Welcome!

Microservices Expo Authors: Elizabeth White, Liz McMillan, Pat Romanski, Gregor Petri, AppDynamics Blog

Related Topics: @CloudExpo, Java IoT, Microservices Expo, Containers Expo Blog, Cloud Security, @BigDataExpo

@CloudExpo: Article

It’s Money That Matters in the Cloud… Well, At Least ROI

Cloud security closes the risk versus reward gap

With all the talk of fiscal cliffs sequestrations, financial binds and “next year’s budget,” I started thinking about cloud security in more tangible ways. Specifically returns on investment, economic impact and total costs of ownership. Just like death and taxes, businesses can add intrusion and attack to the list of sureties. I can hear CFOs all over the world sigh in exasperation as they feel pressured to add another expense line item to minimize the building security threats to their enterprises.

Before you add another decimal place to security budgets, maybe it’s time you consider the how cloud-deployed security options can not only address the complexities of enterprise security ably, but do so at considerable savings.

Study after study promotes that a cloud computing model saves organization money. We know that more and more functionality is moving to the cloud. For things like CRM or other standard business applications, it simply makes sense. We recognize the limited time and funding to run and maintain enterprise applications and the cloud provides that great equalizer. This model extends itself to cloud security and security-as-a-service.

First there are the over-arching savings of cloud-computing in general:

  • Elimination of CapEx costs: no hardware or software to buy (Any “cloud” company that asks you to install a server on your premises to monitor your enterprise isn’t cloud)
  • Pay-as-you-go scalable: Most cloud providers can offer considerable cost savings through economies of scale. The ability to adjust the level of service necessary (elastic provisioning) creates flexibility for increased margins and cost-controls.
  • Zero-day start/On demand delivery of service: no waiting time after the service has been purchased to develop and configure a complex system. This means no development hell or waiting for Phase 2 to be complete in order to start reaping benefits.
  • Head count savings: included in most cloud services are the personnel costs (salary, benefits, overhead, churn/hiring costs) a company does not need to invest in more people and gains the benefit of the security expertise and tribal knowledge of the cloud security provider.
  • Best-of breed resource/expertise expansion: Companies improve their overall business agility through proven technologies supported and updated by the core competencies of the developers. Meanwhile CIOs get to move more IT budget to innovation or enablement programs.

But where are the benefits of cloud security from an ROI perspective:

  • 24/7 Availability: Cloud security is about continuous monitoring.  To properly secure the expanding footprint of an enterprise’s IT landscape, there must be the vigilance to catch analyze and remediate issues as quickly as possible. Like a cancer, if security issues go undetected, they can metastasize and spread. Having a professional monitor a network 7/24/365 (in real time) seems like a luxury for Fortune 500 companies. Cloud security makes this option available for the most modest organizations. The holes in security that are created through intermittent monitoring, vague automation settings and periodic machine log reviews will cost an organization.  But continuous monitoring isn’t a cost center. Preventive and proactive security creates reduced risk (without additional man hours) which allows for redeployed resources and a realignment based of business needs.
  • Unification: The agility from the cloud allows companies to leverage the capabilities of various security solutions looking at multiple parts of the enterprise. This includes intrusion detection, credentialing, access, SSO, web authentication and compliance audits. It not only allows an enterprise to acquire more and greater functionality for virtually the same cost, but it also centralizes the collective intelligence and provides the advantage enhanced visibility through correlated and situational context. This, in turn, creates better and faster decisions which streamline resources and save money.
  • Improved productivity Although there are many examples of this within cloud based security, I will point to one (and use future blogs to expound on others). Using identity management, companies can automatically provision and deprovision users. This service alone can save 75% of the requests across the enterprise. Imagine the additional savings when IT is not slogged down with forgotten password requests/resets along with managing credentials. There are studies that prove that this alone saves companies nearly $200K per year. Now with better employee productivity (because this helps solve BYOD issues) and certain portions of your network safe from data theft and leakage, IT can concentrate on business issues that drive revenue.
  • Compliance: Dozens of man hours are typically needed each month to complete all the reports needed to satisfy a regulatory agency auditor; and for most companies, it’s not just one agency, but several. Through real time correlation, most of the work of identifying, capturing, encrypting and storing(or destroying) certain pieces of information and providing the proof  your best practices are in line with internal and external policies is easier. Because of unification, multi-silo collection and security centralization, 75 hours per month becomes 10. And more importantly, the degree of accuracy of the reporting is significantly better.  And with better reports, the threat of fines disappears.

