Welcome Guest. | Log In | Register | Membership Benefits
  • |   Email this page E-mail
  • |  Print Print
  • |   Bookmark and Share

The Dark Side Of The Cloud

Wave of high-profile breaches of cloud-based services during the past few months a reality check for entrusting your data with these providers, according to a new Dark Reading Analytics report

Jun 17, 2011 | 02:06 PM | 

By Kelly Jackson Higgins
Dark Reading
It hasn't been a banner year for cloud-based services: First it was Amazon's outage, and then the breaches of email marketing provider Epsilon, Sony's PlayStation Network, and others, fueling concerns about just how safe it is to move data out of the data center and into the cloud.

Cloud providers aren't quite there yet when it comes to keeping data as secure as traditional enterprise networks do, security experts say, and it pays to look at their DNA: They tend to host an infrastructure that mirrors the source of their computing power, according to Chris Whitener, chief security strategist for Hewlett-Packard. Amazon’s cloud services are based on its experiences providing an available retail experience. A cloud based on a bank’s excess capacity, meanwhile, might have more security built into it, he notes in Dark Reading's newly released Analytics Alert, "Dark Side of the Cloud Becoming Clearer."

And making things worse, cloud services providers and users see security differently, according to a recent survey by the Ponemon Institute and sponsored by CA Technologies: The data indicates that cloud providers are more focused on cost and speed of deployment than on security. Nearly 80 percent of cloud providers allocate just 10 percent or less of IT resources to security or control-related activities. Fewer than half of the service provider respondents agree or strongly agree that security is a priority, and less than 20 percent of U.S. and European providers consider security a competitive advantage.

This doesn't bode well for cloud adoption: "If the risk of breach outweighs potential cost savings and agility, we may reach a point of ‘cloud stall’ -- where cloud adoption slows or stops -- until organizations believe cloud security is as good as or better than enterprise security," said Mike Denning, CA Technologies' general manager, security, in a statement. The majority of cloud providers (69 percent) believe security is primarily the responsibility of the cloud user, according to the report.

What should enterprises do? Rather than focus on contracts and limiting liability in cloud services deals, focus instead on controls and auditability, according to Josh Corman, director of research at The 451 Group. Corman says there's typically not enough due diligence done before signing with a cloud services provider and handing over your data: “It’s like if you had a date tonight, would you let a random stranger watch your kids?” he says. “No. There is a whole bunch of questions you would ask.”

And not all software-as-a-service providers sufficiently encrypt data. According to Russ Dietz, CTO for SafeNet, a maker of secure network and cloud technologies: “We still have a long way to go,” Dietz says. “SaaS providers could deploy [encryption technologies], but it takes time to integrate them into their systems. We are still in the early days.”

So authentication is as important as encryption to protect sensitive information. Meanwhile, compliance is still an enigma in the cloud. Auditors and enterprises alike are trying to sort out what compliance means in diverse and complex cloud environments -- a process that will continue to evolve as organizations figure out what cloud providers should be held accountable for, and how.

The full Dark Reading report is available for download here.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Cloud Security Reports

report Spot Trouble In The Cloud: Adapting Security Monitoring & Incident Response.
Security monitoring, incident response and forensics are essential, even in the cloud. But the cloud by definition implies relinquishing at least some control, which can make these practices problematic. In this report, we identify the challenges of detecting and responding to security issues in the cloud and discuss the most effective ways to address them.

report Dark Side of the Cloud Becoming Clearer
Recent high-profile breaches against cloud-based services have forced tougher security and closer scrutiny of what to put in the cloud.

report Cloud Security: Understand the Risks Before You Make the Move
Security concerns give many companies pause as they consider migrating portions of their IT operations to cloud-based services. But you can stay safe in the cloud. In this Dark Reading Tech Center report, we explain the risks and guide you in setting appropriate cloud security policies, processes and controls. Plus: How to catch up when security is an afterthought to a cloud migration.

Related Content

The State of Cloud-based Security
Taking a cloud approach to security can improve protection and lower costs. Download this exclusive UBM TechWeb research to explore why cloud-based security may be more effective in today's complex threat environment.

Turning Security Upside-Down
Organizations can no longer rest on their laurels when it comes to IT security. It is time the security industry took a different approach.

Security as a Service: Business Decision Factors
Better understand the business issues in SaaS: the value it unlocks, the costs-direct and indirect-it avoids, and the corollary benefits like efficiency and agility it supports.

How to Protect Your Business from the Coming Malware Storm
The malware storm will force the cost and complexity of premise-based protection to unsustainable levels. To survive, small and midsize businesses must move defenses outside their own walls.