Welcome!

Cloud Expo Authors: Elizabeth White, Liz McMillan, Esmeralda Swartz, Jerry Melnick, Michelle Drolet

Related Topics: Security, Virtualization, Web 2.0, Cloud Expo, GovIT

Security: Interview

Exclusive Q&A with Rich Marcello - Unisys President, Systems & Technology

Security is a big concern as well as privacy of the data once it leaves a client's data centers

Unisys announced in September a four-part cloud computing strategy that will enable clients to move their enterprise application workloads securely to tailored cloud environments and give them confidence in maintaining the integrity of their critical information.

In this Exclusive Q&A with Cloud Computing Journal in the run-up to SYS-CON's 4th International Cloud Computing Conference & Expo (November 2-4, 2009) - Cloud Expo Conference Chair Jeremy Geelan speaks with Rich Marcello - Unisys President, Systems & Technology - about the Unisys Secure Cloud and sets the scene for the upcoming Unisys Cloud-in-a-box.

Cloud Computing Journal: Starting at 35,000 feet, what overall relationships does Unisys see between cloud computing and the increasingly real-time needs of today's enterprise?

Rich Marcello: I believe that  cloud computing will revolutionize the way enterprises obtain IT and business services because of a number of converging factors - 1) the economy has forced enterprises to rethink their traditional cost models and minimize their capital expenditures in favor of pay-as-you-go models, 2) the need for anywhere, anytime IT since data sets continue to grow exponentially, and 3) the  shift in the way IT works with,  for example,  virtualization and automation,  which enable cloud computing.

Cloud Computing Journal: So cloud computing isn't just a buzzword, it's actually a glimpse of the future of enterprise IT so far as you are concerned?

Rich Marcello: Absolutely.  When you think about "IT as a service", ease of delivery, access from anywhere at anytime, the ability to have a totally flexible IT infrastructure, and the cost benefits of a subscription or pay as you go model, you realize very quickly cloud computing, in any of its forms (internal, external, hybrid) is here to stay.

Cloud Computing Journal: I understand, though, there are some concerns with moving to the Cloud.

Marcello: That's right. Security is a big concern as well as privacy of the data once it leaves a client's data centers and the ability of a cloud provider to meet the client's compliance requirements.  Additionally, there's concern about whether or not a client's applications can be moved to the cloud without rewriting them.  Unisys addresses each of these concerns with Unisys Cloud Computing Strategy and solutions portfolio announced June 30, 2009.

Cloud Computing Journal: Tell me more about this new Strategy and what it means to your clients.

Marcello: We announced a four-part cloud computing strategy that will enable clients to move their enterprise application workloads securely to tailored cloud environments and give them confidence in maintaining the integrity of their critical information.  We're delivering on the first two parts this year beginning with our June 30 announcement and the availability of our Cloud Transformation Services, followed by our Unisys Secure Cloud Solution available on July 31.  Our "Cloud-in-a-box" solution planned for later this year is a comprehensive IT infrastructure package that will enable quick and cost-effective implementation of a private cloud.  We also plan to deliver hybrid cloud technologies early next year that will provide the best of managed and dedicated services by combining public and private cloud capabilities.
Our comprehensive Cloud Transformation Services include Advisory and Assessment services that can provide our clients with strategic guidance on how best to move to the cloud.

Cloud Computing Journal: How are you leveraging your breadth of Enterprise IT experience?

Marcello: We believe our strong heritage in Data Center Transformation and Outsourcing is foundational to cloud computing - you can't begin to offer a cloud computing solution unless you understand the data center and are true experts.  We've been helping clients transform their data centers and make the right IT sourcing decisions for a long time by leveraging our services, technology, and outsourcing capabilities so they can achieve maximum return from capital expenditures, reduce operating expenses, and increase business performance.  Our heritage of experience and innovation combined with our independent thinking, innovative infrastructure and sourcing capabilities deliver data center solutions that are secure, productive and reliable.  We see all of this as a key advantage over other cloud providers who are just entering this market.

Cloud Computing Journal: How big an issue is security for enterprises who wish to migrate toward this kind of an infrastructure wholly or in part?

Marcello: As I mentioned earlier, security is the biggest barrier to cloud adoption as cited by organizations and industry analysts, as well as our own clients in a recent survey we conducted.

When it comes to security in a cloud it's really about the workloads and how clients can confidently move them to the cloud.  A lot of vendors talk security in the cloud but we've tackled this issue head-on and believe we have an advantage.  Security is inherent in all Unisys operations and offerings and, like Data Center Transformation and Outsourcing, is one of Unisys four key areas of strength.

