Cloud Security: From Hacking the Mainframe to Protecting Identity

By Andi Mann, Vice President, Strategic Solutions at CA

Cloud computing, mobility, and the Internet of Things are leading us towards a more technology-driven world. In my last blog, I wrote about how the Internet of Things will change our everyday lives, but with these new technologies comes new risks to the organization.

To understand how recent trends are shifting security, let’s revisit the golden age of hacking movies from the ‘80s and ‘90s. A recent post by Alexis Madrigal of The Atlantic sums up this era of Hollywood hackers by saying that “the mainframe was unhackable unless [the hackers] were in the room, in which case, it was simple.” That’s not far off from how IT security was structured in those years. Enterprises secured data by keeping everything inside a corporate firewall and only granting accessed to employees within the perimeter. Typically, the perimeter extended as far as the walls of the building.

When the cloud emerged on the scene, every IT professional said that it was too risky and introduced too many points of vulnerability. They weren’t wrong, but the advantages of the cloud, such as increased productivity, collaboration, and innovation, weren’t about to be ignored by the business. If the IT department just said no to cloud, the business could go elsewhere for their IT services – after all, the cloud doesn’t care who signs the checks. In fact, a recent survey revealed that in 60% of organizations, the business occasionally “circumvents IT and purchases technology on their own to support a project,” a practice commonly referred to as rogue IT, and another recent study found a direct correlation between rogue IT and data loss. This is obviously something that the IT department can’t ignore.

Identity is the New Perimeter

The proliferation of cloud connected devices and users accessing data from outside the firewall demands a shift in the way we secure data. Security is no longer about locking down the perimeter – it’s about understanding who is accessing the information and the data they’re allowed to access. IT needs to implement an identity-centric approach to secure data, but according to a recent Ponemon study, only 29% of organizations are confident that they can authenticate users in the cloud. At first glance, that appears to be a shockingly low number, but if you think about it, how do you verify identity? Usernames and passwords, while still the norm, are not sufficient to prove identity and sure, you can identify a device connected to the network, but can you verify the identity of the person using the device?

In a recent @CloudCommons tweetchat on cloud security, the issue of proving the identity of cloud users kept cropping up:

 Andi Mann

Today’s hackers don’t need to break into your data center to steal your data. They just need an access point and your username and password. That’s why identity and access management is such a critical component of IT security. New technologies are emerging to meet the security challenge, such as strong authentication software that analyzes risk and looks for irregularities when a user tries to access data. If a user tries to access data from a new device, the strong authentication software will recognize that it’s a new device and extra authentication flows kick in that require the user to further verify their identity.

What IT should be doing now to secure identity

To take advantage of cloud computing, mobility, and the Internet of Things in a secure way, the IT department needs to implement these types of new and innovative technologies that focus on verifying identity. In addition to implementing new technologies, the IT department needs to enact a broader cloud and mobile device strategy that puts the right policies and procedures in place and focuses on educating employees to minimize risk. Those in charge of IT security must also establish a trust framework that enforces how you identify, secure and authenticate new employees and devices.

Cloud computing, mobile devices, and the Internet of Things can’t be ignored by IT and the sooner a trust framework and a cloud security strategy is established, the sooner your organization can take advantage of new and innovative technologies, allowing the business to reap the benefits of cloud, mobile, and the Internet of Things, while keeping the data safe and sound. And to me, that sounds like a blockbuster for IT.

 

Andi Mann is vice president of Strategic Solutions at CA Technologies. With over 25 years’ experience across four continents, Andi has deep expertise of enterprise software on cloud, mainframe, midrange, server and desktop systems. Andi has worked within IT for global corporations, with software vendors, and as a leading industry analyst. He has been published in the New York Times, USA Today, Forbes, CIO, Wall Street Journal, and more, and has presented worldwide on virtualization, cloud, automation, and IT management. Andi is a co-author of the popular handbook, ‘Visible Ops – Private Cloud’, and the IT leader’s guide to business innovation, ‘The Innovative CIO’. He blogs at https://pleasediscuss.com/andimann and tweets as @AndiMann.

 

 

 

AppMesh Moves into Big Hole Salesforce Overlooked

AppMesh, a year-old start-up begun by Salesforce veterans, says it’s the first mobile-only CRM app built for sales reps.
The company has no interest in managers – well, at least not yet – only the under-served sales pro.
AppMesh claims to have what it calls a “post-cloud architecture,” an eye-catching way of saying the user can sync data across mobile devices using whatever connectivity’s available but stores all of the info on the device itself, no cloud needed.
Anyway, the widgetry integrates contextual awareness into core phone, calendar and e-mail applications for a unified always-available view of customer data and interactions. In other word, it’ll set user priorities.

read more

Cloud Expo NY: The Answer to Data Scientist Scarcity Lies in Automation

If zettabytes of data exist, why is less than 1% of the world’s data being analyzed today? Seasoned entrepreneur and startup CEO Radhika Subramanian believes that the inability to analyze and gain value from Big Data is because organizations are taking a services-centered approach. As the title of the session implies, Subramanian believes that the data needs to do the talking, not armies of analysts searching and querying databases. Her company has developed high-speed, advanced algorithms to automate pattern detection for rapid, real-time discovery of the “unknown unknowns” in structured and unstructured data.
In their session at the 12th International Cloud Expo, Radhika Subramanian, CEO of Emcien, teams up with internationally renowned High-Performance Computing luminary Dr. David Bader to tackle Big Data’s biggest challenges. Together they will ask, “What if you didn’t have to analyze data at all?

read more

Big Time – Introducing Hadoop on Azure

In the last couple of years Hadoop has become synonymous with Big Data. This framework is so vast and popular that Microsoft recently announced, for the first time in its history, that it is going to invest in this large-scale, open-source project as its solution for Big Data.

