Cloud
4/3/2014
08:10 AM
Tim Wilson
Tim Wilson
Quick Hits
Connect Directly
RSS
E-Mail
50%
50%

Study: Security Fears Continue To Block Cloud Deployment

'Fear of the unknown' still haunts cloud adoption.

LAS VEGAS – Interop Spring 2014 – Concerns about security and governance are still the chief hurdles in deploying cloud technology, particularly when it comes to mission-critical applications, according to a study published this week.

The survey of more than 350 senior IT, which was conducted earlier this year by Unisys and IDG Research, reports that more than 70 percent of respondents feel that security is the chief obstacle in cloud deployment. Concerns about information governance (45 percent) and the ability to meet enterprise standards (42 percent) also ranked as top challenges.

"A lot of what slows cloud deployment is fear of the unknown," says John Kunzier, global director of portfolio marketing at Unisys and one of the authors of the study. "IT executives are not sure how they can trust what the cloud providers are telling them, and how they can collect the data they need about the security of the data that’s in the cloud."

The potential for cost savings and improved efficiency are pushing most companies to try out cloud technology, according to the study. More than half of enterprises with more than 1,000 employees have at least one application or a portion of their organization’s infrastructure in the cloud. About 26 percent of respondents’ enterprise information currently resides in a private cloud environment, and that percentage will grow to about 32 percent in the next 18 months, the study says.

But in many cases, those early deployments are non-critical applications where security is less of a concern, notes Dave Frymier, CISO at Unisys. "At Unisys, we’re certainly experimenting with cloud technology, but mostly for non-mission-critical applications," he says. "I think a lot of [CISOs] feel that way -- they want to test it out."

Fifty-three percent of senior-level IT leaders at 1,000-plus employee organizations said they expect to increase spending on software-as-a-service and cloud-based applications over the next 12 months, the survey says. Forty-four percent of the respondents said they were actively researching or piloting new cloud or SaaS applications.

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
kobrien82
50%
50%
kobrien82,
User Rank: Apprentice
4/11/2014 | 5:34:40 PM
Security should enable, not disable, cloud adoption
Fear shouldn't be an end point in the decision. It's healthy to consider what works and what does not when considering the cloud, and to look to the data to see where and how organizations get themselves into trouble, but it should be part of a general business calcuation that includes the benefits of going to the cloud and thinking through what the risks are. 

Most data breaches and data loss from public cloud platforms are the result of inadvertent user action. That informs a certain approach to discovery, clasification, and control; there are well-known ways to create DLP policies that minimize the accidental breach risk, for example. Tom Scholtz over at Gartner has a really interesting take on the concept of people-centric security and how companies are using it to do this kind of work in a cloud-friendly way: http://my.gartner.com/portal/server.pt?open=512&objID=202&mode=2&PageID=5553&ref=webinar-rss&resId=2546716&srcId=1-2949089475
Stratustician
50%
50%
Stratustician,
User Rank: Strategist
4/10/2014 | 12:11:56 PM
Re: Powerful motivator
I think one of the biggest hurdles is that current IT teams are often based on folks with backgrounds in traditional security (not surprising) which is perimeter based.  Virtualization and cloud are totally different beasts as you take out the physical perimeter and all of a sudden you have this big mass of resources that may or may not even be on site.  This means visibility is been compromised from a security perspective, and honestly, I am sure that scares a lot of IT folks. It's a long way from the old mentality that virtualization security wasn't much of a risk as it was seen as "hacking into a shoebox" with no real threats. Now we are faced with availability, security and integrity concerns and no skillsets to back it up.  It really comes to down to ensuring these security folks have access to the right resources so they are fully aware of all the issues they are dealing with.
Stratustician
50%
50%
Stratustician,
User Rank: Strategist
4/10/2014 | 12:11:52 PM
Re: Powerful motivator
I think one of the biggest hurdles is that current IT teams are often based on folks with backgrounds in traditional security (not surprising) which is perimeter based.  Virtualization and cloud are totally different beasts as you take out the physical perimeter and all of a sudden you have this big mass of resources that may or may not even be on site.  This means visibility is been compromised from a security perspective, and honestly, I am sure that scares a lot of IT folks. It's a long way from the old mentality that virtualization security wasn't much of a risk as it was seen as "hacking into a shoebox" with no real threats. Now we are faced with availability, security and integrity concerns and no skillsets to back it up.  It really comes to down to ensuring these security folks have access to the right resources so they are fully aware of all the issues they are dealing with.
DarkReadingTim
50%
50%
DarkReadingTim,
User Rank: Strategist
4/4/2014 | 8:28:34 AM
Re: Powerful motivator
It was interesting speaking with Unisys' CISO for this story -- even though Unisys has technology that provides visibility and additional security for the cloud, they are still largely limiting their cloud deployments to non-critical apps so far. I think we will see a lot of companies testing out the cloud on their least important, most commodity apps for a long time before we start to see implementations that involve the crown jewels.
macker490
50%
50%
macker490,
User Rank: Ninja
4/4/2014 | 8:20:32 AM
Hardly Surprising
the computer industry hardly has a stelar reputation for security,--- breach after breach after breach with every sort of patch, fix, and snake-oil and the situation continues to get worse

and still nobody wants to pull up the carpet and deal with the underlying issue: insecure operating software.
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
4/3/2014 | 6:10:35 PM
Re: Powerful motivator
Security and privacy are primary obstacles for the diffusion of the popular paradigms. Recent events related to Datagate have seriously compromised the trust in the cloud computing and drastically reduced growth projections.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/3/2014 | 4:55:12 PM
Re: Powerful motivator -- on the other hand....
Comfort level along with some effective security strategies. RAVI ITHAL Chief Architect at Netskope had some interesting thoughts about that in his blog today API-First: 3 Steps For Building Secure Cloud Apps
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 3:31:02 PM
Re: Powerful motivator -- on the other hand....
I think it will just take some time and testing to see how the cloud turns out. Datacenters are protected and controlled but you must rely on others to secure your data in the cloud. There has to be a comfort level with the cloud and only time will tell when that will be.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/3/2014 | 3:25:25 PM
Re: Powerful motivator -- on the other hand....
What would the cloud service provider industry need to do to overcume the FUD and reassure customers? It sounds like -- from this thread -- that its more than just a financial concern.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 2:56:05 PM
Re: Powerful motivator
I think you have a valid point, new technologies will all be adopted at a much slower pace than before.
Page 1 / 2   >   >>
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-1032
Published: 2014-09-17
Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party inf...

CVE-2012-1417
Published: 2014-09-17
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.

CVE-2012-1506
Published: 2014-09-17
SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from th...

CVE-2012-1507
Published: 2014-09-17
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to templates/hrfunct/emppop.php, or (3) uri parameter to index...

CVE-2012-2583
Published: 2014-09-17
Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.

Best of the Web
Dark Reading Radio