Welcome!

@BigDataExpo Authors: Liz McMillan, Jeev Trika, Jayaram Krishnaswamy, Elizabeth White, Pat Romanski

Related Topics: @CloudExpo, Java IoT, Microservices Expo, Containers Expo Blog, Cloud Security, @BigDataExpo

@CloudExpo: Article

It’s Money That Matters in the Cloud… Well, At Least ROI

Cloud security closes the risk versus reward gap

With all the talk of fiscal cliffs sequestrations, financial binds and “next year’s budget,” I started thinking about cloud security in more tangible ways. Specifically returns on investment, economic impact and total costs of ownership. Just like death and taxes, businesses can add intrusion and attack to the list of sureties. I can hear CFOs all over the world sigh in exasperation as they feel pressured to add another expense line item to minimize the building security threats to their enterprises.

Before you add another decimal place to security budgets, maybe it’s time you consider the how cloud-deployed security options can not only address the complexities of enterprise security ably, but do so at considerable savings.

Study after study promotes that a cloud computing model saves organization money. We know that more and more functionality is moving to the cloud. For things like CRM or other standard business applications, it simply makes sense. We recognize the limited time and funding to run and maintain enterprise applications and the cloud provides that great equalizer. This model extends itself to cloud security and security-as-a-service.

First there are the over-arching savings of cloud-computing in general:

  • Elimination of CapEx costs: no hardware or software to buy (Any “cloud” company that asks you to install a server on your premises to monitor your enterprise isn’t cloud)
  • Pay-as-you-go scalable: Most cloud providers can offer considerable cost savings through economies of scale. The ability to adjust the level of service necessary (elastic provisioning) creates flexibility for increased margins and cost-controls.
  • Zero-day start/On demand delivery of service: no waiting time after the service has been purchased to develop and configure a complex system. This means no development hell or waiting for Phase 2 to be complete in order to start reaping benefits.
  • Head count savings: included in most cloud services are the personnel costs (salary, benefits, overhead, churn/hiring costs) a company does not need to invest in more people and gains the benefit of the security expertise and tribal knowledge of the cloud security provider.
  • Best-of breed resource/expertise expansion: Companies improve their overall business agility through proven technologies supported and updated by the core competencies of the developers. Meanwhile CIOs get to move more IT budget to innovation or enablement programs.

But where are the benefits of cloud security from an ROI perspective:

  • 24/7 Availability: Cloud security is about continuous monitoring.  To properly secure the expanding footprint of an enterprise’s IT landscape, there must be the vigilance to catch analyze and remediate issues as quickly as possible. Like a cancer, if security issues go undetected, they can metastasize and spread. Having a professional monitor a network 7/24/365 (in real time) seems like a luxury for Fortune 500 companies. Cloud security makes this option available for the most modest organizations. The holes in security that are created through intermittent monitoring, vague automation settings and periodic machine log reviews will cost an organization.  But continuous monitoring isn’t a cost center. Preventive and proactive security creates reduced risk (without additional man hours) which allows for redeployed resources and a realignment based of business needs.
  • Unification: The agility from the cloud allows companies to leverage the capabilities of various security solutions looking at multiple parts of the enterprise. This includes intrusion detection, credentialing, access, SSO, web authentication and compliance audits. It not only allows an enterprise to acquire more and greater functionality for virtually the same cost, but it also centralizes the collective intelligence and provides the advantage enhanced visibility through correlated and situational context. This, in turn, creates better and faster decisions which streamline resources and save money.
  • Improved productivity Although there are many examples of this within cloud based security, I will point to one (and use future blogs to expound on others). Using identity management, companies can automatically provision and deprovision users. This service alone can save 75% of the requests across the enterprise. Imagine the additional savings when IT is not slogged down with forgotten password requests/resets along with managing credentials. There are studies that prove that this alone saves companies nearly $200K per year. Now with better employee productivity (because this helps solve BYOD issues) and certain portions of your network safe from data theft and leakage, IT can concentrate on business issues that drive revenue.
  • Compliance: Dozens of man hours are typically needed each month to complete all the reports needed to satisfy a regulatory agency auditor; and for most companies, it’s not just one agency, but several. Through real time correlation, most of the work of identifying, capturing, encrypting and storing(or destroying) certain pieces of information and providing the proof  your best practices are in line with internal and external policies is easier. Because of unification, multi-silo collection and security centralization, 75 hours per month becomes 10. And more importantly, the degree of accuracy of the reporting is significantly better.  And with better reports, the threat of fines disappears.