In his session at 12th Cloud Expo | Cloud Expo New York [June 10-13, 2013], delegates will be able to learn how Hadoop works on Windows Azure including an exploration of different storage options, e.g., AVS and S3, how Hadoop on Azure integrates with other cloud services, understanding key scenarios for Hadoop in the Microsoft ecosystem, and discovering Hadoop’s role in a cloud environment.

read more

How to make cloud computing pay

Relying on cloud computing strategies to free up dollars and time that can quickly be re-invested in product and service innovation emerged as the highest priority for respondents in a recent Rackspace survey.

While cost reductions were significant, the greatest contributions were seen in investments in innovation (48%), new product & service development (45%), and boosting sale efforts (38%).

Rackspace recently commissioned a study with market research firm Vanson Bourne, who surveyed 1,300 organizations in the UK and the U.S., including 1,000 Small & Medium Enterprises (SME) and 300 enterprises with 1,000 employees or more.  The methodology included coverage of Financial Services, Retail, IT/Technology, Manufacturing, Business and Professional Services, Media, Logistics, and Mobile Telecommunications sectors, with a further small representative group from other sectors. 

Rackspace also partners often with the Manchester Business School to complete qualitative research, which they also did on this project.  You can find …

Sizing up collaboration: how to measure ROI on your Unified Communications

By Adrian Thirkill, Easynet UK MD

Dust off the bunting and hang the flags out: global IT spending is forecast to increase by 4.1% in 2013  according to Gartner’s latest worldwide IT spending forecast published in March.

This is great news, but when considered within the still-quaking economy it also comes with a caution: it’s more important than ever to make carefully-planned IT investments which add value to a business and create a Return on Investment in a defined time period. Now is not the time for IT Supermarket Sweeps, or for keeping up with the Jones’. 

Unified Communications (UC) is one particular investment which brings about an improved way of working with immediate, tangible business benefits. When securing board buy-in, a commitment to how quickly companies can see a Return on Investment (ROI) from its rollout is often one of the deciding factors.  

To make the …

Cloud Expo New York: See Inside Your Cloud

Tools used by data center and cloud operations teams to manage infrastructure have zero visibility of network traffic in the public cloud or virtual network. And what you can’t see, you can’t manage or secure. A new approach is required to gain visibility to traffic in virtual networks, remote data centers or public cloud infrastructure.
In his session at the 12th International Cloud Expo, David Reoch, Senior Director of Cloud Solutions at Gigamon, will show new techniques that enable existing monitoring, analysis and security tools to gain pervasive visibility into the ever-expanding network fabric.

read more

Healthcare Data on the Cloud – The Reality of Sensitive Information Online

The convenience, efficiency and cost benefits cloud computing offers organizations has made moving healthcare data and records to the cloud make sense for hospitals, physicians and other healthcare providers. Security and data breaches are a concern for any industry utilizing the cloud, but healthcare unfortunately seems to be particularly vulnerable to attacks. The Washington Post recently reported that The Department of Homeland Security is fearful that the health industry is “inviting” an attack with its out-of-date policies and lack of oversight.
A recent WIRED article discussed the current state of healthcare information in the cloud, including specifics on the vulnerabilities facing healthcare providers using cloud applications and why consumers should be concerned about their healthcare data being on the cloud.
According to the article, hackers are particularly interested in healthcare information because of its comparatively substantial dollar value. An individual’s medical identity can be worth as much as $50, a significant amount considering a social security number is worth just $1. With personal medical information in hand, thieves are able to commit medical identity theft by using someone else’s personal information to receive goods or services, potentially wreaking havoc on that person’s records and creating liabilities for service providers and increasing costs for everyone.

read more

Cloud Expo NY | How Private Cloud Works in Real Life: Deployment Examples

Companies around the world are moving into on-premise private cloud environments. Many connect their private cloud to their public cloud service providers.
In his session at the 12th International Cloud Expo, Brian Patrick Donaghy, CEO of Appcore, will talk about examples of what worked, what failed and why we should think about this evolution. Questions covered will include:
Can you really move from virtualization into automated and orchestrated private cloud?
What are the benefits? Costs in money and time? Risks?

read more

Most operators to opt for cloud-based RCS

Despite the operator support behind Rich Communications Services (RCS), it will only be the very biggest international players that deploy the technology in their own networks. The rest will look to cloud-based offerings to fulfil their needs, according to business systems firm SAP Mobile Services.

John Sims, president of SAP Mobile Services, recently told telecoms.com that “only the biggest operators in world will deploy RCS in their networks. But beyond the top five or ten operators globally, the rest of the industry will look for a hosted solution.”

The cloud news categorized.