Welcome!

Microservices Expo Authors: Elizabeth White, Jyoti Bansal, Pat Romanski, AppNeta Blog, Liz McMillan

Related Topics: @CloudExpo, Java IoT, Microservices Expo, Linux Containers, Agile Computing, Cloud Security

@CloudExpo: Article

Making BYOC Work for Your Network

Similar to BYOD, this concept of bring-your-own-cloud (BYOC) is not going anywhere

The proliferation of cloud-based applications for the enterprise grows each day, and more and more professionals have grown dependent on these apps as the consumerization of IT flourishes in today's mobile enterprise. With the consumerization of IT, employees have become their own IT experts and demand that their IT departments add cloud services or enable them to use a particular app with the corporate network. IT departments, naturally, want to use the latest technologies to make the entire company more efficient and productive - and they see how the cloud can help accomplish this. What employees don't often see is that there are roadblocks to rolling out a new service or enabling an app to work with the network. Everything from budget to security to integration issues may cause the IT department to turn down the requests. However, unlike in the past, employees now have the power and the means to just use these services anyway, without IT's approval.

Similar to BYOD, this concept of bring-your-own-cloud (BYOC) is not going anywhere. Just think - it's incredibly easy for employees to access preferred technology offerings on a mobile or personal device, but it's still on the company network. Just download it, watch a YouTube video on how to make it work and voila - you have your cloud service. Any professional with a smartphone is enabled by cloud, social computing, analytics and mobile - and wants to transfer that experience seamlessly between their personal and professional computing.

This obviously poses a huge problem for the company network. IT staff either doesn't know this happened, or is forced to quickly address network and security issues, often leading to Band-Aid fixes. Results from Forrester's Forrsights Workforce Employee Survey, Q4 2012 indicate that at least 85 percent of employees use phone/tablet applications and web-based services, which is putting corporate information security under serious threat. Just to start, BYOC could hypothetically:

  • Denigrate the network - Deploying cloud technologies and operating models muddies the role that networking plays. Further, the impact of the cloud on the networks may not always be clear, and while the network is indeed important to cloud computing, the network also must change in order to facilitate these preferences. In a hybrid environment, the relationship and connection between a user's cloud and the provider's network must be secure - but the structure should be in place beforehand. The bottom line is, no network means no cloud - without networks, users cannot access their cloud services.
  • Challenge traditional security practices - It's really hard to ensure that information on employee-owned hardware and software is secure. For security professionals, BYOC seems like a nightmare. Personal devices are getting smarter and are better able to store and do more with corporate data, especially with the proliferation of personal cloud storage like Evernote, Amazon S3 and even Facebook. They also become a bigger target for hackers.
  • Introduce viruses - In BYOC environments you will inevitably have one employee who leisurely browses the web, opens email attachments, stores phantom files, freely clicks on links, and can't - or rarely - updates their security software. Without a policy in place, this is a veritable virus breeding ground.
  • Expose critical company data over unsecure networks and devices - This one seems pretty obvious, right? Downloading sensitive company files to an iPad, saving it to iCloud, and then connecting to the Starbucks Wi-Fi network down the street is not an ideal scenario - but it's a likely one.

Where does an enterprise start? The pros and cons are clear, and while it's important in this day and age to be accommodating and supportive of the innovative models that professionals take to accomplish their work, day-in and day-out, it's also very important to have a policy and framework in place that keeps all constituents on the same page while living on the same network. Let's start there - what frame of mind when devising a BYOC policy is reasonable and will be accepted by employees?

It's important to have a solid understanding of the stage at which cloud applications have infiltrated the organization. Once an organization understands the true level of cloud adoption across the board, they can better understand the true implications for their network and security, and how critical an organization-wide policy is to institute rules and regulations.

Network Monitoring and Inventory
Solutions exist that will take a complete look at your network and take stock of what is connected to your network (wired and wireless). It will know who owns it, what kind of memory it has, if and what software is installed and running, user information, network configurations and more. This is step one in your diagnosis, but also important throughout to keep track of the state of your network and to dissuade rogue users.

From there, your IT organization can determine how to protect itself from this phenomenon. Users are both the champions for this, as well as the weakest link - they likely own the device and they likely own the storage and access of the corporate data - so it's most important to invest in their knowledge, understanding and commitment to the policy.

Train and Instruct
Let employees know that they are responsible for their devices and cloud service from a cost and upkeep perspective, but also for what happens as a result of any personal computing or professional computing over personal assets. If an employee is not a good fit for any BYOC policy, such as a legal professional, instruct them of a revised policy.

Regardless, physical training of employees should happen over digital programs that they can quickly skip through and provide a digital signature without fully understanding or comprehending the responsibility that is in their hands - literally.

Security, Security, Security
Many companies are aware of how to secure devices that are introduced onto the network. For instance, there are a plethora of mobile device management solutions available that secure, monitor, manage and support mobile devices deployed across a corporate network. But for the cloud, to secure data and applications, it's important to invest in solutions with built-in data loss prevention (DLP), giving users an encrypted storage space on the mobile device to safely store business critical data.

For the network, there are a variety of network access control solutions that will give administrators the ability to enforce role-based access. In some cases, these types of solutions might just be viewed as Band-Aid fixes to a larger problem. Depending on your organization, however, these can be good first steps, building up to the implementation of a more holistic hybrid cloud environment that offers employees a full-scale cloud solution to support such bandwidth.

The bottom line, you must be in the know - you must know where your network stands at all times; you must know what your employees want from a cloud perspective; you must know what they currently have from a cloud perspective; and you must know what the best path is to take for your organization - be that a six-month path of quick-fixes and BYOC policies, or a full-fledged cloud offering that puts your mind at ease and keeps your employees happy.

