Welcome!

Big Data Journal Authors: Nikita Ivanov, Jim Kaskade, Adrian Bridgwater, Pat Romanski, Greg Schulz

Related Topics: Cloud Expo, Java, SOA & WOA, Virtualization, Security, Big Data Journal

Cloud Expo: Article

It’s Money That Matters in the Cloud… Well, At Least ROI

Cloud security closes the risk versus reward gap

With all the talk of fiscal cliffs sequestrations, financial binds and “next year’s budget,” I started thinking about cloud security in more tangible ways. Specifically returns on investment, economic impact and total costs of ownership. Just like death and taxes, businesses can add intrusion and attack to the list of sureties. I can hear CFOs all over the world sigh in exasperation as they feel pressured to add another expense line item to minimize the building security threats to their enterprises.

Before you add another decimal place to security budgets, maybe it’s time you consider the how cloud-deployed security options can not only address the complexities of enterprise security ably, but do so at considerable savings.

Study after study promotes that a cloud computing model saves organization money. We know that more and more functionality is moving to the cloud. For things like CRM or other standard business applications, it simply makes sense. We recognize the limited time and funding to run and maintain enterprise applications and the cloud provides that great equalizer. This model extends itself to cloud security and security-as-a-service.

First there are the over-arching savings of cloud-computing in general:

  • Elimination of CapEx costs: no hardware or software to buy (Any “cloud” company that asks you to install a server on your premises to monitor your enterprise isn’t cloud)
  • Pay-as-you-go scalable: Most cloud providers can offer considerable cost savings through economies of scale. The ability to adjust the level of service necessary (elastic provisioning) creates flexibility for increased margins and cost-controls.
  • Zero-day start/On demand delivery of service: no waiting time after the service has been purchased to develop and configure a complex system. This means no development hell or waiting for Phase 2 to be complete in order to start reaping benefits.
  • Head count savings: included in most cloud services are the personnel costs (salary, benefits, overhead, churn/hiring costs) a company does not need to invest in more people and gains the benefit of the security expertise and tribal knowledge of the cloud security provider.
  • Best-of breed resource/expertise expansion: Companies improve their overall business agility through proven technologies supported and updated by the core competencies of the developers. Meanwhile CIOs get to move more IT budget to innovation or enablement programs.

But where are the benefits of cloud security from an ROI perspective:

  • 24/7 Availability: Cloud security is about continuous monitoring.  To properly secure the expanding footprint of an enterprise’s IT landscape, there must be the vigilance to catch analyze and remediate issues as quickly as possible. Like a cancer, if security issues go undetected, they can metastasize and spread. Having a professional monitor a network 7/24/365 (in real time) seems like a luxury for Fortune 500 companies. Cloud security makes this option available for the most modest organizations. The holes in security that are created through intermittent monitoring, vague automation settings and periodic machine log reviews will cost an organization.  But continuous monitoring isn’t a cost center. Preventive and proactive security creates reduced risk (without additional man hours) which allows for redeployed resources and a realignment based of business needs.
  • Unification: The agility from the cloud allows companies to leverage the capabilities of various security solutions looking at multiple parts of the enterprise. This includes intrusion detection, credentialing, access, SSO, web authentication and compliance audits. It not only allows an enterprise to acquire more and greater functionality for virtually the same cost, but it also centralizes the collective intelligence and provides the advantage enhanced visibility through correlated and situational context. This, in turn, creates better and faster decisions which streamline resources and save money.
  • Improved productivity Although there are many examples of this within cloud based security, I will point to one (and use future blogs to expound on others). Using identity management, companies can automatically provision and deprovision users. This service alone can save 75% of the requests across the enterprise. Imagine the additional savings when IT is not slogged down with forgotten password requests/resets along with managing credentials. There are studies that prove that this alone saves companies nearly $200K per year. Now with better employee productivity (because this helps solve BYOD issues) and certain portions of your network safe from data theft and leakage, IT can concentrate on business issues that drive revenue.
  • Compliance: Dozens of man hours are typically needed each month to complete all the reports needed to satisfy a regulatory agency auditor; and for most companies, it’s not just one agency, but several. Through real time correlation, most of the work of identifying, capturing, encrypting and storing(or destroying) certain pieces of information and providing the proof  your best practices are in line with internal and external policies is easier. Because of unification, multi-silo collection and security centralization, 75 hours per month becomes 10. And more importantly, the degree of accuracy of the reporting is significantly better.  And with better reports, the threat of fines disappears.

