Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

Study: Security Fears Continue To Block Cloud Deployment

'Fear of the unknown' still haunts cloud adoption.

LAS VEGAS – Interop Spring 2014 – Concerns about security and governance are still the chief hurdles in deploying cloud technology, particularly when it comes to mission-critical applications, according to a study published this week.

The survey of more than 350 senior IT, which was conducted earlier this year by Unisys and IDG Research, reports that more than 70 percent of respondents feel that security is the chief obstacle in cloud deployment. Concerns about information governance (45 percent) and the ability to meet enterprise standards (42 percent) also ranked as top challenges.

"A lot of what slows cloud deployment is fear of the unknown," says John Kunzier, global director of portfolio marketing at Unisys and one of the authors of the study. "IT executives are not sure how they can trust what the cloud providers are telling them, and how they can collect the data they need about the security of the data that’s in the cloud."

The potential for cost savings and improved efficiency are pushing most companies to try out cloud technology, according to the study. More than half of enterprises with more than 1,000 employees have at least one application or a portion of their organization’s infrastructure in the cloud. About 26 percent of respondents’ enterprise information currently resides in a private cloud environment, and that percentage will grow to about 32 percent in the next 18 months, the study says.

But in many cases, those early deployments are non-critical applications where security is less of a concern, notes Dave Frymier, CISO at Unisys. "At Unisys, we’re certainly experimenting with cloud technology, but mostly for non-mission-critical applications," he says. "I think a lot of [CISOs] feel that way -- they want to test it out."

Fifty-three percent of senior-level IT leaders at 1,000-plus employee organizations said they expect to increase spending on software-as-a-service and cloud-based applications over the next 12 months, the survey says. Forty-four percent of the respondents said they were actively researching or piloting new cloud or SaaS applications.

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Page 1 / 2   >   >>
jagibbons
100%
0%
jagibbons,
User Rank: Strategist
4/3/2014 | 9:11:43 AM
Powerful motivator
FUD (fear, uncertainty and doubt) is a very strong motivator or demotivator. This is magnified in this post-recessionary period where we are still struggling to improve financial conditions. When you add the fact that many have significant CapEx investments still sitting around, it can be very difficult to make a major move like this.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 10:35:38 AM
Re: Powerful motivator
To your point, "FUD" (good one by the way) is slowing down cloud technologies but it may be for good reason but only time will tell. Cloud computing and storage is too new to chance having all of your data stolen. Will all of the news concerning target and others it makes executives be overly cautious. 
jagibbons
50%
50%
jagibbons,
User Rank: Strategist
4/3/2014 | 10:37:41 AM
Re: Powerful motivator
Cautious and measured is good. Paralyzed by fear, not so much.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 10:43:54 AM
Re: Powerful motivator
Very true, cautiousness is ususally the best. Parallyzed fear will prevent you from making informed decisions also.
IMjustinkern
50%
50%
IMjustinkern,
User Rank: Strategist
4/3/2014 | 11:03:47 AM
Re: Powerful motivator
jagibbons ... definitely agree on the FUD front. Curious: do you think the existence of those CapEx investments will actually push people toward the cloud? Could see that as the greatest motivator of all, especially when the big bosses are parsing budgets. 
jagibbons
100%
0%
jagibbons,
User Rank: Strategist
4/3/2014 | 12:25:19 PM
Re: Powerful motivator
From my experienc, existing CapEx investments will push folk to the cloud when those assets are a) fully depreciated and b) needing to be relaced/refreshed. If they are still in production use, relativly new and still being paid for, that ends up being more of a deterent to cloud adoption.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 2:56:05 PM
Re: Powerful motivator
I think you have a valid point, new technologies will all be adopted at a much slower pace than before.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/3/2014 | 3:25:25 PM
Re: Powerful motivator -- on the other hand....
What would the cloud service provider industry need to do to overcume the FUD and reassure customers? It sounds like -- from this thread -- that its more than just a financial concern.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 3:31:02 PM
Re: Powerful motivator -- on the other hand....
I think it will just take some time and testing to see how the cloud turns out. Datacenters are protected and controlled but you must rely on others to secure your data in the cloud. There has to be a comfort level with the cloud and only time will tell when that will be.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/3/2014 | 4:55:12 PM
Re: Powerful motivator -- on the other hand....
Comfort level along with some effective security strategies. RAVI ITHAL Chief Architect at Netskope had some interesting thoughts about that in his blog today API-First: 3 Steps For Building Secure Cloud Apps
Page 1 / 2   >   >>
Commentary
What the FedEx Logo Taught Me About Cybersecurity
Matt Shea, Head of Federal @ MixMode,  6/4/2021
Edge-DRsplash-10-edge-articles
A View From Inside a Deception
Sara Peters, Senior Editor at Dark Reading,  6/2/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23394
PUBLISHED: 2021-06-13
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
CVE-2021-34682
PUBLISHED: 2021-06-12
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.
CVE-2021-31811
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-31812
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-32552
PUBLISHED: 2021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.