|
|
By Brad Thies |
Article Rating: |
|
January 31, 2018 12:00 PM EST |
Reads: |
140 |
Another day, another breach. No wonder security is tied for the top barrier to cloud adoption, according to 2017 research from RightScale, with 25 percent of survey respondents naming it, alongside expertise and expense, as their greatest challenge.
In the face of security concerns, IT executives have mistakenly found comfort in private clouds over public clouds. The RightScale survey found that enterprises run about 75 percent of workloads in the cloud, with 43 percent done in a private cloud and 32 percent handled in a public cloud.
No doubt, some of the enterprises using a private cloud have serious security protocols. But while private clouds can be protected with all the same tools as their public counterparts, they often aren't. It's probably why Alert Logic discovered that companies using pure public cloud environments averaged 405 security incidents, while hosted private cloud environments averaged 684 incidents.
When Security Matters Most, Go Public
Some executives assume that a lurking compliance requirement forbids the use of a public cloud. But no such hard-and-fast rule exists, and cloud service providers - the reputable ones, anyway - provide clear compliance road maps to their clients.
Other executives fear losing control in the event of a breach in someone else's environment, but these fears are also unfounded. The cloud doesn't fail; the implementation fails, or one party fails to abide by its shared security responsibilities.
Just because data exists in a public cloud environment doesn't mean it's at the mercy of that provider's security controls. And in any case, most public cloud providers have more robust security controls than companies that host their own private clouds.
To be clear, this isn't to say that public clouds are always more secure - only that most companies could enjoy stronger security by letting the experts manage their cloud data. Just about every public cloud provider offers three industry-leading security features:
1. Modern patch management and malware safeguards
Companies using private clouds are responsible for patching their own environments. Poor patch management leads to security vulnerabilities, creating windows for attackers to strike.
Public providers typically have more resources to dedicate to these maintenance cycles. As a general rule, older systems carry known vulnerabilities, including weaker malware defenses, while newer ones offer better anti-exploitation features. Most public cloud companies keep their equipment up-to-date because they don't have to compete for internal resources like private cloud solutions do.
2. Virtual private networks and segmentation
Private environments tend to have more "flat networks" than public ones. Because network segmentation is difficult to administer, many large organizations prefer to manage a single network across the enterprise rather than cordon off critical systems. But fewer walls makes it easier for hackers to access important systems.
Public clouds isolate sensitive applications and data while still pooling resources. Segmented systems stop hackers from moving through networks easily, making public clouds better at limiting damage should a breach occur.
3. Better identification and access management tools
Most hackers don't rely on fancy tricks to gain network access. Per Verizon's 2017 Data Breach Investigations Report, 81 percent of hacking breaches involve stolen or weak passwords.
In my experience, on-premise or private cloud environments tend to use outdated identity and access management tools. These often rely on centralized directories to connect everything. Unfortunately, they expose more than necessary when opening the private cloud to external resources, such as mobile, IoT, and web applications. Public cloud products have improved federating identity management built in, which enables security practices like single sign-on, attribute management, and access control.
Even if a public cloud is breached, the data within isn't necessarily in danger. Clients that manage their own encryption keys stop hackers from deciphering their stolen goods. AWS clients using Box KeySafe, for example, keep their data safe in Box while storing their keys outside of Box's environment.
Virtually every company depends - or will soon depend - on the cloud to store and access data, but misconceptions surrounding public clouds prevent them from making secure choices. Leave it to a company that does cloud security for a living, and you'll drastically drop your chances of being breached.
Brad Thies is the founder and president of BARR Advisory, an assurance and advisory firm specializing in cybersecurity, risk management, and compliance. Brad speaks regularly at industry events such as ISACA conferences, and he is a member of AICPA's Trust Information Integrity Task Force. Brad's advice has been featured in Entrepreneur, Cloud Computing Journal, Small Business CEO, and Information Security Buzz. Prior to founding BARR, Brad managed KPMG's risk consulting division. He is a CPA and CISA.
Brad Thies is principal at Barr Assurance & Advisory Inc., a risk consulting and compliance firm that provides business performance, information technology, and assurance services to clients across a variety of industries. He specializes in helping clients assess, design, and implement processes and controls to meet customer, regulatory, and compliance requirements. Brad is a certified public accountant and a certified information system auditor with more than 10 years of experience in the industry.
@CloudExpo Stories By Aruna Ravichandran  For many of us laboring in the fields of digital transformation, 2017 was a year of high-intensity work and high-reward achievement. So we’re looking forward to a little breather over the end-of-year holiday season.
