Welcome!

Microservices Expo Authors: Derek Weeks, Pat Romanski, Elizabeth White, Miska Kaipiainen, Automic Blog

Related Topics: Cloud Security, Mobile IoT, Microservices Expo, IoT User Interface, Agile Computing, Wearables

Cloud Security: Article

How to Re-imagine Your Business for a Mobile World

And keep your data safe while doing it

There is little argument at this point that the mass adoption of mobile technology and bring-your-own-device (BYOD) strategies by enterprises is a true business technology revolution. At the core, the catalysts driving this revolution are the vast array of mobile devices leveraging soaring bandwidth - 4G - and super-fast internals - quad-core processors - which have become commonplace.

With this high-bandwidth, ultra-capable combination, end users see the productivity and convenience possible by running the newest, most sophisticated business applications on their own personal mobile devices.

And it's not just end users who can benefit. A recent Symantec survey found that innovative companies - early technology adopters, especially of mobile technology - are seeing significantly higher revenue growth and higher profits than traditional organizations; in fact, by nearly 50 percent.

The question facing every enterprise is, "Are we re-imagining our business with mobility as a central component?" Here are some suggestions on how to accomplish this, while keeping sensitive business data secure.

Evaluate App and Data Needs
The previously mentioned Symantec survey found that 84 percent of those successful, innovative companies are proactively adapting their businesses based on business drivers rather than simply reacting to user demand. So, companies need to evaluate. Thus, the first step in re-imagining business in a mobile world is to determine the apps and data end users could utilize - beyond email - to get their jobs done more efficiently.

App Type
Apps for CRM, e-Health and ERP are just a few good examples of line-of-business apps companies in different industries can leverage to improve productivity through mobility. Add to this list cloud-based file storage apps that give users access to their data across computing platforms.

Data Access
Beyond app type, companies must take a closer look at target user groups to determine each segment's specific data access needs. Some users might need resident data on their devices, while others who are likely to have connectivity all the time can manage with cloud-based data. Understanding each group's specific needs will help determine the type of technology approaches possible.

App Procurement
Once app type and data access requirements are well understood, companies need to explore app procurement. For some, the only way to get exactly what is needed is to build a custom app or have one built for them. However, hundreds of thousands of apps are already available for the most popular mobile operating systems and, in many instances, the perfect app likely already exists.

Keep App and Data Security Top of Mind
The Symantec survey referenced earlier also found that the innovative companies who are leading the way in mobility adoption also experience about twice as many mobile security-related incidents, such as loss of corporate data. This leads to a second question enterprises must ask, "How do we keep our sensitive data safe in a mobile world?"

From a high level, there are really two approaches to keeping business data on mobile devices secure. The first is protecting data at the device level and the second is protecting it at the app level.

Device Level Data Protection
Data protection on mobile devices at the device level largely involves mobile device management (MDM) software. MDM provides business IT with control over complete devices and, as such, policies can ensure devices are password-protected and also provide the ability to remotely lock or wipe devices in the event of a loss or theft and even prevent the forwarding of emails.

However, MDM cannot address other data loss-related concerns such as copy and pasting of sensitive information or, more important, protecting corporate data in applications beyond the email client.

Thus, the device level approach creates an environment where it becomes far too easy for sensitive data to mingle with personal apps and leak out through, for example, a web-based email account, social networking application or personal cloud storage. This can all occur without IT ever knowing.

App Level Data Protection
The next logical area where enterprises can implement and enforce policies to keep data on mobile devices secure is at the app level. The previous iterations of this approach involved sandboxing technologies, where corporate data on mobile devices is held in an established digital container on devices, and data flow from the sandbox or container is controlled. This approach prevents the confluence of personal and corporate data, the ability to copy and paste data accessed from within the sandbox to other areas on the device, and unauthorized email forwards from within the sandbox.

This sandbox approach worked well when email was the only app businesses wanted to mobilize. However, as companies re-imagine their businesses with a focus on mobility, this approach falls short. Any corporate app that needs protection has to be built in or modified to fit into the sandbox. With the diversity of apps available, this approach is very limiting and even the early proponents of this technology are moving on to other strategies.

One of these strategies is mobile application management (MAM), which addresses the limitations of sandboxes while still meeting corporate security needs. MAM technology allows companies to wrap their corporate apps and the data tied to them in their own security and management layers. This gives enterprises complete control of their apps and data while leaving user-owned information untouched. In contrast to the legacy sandboxing approach, it does this without any additional overhead, either from affecting device usage or source code modifications.

