TL;DR: Automated data discovery and classification were used before workloads moved to AWS in a financial services migration, reducing blind spots across sensitive data and embedded secrets while feeding findings into Security Hub, according to BigID. The core lesson is that cloud modernisation fails when governance starts after migration rather than before.
NHIMG editorial — based on content published by BigID: Visibility before Velocity and the role of data intelligence in cloud migration
By the numbers:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
Questions worth separating out
Q: What breaks when cloud migration starts before data discovery?
A: Cloud migration starts to fail when teams move applications before they know what sensitive data, secrets, and regulated records already exist.
Q: Why do embedded secrets increase cloud migration risk?
A: Embedded secrets matter because they are credentials, not just data.
Q: How do you know if classification is actually reducing cloud risk?
A: Classification is working when it changes operational decisions, not when it just produces labels.
Practitioner guidance
- Inventory sensitive data before workload migration Map PII, personal data, and application secrets across structured and unstructured repositories before moving any workloads into AWS or another cloud platform.
- Classify secrets as governed access-bearing assets Treat embedded API keys, tokens, and certificates as access paths that require discovery, ownership, and lifecycle handling alongside the data they protect.
- Feed classified findings into operational response tools Push discovery results into a shared security console such as Security Hub so cloud and data teams work from one prioritized view of sensitive exposure.
What's in the full article
BigID's full article covers the operational detail this post intentionally leaves for the source:
- How the discovery and classification workflow was applied across legacy systems and AWS services before migration
- How findings were operationalised through AWS Security Hub for triage and response
- How the programme reduced blind spots across structured databases and unstructured storage
- How the organisation aligned data sensitivity with cloud remediation priorities
👉 Read BigID's analysis of visibility-first cloud migration and data governance →
Cloud migration without data visibility: what IAM teams need to know?
Explore further
Data visibility is now a prerequisite for cloud governance: moving workloads before understanding the data estate simply relocates risk into a more scalable environment. Classification gives security teams a basis for control selection, retention decisions, and access scoping. For IAM and cloud teams, the practitioner conclusion is clear: cloud migration should begin with inventory, not infrastructure.
A question worth separating out:
Q: How should security teams maintain identity assurance during cloud migration?
A: Security teams should treat migration as an identity control redesign, not just a platform move. Preserve strong MFA, recovery assurance, and admin access rules across both cloud and on-premises environments, then verify that fallback paths do not reduce assurance below the primary sign-in standard. Continuity matters more than cloud placement.
👉 Read our full editorial: Data visibility before cloud migration lowers risk in finance