Gartner estimates the annual cost to own and manage traditional on premise security software applications can be 4X the initial purchase. This is chiefly due to the need to acquire and maintain the resources to support the deployment. In many cases, for less than what a company pays for in support and maintenance of these on premise initiatives, they could have twice the capability from the cloud.

When it’s money that matters, the bottom line should be as much about saving as it is spending; as long as the result is a positive return on the investment. Enterprise security is not different. For years seen as a cost center, through cloud-based solutions it can now be redefined as a revenue enablement mechanism. Certainly there are costs involved in a maintaining a safe network perimeter, protecting and securing data and compliance auditing. However, by exploiting the benefits and strengths provided by cloud based security, you can prudently and effectively contain the issues with plentiful resources to reinvest in your core competencies and focus on driving business forward. Security issues will not go away, but you can direct less at them and in return, receive more greater results.

When looking at the cloud in term of security…sometimes you can have your cake and eat it too.

 

Kevin Nikkhoo
www.cloudaccess.com

More Stories By Kevin Nikkhoo

With more than 32 years of experience in information technology, and an extensive and successful entrepreneurial background, Kevin Nikkhoo is the CEO of the dynamic security-as-a-service startup Cloud Access. CloudAccess is at the forefront of the latest evolution of IT asset protection--the cloud.

Kevin holds a Bachelor of Science in Computer Engineering from McGill University, Master of Computer Engineering at California State University, Los Angeles, and an MBA from the University of Southern California with emphasis in entrepreneurial studies.