With MAM, controls such as authentication, encryption, data loss prevention and expiration - apps and data can be manually expired or set to automatically remove themselves from devices based on perimeters established by administrators - can all be applied to corporate apps and other resources on otherwise unmanaged, user-owned devices. In this way, complete end-to-end visibility and control over where sensitive data is flowing - regardless of what mobile application or service is being used to traffic the data - can be achieved and, just as important, maintained.

In addition, MAM allows multiple corporate apps to securely communicate with each other and for data traffic segregation, so all traffic from corporate apps can be routed through the corporate network while the personal traffic is left unmonitored.

It is important to note, however, that MAM as a term is being used loosely within the industry. Different technology vendors use it to describe different things. Some refer to app distribution functionality as MAM and still others refer to simple app blocking as MAM.

From an enterprise perspective, however, MAM should be more than that. More than simply distributing the right apps and blocking the wrong ones, MAM is about protecting the corporate apps and data on mobile devices by taking management from a device level to an application level. It is the most effective tool for separating corporate data from personal data to make safe, effective BYOD policies possible.

Re-imagining business for a mobile world, while not without its growing pains, can be a fairly straightforward process. However, to re-imagine business for a mobile world confidently, MAM should be a part of every discussion.

More Stories By Swarna Podila

Swarna Podila serves as a senior manager with the Enterprise Mobility Group at Symantec, responsible for the messaging, positioning, go-to-market strategy and overall evangelism of mobile security and management products and services. In her role, she focuses on the enterprise routes to market, messaging the solutions for on-premise and cloud deployments. At Symantec, Podila has promoted the idea of user-centric and information-centric view and anytime, anywhere productivity.