We address security by ensuring operational excellence.   Unisys Secure Cloud services teams operate ISO 20000-certified delivery processes that are ITIL V3-compliant.  All of this protection is delivered in independently audited and ISO 270001-certified delivery centers. We utilize security best practices - a layered multi-vendor approach to security with Intrusion Detection and Prevention Services (IDPS), firewall management, 24x7 security monitoring, advanced correlation and analytics, auditable logs, and so forth.

From a cloud perspective, our commitment is to provide a security framework that is as good as or better than any clients could establish for themselves.  We do all of this and more with the addition of our patent-pending Stealth technology that allows private communities of interest based on FIPS 140-2, 256-bit Advanced Encryption Standard (AES) encryption and cloaks the data with proprietary "bit splitting".   Unlike other approaches to security, Unisys Stealth is very simple to deploy and does not require rewriting applications.  We believe this is a key differentiator as Stealth technology allows different groups in a multi-tenant client environment to share the same IT infrastructure without fear of exposing one client's data to another, and there's no need for the client to rewrite the applications it chooses to move to the cloud.

Cloud Computing Journal: What kinds of applications need security that your cloud offers?

Marcello: Clients who have workloads that require application, database or user security will have exposure if they put such workloads onto an unsecured cloud service.  Consequently, today companies are primarily using unsecured cloud services for workloads that have few security needs, such as Application Development and Testing or basic Web services, along with some less secure email workloads.

With Unisys Secure Cloud, you can move conventional business applications that contain patient data, employee, financial, or customer information, or document management or disaster recovery applications to the cloud environment.  In addition to security, most of these applications tend to require quite a bit of IT infrastructure and staff time to manage even though they tend to run in spurts and are quite cyclical or the workloads can dramatically vary in size from one period to the next.  For example, they may only run at the end of day, end of week, month, or year.  Some good examples are: Budgeting and planning; or HR systems like employee self-service, or time reporting.  Retailers have massive swings in system demand from one season to the next and need flexible capacity.  IT also has workloads that are cyclical in nature, including back-up, disaster recovery, and quality assurance, each of which has very high security requirements.   And, most of the time they are not using all of the hardware dedicated to them. This is why the average enterprise server utilization is only 5-10%. Think of the savings in capital and IT operations if these applications could be moved to a cloud service where you only pay for what you use.

Lastly, large OLTP-based workloads, or ERP systems or web store fronts are the most critical applications for your business.  If you are a manufacturer, it could be your order, inventory and supply chain systems; for banks, it's core systems like deposits, transfers, etc;  for airlines it would be the reservation systems. When these go down, the business is all but dead. Therefore, these are the kinds of systems that make sense to continue to invest in traditional, in-house IT infrastructures. Because these kinds of workloads tend to run nearly all the time, it makes good economic sense to buy the infrastructures to support them.

Cloud Computing Journal: How would someone decide if cloud computing is right for their business and which workloads to move?

Marcello: It's really about understanding what makes the most business sense for the client and what they are trying to accomplish.  As part of the June 30th announcement, we have Unisys Cloud Transformation Services, available now, which allow clients to plan and migrate to the type of cloud environment that best meets their business goals.  These services help clients assess what application workloads can be moved to the cloud, how that can be done, and the technology, financial and security implications of their choices.

Cloud Computing Journal: How about virtualization and automation, where do they fit in the big picture?

Marcello: These are fundamental to cloud computing and for Unisys, our Real-Time Infrastructure technology powers our cloud.  Virtualization is an enabler that helps us supply only the needed amount of IT resources based on the workload demand of the business at any given time.  Automation adds elasticity to the environment, reduces the time needed for changes, and eliminates or at least simplifies the manual intervention in a potentially rapidly changing environment.

Cloud Computing Journal: And what kinds of governance and service management tools does the enterprise need?

Marcello: From a service management perspective, many vendors operate as siloed mechanisms.  Unisys, on the other hand, has built into our secure cloudware stack an integration layer that enables us to interface with our clients' service management framework as well.  The virtual data center, regardless of the location of the resources, is managed seamlessly.  Unisys makes it look like one holistic environment. A key point to keep in mind is how hard it is for any IT organization to develop world class governance and service management.  With Unisys Secure Cloud Solution and "Cloud in a Box" we have developed a broad set of ITIL best practices, which are fully automated, and which allow us and our clients to run a very efficient IT infrastructure. With this, a lot of automation occurs, and this can save money by minimizing manual tasks, reducing errors, and getting much higher utilization rates.

Cloud Computing Journal: What verticals among your customers are leading the adoption of the Cloud?

Marcello: We're getting a number of inquiries from a broad range of Unisys clients in telco's, financial institutions, transportation, and the public sector as well as partners who are interested in Unisys hosting their solutions within our Secure Cloud.

Cloud Computing Journal: What does Cloud Computing have to offer to mid-tier enterprises?