@BigDataExpo Stories
The vision of a connected smart home is becoming reality with the application of integrated wireless technologies in devices and appliances. The use of standardized and TCP/IP networked wireless technologies in line-powered and battery operated sensors and controls has led to the adoption of radios in the 2.4GHz band, including Wi-Fi, BT/BLE and 802.15.4 applied ZigBee and Thread. This is driving the need for robust wireless coexistence for multiple radios to ensure throughput performance and th...
SYS-CON Events announced today that Commvault, a global leader in enterprise data protection and information management, has been named “Bronze Sponsor” of SYS-CON's 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Commvault is a leading provider of data protection and information management solutions, helping companies worldwide activate their data to drive more value and business insight and to transform moder...
If you’re responsible for an application that depends on the data or functionality of various IoT endpoints – either sensors or devices – your brand reputation depends on the security, reliability, and compliance of its many integrated parts. If your application fails to deliver the expected business results, your customers and partners won't care if that failure stems from the code you developed or from a component that you integrated. What can you do to ensure that the endpoints work as expect...
An IoT product’s log files speak volumes about what’s happening with your products in the field, pinpointing current and potential issues, and enabling you to predict failures and save millions of dollars in inventory. But until recently, no one knew how to listen. In his session at @ThingsExpo, Dan Gettens, Chief Research Officer at OnProcess, will discuss recent research by Massachusetts Institute of Technology and OnProcess Technology, where MIT created a new, breakthrough analytics model f...
SYS-CON Events announced today that Bsquare has been named “Silver Sponsor” of SYS-CON's @ThingsExpo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. For more than two decades, Bsquare has helped its customers extract business value from a broad array of physical assets by making them intelligent, connecting them, and using the data they generate to optimize business processes.
Technology vendors and analysts are eager to paint a rosy picture of how wonderful IoT is and why your deployment will be great with the use of their products and services. While it is easy to showcase successful IoT solutions, identifying IoT systems that missed the mark or failed can often provide more in the way of key lessons learned. In his session at @ThingsExpo, Peter Vanderminden, Principal Industry Analyst for IoT & Digital Supply Chain to Flatiron Strategies, will focus on how IoT de...
Most of us already know that adopting new cloud applications can boost a business’s productivity by enabling organizations to be more agile and ready to change course in our fast-moving and connected digital world. But the rapid adoption of cloud apps and services also brings with it profound security threats, including visibility and control challenges that aren’t present in traditional on-premises environments. At the same time, the cloud – because of its interconnected, flexible and adaptable...
Digital transformation is too big and important for our future success to not understand the rules that apply to it. The first three rules for winning in this age of hyper-digital transformation are: Advantages in speed, analytics and operational tempos must be captured by implementing an optimized information logistics system (OILS) Real-time operational tempos (IT, people and business processes) must be achieved Businesses that can "analyze data and act and with speed" will dominate those t...
Information technology is an industry that has always experienced change, and the dramatic change sweeping across the industry today could not be truthfully described as the first time we've seen such widespread change impacting customer investments. However, the rate of the change, and the potential outcomes from today's digital transformation has the distinct potential to separate the industry into two camps: Organizations that see the change coming, embrace it, and successful leverage it; and...
There is growing need for data-driven applications and the need for digital platforms to build these apps. In his session at 19th Cloud Expo, Muddu Sudhakar, VP and GM of Security & IoT at Splunk, will cover different PaaS solutions and Big Data platforms that are available to build applications. In addition, AI and machine learning are creating new requirements that developers need in the building of next-gen apps. The next-generation digital platforms have some of the past platform needs a...
Without a clear strategy for cost control and an architecture designed with cloud services in mind, costs and operational performance can quickly get out of control. To avoid multiple architectural redesigns requires extensive thought and planning. Boundary (now part of BMC) launched a new public-facing multi-tenant high resolution monitoring service on Amazon AWS two years ago, facing challenges and learning best practices in the early days of the new service. In his session at 19th Cloud Exp...
SYS-CON Events announced today that Secure Channels will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. The bedrock of Secure Channels Technology is a uniquely modified and enhanced process based on superencipherment. Superencipherment is the process of encrypting an already encrypted message one or more times, either using the same or a different algorithm.
Almost two-thirds of companies either have or soon will have IoT as the backbone of their business in 2016. However, IoT is far more complex than most firms expected. How can you not get trapped in the pitfalls? In his session at @ThingsExpo, Tony Shan, a renowned visionary and thought leader, will introduce a holistic method of IoTification, which is the process of IoTifying the existing technology and business models to adopt and leverage IoT. He will drill down to the components in this fra...
I'm a lonely sensor. I spend all day telling the world how I'm feeling, but none of the other sensors seem to care. I want to be connected. I want to build relationships with other sensors to be more useful for my human. I want my human to understand that when my friends next door are too hot for a while, I'll soon be flaming. And when all my friends go outside without me, I may be left behind. Don't just log my data; use the relationship graph. In his session at @ThingsExpo, Ryan Boyd, Engi...
SYS-CON Events announced today that Pulzze Systems will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Pulzze Systems, Inc. provides infrastructure products for the Internet of Things to enable any connected device and system to carry out matched operations without programming. For more information, visit http://www.pulzzesystems.com.
DevOps at Cloud Expo – being held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real results. Am...
The Internet of Things can drive efficiency for airlines and airports. In their session at @ThingsExpo, Shyam Varan Nath, Principal Architect with GE, and Sudip Majumder, senior director of development at Oracle, will discuss the technical details of the connected airline baggage and related social media solutions. These IoT applications will enhance travelers' journey experience and drive efficiency for the airlines and the airports. The session will include a working demo and a technical d...
The Transparent Cloud-computing Consortium (abbreviation: T-Cloud Consortium) will conduct research activities into changes in the computing model as a result of collaboration between "device" and "cloud" and the creation of new value and markets through organic data processing High speed and high quality networks, and dramatic improvements in computer processing capabilities, have greatly changed the nature of applications and made the storing and processing of data on the network commonplace.
Traditional on-premises data centers have long been the domain of modern data platforms like Apache Hadoop, meaning companies who build their business on public cloud were challenged to run Big Data processing and analytics at scale. But recent advancements in Hadoop performance, security, and most importantly cloud-native integrations, are giving organizations the ability to truly gain value from all their data. In his session at 19th Cloud Expo, David Tishgart, Director of Product Marketing ...
Enterprise IT has been in the era of Hybrid Cloud for some time now. But it seems most conversations about Hybrid are focused on integrating AWS, Microsoft Azure, or Google ECM into existing on-premises systems. Where is all the Private Cloud? What do technology providers need to do to make their offerings more compelling? How should enterprise IT executives and buyers define their focus, needs, and roadmap, and communicate that clearly to the providers?