Gartner estimates the annual cost to own and manage traditional on premise security software applications can be 4X the initial purchase. This is chiefly due to the need to acquire and maintain the resources to support the deployment. In many cases, for less than what a company pays for in support and maintenance of these on premise initiatives, they could have twice the capability from the cloud.

When it’s money that matters, the bottom line should be as much about saving as it is spending; as long as the result is a positive return on the investment. Enterprise security is not different. For years seen as a cost center, through cloud-based solutions it can now be redefined as a revenue enablement mechanism. Certainly there are costs involved in a maintaining a safe network perimeter, protecting and securing data and compliance auditing. However, by exploiting the benefits and strengths provided by cloud based security, you can prudently and effectively contain the issues with plentiful resources to reinvest in your core competencies and focus on driving business forward. Security issues will not go away, but you can direct less at them and in return, receive more greater results.

When looking at the cloud in term of security…sometimes you can have your cake and eat it too.

 

Kevin Nikkhoo
www.cloudaccess.com

More Stories By Kevin Nikkhoo

With more than 32 years of experience in information technology, and an extensive and successful entrepreneurial background, Kevin Nikkhoo is the CEO of the dynamic security-as-a-service startup Cloud Access. CloudAccess is at the forefront of the latest evolution of IT asset protection--the cloud.

Kevin holds a Bachelor of Science in Computer Engineering from McGill University, Master of Computer Engineering at California State University, Los Angeles, and an MBA from the University of Southern California with emphasis in entrepreneurial studies.