Marcello: Cloud computing is compelling for mid-tier enterprises since it minimizes the need for capital expenditures as well as lowers the need for on-going operational support.  They will be interested in our Secure Cloud Solution, especially secure Software as a Service (SaaS).

Additionally for those clients who want to build an internal cloud, the Unisys Cloud-in-a-box that we'll deliver later this year will be a cost-effective, simplified cloud deployment alternative.

More Stories By Jeremy Geelan

Jeremy Geelan is Chairman & CEO of the 21st Century Internet Group, Inc. and an Executive Academy Member of the International Academy of Digital Arts & Sciences. Formerly he was President & COO at Cloud Expo, Inc. and Conference Chair of the worldwide Cloud Expo series. He appears regularly at conferences and trade shows, speaking to technology audiences across six continents. You can follow him on twitter: @jg21.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


Cloud Expo Breaking News
Next-Gen Cloud. Whatever you call it, there’s a higher calling for cloud computing that requires providers to change their spots and move from a commodity mindset to a premium one. Businesses can no longer maintain the status quo that today’s service providers offer. Yes, the continuity, speed, mobility, data access and connectivity are staples of the cloud and always will be. But cloud providers that plan to not only exist tomorrow – but to lead – know that security must be the top priority for the cloud and are delivering it now. In his session at 14th Cloud Expo, Kurt Hagerman, Chief Information Security Officer at FireHost, will detail why and how you can have both infrastructure performance and enterprise-grade security – and what tomorrow's cloud provider will look like.
The social media expansion has shown just how people are eager to share their experiences with the rest of the world. Cloud technology is the perfect platform to satisfy this need given its great flexibility and readiness. At Cynny, we aim to revolutionize how people share and organize their digital life through a brand new cloud service, starting from infrastructure to the users’ interface. A revolution that began from inventing and designing our very own infrastructure: we have created the first server network powered solely by ARM CPU. The microservers have “organism-like” features, differentiating them from any of the current technologies. Benefits include low consumption of energy, making Cynny the ecologically friendly alternative for storage as well as cheaper infrastructure, lower running costs, etc.
The revolution that happened in the server universe over the past 15 years has resulted in an eco-system that is more open, more democratically innovative and produced better results in technically challenging dimensions like scale. The underpinnings of the revolution were common hardware, standards based APIs (ex. POSIX) and a strict adherence to layering and isolation between applications, daemons and kernel drivers/modules which allowed multiple types of development happen in parallel without hindering others. Put simply, today's server model is built on a consistent x86 platform with few surprises in its core components. A kernel abstracts away the platform, so that applications and daemons are decoupled from the hardware. In contrast, networking equipment is still stuck in the mainframe era. Today, networking equipment is a single appliance, including hardware, OS, applications and user interface come as a monolithic entity from a single vendor. Switching between different vendor'...
More and more enterprises today are doing business by opening up their data and applications through APIs. Though forward-thinking and strategic, exposing APIs also increases the surface area for potential attack by hackers. To benefit from APIs while staying secure, enterprises and security architects need to continue to develop a deep understanding about API security and how it differs from traditional web application security or mobile application security. In his session at 14th Cloud Expo, Sachin Agarwal, VP of Product Marketing and Strategy at SOA Software, will walk you through the various aspects of how an API could be potentially exploited. He will discuss the necessary best practices to secure your data and enterprise applications while continue continuing to support your business’s digital initiatives.
Web conferencing in a public cloud has the same risks as any other cloud service. If you have ever had concerns over the types of data being shared in your employees’ web conferences, such as IP, financials or customer data, then it’s time to look at web conferencing in a private cloud. In her session at 14th Cloud Expo, Courtney Behrens, Senior Marketing Manager at Brother International, will discuss how issues that had previously been out of your control, like performance, advanced administration and compliance, can now be put back behind your firewall.
Cloud backup and recovery services are critical to safeguarding an organization’s data and ensuring business continuity when technical failures and outages occur. With so many choices, how do you find the right provider for your specific needs? In his session at 14th Cloud Expo, Daniel Jacobson, Technology Manager at BUMI, will outline the key factors including backup configurations, proactive monitoring, data restoration, disaster recovery drills, security, compliance and data center resources. Aside from the technical considerations, the secret sauce in identifying the best vendor is the level of focus, expertise and specialization of their engineering team and support group, and how they monitor your day-to-day backups, provide recommendations, and guide you through restores when necessary.
Cloud scalability and performance should be at the heart of every successful Internet venture. The infrastructure needs to be resilient, flexible, and fast – it’s best not to get caught thinking about architecture until the middle of an emergency, when it's too late. In his interactive, no-holds-barred session at 14th Cloud Expo, Phil Jackson, Development Community Advocate for SoftLayer, will dive into how to design and build-out the right cloud infrastructure.
