Cybercriminals try to hack into corporate cloud services every day – an expert shares nine steps to secure your data
23.5.2025 08:55:00 EEST | DNA Oyj | Press release
Cloud services are becoming an increasingly common part of corporate daily life, and will become even more widespread over the coming years. Yet the security of these services is constantly being tested, and criminals are looking for ways to gain access to data in cloud every day. Kaapro Kanto, Vice President, Network & Cloud at DNA Corporate Business, lists the most common mistakes that lead to data in cloud being compromised – as well as nine steps to safeguard against security threats.

Cloud services enable easy access to data and applications from anywhere, the fast and flexible scaling of resources, and cost savings. Yet in recent years, a number of cases have emerged in which corporate data has been compromised. Is it safe to use cloud services?
Kaapro Kanto, Vice President, Network & Cloud at DNA Corporate Business, says that the cloud is fundamentally an excellent and secure solution for managing a company's data, as long as it is used correctly. For example, a costly mistake can be made at the service selection stage.
“For me, it’s a clear red flag if the service provider doesn’t specify how security will be implemented in the service as a whole, or what industry standards it meets. If the overall picture is not clear or the provider cannot provide a comprehensive security description, I would keep looking for another service provider,” says Kanto.
Kanto also highlights another problem: when a company does not have a standardised process for procurement and management of its services. In other words, there is no holistic plan how various services integrate into a cohesive architecture.
“Unfortunately, you often see all kinds of point solutions in which the same features have in fact been acquired several times via different services. But they’ve simply not been widely adopted and integrated into the company’s cloud architecture. Each new service must be carefully protected, and users must be trained to use them in a way that does not compromise security,” says Kanto.
Nine steps to safer cloud services
Cloud service providers invest heavily in security and often offer advanced solutions to safeguard their own services. It is vital to deploy these solutions when procuring services. A euro saved on a service licence can easily cost more in the form of higher risks due to inadequate controls. In order to get the basics right, Kanto lists nine things to consider when introducing cloud computing:
- Risk management: It is important to identify and assess the risks associated with cloud services and specify how you will manage them. For example, does your company have data that can be exported to the cloud or does it depend on cloud operations and connectivity?
- Assess the service provider: It’s worth choosing a reliable cloud service provider from the outset – one that adheres to strict security standards and offers comprehensive security solutions. Before choosing a service, you should check the service provider's data security practices to ensure that they meet all the requirements and industry standards.
- Access management: You must be aware of how a cloud service’s user data is linked to your company’s business processes, and ensure that multi-factor authentication is implemented for all users.
- Online safety: Even if the services are located in the cloud, you should ensure that access is restricted to corporate network solutions. This increases the security of the service by reducing the attack surface. When connections to services are made through a corporate network, it reduces the chance of criminal attacks.
- Logging and monitoring: The cloud service must implement comprehensive logging practices, and this log should also be monitored. Monitoring will enable you to detect any irregularities early on, before they have a chance to cause significant damage to the company.
- Information security principles: It is important to establish and maintain clear security policies that cover all aspects of cloud security. This includes access rights management, data encryption, access monitoring and regular information security audits.
- Training and raising awareness: Employees should receive preemptive training so that they can identify and avoid security threats such as phishing and malware. It is also important to raise employees’ awareness of potential threats, so they will know the correct action to take.
- Backups and recovery plans: In order to minimise risks, it is a good idea to perform regular backups and ensure that your recovery plans are up to date. This will help you to recover your data quickly in the event of data loss or an attack.
- Contracts: Up-to-date contracts with clearly defined roles and responsibilities are also important in cloud computing. They ensure that information security is implemented by the right people. It is also important for these contracts to specify how use of a service will be terminated, in which case the data will be transferred and then deleted from the service.
Media enquiries:
Kaapro Kanto, Vice President, Network & Cloud, DNA Plc, tel. +358 (0)40 059 9020, kaapro.kanto@dna.fi
DNA Corporate Communications, tel. +358 44 044 8000, communications@dna.fi
Images
DNA is one of the leading telecommunications companies in Finland. Our purpose is to connect you to what matters most. We offer connections, services and devices for homes and workplaces, contributing to the digitalisation of society. Already for years, DNA customers have been among the world leaders in mobile data usage. DNA has about 3.7 million subscriptions in its fixed and mobile communications networks. The company has been awarded numerous times as an excellent employer and family-friendly workplace. In 2024, our total revenue was EUR 1,100 million and we employ about 1,600 people around Finland. DNA is a part of Telenor Group, a leading telecommunications company across the Nordics. More information: www.dna.fi, Facebook @DNA.fi, Instagram and Threads @dna_fi and LinkedIn @DNA-Oyj.
