As enterprises move mission-critical assets to the cloud, they must often sacrifice control. Even enterprises that maintain their own private clouds nearly always still rely on at least some SaaS and public cloud services, which means that mission-critical data often resides in clouds over which the enterprise has little control.

A recent survey by 451 Research found that 98% of enterprises are using or plan to use at least two cloud infrastructure providers, while 31% are already using four or more. Moving up the stack to the application layer, 96% subscribe to or plan to adopt at least two SaaS applications, with 45% now using SaaS applications from five or more providers.

The reasons enterprises cite for multicloud use include the need to support work from home (WFH) employees during the COVID-19 pandemic, collaboration with partners and suppliers, and a greater capability to scale via the cloud.

Even though multicloud is the new enterprise reality, it doesn’t mean that enterprises have figured out how to manage that new reality. Recent research from Enterprise Management Associates (EMA) forecasts that 88% of enterprises will adopt multiple cloud services by 2024, up from 72% in 2022. However, EMA found that only 35% of enterprises believe that their multicloud networking strategies have been successful, and only 24% of the 351 IT organizations surveyed were satisfied with their multicloud network monitoring and observability capabilities.

While the tools exist to enable enterprises to start retaking control of multicloud environments, piecing together the right discovery, protection, and management solution often requires working with multiple tools and several vendors to cut through the cloud confusion.

Below are four key lessons from organizations that recently cut through the thorny problem of multicloud management:

1. Cloud sprawl creates big IT blind spots

The Boston Red Sox were struggling to manage the complexity of their multicloud operations. Randy George, vice president of technology operations for the Boston Red Sox, explained that in recent years, the team’s cloud footprint had grown dramatically, encompassing everything from CRM tools to apps for scouting and development to mission-critical line-of-business software.

“It’s incredible how many cloud applications people use,” George added. “Some of them are just small productivity tools, but others like Trello, Asana and Confluence may have started with one or two people, but now we have [hundreds of users].” In other words, the IT team had to figure out which cloud resources were mission-critical before they could develop the right policies to control them.

With SaaS so firmly embedded in the knowledge work mainstream, this is a problem that will only get worse over time. What used to be considered shadow IT is simply how software has evolved, with many SaaS apps adopted without IT input. While applications like Asana and Trello may be mission-critical for many knowledge workers, creating and storing enterprise IP in third-party applications poses severe risks, as Google, Twitter, and Zoom users have recently discovered.

For the Red Sox, step one towards a secure, sustainable multicloud future involved the cybersecurity team assessing cloud and SaaS applications for risks. Applications that stored sensitive data and/or posed significant risks were required to have stronger multifactor authentication through Okta.

Controlling access and identity was only one piece of the cloud management puzzle, though.

2. Cloud deployments create new data silos

Since many cloud applications and systems operated in isolation, finding a way to unify data management and cloud security seemed nearly impossible. Vendors have long pitched public cloud computing as a way to break free from on-premises data silos, but what often happens instead is that things like data portability, networking constraints, and data integrity issues end up recreating silos in the cloud.

Thus, the Red Sox also searched for a tool that would break down the data silos that spring up in separate clouds. “We fingerprinted over a thousand applications in our environment,” George said. The IT team then had to correlate that information with the 200 known applications in use, which included everything from internal communication tools to apps used for scouting and player development to modern CRM systems that track ticket sales and fan engagement.

For the Red Sox, breaking down those cloud silos meant figuring out how to protect and manage all of that data in a unified way. The Red Sox engaged with an Okta partner, the startup HYCU, which offers data protection as a service. The Red Sox started with a narrow goal: protecting their Google Cloud Platform (GCP) environment and replicating their on-premises Dell Isilon cluster and migrating it to the cloud.

However, as the Red Sox began working with the startup, they realized that it could help them unify how they manage various clouds, so they broadened how they would use the HYCU service to protect and manage data across a broad range of cloud applications.

3. Enterprises turn to startups to plug gaps in the solution chain

Like the Red Sox, Nutreco, an agribusiness multinational based in the Netherlands, ended up working with a startup to meet their multicloud challenges.

Nutreco was considering moving its on-premises VMware-based infrastructure to the cloud, but the company required disaster recovery (DR) and business continuity (BC) capabilities for the virtual machines (VMs) that they were planning to migrate into Microsoft’s Azure VMware Solution (AVS). However, deploying traditional on-premises DR software to AVS would have driven infrastructure costs beyond the project’s budget.

Nutreco also prioritized quick recovery times, minimal risk of data loss for critical applications, and automated monitoring and management, so they could scale DR operations across hundreds of VMs. The company turned to Microsoft for help, searching for a Microsoft solution or partner that would enable them to build the cloud infrastructure necessary to support more than 100 facilities in more than 30 countries.

Nutreco worked with Microsoft and its partner, JetStream, a startup that provides cloud-native DR and continuous data protection, to build a system that supports different storage tiers that match different SLAs and budget requirements. “Deploying JetStream DR has given us confidence in our ability to recover workloads without losing data and at a speed that minimizes any potential interruption to our business operations,” said Rene Smetsers, IT Director, Nutreco Global IT Services.

Nutreco deployed a combination of Microsoft Azure Blob Storage, Azure NetApp Files (ANF), and VSAN storage, with JetStream DR Continuous Data Protection software managing data across multiple clusters with more than 500 VMs in the Azure VMware Solution.

According to Nutreco, today more than 50TB of mission-critical data stored in those 500+ VMs is now protected, with the combined solution delivering near-zero RPOs (Recovery Point Objectives) and RTOs (Recovery Time Objectives).

4. Modern data protection requires pinpoint precision

For the Red Sox, the biggest multicloud data management challenge was not just backing up the data, but also doing it with precision, understanding the intricate dynamics of what needed the most protection and when. The Red Sox used HYCU’s data visualization tool, R-Graph, to tackle this problem.

R-Graph illustrated, in real-time, the status of each of their Okta-integrated applications. This allowed the Red Sox to discern which applications were shielded and which required immediate attention. This visual aid eliminated guesswork, letting the team strategically allocate resources, ensuring maximum protection based on an application’s risk profile and organizational significance.

“The amount of data we’re taking in as a business now is mission critical,” George said. “Not a single day goes by where we’re not adding one or two applications within Okta.”

Now, George and his team have the tools in place, from strong authentication and SSO to continuous data protection, to manage that steady cloud growth without introducing new risks.