Gartner estimates the annual cost to own and manage traditional on premise security software applications can be 4X the initial purchase. This is chiefly due to the need to acquire and maintain the resources to support the deployment. In many cases, for less than what a company pays for in support and maintenance of these on premise initiatives, they could have twice the capability from the cloud.

When it’s money that matters, the bottom line should be as much about saving as it is spending; as long as the result is a positive return on the investment. Enterprise security is not different. For years seen as a cost center, through cloud-based solutions it can now be redefined as a revenue enablement mechanism. Certainly there are costs involved in a maintaining a safe network perimeter, protecting and securing data and compliance auditing. However, by exploiting the benefits and strengths provided by cloud based security, you can prudently and effectively contain the issues with plentiful resources to reinvest in your core competencies and focus on driving business forward. Security issues will not go away, but you can direct less at them and in return, receive more greater results.

When looking at the cloud in term of security…sometimes you can have your cake and eat it too.

 

Kevin Nikkhoo
www.cloudaccess.com

More Stories By Kevin Nikkhoo

With more than 32 years of experience in information technology, and an extensive and successful entrepreneurial background, Kevin Nikkhoo is the CEO of the dynamic security-as-a-service startup Cloud Access. CloudAccess is at the forefront of the latest evolution of IT asset protection--the cloud.

Kevin holds a Bachelor of Science in Computer Engineering from McGill University, Master of Computer Engineering at California State University, Los Angeles, and an MBA from the University of Southern California with emphasis in entrepreneurial studies.

