Welcome!

@CloudExpo Authors: Liz McMillan, Pat Romanski, Dana Gardner, Elizabeth White, Jeev Trika

Related Topics: Cloud Security, Java IoT, Linux Containers, @CloudExpo

Cloud Security: Article

Einstein, Sharks and Clouds: IT Security in the Cloud

Security, while a very real and legitimate concern is relative

What can these things possibly have in common?  In a word - relativity. 

I'm reminded of the old joke, two guys are swimming in the ocean when they notice a shark and one guy takes off swimming towards the boat, while the other says, "What are you doing?  We can't swim faster than a shark", the other replies, "I don't need to swim faster than a shark, just faster than you."

Lately there has been a barrage of articles with regards to cloud security, and some very public demonstrations of outages with Facebook and Twitter.  Its been a field day for many who oppose the cloud computing model.  Let me get this out of the way so that there is no misunderstanding, yes, I agree with most on the need for better security in the cloud, and rest assured, the cloud service providers are motivated to work on it.  That being said, lets move on. 

Security, while a very real and legitimate concern is relative.  While IT security has improved over the years I've been in this business, there are IT security breaches at banks, governments, educational institutions, retailers, and many other organizations which are not using the cloud today.  Just do a simple Google search and you'll find plenty of ammo on the need for better security, cloud or no cloud.

While the discussion of cloud security is certainly a very important one, lets not forget that it's a discussion that's relative to the level of security in the current business environment of those considering moving to the cloud today. 

Many of us who have spent our careers in or around IT recognize many of the security issues that cloud service providers will need to address.  This is particularly true for those that have spent most of that time at large, enterprise organizations.  We have to stop and remind ourselves, who are the prime, early adopter candidates for cloud computing? The answer here seems to be SMB

So lets talk about SMB IT practices for a moment, and lets begin with the smallest of organizations, say 1-20 employees.  Most of these companies can't afford IT staff, have no backup for their business records, have underutilized servers, have no security plan, or what many other IT professionals recognize as best practices in the industry, never mind security.  Disaster, backup and recovery?  Oh, yes, it's that tape backup in the desk next to the computer.  They fax and e.mail "secure" documents around sometimes to the wrong fax or (external) e.mail address - oops, there goes Joe's private medical records.  In these cases, cloud computing begins to look pretty attractive.

We can repeat this story on a gradual scale adding  IT headcount along the way.  How many IT people in a 20-50 employee organization?  50-100, 100-500?  Certainly, some of the aforementioned issues get addressed, though not all, as they're dealing with many IT issues, are probably understaffed, and overwhelmed.  Lets not forget we're talking about small businesses across all industries - accountants, doctors, lawyers, architects, retailers, and others, not necessarily small IT businesses.  Add in the greatest recession since WWII, and well, you can see how the cloud value proposition begins to make sense to many in this segment of the market.  Those small organizations will likely benefit from a move to the cloud, and will be more competitive as a result. 

Last one with the legacy traditional IT environment, please turn off the lights, and try to stay ahead of the sharks.

-Tune The Future-

More Stories By Ray DePena

Ray DePena worked at IBM for over 12 years in various senior global roles in managed hosting sales, services sales, global marketing programs (business innovation), marketing management, partner management, and global business development.
His background includes software development, computer networking, systems engineering, and IT project management. He holds an MBA in Information Systems, Marketing, and International Business from New York University’s Stern School of Business, and a BBA in Computer Systems from the City University of New York at Baruch College.

Named one of the World's 30 Most Influential Cloud Computing Bloggers in 2009, Top 50 Bloggers on Cloud Computing in 2010, and Top 100 Bloggers on Cloud Computing in 2011, he is the Founder and Editor of Amazon.com Journal,Competitive Business Innovation Journal,and Salesforce.com Journal.