Prior to Symantec, Podila served a product marketing consultant at Citrix. There she was responsible for the messaging and launching of the company’s networking products. Prior to Citrix, she worked at a software startup and was responsible for their transition from stealth mode to a mid-sized company. She was responsible for product messaging, identifying routes to market and sales enablement. With over 10 years experience in the IT industry, Podila has held a number of roles in product strategy, marketing and engineering. She has an undergraduate degree in Electronics and Communications Engineering and an MBA from Santa Clara University.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@MicroservicesExpo Stories
Analysis of 25,000 applications reveals 6.8% of packages/components used included known defects. Organizations standardizing on components between 2 - 3 years of age can decrease defect rates substantially. Open source and third-party packages/components live at the heart of high velocity software development organizations. Today, an average of 106 packages/components comprise 80 - 90% of a modern application, yet few organizations have visibility into what components are used where.
SYS-CON Events announced today that Tintri Inc., a leading producer of VM-aware storage (VAS) for virtualization and cloud environments, will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Tintri VM-aware storage is the simplest for virtualized applications and cloud. Organizations including GE, Toyota, United Healthcare, NASA and 6 of the Fortune 15 have said “No to LUNs.” With Tintri they mana...
The Jevons Paradox suggests that when technological advances increase efficiency of a resource, it results in an overall increase in consumption. Writing on the increased use of coal as a result of technological improvements, 19th-century economist William Stanley Jevons found that these improvements led to the development of new ways to utilize coal. In his session at 19th Cloud Expo, Mark Thiele, Chief Strategy Officer for Apcera, will compare the Jevons Paradox to modern-day enterprise IT, e...
Throughout history, various leaders have risen up and tried to unify the world by conquest. Fortunately, none of their plans have succeeded. The world goes on just fine with each country ruling itself; no single ruler is necessary. That’s how it is with the container platform ecosystem, as well. There’s no need for one all-powerful, all-encompassing container platform. Think about any other technology sector out there – there are always multiple solutions in every space. The same goes for conta...
SYS-CON Events announced today the Enterprise IoT Bootcamp, being held November 1-2, 2016, in conjunction with 19th Cloud Expo | @ThingsExpo at the Santa Clara Convention Center in Santa Clara, CA. Combined with real-world scenarios and use cases, the Enterprise IoT Bootcamp is not just based on presentations but with hands-on demos and detailed walkthroughs. We will introduce you to a variety of real world use cases prototyped using Arduino, Raspberry Pi, BeagleBone, Spark, and Intel Edison. Y...
Let's recap what we learned from the previous chapters in the series: episode 1 and episode 2. We learned that a good rollback mechanism cannot be designed without having an intimate knowledge of the application architecture, the nature of your components and their dependencies. Now that we know what we have to restore and in which order, the question is how?
Whether they’re located in a public, private, or hybrid cloud environment, cloud technologies are constantly evolving. While the innovation is exciting, the end mission of delivering business value and rapidly producing incremental product features is paramount. In his session at @DevOpsSummit at 19th Cloud Expo, Kiran Chitturi, CTO Architect at Sungard AS, will discuss DevOps culture, its evolution of frameworks and technologies, and how it is achieving maturity. He will also cover various st...
If you’re responsible for an application that depends on the data or functionality of various IoT endpoints – either sensors or devices – your brand reputation depends on the security, reliability, and compliance of its many integrated parts. If your application fails to deliver the expected business results, your customers and partners won't care if that failure stems from the code you developed or from a component that you integrated. What can you do to ensure that the endpoints work as expect...
In his general session at 18th Cloud Expo, Lee Atchison, Principal Cloud Architect and Advocate at New Relic, discussed cloud as a ‘better data center’ and how it adds new capacity (faster) and improves application availability (redundancy). The cloud is a ‘Dynamic Tool for Dynamic Apps’ and resource allocation is an integral part of your application architecture, so use only the resources you need and allocate /de-allocate resources on the fly.
Enterprise IT has been in the era of Hybrid Cloud for some time now. But it seems most conversations about Hybrid are focused on integrating AWS, Microsoft Azure, or Google ECM into existing on-premises systems. Where is all the Private Cloud? What do technology providers need to do to make their offerings more compelling? How should enterprise IT executives and buyers define their focus, needs, and roadmap, and communicate that clearly to the providers?
More and more companies are looking to microservices as an architectural pattern for breaking apart applications into more manageable pieces so that agile teams can deliver new features quicker and more effectively. What this pattern has done more than anything to date is spark organizational transformations, setting the foundation for future application development. In practice, however, there are a number of considerations to make that go beyond simply “build, ship, and run,” which changes ho...
Using new techniques of information modeling, indexing, and processing, new cloud-based systems can support cloud-based workloads previously not possible for high-throughput insurance, banking, and case-based applications. In his session at 18th Cloud Expo, John Newton, CTO, Founder and Chairman of Alfresco, described how to scale cloud-based content management repositories to store, manage, and retrieve billions of documents and related information with fast and linear scalability. He addres...
SYS-CON Events announced today that Commvault, a global leader in enterprise data protection and information management, has been named “Bronze Sponsor” of SYS-CON's 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Commvault is a leading provider of data protection and information management solutions, helping companies worldwide activate their data to drive more value and business insight and to transform moder...
SYS-CON Events announced today that eCube Systems, a leading provider of middleware modernization, integration, and management solutions, will exhibit at @DevOpsSummit at 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. eCube Systems offers a family of middleware evolution products and services that maximize return on technology investment by leveraging existing technical equity to meet evolving business needs. ...
The many IoT deployments around the world are busy integrating smart devices and sensors into their enterprise IT infrastructures. Yet all of this technology – and there are an amazing number of choices – is of no use without the software to gather, communicate, and analyze the new data flows. Without software, there is no IT. In this power panel at @ThingsExpo, moderated by Conference Chair Roger Strukhoff, panelists will look at the protocols that communicate data and the emerging data analy...
Large enterprises today are juggling an enormous variety of network equipment. Business users are asking for specific network throughput guarantees when it comes to their critical applications, legal departments require compliance with mandated regulatory frameworks, and operations are asked to do more with shrinking budgets. All these requirements do not easily align with existing network architectures; hence, network operators are continuously faced with a slew of granular parameter change req...
Monitoring of Docker environments is challenging. Why? Because each container typically runs a single process, has its own environment, utilizes virtual networks, or has various methods of managing storage. Traditional monitoring solutions take metrics from each server and applications they run. These servers and applications running on them are typically very static, with very long uptimes. Docker deployments are different: a set of containers may run many applications, all sharing the resource...
All clouds are not equal. To succeed in a DevOps context, organizations should plan to develop/deploy apps across a choice of on-premise and public clouds simultaneously depending on the business needs. This is where the concept of the Lean Cloud comes in - resting on the idea that you often need to relocate your app modules over their life cycles for both innovation and operational efficiency in the cloud. In his session at @DevOpsSummit at19th Cloud Expo, Valentin (Val) Bercovici, CTO of So...
There is little doubt that Big Data solutions will have an increasing role in the Enterprise IT mainstream over time. Big Data at Cloud Expo - to be held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA - has announced its Call for Papers is open. Cloud computing is being adopted in one form or another by 94% of enterprises today. Tens of billions of new devices are being connected to The Internet of Things. And Big Data is driving this bus. An exponential increase is...
SYS-CON Events has announced today that Roger Strukhoff has been named conference chair of Cloud Expo and @ThingsExpo 2016 Silicon Valley. The 19th Cloud Expo and 6th @ThingsExpo will take place on November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. "The Internet of Things brings trillions of dollars of opportunity to developers and enterprise IT, no matter how you measure it," stated Roger Strukhoff. "More importantly, it leverages the power of devices and the Interne...