The Wayback Machine - https://web.archive.org/web/20160403202204/http://cloudcomputing.sys-con.com:80/node/3610206

Welcome!

@CloudExpo Authors: Carmen Gonzalez, Anders Wallgren, Elizabeth White, Harry Trott, Pat Romanski

Related Topics: @CloudExpo, Cloud Security, @BigDataExpo, @DevOpsSummit

@CloudExpo: Article

Cloud Security Innovation in 2016 | @CloudExpo #Cloud #IoT #BigData

In 2016, watch for more solutions providers to launch additional features and capabilities to enhance cloud security

What Are the Four Biggest Drivers of Cloud Security Innovation in 2016?

The rise of cloud-based infrastructure was one of the biggest developments in IT during the past few years, and now we are seeing extensive innovations in cloud security as well. More companies are moving their business-critical data away from onsite data centers and into cloud-based infrastructure. With that in mind, 2016 is going to be another dynamic year for cloud security, as more users and IT teams will be looking for ways to enhance their cloud security while achieving heightened visibility of their cloud-based IT assets. The migration of business workloads to the cloud brings many benefits, but one potential challenge is that the "old ways" of managing IT security don't work as well in the cloud environment.

In 2016, we're going to see some significant changes to cloud security. The reason: cloud infrastructure has certain vulnerabilities that require new security solutions designed specifically for the new realities of the cloud. Attacks on cloud-based infrastructure will continue to grow in sophistication and scale, especially as a greater volume of high-value data gets stored in the cloud. With these risks and opportunities becoming more urgent than ever for IT managers and security teams, we can expect to see four major drivers of cloud security innovation in 2016.

Rise of serverless frameworks
Amazon Web Services (AWS) Lambda is a prominent example of the new wave of serverless frameworks and code-PaaS (code-based Platform-as-a-Service). With serverless frameworks, IT teams on the user side are no longer expected to manage their own operating system, container (Docker, LXC, etc.) or virtual machine. This is a massive change from a security standpoint, because it is going to require IT teams to protect APIs against attacks - and this is a new type of attack vector that the IT teams might not have seen before.

"Fire-hose" streams on the control plane
In a cloud environment, the control plane is vulnerable to automated attacks - unless IT organizations prepare by implementing real-time alerts and develop capacity for immediate incident response.

One of the most promising trends in this area, which we will see more of in 2016, is that more host and network-based security measures are migrating to the cloud's control plane, making it possible to deliver serverless-process events, host events, and network events via APIs. Security teams will benefit from seeing real-time "fire-hose" streams on the control plane, instead of having to rely on the slower discovery methods available from traditional in-line network or data center security tools.

Integrating security into the CI/CD pipeline
Security is increasingly no longer being thought of as a "separate" entity from developing and deploying apps and workloads in the cloud. This is another of the most important innovations in cloud security, this change of mindset. Cloud security is becoming more native to, and integrated with, the continuous integration and continuous deployment (CI/CD) pipeline. This means that in 2016, we will see more IT organizations achieve more agile security operations that are better aligned with the philosophy and practices of DevOps.

Bringing security into the CI/CD process makes it possible for popular tools like Jenkins to offer automated security validation as well as new code verification. Instead of being an afterthought or a separate step, cloud security is becoming integrated into the overall quality-assurance process within the continuous deployment pipeline.

More innovation - or acquisitions - by big security providers
The big companies in IT security are going to start to see increasing pressure to deliver next generation cloud security solutions - or else they're going to lose market share to smaller companies that are fully up to speed on the new realities of the cloud. In 2016, watch for two big emerging trends among the big incumbent security providers:

First, look for the big companies to start announcing new product innovations in cloud security - or they will start acquiring more small vendors that own innovative solutions. Second, Amazon Web Services and Microsoft's Azure will be competing like never before to use security as a competitive advantage - each of these cloud services giants will be offering new and expanded cloud security capabilities in order to retain (and gain) market share. One of the areas of focus for new cloud security features will be the shared security model, as cloud services providers seek to give customers more visibility into what's happening in their cloud infrastructure.

The past few years have seen great innovation in cloud services - now in 2016, watch for more solutions providers to launch additional features and capabilities to enhance cloud security. The same security practices that worked in the past are not good enough for the new realities and opportunities of the cloud - cloud security demands a new cloud-focused mindset. Fortunately there are many innovations on the horizon to deliver the flexibility and real-time awareness that organizations need to secure their cloud-based assets.