Alternative languages
Subscribe to releases from DNA Oyj
Subscribe to all the latest releases from DNA Oyj by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from DNA Oyj
DNA:n toukokuun 2026 myydyimmät puhelimet ja älykellot1.6.2026 08:00:00 EEST | Tiedote
DNA:n myyntitilastojen mukaan suomalaiset kuluttajat suosivat toukokuussa erityisesti keskihintaisia Android-älypuhelimia sekä Applen uusimpia iPhone 17 -sarjan malleja. Myydyimmän puhelimen paikan otti Samsung Galaxy A16, kun taas yritysasiakkaiden ostetuin puhelin oli Apple iPhone 16e 5G. Toukokuun myydyin älykello oli puolestaan ZTE K2 -lasten kellopuhelin.
DNA:n liittymät auttavat tunnistamaan huijaus- ja massapuhelut27.5.2026 10:43:37 EEST | Tiedote
DNA tarjoaa ainoana operaattorina Suomessa liittymiä, jotka tunnistavat huijauspuheluja ja häiritsevästi soittavia massapuheluja. Uusi DNA Numerovahti -palvelu toimii ilman erikseen ladattavaa sovellusta ja riippumatta siitä, minkä merkkinen asiakkaan päätelaite on. DNA Numerovahti on maksuton lisäpalvelu kuluttajien uusissa DNA Huoleton Plus -liittymissä sekä yritysasiakkaiden DNA Business Varma -liittymissä. Molempiin liittymiin sisältyy myös turvallinen nettiselaus. Lisäksi yritysasiakkaat voivat ostaa palvelun erillisenä kuukausimaksullisena lisäpalveluna liittymiinsä.
DNA subscriptions help identify fraud calls and spam calls27.5.2026 10:43:37 EEST | Press release
DNA is the only operator in Finland to offer subscriptions that identify fraud calls and nuisance spam calls. The new DNA Numerovahti service works without a separately downloaded app, and regardless of the brand of the customer’s device. DNA Numerovahti is a free add-on service included in new DNA Huoleton Plus subscriptions for consumers and DNA Business Varma subscriptions for corporate customers. Both subscriptions also include secure web browsing. In addition, corporate customers can purchase the service as a separate monthly add-on to their subscriptions.
Älypuhelinten käyttö vähenee pienillä lapsilla – pelkkä rajoittaminen ei silti riitä20.5.2026 09:15:00 EEST | Tiedote
DNA panostaa vahvasti ja pitkäjänteisesti lasten digiturvataitojen kehittämiseen yhteistyökumppaninsa Suojellaan Lapsia ry:n kanssa, joka on järjestänyt pienille koululaisille digiturvatyöpajoja jo useamman vuoden ajan. Tänä keväänä yhtiö jakoi lisäksi digitaitojen tehtävävihkoja yli 230 000 suomalaiseen kotiin. Vaikka älypuhelinten käyttö aloitetaan aiempaa myöhemmin, lapset kohtaavat verkossa suuriakin riskejä – ja siksi digiturvataitojen merkitys korostuu entisestään. Aihe korostuu juuri nyt, kun koululaisten kesälomat alkavat ennen vanhempien lomakautta. Kesäkuussa moni lapsi viettää pitkiä aikoja kotona ja verkossa ilman aikuisen valvontaa, mikä lisää riskiä kohdata haitallista sisältöä tai epäasiallisia yhteydenottoja.
Smartphone use is declining among small children – but limiting the use is not enough20.5.2026 09:15:00 EEST | Press release
DNA is consistently developing children’s digital safety skills together with its partner Protect Children Association, which has been organizing digital safety workshops for young schoolchildren for several years. This spring, the company also distributed digital skills exercise booklets to more than 230,000 Finnish homes. Although children are starting to use smartphones later than before, they still face major risks online – which makes digital safety skills more important than ever. The topic is particularly relevant right now, as school summer holidays begin before many parents start their own vacations. In June, many children spend long periods at home and online without adult supervision, which increases the risk of encountering harmful content or inappropriate contact.
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom

