[Banks] need to be more dynamic, they need to recognize that it’s going to be a fluid world—it’s going to be a new reality.”

Tags: Cloud computing
ShareTweetPin

Author

Monica C. Meinert

Monica C. Meinert

Monica C. Meinert is a senior editor at the ABA Banking Journal and VP for executive communications at the American Bankers Association.

Related Posts

Appeals court upholds Fed decision to deny crypto firm master account

Appeals court upholds Fed decision to deny crypto firm master account

Legal
October 31, 2025

A federal appeals court ruled that the Federal Reserve is not obligated to grant a master account to a cryptocurrency firm, as the move would “impair the Fed’s ability to safeguard our nation’s financial system.”

Treasury Department seeks feedback on stablecoins, illicit activities

Lawmakers, policymakers express concern about interest-bearing stablecoins

Newsbytes
October 29, 2025

Several policymakers raised concerns with media outlets in recent days about a loophole in the Genius Act that allows stablecoin issuers to avoid its prohibition on paying interest.

Federal court finds CFPB funding structure constitutional

Court temporarily halts Section 1033 rule enforcement

Compliance and Risk
October 29, 2025

A federal court issued an order preventing the CFPB from enforcing its rule on financial data sharing while the bureau reassesses the regulation.

Trump orders creation of AI ‘action plan’

ABA makes recommendations for AI policy, regulatory reform

Cybersecurity
October 27, 2025

ABA submitted bank-specific recommendations on policy and regulation of artificial intelligence as the Trump administration seeks to make the U.S. a leader in the technology.

ABA, SBAs: CFPB RFI shows ‘deeply flawed conclusions’ on consumer financial markets  

Staying ahead of criminals to protect ATMs

Compliance and Risk
October 27, 2025

Banks can subscribe to security-related alerts, updates or portals offered by ATM manufacturers themselves to better understand evolving threats.

ABA urges FCC to modernize calling rules, strengthen fraud protections

ABA urges FCC to modernize calling rules, strengthen fraud protections

Compliance and Risk
October 22, 2025

ABA is urging the FCC to issue a notice of proposed rulemaking that would adopt several ABA requests to modernize the commission's Telephone Consumer Protection Act rules and combat illegal call spoofing. The FCC is scheduled to vote...

NEWSBYTES

Appeals court upholds Fed decision to deny crypto firm master account

October 31, 2025

ABA DataBank: Candy prices outpace headline inflation

October 31, 2025

Survey: Small-business owners generally happy with their banks

October 31, 2025

SPONSORED CONTENT

5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025
What good looks like in Small Business Lending – and how to get there

What good looks like in Small Business Lending – and how to get there

October 1, 2025

PODCASTS

Podcast: Why branches are top priority for PNC

October 23, 2025

Podcast: From tractors to drones, how farming tech affects ag lending

October 16, 2025

Podcast: Bigger data boosts financial inclusion at Synchrony

October 9, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.