But we’re going to have to get right back on the Continuous Delivery bullet train in 2018. Markets move too fast and customer expectations elevate too precipitously for businesses to rest on their laurels.
Here’s a DevOps “to-do list” for 2018 that should be priorities for anyone w... Jan. 31, 2018 01:00 PM EST Reads: 2,099 | By Ed Featherston  Blockchain. A day doesn’t seem to go by without seeing articles and discussions about the technology. According to PwC executive Seamus Cushley, approximately $1.4B has been invested in blockchain just last year. In Gartner’s recent hype cycle for emerging technologies, blockchain is approaching the peak. It is considered by Gartner as one of the ‘Key platform-enabling technologies to track.’ While there is a lot of ‘hype vs reality’ discussions going on, there is no arguing that blockchain is b... Jan. 31, 2018 12:45 PM EST Reads: 4,561 | By Stackify Blog  The word polymorphism is used in various contexts and describes situations in which something occurs in several different forms. In computer science, it describes the concept that objects of different types can be accessed through the same interface. Each type can provide its own, independent implementation of this interface. It is one of the core concepts of object-oriented programming (OOP). Jan. 31, 2018 12:30 PM EST Reads: 1,779 | By Elizabeth White  DevOps promotes continuous improvement through a culture of collaboration. But in real terms, how do you: Integrate activities across diverse teams and services? Make objective decisions with system-wide visibility? Use feedback loops to enable learning and improvement?
With technology insights and real-world examples, in his general session at @DevOpsSummit, at 21st Cloud Expo, Andi Mann, Chief Technology Advocate at Splunk, explored how leading organizations use data-driven DevOps to close th... Jan. 31, 2018 12:15 PM EST Reads: 3,484 | By Brad Thies  Another day, another breach. No wonder security is tied for the top barrier to cloud adoption, according to 2017 research from RightScale, with 25 percent of survey respondents naming it, alongside expertise and expense, as their greatest challenge.
In the face of security concerns, IT executives have mistakenly found comfort in private clouds over public clouds. The RightScale survey found that enterprises run about 75 percent of workloads in the cloud, with 43 percent done in a private clou... Jan. 31, 2018 12:00 PM EST Reads: 140 | By Jason Bloomberg  I believe that this may finally be the year that the CIO role ‘crosses the Rubicon,' leaving behind its traditional, IT-focused orientation. But I don't believe that either of the previous predictions of this outcome — fading into oblivion or rising to a business executive level — is correct.
Instead, I think this is the year that we will see the role of the CIO transformed into something altogether different.
Jan. 31, 2018 11:30 AM EST Reads: 172 | By Jason Bloomberg  It’s conference season and, as you might expect, Jason and I have been on the road covering a bunch of them. It’s always great to see what the disruptive players in the market are doing — and this year did not disappoint. But there is one thing that repeatedly happens that just gets under my skin: transformation-washing.
As Jason explained in a Forbes article over a year ago, ‘washing’ is when a vendor (or pundit) applies a buzzword loosely in an overt attempt to attach themselves to its buzz. ... Jan. 31, 2018 10:00 AM EST Reads: 4,054 | By Ram Sonagara  The IoT Will Grow: In what might be the most obvious prediction of the decade, the IoT will continue to expand next year, with more and more devices coming online every single day. What isn’t so obvious about this prediction: where that growth will occur. The retail, healthcare, and industrial/supply chain industries will likely see the greatest growth. Forrester Research has predicted the IoT will become “the backbone” of customer value as it continues to grow. It is no surprise that retail is ... Jan. 31, 2018 08:00 AM EST Reads: 500 | By Yeshim Deniz  DX World EXPO, LLC, a Lighthouse Point, Florida-based startup trade show producer and the creator of "DXWorldEXPO® - Digital Transformation Conference & Expo" has announced its executive management team. The team is headed by Levent Selamoglu, who has been named CEO. "Now is the time for a truly global DX event, to bring together the leading minds from the technology world in a conversation about Digital Transformation," he said in making the announcement. Jan. 31, 2018 05:00 AM EST Reads: 1,702 | By Jason Bloomberg  The rise of the market for No-Code platforms and tools has given rise to a burgeoning population of ‘citizen developers’ – non-technical business personnel who can use these platforms to build an increasingly powerful set of business applications without writing a line of code.
As this market matures, different platforms focus on different challenges. As a result, a wider range of ‘citizen’ roles also evolve, such as citizen process creators and citizen data analysts.
High on this list: th... Jan. 30, 2018 07:30 PM EST Reads: 488 | By Stackify Blog  How is DevOps going within your organization? If you need some help measuring just how well it is going, we have prepared a list of some key DevOps metrics to track. These metrics can help you understand how your team is doing over time.
