The Federal Cloud Requires a Mission-Based Balance of Security, Performance and Cost

Presented by FedHive & Carahsoft

The familiar technology tradeoff suggests that organizations can optimize security, performance or cost, but not all three. Michael Cardaci does not believe federal agencies should accept that limitation without first examining the mission and the information involved.

Cardaci, CEO of FedHIVE, sees the three considerations as part of a spectrum. At one extreme, an agency might create a highly restrictive environment that maximizes security but becomes slow and expensive to use. At the other, it might prioritize speed and affordability while accepting a level of risk that is inappropriate for the mission.

Screenshot 2026-07-30 at 3.25.50 PMThe answer is not to choose one universal position on that spectrum. It is to understand where each system belongs.

“You want to understand what the mission is trying to do,” Cardaci said, “because data has a spectrum.”

Some information requires the strongest available safeguards. Other information may present less risk if it is exposed. Mission owners and technology teams must work together to understand the potential effect of a compromise before deciding how the system should be designed.

Cardaci said the analysis should include both the number of people who could be affected and the seriousness of the harm. A small data set might involve relatively few individuals but create severe consequences for each one. Another system may reach a large population while containing less sensitive information.

Those variables help agencies determine the appropriate security posture.

The government’s accelerating modernization efforts make that judgment increasingly important. Federal leaders are encouraging agencies to use more commercial technology and move additional workloads into the cloud. That can bring innovation into government, but it also raises the stakes surrounding architecture and security decisions.

The federal government holds broad collections of information about citizens and operates services people depend on. A private company might be able to absorb an incident involving a narrow customer group. An agency may be protecting health records, financial information or data connected to a critical public mission.

“The government really has only one shot at it,” Cardaci said.

That responsibility does not mean every workload belongs in the same environment. Agencies should look across the entire distribution of their technology portfolios and decide how much should remain on premises, how much belongs in a private cloud and how much can move to a commercial hyperscale provider.

Each choice creates a different combination of flexibility, cost, performance and security.

Agencies must also consider the security of the broader commercial cloud environment, not only specialized government regions. As more commercial products and platforms become part of federal operations, the resilience of those environments will have a direct effect on government missions.

The cloud itself has also changed.

Screenshot 2026-07-30 at 3.25.36 PMDuring the federal government’s early adoption period, agencies often viewed the cloud largely as a new place to store information. Data moved from agency-owned infrastructure into a remote environment, but users did not necessarily perform their daily work there.

Today, cloud platforms host applications, workflows and operational data. Employees connect from government offices, homes and remote mission locations. More people are accessing systems through more devices and networks.

That expanded use changes the security problem.

“When it was just, ‘We’re moving data to the cloud,’ you had to have this bubble around it,” Cardaci said. “Now you have more people accessing these clouds from different areas.”

Agencies therefore need to secure not only the stored information but also the identities, connections, applications and activities surrounding it. The cloud has become a working environment, and security must account for the way people actually interact with it.

The rise of AI and automation adds another layer of complexity. Technology providers must continually adapt their security practices as new vulnerabilities and attack methods emerge. A company cannot assume that the controls it developed years ago will remain sufficient.

Industry must remain engaged with government, understand how agencies need to consume technology and adjust as missions evolve. Government, in turn, needs the technical capacity to evaluate what providers are offering and integrate it into existing operations.

Cardaci sees the evolution of FedRAMP as an encouraging sign.

The program’s move toward continuous evidence and an ongoing understanding of security posture is better suited to the modern cloud than an assessment that captures only one point in time.

“The idea of not just having a moment in time, but actually having an ongoing understanding of what the health of security is—I think that’s the right direction,” he said.

The goal should be awareness that is as close to real time as the risk requires. Systems change, vulnerabilities appear and users interact with technology long after the initial authorization. Agencies need current information about their exposure if they are going to respond before an issue becomes a significant incident.

That does not mean friction will disappear.

Government has a limited appetite for mistakes because of the amount and sensitivity of the information it holds. Agencies must vet providers before granting access and continue monitoring them after adoption. Every new service becomes another environment that must be understood and protected.

“There’s always going to be some friction,” Cardaci said.

The question is whether that friction comes from meaningful security activity or from outdated processes that do little to reduce risk. Agencies should seek faster and more innovative ways to evaluate providers, but speed cannot come at the expense of understanding what is being introduced into the environment.

That distinction is why Cardaci emphasizes operational security rather than documented security.

A provider may be able to produce a package showing that it satisfied a set of requirements. The more important question is how the company behaves: whether it monitors its systems, anticipates emerging threats and proactively tells agency customers how it is improving protection.

Federal leaders should look for partners that can explain not just how they met today’s requirements, but how they are preparing for what comes next.

The strongest cloud strategy will not treat security, performance and cost as competing goals with a universal answer. It will continually align those goals with the mission, the sensitivity of the data and the consequences of failure.

That balance may differ from one workload to another, and it will change over time. What should remain constant is the agency’s ability to understand the risk it is accepting and the provider’s ability to demonstrate how it is protecting the mission in practice.