Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Study: Security Fears Continue To Block Cloud Deployment
Threaded  |  Newest First  |  Oldest First
jagibbons
100%
0%
jagibbons,
User Rank: Strategist
4/3/2014 | 9:11:43 AM
Powerful motivator
FUD (fear, uncertainty and doubt) is a very strong motivator or demotivator. This is magnified in this post-recessionary period where we are still struggling to improve financial conditions. When you add the fact that many have significant CapEx investments still sitting around, it can be very difficult to make a major move like this.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 10:35:38 AM
Re: Powerful motivator
To your point, "FUD" (good one by the way) is slowing down cloud technologies but it may be for good reason but only time will tell. Cloud computing and storage is too new to chance having all of your data stolen. Will all of the news concerning target and others it makes executives be overly cautious. 
jagibbons
50%
50%
jagibbons,
User Rank: Strategist
4/3/2014 | 10:37:41 AM
Re: Powerful motivator
Cautious and measured is good. Paralyzed by fear, not so much.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 10:43:54 AM
Re: Powerful motivator
Very true, cautiousness is ususally the best. Parallyzed fear will prevent you from making informed decisions also.
DarkReadingTim
50%
50%
DarkReadingTim,
User Rank: Strategist
4/4/2014 | 8:28:34 AM
Re: Powerful motivator
It was interesting speaking with Unisys' CISO for this story -- even though Unisys has technology that provides visibility and additional security for the cloud, they are still largely limiting their cloud deployments to non-critical apps so far. I think we will see a lot of companies testing out the cloud on their least important, most commodity apps for a long time before we start to see implementations that involve the crown jewels.
Stratustician
50%
50%
Stratustician,
User Rank: Moderator
4/10/2014 | 12:11:52 PM
Re: Powerful motivator
I think one of the biggest hurdles is that current IT teams are often based on folks with backgrounds in traditional security (not surprising) which is perimeter based.  Virtualization and cloud are totally different beasts as you take out the physical perimeter and all of a sudden you have this big mass of resources that may or may not even be on site.  This means visibility is been compromised from a security perspective, and honestly, I am sure that scares a lot of IT folks. It's a long way from the old mentality that virtualization security wasn't much of a risk as it was seen as "hacking into a shoebox" with no real threats. Now we are faced with availability, security and integrity concerns and no skillsets to back it up.  It really comes to down to ensuring these security folks have access to the right resources so they are fully aware of all the issues they are dealing with.
Stratustician
50%
50%
Stratustician,
User Rank: Moderator
4/10/2014 | 12:11:56 PM
Re: Powerful motivator
I think one of the biggest hurdles is that current IT teams are often based on folks with backgrounds in traditional security (not surprising) which is perimeter based.  Virtualization and cloud are totally different beasts as you take out the physical perimeter and all of a sudden you have this big mass of resources that may or may not even be on site.  This means visibility is been compromised from a security perspective, and honestly, I am sure that scares a lot of IT folks. It's a long way from the old mentality that virtualization security wasn't much of a risk as it was seen as "hacking into a shoebox" with no real threats. Now we are faced with availability, security and integrity concerns and no skillsets to back it up.  It really comes to down to ensuring these security folks have access to the right resources so they are fully aware of all the issues they are dealing with.
IMjustinkern
50%
50%
IMjustinkern,
User Rank: Strategist
4/3/2014 | 11:03:47 AM
Re: Powerful motivator
jagibbons ... definitely agree on the FUD front. Curious: do you think the existence of those CapEx investments will actually push people toward the cloud? Could see that as the greatest motivator of all, especially when the big bosses are parsing budgets. 
jagibbons
100%
0%
jagibbons,
User Rank: Strategist
4/3/2014 | 12:25:19 PM
Re: Powerful motivator
From my experienc, existing CapEx investments will push folk to the cloud when those assets are a) fully depreciated and b) needing to be relaced/refreshed. If they are still in production use, relativly new and still being paid for, that ends up being more of a deterent to cloud adoption.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 2:56:05 PM
Re: Powerful motivator
I think you have a valid point, new technologies will all be adopted at a much slower pace than before.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/3/2014 | 3:25:25 PM
Re: Powerful motivator -- on the other hand....
What would the cloud service provider industry need to do to overcume the FUD and reassure customers? It sounds like -- from this thread -- that its more than just a financial concern.
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/3/2014 | 3:31:02 PM
Re: Powerful motivator -- on the other hand....
I think it will just take some time and testing to see how the cloud turns out. Datacenters are protected and controlled but you must rely on others to secure your data in the cloud. There has to be a comfort level with the cloud and only time will tell when that will be.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/3/2014 | 4:55:12 PM
Re: Powerful motivator -- on the other hand....
Comfort level along with some effective security strategies. RAVI ITHAL Chief Architect at Netskope had some interesting thoughts about that in his blog today API-First: 3 Steps For Building Secure Cloud Apps
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
4/3/2014 | 6:10:35 PM
Re: Powerful motivator
Security and privacy are primary obstacles for the diffusion of the popular paradigms. Recent events related to Datagate have seriously compromised the trust in the cloud computing and drastically reduced growth projections.
macker490
50%
50%
macker490,
User Rank: Ninja
4/4/2014 | 8:20:32 AM
Hardly Surprising
the computer industry hardly has a stelar reputation for security,--- breach after breach after breach with every sort of patch, fix, and snake-oil and the situation continues to get worse

and still nobody wants to pull up the carpet and deal with the underlying issue: insecure operating software.
kobrien82
50%
50%
kobrien82,
User Rank: Apprentice
4/11/2014 | 5:34:40 PM
Security should enable, not disable, cloud adoption
Fear shouldn't be an end point in the decision. It's healthy to consider what works and what does not when considering the cloud, and to look to the data to see where and how organizations get themselves into trouble, but it should be part of a general business calcuation that includes the benefits of going to the cloud and thinking through what the risks are. 

Most data breaches and data loss from public cloud platforms are the result of inadvertent user action. That informs a certain approach to discovery, clasification, and control; there are well-known ways to create DLP policies that minimize the accidental breach risk, for example. Tom Scholtz over at Gartner has a really interesting take on the concept of people-centric security and how companies are using it to do this kind of work in a cloud-friendly way: http://my.gartner.com/portal/server.pt?open=512&objID=202&mode=2&PageID=5553&ref=webinar-rss&resId=2546716&srcId=1-2949089475


News
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
Slideshows
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
Commentary
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31793
PUBLISHED: 2021-05-06
An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell. The binary app offers a web server on port 80 that allows an unauthenticated user to take a snapshot from the doorbell camera via the ...
CVE-2021-31916
PUBLISHED: 2021-05-06
An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a syst...
CVE-2021-31918
PUBLISHED: 2021-05-06
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.
CVE-2019-25043
PUBLISHED: 2021-05-06
ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.
CVE-2020-18889
PUBLISHED: 2021-05-06
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.