Welcome!

Microservices Expo Authors: Liz McMillan, Pat Romanski, Carmen Gonzalez, Elizabeth White, Jason Bloomberg

Related Topics: Mobile IoT, Microservices Expo, Wearables, Cloud Security

Mobile IoT: Blog Post

The Challenge of BYOD

Managing security in a mobile universe

Don’t care how…I want it now!
-Veruca Salt (Willy Wonka and the Chocolate Factory)

We live and work in a world of immediate gratification. In the name of greater productivity if you need to check inventory from a supplier’s warehouse…click there it is. Share a file on Dropbox, no problem. Add detail about a meeting in the sales database… click! Update your Facebook or LinkedIn status. Email a white paper to a potential client...click, click. Want to see that flying pig meme…well, you get the picture.

Now that’s not necessarily a bad thing…unless you’re an IT professional and the those accessing and storing your network assets use unsecured/unauthorized devices while potentially bypassing security protocols. But unlike Veruca Salt quoted above, it isn’t the user who falls into the garbage chute—the risk is to the security of the network. And it's happening more often than you think.

Many organizations are now allowing employees to use their personally-owned devices for work purposes with the goal of achieving improved employee satisfaction and productivity. However, this comes at an IT price. Users love the mobility and the immediacy of smart phones and tablets, but forget these devices are just hand-held computers prone to the same intrusions, attacks, viruses and risks as the computers used in the office. The larger problem is many users don’t see that, so every time they sign on to your network or download an app, it creates a wider and wider vulnerability gap for the enterprise network.

This issue is not unique to a company of any particular size or one vertical market, however the solution, whereas not simple, is clear. There are several moving parts that require elements of identity management, access management, SIEM, WebSSO and SaaS SSO. It incorporates a suite of integrated answers that together can let you rest a little better at night. The idea that if you build a strong perimeter or have users install anti-virus on their devices, the problem goes away. It simply puts the finger in the dyke, and the overriding issue still exists. Your proprietary assets are still exposed.

First off, regardless of whether you approach the solution from the cloud or more terrestrial confines, you need to rethink the risk, revise the policy and enforce the rules. You have to consider how best to maintain compliance (PCI, HIPAA, and/or Sarbanes-Oxley), and you need to incorporate the answer holistically. To this end you need new protocols to authenticate and credential users, define authorization rules based on very specific rights and profiles and monitor traffic patterns to identify, alert and act on any unusual activity.

This takes time, money and manpower. All of which are typically in short supply for new IT initiatives. That is why I advocate security-as-a-service. BYOD is a threat that will only grow exponentially and the longer you wait to address the issue head on, the greater the vulnerability gap. However, by taking advantage of the integrated solutions managed from the cloud, organizations gain the benefit of cost-effective, seamless, on-demand, scalable coverage. If you already have a strong SSO, then you don’t add it. If all you require is additional resources to improve intrusion detection and/or password management, the cloud solution exists to leverage your existing architecture. Essentially cloud-based security fills the vulnerability gap with proven and tested solutions monitored 7/24/365.

Managing security in the cloud provides the resource bandwidth to create the rules, easily provision or deprovision devices, automate the alerts and incorporate a more comprehensive and layered protection strategy that includes the BYOD crowd.

But whatever your decision, you need to address the issue sooner than later, because if you don’t take charge, your employees will self-serve based on their own needs. There’s a prescient blog by Joe Onisick of Network Computing who said:

“If you don’t support a particular device, employees will begin to find ways to self-support it. They will bypass corporate IT and, with that, bypass security, compliance, change management and audit logging. It’s a problem that will continue to get worse, and, as with any problem, an ounce of prevention is worth a pound of cure.”

More Stories By Kevin Nikkhoo

With more than 32 years of experience in information technology, and an extensive and successful entrepreneurial background, Kevin Nikkhoo is the CEO of the dynamic security-as-a-service startup Cloud Access. CloudAccess is at the forefront of the latest evolution of IT asset protection--the cloud.