The word DevOps means different things to different people. Some say it a culture and every vendor in the industry claims that their tools help with DevOps. Depending on how you define DevOps, some of these metrics may matter more or less to you and your team. Jan. 11, 2018 01:00 PM EST Reads: 2,608 | By Otto Berkes  Every year about this time, we gaze into crystal balls to divine the future of our industry – or at least where it’s headed over the next 365 days. The result is often a triumph of incrementalism: we predict that we will get more of what we already have. The truth is, technology isn’t as revolutionary as we often think – and commenting on incremental changes alone may not help us understand what lies ahead.
Along with a few near-term predictions – so hard to resist – I’d also like to make some ... Jan. 11, 2018 11:00 AM EST Reads: 2,090 | By Elizabeth White  "Space Monkey by Vivent Smart Home is a product that is a distributed cloud-based edge storage network. Vivent Smart Home, our parent company, is a smart home provider that places a lot of hard drives across homes in North America," explained JT Olds, Director of Engineering, and Brandon Crowfeather, Product Manager, at Vivint Smart Home, in this SYS-CON.tv interview at @ThingsExpo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Dec. 31, 2017 12:00 PM EST Reads: 2,536 | By Pat Romanski  SYS-CON Events announced today that Conference Guru has been named “Media Sponsor” of the 22nd International Cloud Expo, which will take place on June 5-7, 2018, at the Javits Center in New York, NY.
A valuable conference experience generates new contacts, sales leads, potential strategic partners and potential investors; helps gather competitive intelligence and even provides inspiration for new products and services. Conference Guru works with conference organizers to pass great deals to gre... Dec. 30, 2017 11:00 AM EST Reads: 2,351 | By Liz McMillan  DevOps is under attack because developers don’t want to mess with infrastructure. They will happily own their code into production, but want to use platforms instead of raw automation. That’s changing the landscape that we understand as DevOps with both architecture concepts (CloudNative) and process redefinition (SRE).
Rob Hirschfeld’s recent work in Kubernetes operations has led to the conclusion that containers and related platforms have changed the way we should be thinking about DevOps and... Dec. 30, 2017 11:00 AM EST Reads: 2,016 | By Liz McMillan  In his Opening Keynote at 21st Cloud Expo, John Considine, General Manager of IBM Cloud Infrastructure, led attendees through the exciting evolution of the cloud. He looked at this major disruption from the perspective of technology, business models, and what this means for enterprises of all sizes. John Considine is General Manager of Cloud Infrastructure Services at IBM. In that role he is responsible for leading IBM’s public cloud infrastructure including strategy, development, and offering m... Dec. 29, 2017 12:00 PM EST Reads: 3,430 | By Elizabeth White  Companies are harnessing data in ways we once associated with science fiction. Analysts have access to a plethora of visualization and reporting tools, but considering the vast amount of data businesses collect and limitations of CPUs, end users are forced to design their structures and systems with limitations. Until now. As the cloud toolkit to analyze data has evolved, GPUs have stepped in to massively parallel SQL, visualization and machine learning. Dec. 29, 2017 11:00 AM EST Reads: 4,237 | By Elizabeth White  The next XaaS is CICDaaS. Why? Because CICD saves developers a huge amount of time. CD is an especially great option for projects that require multiple and frequent contributions to be integrated. But… securing CICD best practices is an emerging, essential, yet little understood practice for DevOps teams and their Cloud Service Providers. The only way to get CICD to work in a highly secure environment takes collaboration, patience and persistence. Building CICD in the cloud requires rigorous ar... Dec. 29, 2017 11:00 AM EST Reads: 1,880 | By Liz McMillan  "Evatronix provides design services to companies that need to integrate the IoT technology in their products but they don't necessarily have the expertise, knowledge and design team to do so," explained Adam Morawiec, VP of Business Development at Evatronix, in this SYS-CON.tv interview at @ThingsExpo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Dec. 29, 2017 08:00 AM EST Reads: 3,578 | By Pat Romanski  To get the most out of their data, successful companies are not focusing on queries and data lakes, they are actively integrating analytics into their operations with a data-first application development approach. Real-time adjustments to improve revenues, reduce costs, or mitigate risk rely on applications that minimize latency on a variety of data sources. In his session at @BigDataExpo, Jack Norris, Senior Vice President, Data and Applications at MapR Technologies, reviewed best practices to ... Dec. 28, 2017 02:00 PM EST Reads: 4,637 |
|
|
|
|
|
|