Data breaches remain the No. 1 cloud security threat, costing companies millions of dollars per breach not to mention permanent reputational damage and loss of trust. But when and if the Pentagon suffers a breach, there’s a lot more to worry about than cost.

That’s why the $10 billion, 10-year JEDI cloud contract is such a big deal.

The Joint Enterprise Defense Infrastructure (JEDI) cloud program will move about 80% of all Department of Defense (DoD) data off premises and into a single cloud. While the contract award hit a snag last month — the Pentagon inspector general is investigating potential “misconduct” related to JEDI — Amazon Web Services (AWS) and Microsoft Azure remain the frontrunners.

Meanwhile, most enterprises (85%) operate across multiple clouds. This is largely to increase flexibility and save money by avoiding vendor lock-in and using the best infrastructure for a given workload. But multicloud also has security and resiliency benefits such as protecting data in case of a massive cloud outage or attack.

Smart Pentagon Cloud Strategy?

In fact, JEDI seems to go against the U.S. government’s own Cloud Smart Strategy, which stresses the importance of multi- and hybrid-cloud and a “technology neutral” approach.

IBM, which filed a protest against JEDI, argued that the solicitation’s “primary flaw” is that is locks the military into a single cloud provider for 10 years.

“No business in the world would build a cloud the way JEDI would and then lock into it for a decade,” Sam Gordy, general manager of IBM U.S. Federal, wrote in a blog post. “JEDI turns its back on the preferences of Congress and the administration, is a bad use of taxpayer dollars, and was written with just one company in mind. America’s warfighters deserve better.”

Additionally, a single cloud environment for the entire U.S. military is a bad idea because it gives attackers a sole target should they try to take out the Pentagon’s IT backbone, IBM says.

Plus, if Amazon wins the bid this means that the DoD and CIA will both store their data in the same cloud, which could pose an even greater security risk because a hacker could access both agencies’ data in the one cloud.

“The world’s largest businesses are increasingly moving in a multicloud direction because of security, flexibility, and resilience; the Pentagon is moving in precisely the opposite direction,” Gordy wrote.

Of course, IBM has a vested interest in arguing these points. It bid for the $10 billion contract before the Pentagon ruled it (and Oracle) out of contention because its cloud did not meet “minimum requirements” for working with highly classified and sensitive military data. Still, security, flexibility, and resilience are valid reasons to use multiple clouds.

CSA Weighs In on JEDI

If anything, JEDI poses more of a risk management than a security issue, said Cloud Security Alliance (CSA) co-founder and CEO Jim Reavis. If the bulk of the DoD data is stored in one cloud and it goes down, then warfighters might not have access to the services and systems they need.

However, cloud contracts do tend to be multi-year deals, and both AWS and Azure are “very well run and very secure,” he said. “How the industry has been working to mitigate [security risk] is to move more into containerization.”

CSA Federal Director Katie Lewin, who was also the first director of the Federal Risk and Authorization Management Program (FedRAMP), agreed that using containers makes workloads and data more portable and helps address potential security risks. “While there is some risk that has to be mitigated, the positives are the warfighter will have access to the information he or she needs on one platform, if it’s deployed in the right way. The warfighter doesn’t need to learn three different systems and get connected to all of them.”

Lewin also pointed to the contract’s two-year base period with three option periods (3 years + 3 years + 2 years) for a total of 10 years. This means the Pentagon could move to a different cloud after two years. “If it is really bad they could cancel it,” she said, but acknowledged that’s not very practical.

“[JEDI] does bring some more integration, but it’s not creating homogeneity at all,” CSA's Reavis said. “The overall DoD beyond the Pentagon is going to be very hybrid, multicloud forever.”

Emerging Warfare Tech

Because the stakes are so high, the DoD will undoubtedly invest heavily in physical and software-defined security and isolation, Reavis added. “It is going to be more unique to defense then you would see even in traditional high-end, very expensive enterprise adoption of cloud,” he said. “They’re going to spend a lot more on physical isolation of data centers down to servers, there will be very extensive, multi-factor authentication and identity management strategies that should mitigate a lot of these run of the mill, let’s go hit specific soldiers with spear phishing attacks.”

Is JEDI a security risk? Both Amazon and Azure have secure, government-ready storage. But it would be foolish to assume either — or any cloud provider, for that matter — is inherently bulletproof.

Perhaps more importantly: we don’t know what technologies will emerge in the upcoming years that will influence warfare — or which cloud provider will have the better networking and artificial intelligence (AI) to support these technologies. And JEDI makes it difficult to change course or at least use newer technologies from different cloud providers as they become available.

Undoubtedly nation-states, which are becoming increasingly sophisticated in their attacks, will spend massive amounts trying to hack into the cloud no matter who wins the deal. Time will tell if JEDI’s a $10 billion security risk. But at the very least it’s not best practices.