@BigDataExpo Stories
SYS-CON Events announced today that Gridstore™, the leader in hyper-converged infrastructure purpose-built to optimize Microsoft workloads, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Gridstore™ is the leader in hyper-converged infrastructure purpose-built for Microsoft workloads and designed to accelerate applications in virtualized environments. Gridstore’s hyper-converged infrastructure is the ...
There's Big Data, then there's really Big Data from the Internet of Things. IoT is evolving to include many data possibilities like new types of event, log and network data. The volumes are enormous, generating tens of billions of logs per day, which raise data challenges. Early IoT deployments are relying heavily on both the cloud and managed service providers to navigate these challenges. In her session at Big Data Expo®, Hannah Smalltree, Director at Treasure Data, discussed how IoT, Big D...
"SAP had made a big transition into the cloud as we believe it has significant value for our customers, drives innovation and is easy to consume. When you look at the SAP portfolio, SAP HANA is the underlying platform and it powers all of our platforms and all of our analytics," explained Thorsten Leiduck, VP ISVs & Digital Commerce at SAP, in this SYS-CON.tv interview at 15th Cloud Expo, held Nov 4-6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
SAP is delivering break-through innovation combined with fantastic user experience powered by the market-leading in-memory technology, SAP HANA. In his General Session at 15th Cloud Expo, Thorsten Leiduck, VP ISVs & Digital Commerce, SAP, discussed how SAP and partners provide cloud and hybrid cloud solutions as well as real-time Big Data offerings that help companies of all sizes and industries run better. SAP launched an application challenge to award the most innovative SAP HANA and SAP HANA...
DevOps Summit 2015 New York, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that it is now accepting Keynote Proposals. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete...
Explosive growth in connected devices. Enormous amounts of data for collection and analysis. Critical use of data for split-second decision making and actionable information. All three are factors in making the Internet of Things a reality. Yet, any one factor would have an IT organization pondering its infrastructure strategy. How should your organization enhance its IT framework to enable an Internet of Things implementation? In his session at Internet of @ThingsExpo, James Kirkland, Chief Ar...
Comparing cloud providers is complicated. With constant price drops and the frequent introduction of new instance types, no matter what answer you come up with today it is sure to change in three months. Taking into account differences in performance, it gets even more confusing when you realize that applications run differently on different clouds. One thing is certain though: price in a vacuum doesn’t tell you the whole story. In fact, it’s a lot like selecting a car based on sticker price an...
The 4th International DevOps Summit, co-located with16th International Cloud Expo – being held June 9-11, 2015, at the Javits Center in New York City, NY – announces that its Call for Papers is now open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's large...
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is now open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
The security devil is always in the details of the attack: the ones you've endured, the ones you prepare yourself to fend off, and the ones that, you fear, will catch you completely unaware and defenseless. The Internet of Things (IoT) is nothing if not an endless proliferation of details. It's the vision of a world in which continuous Internet connectivity and addressability is embedded into a growing range of human artifacts, into the natural world, and even into our smartphones, appliances, a...
The very name is kind of ridiculous, don’t you think? The word “ephemeral” means it can go away. It’s temporary. Fleeting, even. So why would I want to depend on storing something in a medium that can disappear without warning? And why am I forced to buy more of it when all I want is more CPUs or RAM? Welcome to the paradox of ephemeral storage from cloud computing providers. Ephemeral storage exists only because of how first-generation cloud providers chunk up servers. The business model is ...
The Internet of Things promises to transform businesses (and lives), but navigating the business and technical path to success can be difficult to understand. In his session at @ThingsExpo, Sean Lorenz, Technical Product Manager for Xively at LogMeIn, demonstrated how to approach creating broadly successful connected customer solutions using real world business transformation studies including New England BioLabs and more.
How do APIs and IoT relate? The answer is not as simple as merely adding an API on top of a dumb device, but rather about understanding the architectural patterns for implementing an IoT fabric. There are typically two or three trends: Exposing the device to a management framework Exposing that management framework to a business centric logic Exposing that business layer and data to end users. This last trend is the IoT stack, which involves a new shift in the separation of what stuff happe...
An entirely new security model is needed for the Internet of Things, or is it? Can we save some old and tested controls for this new and different environment? In his session at @ThingsExpo, New York's at the Javits Center, Davi Ottenheimer, EMC Senior Director of Trust, reviewed hands-on lessons with IoT devices and reveal a new risk balance you might not expect. Davi Ottenheimer, EMC Senior Director of Trust, has more than nineteen years' experience managing global security operations and asse...
The definition of IoT is not new, in fact it’s been around for over a decade. What has changed is the public's awareness that the technology we use on a daily basis has caught up on the vision of an always on, always connected world. If you look into the details of what comprises the IoT, you’ll see that it includes everything from cloud computing, Big Data analytics, “Things,” Web communication, applications, network, storage, etc. It is essentially including everything connected online from ha...
The 3rd International @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that it is now accepting Keynote Proposals. The Internet of Things (IoT) is the most profound change in personal and enterprise IT since the creation of the Worldwide Web more than 20 years ago. All major researchers estimate there will be tens of billions devices - computers, smartphones, tablets, and sensors - connected to th...
The Internet of Things will greatly expand the opportunities for data collection and new business models driven off of that data. In her session at @ThingsExpo, Esmeralda Swartz, CMO of MetraTech, discussed how for this to be effective you not only need to have infrastructure and operational models capable of utilizing this new phenomenon, but increasingly service providers will need to convince a skeptical public to participate. Get ready to show them the money!
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is now open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
The Internet of Things is tied together with a thin strand that is known as time. Coincidentally, at the core of nearly all data analytics is a timestamp. When working with time series data there are a few core principles that everyone should consider, especially across datasets where time is the common boundary. In his session at Internet of @ThingsExpo, Jim Scott, Director of Enterprise Strategy & Architecture at MapR Technologies, discussed single-value, geo-spatial, and log time series dat...
SYS-CON Events announced today that Cloudian, Inc., the leading provider of hybrid cloud storage solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Cloudian, Inc., is a Foster City, California - based software company specializing in cloud storage software. The main product is Cloudian, an Amazon S3-compliant cloud object storage platform, the bedrock of cloud computing systems, that enables c...