@MicroservicesExpo Stories
Whether they’re located in a public, private, or hybrid cloud environment, cloud technologies are constantly evolving. While the innovation is exciting, the end mission of delivering business value and rapidly producing incremental product features is paramount. In his session at @DevOpsSummit at 19th Cloud Expo, Kiran Chitturi, CTO Architect at Sungard AS, will discuss DevOps culture, its evolution of frameworks and technologies, and how it is achieving maturity. He will also cover various st...
SYS-CON Events announced today that eCube Systems, a leading provider of middleware modernization, integration, and management solutions, will exhibit at @DevOpsSummit at 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. eCube Systems offers a family of middleware evolution products and services that maximize return on technology investment by leveraging existing technical equity to meet evolving business needs. ...
All clouds are not equal. To succeed in a DevOps context, organizations should plan to develop/deploy apps across a choice of on-premise and public clouds simultaneously depending on the business needs. This is where the concept of the Lean Cloud comes in - resting on the idea that you often need to relocate your app modules over their life cycles for both innovation and operational efficiency in the cloud. In his session at @DevOpsSummit at19th Cloud Expo, Valentin (Val) Bercovici, CTO of So...
SYS-CON Events has announced today that Roger Strukhoff has been named conference chair of Cloud Expo and @ThingsExpo 2016 Silicon Valley. The 19th Cloud Expo and 6th @ThingsExpo will take place on November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. "The Internet of Things brings trillions of dollars of opportunity to developers and enterprise IT, no matter how you measure it," stated Roger Strukhoff. "More importantly, it leverages the power of devices and the Interne...
19th Cloud Expo, taking place November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Meanwhile, 94% of enterpri...
In this strange new world where more and more power is drawn from business technology, companies are effectively straddling two paths on the road to innovation and transformation into digital enterprises. The first path is the heritage trail – with “legacy” technology forming the background. Here, extant technologies are transformed by core IT teams to provide more API-driven approaches. Legacy systems can restrict companies that are transitioning into digital enterprises. To truly become a lea...
Video experiences should be unique and exciting! But that doesn’t mean you need to patch all the pieces yourself. Users demand rich and engaging experiences and new ways to connect with you. But creating robust video applications at scale can be complicated, time-consuming and expensive. In his session at @ThingsExpo, Zohar Babin, Vice President of Platform, Ecosystem and Community at Kaltura, will discuss how VPaaS enables you to move fast, creating scalable video experiences that reach your...
Internet of @ThingsExpo, taking place November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 19th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The Internet of Things (IoT) is the most profound change in personal and enterprise IT since the creation of the Worldwide Web more than 20 years ago. All major researchers estimate there will be tens of billions devices - comp...
SYS-CON Events announced today that Tintri Inc., a leading producer of VM-aware storage (VAS) for virtualization and cloud environments, will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Tintri VM-aware storage is the simplest for virtualized applications and cloud. Organizations including GE, Toyota, United Healthcare, NASA and 6 of the Fortune 15 have said “No to LUNs.” With Tintri they mana...
In his general session at 18th Cloud Expo, Lee Atchison, Principal Cloud Architect and Advocate at New Relic, discussed cloud as a ‘better data center’ and how it adds new capacity (faster) and improves application availability (redundancy). The cloud is a ‘Dynamic Tool for Dynamic Apps’ and resource allocation is an integral part of your application architecture, so use only the resources you need and allocate /de-allocate resources on the fly.
Apache Hadoop is a key technology for gaining business insights from your Big Data, but the penetration into enterprises is shockingly low. In fact, Apache Hadoop and Big Data proponents recognize that this technology has not yet achieved its game-changing business potential. In his session at 19th Cloud Expo, John Mertic, director of program management for ODPi at The Linux Foundation, will explain why this is, how we can work together as an open data community to increase adoption, and the i...
DevOps at Cloud Expo – being held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real results. Am...
SYS-CON Events announced today that LeaseWeb USA, a cloud Infrastructure-as-a-Service (IaaS) provider, will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. LeaseWeb is one of the world's largest hosting brands. The company helps customers define, develop and deploy IT infrastructure tailored to their exact business needs, by combining various kinds cloud solutions.
About a year ago we tuned into “the need for speed” and how a concept like "serverless computing” was increasingly catering to this. We are now a year further and the term “serverless” is taking on unexpected proportions. With some even seeing it as the successor to cloud in general or at least as a successor to the clouds’ poorer cousin in terms of revenue, hype and adoption: PaaS. The question we need to ask is whether this constitutes an example of Hype Hopping: to effortlessly pivot to the ...
DevOps and microservices are permeating software engineering teams broadly, whether these teams are in pure software shops but happen to run a business, such Uber and Airbnb, or in companies that rely heavily on software to run more traditional business, such as financial firms or high-end manufacturers. Microservices and DevOps have created software development and therefore business speed and agility benefits, but they have also created problems; specifically, they have created software sec...
Much of the value of DevOps comes from a (renewed) focus on measurement, sharing, and continuous feedback loops. In increasingly complex DevOps workflows and environments, and especially in larger, regulated, or more crystallized organizations, these core concepts become even more critical. In his session at @DevOpsSummit at 18th Cloud Expo, Andi Mann, Chief Technology Advocate at Splunk, showed how, by focusing on 'metrics that matter,' you can provide objective, transparent, and meaningful f...
Information technology is an industry that has always experienced change, and the dramatic change sweeping across the industry today could not be truthfully described as the first time we've seen such widespread change impacting customer investments. However, the rate of the change, and the potential outcomes from today's digital transformation has the distinct potential to separate the industry into two camps: Organizations that see the change coming, embrace it, and successful leverage it; and...
With the rise of Docker, Kubernetes, and other container technologies, the growth of microservices has skyrocketed among dev teams looking to innovate on a faster release cycle. This has enabled teams to finally realize their DevOps goals to ship and iterate quickly in a continuous delivery model. Why containers are growing in popularity is no surprise — they’re extremely easy to spin up or down, but come with an unforeseen issue. However, without the right foresight, DevOps and IT teams may lo...
The Jevons Paradox suggests that when technological advances increase efficiency of a resource, it results in an overall increase in consumption. Writing on the increased use of coal as a result of technological improvements, 19th-century economist William Stanley Jevons found that these improvements led to the development of new ways to utilize coal. In his session at 19th Cloud Expo, Mark Thiele, Chief Strategy Officer for Apcera, will compare the Jevons Paradox to modern-day enterprise IT, e...
Digitization is driving a fundamental change in society that is transforming the way businesses work with their customers, their supply chains and their people. Digital transformation leverages DevOps best practices, such as Agile Parallel Development, Continuous Delivery and Agile Operations to capitalize on opportunities and create competitive differentiation in the application economy. However, information security has been notably absent from the DevOps movement. Speed doesn’t have to negat...