Kevin holds a Bachelor of Science in Computer Engineering from McGill University, Master of Computer Engineering at California State University, Los Angeles, and an MBA from the University of Southern California with emphasis in entrepreneurial studies.

Microservices Articles
Modern software design has fundamentally changed how we manage applications, causing many to turn to containers as the new virtual machine for resource management. As container adoption grows beyond stateless applications to stateful workloads, the need for persistent storage is foundational - something customers routinely cite as a top pain point. In his session at @DevOpsSummit at 21st Cloud Expo, Bill Borsari, Head of Systems Engineering at Datera, explored how organizations can reap the bene...
"NetApp's vision is how we help organizations manage data - delivering the right data in the right place, in the right time, to the people who need it, and doing it agnostic to what the platform is," explained Josh Atwell, Developer Advocate for NetApp, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
The Jevons Paradox suggests that when technological advances increase efficiency of a resource, it results in an overall increase in consumption. Writing on the increased use of coal as a result of technological improvements, 19th-century economist William Stanley Jevons found that these improvements led to the development of new ways to utilize coal. In his session at 19th Cloud Expo, Mark Thiele, Chief Strategy Officer for Apcera, compared the Jevons Paradox to modern-day enterprise IT, examin...
In his session at 20th Cloud Expo, Mike Johnston, an infrastructure engineer at Supergiant.io, discussed how to use Kubernetes to set up a SaaS infrastructure for your business. Mike Johnston is an infrastructure engineer at Supergiant.io with over 12 years of experience designing, deploying, and maintaining server and workstation infrastructure at all scales. He has experience with brick and mortar data centers as well as cloud providers like Digital Ocean, Amazon Web Services, and Rackspace. H...
Skeuomorphism usually means retaining existing design cues in something new that doesn’t actually need them. However, the concept of skeuomorphism can be thought of as relating more broadly to applying existing patterns to new technologies that, in fact, cry out for new approaches. In his session at DevOps Summit, Gordon Haff, Senior Cloud Strategy Marketing and Evangelism Manager at Red Hat, will discuss why containers should be paired with new architectural practices such as microservices ra...
In his session at 20th Cloud Expo, Scott Davis, CTO of Embotics, discussed how automation can provide the dynamic management required to cost-effectively deliver microservices and container solutions at scale. He also discussed how flexible automation is the key to effectively bridging and seamlessly coordinating both IT and developer needs for component orchestration across disparate clouds – an increasingly important requirement at today’s multi-cloud enterprise.
The Software Defined Data Center (SDDC), which enables organizations to seamlessly run in a hybrid cloud model (public + private cloud), is here to stay. IDC estimates that the software-defined networking market will be valued at $3.7 billion by 2016. Security is a key component and benefit of the SDDC, and offers an opportunity to build security 'from the ground up' and weave it into the environment from day one. In his session at 16th Cloud Expo, Reuven Harrison, CTO and Co-Founder of Tufin, ...
DevOps is often described as a combination of technology and culture. Without both, DevOps isn't complete. However, applying the culture to outdated technology is a recipe for disaster; as response times grow and connections between teams are delayed by technology, the culture will die. A Nutanix Enterprise Cloud has many benefits that provide the needed base for a true DevOps paradigm. In their Day 3 Keynote at 20th Cloud Expo, Chris Brown, a Solutions Marketing Manager at Nutanix, and Mark Lav...
Many organizations are now looking to DevOps maturity models to gauge their DevOps adoption and compare their maturity to their peers. However, as enterprise organizations rush to adopt DevOps, moving past experimentation to embrace it at scale, they are in danger of falling into the trap that they have fallen into time and time again. Unfortunately, we've seen this movie before, and we know how it ends: badly.
TCP (Transmission Control Protocol) is a common and reliable transmission protocol on the Internet. TCP was introduced in the 70s by Stanford University for US Defense to establish connectivity between distributed systems to maintain a backup of defense information. At the time, TCP was introduced to communicate amongst a selected set of devices for a smaller dataset over shorter distances. As the Internet evolved, however, the number of applications and users, and the types of data accessed and...