Your organization is migrating a sensitive data processing workflow for customer Personally Identifiable Information (PII) from on-premises to Google Cloud. What security measures should you design to mitigate the risk of data exfiltration in the cloud environment?