Cloud Data analytics security/risk assessment

Would like to assess the data analytics solution in terms of security/risk for service below
(which uses Cloud):

"AAA Solutions, a local- based data and analytics consultancy, provides Information Management and Analytics support to our clients. Our seasoned practitioners bring established tried and trusted models developed through years of practical hands-on implementation and successful project delivery of Data Warehouse, Business Intelligence & Analytics systems. We apply an optimum mix of descriptive, diagnostic, predictive and prescriptive methods to drive business value, cost efficiencies and manage risk.
    To establish the Forecasting & Analytics System (FAS) integrating with the top-of-the-line Business Intelligence system and automation of the external variable extraction process to streamline analytics workflow.
    Data Source is using Qlik N-printing;
    Data Integration & Transaction svcs is using MS SSIS;
    Data Marts layer is by MS SQL 2017;
    Power BI is by O365;
    our on-prem AD sync to O365 AD"

Can only currently think in terms of encryption of data in transit, at rest & at endpoint.
What about data integrity (ConnectDirect did checksumming), cloud security (esp this one)?

I like MS SQL 2017 (as MS SQL 2016 only offers DB encryption in Enterprise Edition) offers
DB encryption even for the non-Enterprise edition
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

sunhuxAuthor Commented:
Vendor just told me there are clients requesting for ConnectDirect
(for critical data integrity) but it's out of scope.   2FA/MFA is out of
 scope too (I just want to discourage credentials sharing within
 staff tho staff can still share OTP by forwarding) but it's more

More inputs:  API security requires certification?
"Data required from 3rd Party Data Providers will be retrieved (on
 schedule) via API calls using purpose-built Python scripts, running
 on the Amazon EC2 VM.
 Forecasting analysts (ie our users) can update each run’s parameters
 in a customised Excel configuration file. When ready, this configuration
 file can be “uploaded” into the Amazon S3 Bucket using AWS CLI or
 other (possibly payable) GUI client tools (e.g. CloudBerry S3 Explorer)
 as appropriate"
sunhuxAuthor Commented:
We'll enable TDE for MS SQL  &  AWS offers agentless AV
(ie can scan even a stripped-down VM guest OS)
sunhuxAuthor Commented:
We'll enable TDE for MS SQL  &  AWS offers agentless AV
(ie can scan even a stripped-down VM guest OS)

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.