Welcome!

Microservices Expo Authors: Liz McMillan, Pat Romanski, Elizabeth White, Mehdi Daoudi, Yeshim Deniz

Related Topics: Cloud Security, Java IoT, Linux Containers, @CloudExpo

Cloud Security: Article

Einstein, Sharks and Clouds: IT Security in the Cloud

Security, while a very real and legitimate concern is relative

What can these things possibly have in common?  In a word - relativity. 

I'm reminded of the old joke, two guys are swimming in the ocean when they notice a shark and one guy takes off swimming towards the boat, while the other says, "What are you doing?  We can't swim faster than a shark", the other replies, "I don't need to swim faster than a shark, just faster than you."

Lately there has been a barrage of articles with regards to cloud security, and some very public demonstrations of outages with Facebook and Twitter.  Its been a field day for many who oppose the cloud computing model.  Let me get this out of the way so that there is no misunderstanding, yes, I agree with most on the need for better security in the cloud, and rest assured, the cloud service providers are motivated to work on it.  That being said, lets move on. 

Security, while a very real and legitimate concern is relative.  While IT security has improved over the years I've been in this business, there are IT security breaches at banks, governments, educational institutions, retailers, and many other organizations which are not using the cloud today.  Just do a simple Google search and you'll find plenty of ammo on the need for better security, cloud or no cloud.

While the discussion of cloud security is certainly a very important one, lets not forget that it's a discussion that's relative to the level of security in the current business environment of those considering moving to the cloud today. 

Many of us who have spent our careers in or around IT recognize many of the security issues that cloud service providers will need to address.  This is particularly true for those that have spent most of that time at large, enterprise organizations.  We have to stop and remind ourselves, who are the prime, early adopter candidates for cloud computing? The answer here seems to be SMB

So lets talk about SMB IT practices for a moment, and lets begin with the smallest of organizations, say 1-20 employees.  Most of these companies can't afford IT staff, have no backup for their business records, have underutilized servers, have no security plan, or what many other IT professionals recognize as best practices in the industry, never mind security.  Disaster, backup and recovery?  Oh, yes, it's that tape backup in the desk next to the computer.  They fax and e.mail "secure" documents around sometimes to the wrong fax or (external) e.mail address - oops, there goes Joe's private medical records.  In these cases, cloud computing begins to look pretty attractive.

We can repeat this story on a gradual scale adding  IT headcount along the way.  How many IT people in a 20-50 employee organization?  50-100, 100-500?  Certainly, some of the aforementioned issues get addressed, though not all, as they're dealing with many IT issues, are probably understaffed, and overwhelmed.  Lets not forget we're talking about small businesses across all industries - accountants, doctors, lawyers, architects, retailers, and others, not necessarily small IT businesses.  Add in the greatest recession since WWII, and well, you can see how the cloud value proposition begins to make sense to many in this segment of the market.  Those small organizations will likely benefit from a move to the cloud, and will be more competitive as a result. 

Last one with the legacy traditional IT environment, please turn off the lights, and try to stay ahead of the sharks.

-Tune The Future-

More Stories By Ray DePena

Ray DePena worked at IBM for over 12 years in various senior global roles in managed hosting sales, services sales, global marketing programs (business innovation), marketing management, partner management, and global business development.
His background includes software development, computer networking, systems engineering, and IT project management. He holds an MBA in Information Systems, Marketing, and International Business from New York University’s Stern School of Business, and a BBA in Computer Systems from the City University of New York at Baruch College.

Named one of the World's 30 Most Influential Cloud Computing Bloggers in 2009, Top 50 Bloggers on Cloud Computing in 2010, and Top 100 Bloggers on Cloud Computing in 2011, he is the Founder and Editor of Amazon.com Journal,Competitive Business Innovation Journal,and Salesforce.com Journal.

He currently serves as an Industry Advisor for the Higher Education Sector on a National Science Foundation Initiative on Computational Thinking. Born and raised in New York City, Mr. DePena now lives in northern California. He can be followed on:

Twitter: @RayDePena   |   LinkedIn   |   Facebook   |   Google+

Microservices Articles
"We focus on SAP workloads because they are among the most powerful but somewhat challenging workloads out there to take into public cloud," explained Swen Conrad, CEO of Ocean9, Inc., in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
"NetApp's vision is how we help organizations manage data - delivering the right data in the right place, in the right time, to the people who need it, and doing it agnostic to what the platform is," explained Josh Atwell, Developer Advocate for NetApp, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
The explosion of new web/cloud/IoT-based applications and the data they generate are transforming our world right before our eyes. In this rush to adopt these new technologies, organizations are often ignoring fundamental questions concerning who owns the data and failing to ask for permission to conduct invasive surveillance of their customers. Organizations that are not transparent about how their systems gather data telemetry without offering shared data ownership risk product rejection, regu...
Containers and Kubernetes allow for code portability across on-premise VMs, bare metal, or multiple cloud provider environments. Yet, despite this portability promise, developers may include configuration and application definitions that constrain or even eliminate application portability. In this session we'll describe best practices for "configuration as code" in a Kubernetes environment. We will demonstrate how a properly constructed containerized app can be deployed to both Amazon and Azure ...
In his keynote at 19th Cloud Expo, Sheng Liang, co-founder and CEO of Rancher Labs, discussed the technological advances and new business opportunities created by the rapid adoption of containers. With the success of Amazon Web Services (AWS) and various open source technologies used to build private clouds, cloud computing has become an essential component of IT strategy. However, users continue to face challenges in implementing clouds, as older technologies evolve and newer ones like Docker c...
The now mainstream platform changes stemming from the first Internet boom brought many changes but didn’t really change the basic relationship between servers and the applications running on them. In fact, that was sort of the point. In his session at 18th Cloud Expo, Gordon Haff, senior cloud strategy marketing and evangelism manager at Red Hat, will discuss how today’s workloads require a new model and a new platform for development and execution. The platform must handle a wide range of rec...
"DivvyCloud as a company set out to help customers automate solutions to the most common cloud problems," noted Jeremy Snyder, VP of Business Development at DivvyCloud, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
"Outscale was founded in 2010, is based in France, is a strategic partner to Dassault Systémes and has done quite a bit of work with divisions of Dassault," explained Jackie Funk, Digital Marketing exec at Outscale, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
Adding public cloud resources to an existing application can be a daunting process. The tools that you currently use to manage the software and hardware outside the cloud aren’t always the best tools to efficiently grow into the cloud. All of the major configuration management tools have cloud orchestration plugins that can be leveraged, but there are also cloud-native tools that can dramatically improve the efficiency of managing your application lifecycle. In his session at 18th Cloud Expo, ...
Containers, microservices and DevOps are all the rage lately. You can read about how great they are and how they’ll change your life and the industry everywhere. So naturally when we started a new company and were deciding how to architect our app, we went with microservices, containers and DevOps. About now you’re expecting a story of how everything went so smoothly, we’re now pushing out code ten times a day, but the reality is quite different.