You use an agile process; your goal is to make your organization more agile. What about your data infrastructure? The truth is, today’s databases are anything but agile – they are effectively static repositories that are cumbersome to work with, difficult to change, and cannot keep pace with application demands. Performance suffers as a result, and it takes far longer than it should to deliver on new features and capabilities needed to make your organization competitive. As your application and business needs change, data repositories and structures get outmoded rapidly, resulting in increased work for application developers and slow performance for end users. Further, as data sizes grow into the Big Data realm, this problem is exacerbated and becomes even more difficult to address. A seemingly simple schema change can take hours (or more) to perform, and as requirements evolve the disconnect between existing data structures and actual needs diverge.
SYS-CON Events announced today that SherWeb, a long-time leading provider of cloud services and Microsoft's 2013 World Hosting Partner of the Year, will exhibit at SYS-CON's 14th International Cloud Expo®, which will take place on June 10–12, 2014, at the Javits Center in New York City, New York. A worldwide hosted services leader ranking in the prestigious North American Deloitte Technology Fast 500TM, and Microsoft's 2013 World Hosting Partner of the Year, SherWeb provides competitive cloud solutions to businesses and partners around the world. Founded in 1998, SherWeb is a privately owned company headquartered in Quebec, Canada. Its service portfolio includes Microsoft Exchange, SharePoint, Lync, Dynamics CRM and more.
The world of cloud and application development is not just for the hardened developer these days. In their session at 14th Cloud Expo, Phil Jackson, Development Community Advocate for SoftLayer, and Harold Hannon, Sr. Software Architect at SoftLayer, will pull back the curtain of the architecture of a fun demo application purpose-built for the cloud. They will focus on demonstrating how they leveraged compute, storage, messaging, and other cloud elements hosted at SoftLayer to lower the effort and difficulty of putting together a useful application. This will be an active demonstration and review of simple command-line tools and resources, so don’t be afraid if you are not a seasoned developer.
SYS-CON Events announced today that BUMI, a premium managed service provider specializing in data backup and recovery, will exhibit at SYS-CON's 14th International Cloud Expo®, which will take place on June 10–12, 2014, at the Javits Center in New York City, New York. Manhattan-based BUMI (Backup My Info!) is a premium managed service provider specializing in data backup and recovery. Founded in 2002, the company’s Here, There and Everywhere data backup and recovery solutions are utilized by more than 500 businesses. BUMI clients include professional service organizations such as banking, financial, insurance, accounting, hedge funds and law firms. The company is known for its relentless passion for customer service and support, and has won numerous awards, including Customer Service Provider of the Year and 10 Best Companies to Work For.
Chief Security Officers (CSO), CIOs and IT Directors are all concerned with providing a secure environment from which their business can innovate and customers can safely consume without the fear of Distributed Denial of Service attacks. To be successful in today's hyper-connected world, the enterprise needs to leverage the capabilities of the web and be ready to innovate without fear of DDoS attacks, concerns about application security and other threats. Organizations face great risk from increasingly frequent and sophisticated attempts to render web properties unavailable, and steal intellectual property or personally identifiable information. Layered security best practices extend security beyond the data center, delivering DDoS protection and maintaining site performance in the face of fast-changing threats.
From data center to cloud to the network. In his session at 3rd SDDC Expo, Raul Martynek, CEO of Net Access, will identify the challenges facing both data center providers and enterprise IT as they relate to cross-platform automation. He will then provide insight into designing, building, securing and managing the technology as an integrated service offering. Topics covered include: High-density data center design Network (and SDN) integration and automation Cloud (and hosting) infrastructure considerations Monitoring and security Management approaches Self-service and automation
In his session at 14th Cloud Expo, David Holmes, Vice President at OutSystems, will demonstrate the immense power that lives at the intersection of mobile apps and cloud application platforms. Attendees will participate in a live demonstration – an enterprise mobile app will be built and changed before their eyes – on their own devices. David Holmes brings over 20 years of high-tech marketing leadership to OutSystems. Prior to joining OutSystems, he was VP of Global Marketing for Damballa, a leading provider of network security solutions. Previously, he was SVP of Global Marketing for Jacada where his branding and positioning expertise helped drive the company from start-up days to a $55 million initial public offering on Nasdaq.
Performance is the intersection of power, agility, control, and choice. If you value performance, and more specifically consistent performance, you need to look beyond simple virtualized compute. Many factors need to be considered to create a truly performant environment. In his General Session at 14th Cloud Expo, Marc Jones, Vice President of Product Innovation for SoftLayer, will explain how to take advantage of a multitude of compute options and platform features to make cloud the cornerstone of your online presence.