He currently serves as an Industry Advisor for the Higher Education Sector on a National Science Foundation Initiative on Computational Thinking. Born and raised in New York City, Mr. DePena now lives in northern California. He can be followed on:

Twitter: @RayDePena   |   LinkedIn   |   Facebook   |   Google+

@CloudExpo Stories
In the world of DevOps there are ‘known good practices’ – aka ‘patterns’ – and ‘known bad practices’ – aka ‘anti-patterns.' Many of these patterns and anti-patterns have been developed from real world experience, especially by the early adopters of DevOps theory; but many are more feasible in theory than in practice, especially for more recent entrants to the DevOps scene. In this power panel at @DevOpsSummit at 18th Cloud Expo, moderated by DevOps Conference Chair Andi Mann, panelists will dis...
See storage differently! Storage performance problems have only gotten worse and harder to solve as applications have become largely virtualized and moved to a cloud-based infrastructure. Storage performance in a virtualized environment is not just about IOPS, it is about how well that potential performance is guaranteed to individual VMs for these apps as the number of VMs keep going up real time. In his session at 18th Cloud Expo, Dhiraj Sehgal, in product and marketing at Tintri, will discu...
trust and privacy in their ecosystem. Assurance and protection of device identity, secure data encryption and authentication are the key security challenges organizations are trying to address when integrating IoT devices. This holds true for IoT applications in a wide range of industries, for example, healthcare, consumer devices, and manufacturing. In his session at @ThingsExpo, Lancen LaChance, vice president of product management, IoT solutions at GlobalSign, will teach IoT developers how t...
The pace of innovation, vendor lock-in, production sustainability, cost-effectiveness, and managing risk… In his session at 18th Cloud Expo, Dan Choquette, Founder of RackN, will discuss how CIOs are challenged finding the balance of finding the right tools, technology and operational model that serves the business the best. He will discuss how clouds, open source software and infrastructure solutions have benefits but also drawbacks and how workload and operational portability between vendors...
When it comes to IoT in the enterprise, namely the commercial building and hospitality markets, a benefit not getting the attention it deserves is energy efficiency, and IoT's direct impact on a cleaner, greener environment when installed in smart buildings. Until now clean technology was offered piecemeal and led with point solutions that require significant systems integration to orchestrate and deploy. There didn't exist a 'top down' approach that can manage and monitor the way a Smart Buildi...
So, you bought into the current machine learning craze and went on to collect millions/billions of records from this promising new data source. Now, what do you do with them? Too often, the abundance of data quickly turns into an abundance of problems. How do you extract that "magic essence" from your data without falling into the common pitfalls? In her session at @ThingsExpo, Natalia Ponomareva, Software Engineer at Google, will provide tips on how to be successful in large scale machine lear...
SYS-CON Events announced today that Peak 10, Inc., a national IT infrastructure and cloud services provider, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Peak 10 provides reliable, tailored data center and network services, cloud and managed services. Its solutions are designed to scale and adapt to customers’ changing business needs, enabling them to lower costs, improve performance and focus inter...
You think you know what’s in your data. But do you? Most organizations are now aware of the business intelligence represented by their data. Data science stands to take this to a level you never thought of – literally. The techniques of data science, when used with the capabilities of Big Data technologies, can make connections you had not yet imagined, helping you discover new insights and ask new questions of your data. In his session at @ThingsExpo, Sarbjit Sarkaria, data science team lead ...
SYS-CON Events announced today that Ericsson has been named “Gold Sponsor” of SYS-CON's @ThingsExpo, which will take place on June 7-9, 2016, at the Javits Center in New York, New York. Ericsson is a world leader in the rapidly changing environment of communications technology – providing equipment, software and services to enable transformation through mobility. Some 40 percent of global mobile traffic runs through networks we have supplied. More than 1 billion subscribers around the world re...
The demand for organizations to expand their infrastructure to multiple IT environments like the cloud, on-premise, mobile, bring your own device (BYOD) and the Internet of Things (IoT) continues to grow. As this hybrid infrastructure increases, the challenge to monitor the security of these systems increases in volume and complexity. In his session at 18th Cloud Expo, Stephen Coty, Chief Security Evangelist at Alert Logic, will show how properly configured and managed security architecture can...
