Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

Study: Security Fears Continue To Block Cloud Deployment

'Fear of the unknown' still haunts cloud adoption.

LAS VEGAS – Interop Spring 2014 – Concerns about security and governance are still the chief hurdles in deploying cloud technology, particularly when it comes to mission-critical applications, according to a study published this week.

The survey of more than 350 senior IT, which was conducted earlier this year by Unisys and IDG Research, reports that more than 70 percent of respondents feel that security is the chief obstacle in cloud deployment. Concerns about information governance (45 percent) and the ability to meet enterprise standards (42 percent) also ranked as top challenges.

"A lot of what slows cloud deployment is fear of the unknown," says John Kunzier, global director of portfolio marketing at Unisys and one of the authors of the study. "IT executives are not sure how they can trust what the cloud providers are telling them, and how they can collect the data they need about the security of the data that’s in the cloud."

The potential for cost savings and improved efficiency are pushing most companies to try out cloud technology, according to the study. More than half of enterprises with more than 1,000 employees have at least one application or a portion of their organization’s infrastructure in the cloud. About 26 percent of respondents’ enterprise information currently resides in a private cloud environment, and that percentage will grow to about 32 percent in the next 18 months, the study says.

But in many cases, those early deployments are non-critical applications where security is less of a concern, notes Dave Frymier, CISO at Unisys. "At Unisys, we’re certainly experimenting with cloud technology, but mostly for non-mission-critical applications," he says. "I think a lot of [CISOs] feel that way -- they want to test it out."

Fifty-three percent of senior-level IT leaders at 1,000-plus employee organizations said they expect to increase spending on software-as-a-service and cloud-based applications over the next 12 months, the survey says. Forty-four percent of the respondents said they were actively researching or piloting new cloud or SaaS applications.

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
jagibbons
100%
0%
jagibbons,
User Rank: Strategist
4/3/2014 | 12:25:19 PM
Re: Powerful motivator
From my experienc, existing CapEx investments will push folk to the cloud when those assets are a) fully depreciated and b) needing to be relaced/refreshed. If they are still in production use, relativly new and still being paid for, that ends up being more of a deterent to cloud adoption.
IMjustinkern
50%
50%
IMjustinkern,
User Rank: Strategist
4/3/2014 | 11:03:47 AM
Re: Powerful motivator
jagibbons ... definitely agree on the FUD front. Curious: do you think the existence of those CapEx investments will actually push people toward the cloud? Could see that as the greatest motivator of all, especially when the big bosses are parsing budgets. 
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 10:43:54 AM
Re: Powerful motivator
Very true, cautiousness is ususally the best. Parallyzed fear will prevent you from making informed decisions also.
jagibbons
50%
50%
jagibbons,
User Rank: Strategist
4/3/2014 | 10:37:41 AM
Re: Powerful motivator
Cautious and measured is good. Paralyzed by fear, not so much.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 10:35:38 AM
Re: Powerful motivator
To your point, "FUD" (good one by the way) is slowing down cloud technologies but it may be for good reason but only time will tell. Cloud computing and storage is too new to chance having all of your data stolen. Will all of the news concerning target and others it makes executives be overly cautious. 
jagibbons
100%
0%
jagibbons,
User Rank: Strategist
4/3/2014 | 9:11:43 AM
Powerful motivator
FUD (fear, uncertainty and doubt) is a very strong motivator or demotivator. This is magnified in this post-recessionary period where we are still struggling to improve financial conditions. When you add the fact that many have significant CapEx investments still sitting around, it can be very difficult to make a major move like this.
<<   <   Page 2 / 2
COVID-19: Latest Security News & Commentary
Dark Reading Staff 11/19/2020
New Proposed DNS Security Features Released
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/19/2020
How to Identify Cobalt Strike on Your Network
Zohar Buber, Security Analyst,  11/18/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: A GONG is as good as a cyber attack.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25660
PUBLISHED: 2020-11-23
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph...
CVE-2020-25688
PUBLISHED: 2020-11-23
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a...
CVE-2020-25696
PUBLISHED: 2020-11-23
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating sy...
CVE-2020-26229
PUBLISHED: 2020-11-23
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical - it was not possible to actually reproduce the vulnerability...
CVE-2020-28984
PUBLISHED: 2020-11-23
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.