More Stories By Tim Prendergast

Tim Prendergast is founder and CEO of Evident.io. With well over two decades of pushing the limits of technology, he created Evident.io as the first security company focused solely on programmatic infrastructures (cloud). His prior experience includes leading technology teams at Adobe, Ingenuity, Ticketmaster and McAfee. He holds over 15 years’ security experience, including eight in AWS security experience and three years in the Adobe AWS infrastructure from inception to production. Follow Tim on LinkedIn and Twitter.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@CloudExpo Stories
There are over 120 breakout sessions in all, with Keynotes, General Sessions, and Power Panels adding to three days of incredibly rich presentations and content. Join @ThingsExpo conference chair Roger Strukhoff (@IoT2040), June 7-9, 2016 in New York City, for three days of intense 'Internet of Things' discussion and focus, including Big Data's indespensable role in IoT, Smart Grids and Industrial Internet of Things, Wearables and Consumer IoT, as well as (new) IoT's use in Vertical Markets.
SYS-CON Events announced today that DatacenterDynamics has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY. DatacenterDynamics is a brand of DCD Group, a global B2B media and publishing company that develops products to help senior professionals in the world's most ICT dependent organizations make risk-based infrastructure and capacity decisions.
@DevOpsSummit has been named the ‘Top DevOps Influencer' by iTrend. iTrend processes millions of conversations, tweets, interactions, news articles, press releases, blog posts - and extract meaning form them and analyzes mobile and desktop software platforms used to communicate, various metadata (such as geo location), and automation tools. In overall placement, @DevOpsSummit ranked as the number one ‘DevOps Influencer' followed by @CloudExpo at third, and @MicroservicesE at 24th.
SYS-CON Events announced today CrowdReviews.com has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY. CrowdReviews.com is the first buyer’s guide that ranks products and services based on client reviews.
SYS-CON Events announced today that Commvault, a global leader in enterprise data protection and information management, has been named “Bronze Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Commvault is a leading provider of data protection and information management...
SYS-CON Events announced today TechTarget has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. TechTarget is the Web’s leading destination for serious technology buyers researching and making enterprise technology decisions. Its extensive global networ...
SYS-CON Events announced today that eCube Systems, the leading provider of modern development tools and best practices for Continuous Integration on OpenVMS, will exhibit at SYS-CON's @DevOpsSummit at Cloud Expo New York, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. eCube Systems offers a family of middleware products and development tools that maximize return on technology investment by leveraging existing technical equity to meet evolving business needs....
@DevOpsSummit taking place June 7-9, 2016 at Javits Center, New York City, and Nov 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with the 18th International @CloudExpo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world.
As the world moves towards more DevOps and Microservices, application deployment to the cloud ought to become a lot simpler. The Microservices architecture, which is the basis of many new age distributed systems such as OpenStack and NetFlix, is at the heart of Cloud Foundry – a complete developer-oriented Platform as a Service (PaaS) that is IaaS agnostic and supports vCloud, OpenStack and AWS.
NHK, Japan Broadcasting, will feature the upcoming @ThingsExpo Silicon Valley in a special 'Internet of Things' and smart technology documentary that will be filmed on the expo floor between November 3 to 5, 2015, in Santa Clara. NHK is the sole public TV network in Japan equivalent to the BBC in the UK and the largest in Asia with many award-winning science and technology programs. Japanese TV is producing a documentary about IoT and Smart technology and will be covering @ThingsExpo Silicon Val...
SYS-CON Events announced today BZ Media LLC has been named “Media Sponsor” of SYS-CON's 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. BZ Media LLC is a high-tech media company that produces technical conferences and expositions, and publishes a magazine, newsletters and websites in the software development, SharePoint, mobile development and Commercial Drone markets.
WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web communications world. The 6th WebRTC Summit continues our tradition of delivering the latest and greatest presentations within the world of WebRTC. Topics include voice calling, video chat, P2P file sharing, and use cases that have already leveraged the power and convenience of WebRTC.
Spirent Communications has announced the availability of Spirent TestCenter WLAN test capability, with the highest-performing and most realistic 802.11 wireless local area network (WLAN) multi-client emulation scenarios available on the market today. Spirent TestCenter WLAN is used for functionality and performance testing of Access Points (APs) and end-to-end testing of WLAN ecosystems that include WLAN access controllers and gateways. It emulates a large number of realistic WLAN clients throu...
SYS-CON Events announced today the How to Create Angular 2 Clients for the Cloud Workshop, being held June 7, 2016, in conjunction with 18th Cloud Expo | @ThingsExpo, at the Javits Center in New York, NY. Angular 2 is a complete re-write of the popular framework AngularJS. Programming in Angular 2 is greatly simplified. Now it’s a component-based well-performing framework. The immersive one-day workshop led by Yakov Fain, a Java Champion and a co-founder of the IT consultancy Farata Systems and...
SYS-CON Events announced today that Isomorphic Software will exhibit at SYS-CON's [email protected] at Cloud Expo New York, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Isomorphic Software provides the SmartClient HTML5/AJAX platform, the most advanced technology for building rich, high-productivity enterprise web applications for any device. SmartClient couples the industry’s broadest, deepest UI component set with a java server framework to deliver an end-...
SYS-CON Events announced today that delaPlex will exhibit at SYS-CON's @ThingsExpo, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. delaPlex pioneered Software Development as a Service (SDaaS), which provides scalable resources to build, test, and deploy software. It’s a fast and more reliable way to develop a new product or expand your in-house team.
Using new techniques of information modeling, indexing, and processing, new cloud-based systems can support cloud-based workloads previously not possible for high-throughput insurance, banking, and case-based applications. In his session at 18th Cloud Expo, John Newton, CTO, Founder and Chairman of Alfresco, will describe how to scale cloud-based content management repositories to store, manage, and retrieve billions of documents and related information with fast and linear scalability. He wi...
SYS-CON Events announced today CyberTrend has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
As devices, sensors, objects and people are given digital identities that connect them to the Internet by the billions, the need for security and privacy becomes a critical factor for both market adoption and safety. The 40-year-old security methods we now use on our PCs and networks cannot address many of these IoT devices.
SYS-CON Events announced today that Chetu Inc., a worldwide leader in custom software solutions for niche businesses, software-defined storage and data services platform, will exhibit at SYS-CON's @ThingsExpo, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Founded in 2000, Chetu Inc. is a global provider of customized software development solutions and IT staff augmentation services for software technology providers. By providing clients with unparalleled ni...