Cloud
4/3/2014
08:10 AM
Tim Wilson
Tim Wilson
Quick Hits
Connect Directly
RSS
E-Mail
50%
50%

Study: Security Fears Continue To Block Cloud Deployment

'Fear of the unknown' still haunts cloud adoption.

LAS VEGAS – Interop Spring 2014 – Concerns about security and governance are still the chief hurdles in deploying cloud technology, particularly when it comes to mission-critical applications, according to a study published this week.

The survey of more than 350 senior IT, which was conducted earlier this year by Unisys and IDG Research, reports that more than 70 percent of respondents feel that security is the chief obstacle in cloud deployment. Concerns about information governance (45 percent) and the ability to meet enterprise standards (42 percent) also ranked as top challenges.

"A lot of what slows cloud deployment is fear of the unknown," says John Kunzier, global director of portfolio marketing at Unisys and one of the authors of the study. "IT executives are not sure how they can trust what the cloud providers are telling them, and how they can collect the data they need about the security of the data that’s in the cloud."

The potential for cost savings and improved efficiency are pushing most companies to try out cloud technology, according to the study. More than half of enterprises with more than 1,000 employees have at least one application or a portion of their organization’s infrastructure in the cloud. About 26 percent of respondents’ enterprise information currently resides in a private cloud environment, and that percentage will grow to about 32 percent in the next 18 months, the study says.

But in many cases, those early deployments are non-critical applications where security is less of a concern, notes Dave Frymier, CISO at Unisys. "At Unisys, we’re certainly experimenting with cloud technology, but mostly for non-mission-critical applications," he says. "I think a lot of [CISOs] feel that way -- they want to test it out."

Fifty-three percent of senior-level IT leaders at 1,000-plus employee organizations said they expect to increase spending on software-as-a-service and cloud-based applications over the next 12 months, the survey says. Forty-four percent of the respondents said they were actively researching or piloting new cloud or SaaS applications.

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
kobriencl
50%
50%
kobriencl,
User Rank: Apprentice
4/11/2014 | 5:34:40 PM
Security should enable, not disable, cloud adoption
Fear shouldn't be an end point in the decision. It's healthy to consider what works and what does not when considering the cloud, and to look to the data to see where and how organizations get themselves into trouble, but it should be part of a general business calcuation that includes the benefits of going to the cloud and thinking through what the risks are. 

Most data breaches and data loss from public cloud platforms are the result of inadvertent user action. That informs a certain approach to discovery, clasification, and control; there are well-known ways to create DLP policies that minimize the accidental breach risk, for example. Tom Scholtz over at Gartner has a really interesting take on the concept of people-centric security and how companies are using it to do this kind of work in a cloud-friendly way: http://my.gartner.com/portal/server.pt?open=512&objID=202&mode=2&PageID=5553&ref=webinar-rss&resId=2546716&srcId=1-2949089475
Stratustician
50%
50%
Stratustician,
User Rank: Apprentice
4/10/2014 | 12:11:56 PM
Re: Powerful motivator
I think one of the biggest hurdles is that current IT teams are often based on folks with backgrounds in traditional security (not surprising) which is perimeter based.  Virtualization and cloud are totally different beasts as you take out the physical perimeter and all of a sudden you have this big mass of resources that may or may not even be on site.  This means visibility is been compromised from a security perspective, and honestly, I am sure that scares a lot of IT folks. It's a long way from the old mentality that virtualization security wasn't much of a risk as it was seen as "hacking into a shoebox" with no real threats. Now we are faced with availability, security and integrity concerns and no skillsets to back it up.  It really comes to down to ensuring these security folks have access to the right resources so they are fully aware of all the issues they are dealing with.
Stratustician
50%
50%
Stratustician,
User Rank: Apprentice
4/10/2014 | 12:11:52 PM
Re: Powerful motivator
I think one of the biggest hurdles is that current IT teams are often based on folks with backgrounds in traditional security (not surprising) which is perimeter based.  Virtualization and cloud are totally different beasts as you take out the physical perimeter and all of a sudden you have this big mass of resources that may or may not even be on site.  This means visibility is been compromised from a security perspective, and honestly, I am sure that scares a lot of IT folks. It's a long way from the old mentality that virtualization security wasn't much of a risk as it was seen as "hacking into a shoebox" with no real threats. Now we are faced with availability, security and integrity concerns and no skillsets to back it up.  It really comes to down to ensuring these security folks have access to the right resources so they are fully aware of all the issues they are dealing with.
DarkReadingTim
50%
50%
DarkReadingTim,
User Rank: Strategist
4/4/2014 | 8:28:34 AM
Re: Powerful motivator
It was interesting speaking with Unisys' CISO for this story -- even though Unisys has technology that provides visibility and additional security for the cloud, they are still largely limiting their cloud deployments to non-critical apps so far. I think we will see a lot of companies testing out the cloud on their least important, most commodity apps for a long time before we start to see implementations that involve the crown jewels.
macker490
50%
50%
macker490,
User Rank: Ninja
4/4/2014 | 8:20:32 AM
Hardly Surprising
the computer industry hardly has a stelar reputation for security,--- breach after breach after breach with every sort of patch, fix, and snake-oil and the situation continues to get worse

and still nobody wants to pull up the carpet and deal with the underlying issue: insecure operating software.
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
4/3/2014 | 6:10:35 PM
Re: Powerful motivator
Security and privacy are primary obstacles for the diffusion of the popular paradigms. Recent events related to Datagate have seriously compromised the trust in the cloud computing and drastically reduced growth projections.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/3/2014 | 4:55:12 PM
Re: Powerful motivator -- on the other hand....
Comfort level along with some effective security strategies. RAVI ITHAL Chief Architect at Netskope had some interesting thoughts about that in his blog today API-First: 3 Steps For Building Secure Cloud Apps
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 3:31:02 PM
Re: Powerful motivator -- on the other hand....
I think it will just take some time and testing to see how the cloud turns out. Datacenters are protected and controlled but you must rely on others to secure your data in the cloud. There has to be a comfort level with the cloud and only time will tell when that will be.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/3/2014 | 3:25:25 PM
Re: Powerful motivator -- on the other hand....
What would the cloud service provider industry need to do to overcume the FUD and reassure customers? It sounds like -- from this thread -- that its more than just a financial concern.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 2:56:05 PM
Re: Powerful motivator
I think you have a valid point, new technologies will all be adopted at a much slower pace than before.
Page 1 / 2   >   >>
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4734
Published: 2014-07-21
Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

CVE-2014-4960
Published: 2014-07-21
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

CVE-2014-5016
Published: 2014-07-21
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to appl...

CVE-2014-5017
Published: 2014-07-21
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter...

CVE-2014-5018
Published: 2014-07-21
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Where do information security startups come from? More important, how can I tell a good one from a flash in the pan? Learn how to separate ITSec wheat from chaff in this episode.