As a cloud provider that has been providing SaaS for 10 years we have seen a change in mind set of ICT managers in the last 12 months, especially in the UK public sector with the launch of the G-Cloud programme. Many organisations are naturally cautious about where they store their corporate assets, which is why the UK government is focussing on independent security certification and accreditation of cloud suppliers. Although we have always treated this subject seriously, it was not until we went through formal ISO 27001 certification that we understood the detailed questions we would ask of the Cloud suppliers we use, especially with regard to independent assessment of their security measures. As an industry that often provides virtualised services via flashy web sites, we need to make sure that clients can validate and trust our marketing statements on cloud security. Only when this happens then the market will grow exponentially.