Many private cloud projects were built to deliver self-service access to development and test resources. While those clouds delivered faster access to resources, they lacked visibility, control and security needed for production deployments. In their session at 18th Cloud Expo, Steve Anderson, Product Manager at BMC Software, and Rick Lefort, Principal Technical Marketing Consultant at BMC Software, will discuss how a cloud designed for production operations not only helps accelerate developer...
The IoTs will challenge the status quo of how IT and development organizations operate. Or will it? Certainly the fog layer of IoT requires special insights about data ontology, security and transactional integrity. But the developmental challenges are the same: People, Process and Platform. In his session at @ThingsExpo, Craig Sproule, CEO of Metavine, will demonstrate how to move beyond today's coding paradigm and share the must-have mindsets for removing complexity from the development proc...
Much of the value of DevOps comes from a (renewed) focus on measurement, sharing, and continuous feedback loops. In increasingly complex DevOps workflows and environments, and especially in larger, regulated, or more crystallized organizations, these core concepts become even more critical. In his session at @DevOpsSummit at 18th Cloud Expo, Andi Mann, Chief Technology Advocate at Splunk, will show how, by focusing on 'metrics that matter,' you can provide objective, transparent, and meaningfu...
Artificial Intelligence has the potential to massively disrupt IoT. In his session at 18th Cloud Expo, AJ Abdallat, CEO of Beyond AI, will discuss what the five main drivers are in Artificial Intelligence that could shape the future of the Internet of Things. AJ Abdallat is CEO of Beyond AI. He has over 20 years of management experience in the fields of artificial intelligence, sensors, instruments, devices and software for telecommunications, life sciences, environmental monitoring, process...
Redis is not only the fastest database, but it has become the most popular among the new wave of applications running in containers. Redis speeds up just about every data interaction between your users or operational systems. In his session at 18th Cloud Expo, Dave Nielsen, Developer Relations at Redis Labs, will shares the functions and data structures used to solve everyday use cases that are driving Redis' popularity.
In his session at 18th Cloud Expo, Sagi Brody, Chief Technology Officer at Webair Internet Development Inc., will focus on real world deployments of DDoS mitigation strategies in every layer of the network. He will give an overview of methods to prevent these attacks and best practices on how to provide protection in complex cloud platforms. He will also outline what we have found in our experience managing and running thousands of Linux and Unix managed service platforms and what specifically c...
The increasing popularity of the Internet of Things necessitates that our physical and cognitive relationship with wearable technology will change rapidly in the near future. This advent means logging has become a thing of the past. Before, it was on us to track our own data, but now that data is automatically available. What does this mean for mHealth and the "connected" body? In her session at @ThingsExpo, Lisa Calkins, CEO and co-founder of Amadeus Consulting, will discuss the impact of wea...
Increasing IoT connectivity is forcing enterprises to find elegant solutions to organize and visualize all incoming data from these connected devices with re-configurable dashboard widgets to effectively allow rapid decision-making for everything from immediate actions in tactical situations to strategic analysis and reporting. In his session at 18th Cloud Expo, Shikhir Singh, Senior Developer Relations Manager at Sencha, will discuss how to create HTML5 dashboards that interact with IoT devic...
Whether your IoT service is connecting cars, homes, appliances, wearable, cameras or other devices, one question hangs in the balance – how do you actually make money from this service? The ability to turn your IoT service into profit requires the ability to create a monetization strategy that is flexible, scalable and working for you in real-time. It must be a transparent, smoothly implemented strategy that all stakeholders – from customers to the board – will be able to understand and comprehe...
SYS-CON Events announced today that SoftLayer, an IBM Company, has been named “Gold Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York, New York. SoftLayer, an IBM Company, provides cloud infrastructure as a service from a growing number of data centers and network points of presence around the world. SoftLayer’s customers range from Web startups to global enterprises.