More Stories By Paul Diamond

Paul Diamond is Technology Sales Engineer at Markley Group. He comes to Markley Group with over 30 years experience in various technology roles, most of them in the Banking and Financial Services sectors. Prior to joining Markley Group, he spent several years at Brown Brothers Harriman (BBH) where he served as infrastructure manager, chief technologist and project manager. While there, he lead a Strategic Planning and Innovation team charged with creating both short and long term strategic technology plans to consolidate data centers, create regional operations centers and build data storage and archival operations plans.

Paul is an innovative thinker, known for being an early adopter of trends like VOIP, which he brought to BBH in 2005 to lessen costs while improving overall service and coverage capabilities.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@MicroservicesExpo Stories
DevOps is often described as a combination of technology and culture. Without both, DevOps isn't complete. However, applying the culture to outdated technology is a recipe for disaster; as response times grow and connections between teams are delayed by technology, the culture will die. A Nutanix Enterprise Cloud has many benefits that provide the needed base for a true DevOps paradigm. In his Day 3 Keynote at 20th Cloud Expo, Chris Brown, a Solutions Marketing Manager at Nutanix, will explore t...
Software development is a moving target. You have to keep your eye on trends in the tech space that haven’t even happened yet just to stay current. Consider what’s happened with augmented reality (AR) in this year alone. If you said you were working on an AR app in 2015, you might have gotten a lot of blank stares or jokes about Google Glass. Then Pokémon GO happened. Like AR, the trends listed below have been building steam for some time, but they’ll be taking off in surprising new directions b...
Everyone wants to use containers, but monitoring containers is hard. New ephemeral architecture introduces new challenges in how monitoring tools need to monitor and visualize containers, so your team can make sense of everything. In his session at @DevOpsSummit, David Gildeh, co-founder and CEO of Outlyer, will go through the challenges and show there is light at the end of the tunnel if you use the right tools and understand what you need to be monitoring to successfully use containers in your...
What if you could build a web application that could support true web-scale traffic without having to ever provision or manage a single server? Sounds magical, and it is! In his session at 20th Cloud Expo, Chris Munns, Senior Developer Advocate for Serverless Applications at Amazon Web Services, will show how to build a serverless website that scales automatically using services like AWS Lambda, Amazon API Gateway, and Amazon S3. We will review several frameworks that can help you build serverle...
@DevOpsSummit has been named the ‘Top DevOps Influencer' by iTrend. iTrend processes millions of conversations, tweets, interactions, news articles, press releases, blog posts - and extract meaning form them and analyzes mobile and desktop software platforms used to communicate, various metadata (such as geo location), and automation tools. In overall placement, @DevOpsSummit ranked as the number one ‘DevOps Influencer' followed by @CloudExpo at third, and @MicroservicesE at 24th.
The IT industry is undergoing a significant evolution to keep up with cloud application demand. We see this happening as a mindset shift, from traditional IT teams to more well-rounded, cloud-focused job roles. The IT industry has become so cloud-minded that Gartner predicts that by 2020, this cloud shift will impact more than $1 trillion of global IT spending. This shift, however, has left some IT professionals feeling a little anxious about what lies ahead. The good news is that cloud computin...
SYS-CON Events announced today that HTBase will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. HTBase (Gartner 2016 Cool Vendor) delivers a Composable IT infrastructure solution architected for agility and increased efficiency. It turns compute, storage, and fabric into fluid pools of resources that are easily composed and re-composed to meet each application’s needs. With HTBase, companies can quickly prov...
Culture is the most important ingredient of DevOps. The challenge for most organizations is defining and communicating a vision of beneficial DevOps culture for their organizations, and then facilitating the changes needed to achieve that. Often this comes down to an ability to provide true leadership. As a CIO, are your direct reports IT managers or are they IT leaders? The hard truth is that many IT managers have risen through the ranks based on their technical skills, not their leadership abi...
The essence of cloud computing is that all consumable IT resources are delivered as services. In his session at 15th Cloud Expo, Yung Chou, Technology Evangelist at Microsoft, demonstrated the concepts and implementations of two important cloud computing deliveries: Infrastructure as a Service (IaaS) and Platform as a Service (PaaS). He discussed from business and technical viewpoints what exactly they are, why we care, how they are different and in what ways, and the strategies for IT to transi...
After more than five years of DevOps, definitions are evolving, boundaries are expanding, ‘unicorns’ are no longer rare, enterprises are on board, and pundits are moving on. Can we now look at an evolution of DevOps? Should we? Is the foundation of DevOps ‘done’, or is there still too much left to do? What is mature, and what is still missing? What does the next 5 years of DevOps look like? In this Power Panel at DevOps Summit, moderated by DevOps Summit Conference Chair Andi Mann, panelists l...
Thanks to Docker and the DevOps revolution, microservices have emerged as the new way to build and deploy applications — and there are plenty of great reasons to embrace the microservices trend. If you are going to adopt microservices, you also have to understand that microservice architectures have many moving parts. When it comes to incident management, this presents an important difference between microservices and monolithic architectures. More moving parts mean more complexity to monitor an...
All organizations that did not originate this moment have a pre-existing culture as well as legacy technology and processes that can be more or less amenable to DevOps implementation. That organizational culture is influenced by the personalities and management styles of Executive Management, the wider culture in which the organization is situated, and the personalities of key team members at all levels of the organization. This culture and entrenched interests usually throw a wrench in the work...
DevOps is often described as a combination of technology and culture. Without both, DevOps isn't complete. However, applying the culture to outdated technology is a recipe for disaster; as response times grow and connections between teams are delayed by technology, the culture will die. A Nutanix Enterprise Cloud has many benefits that provide the needed base for a true DevOps paradigm.
Microservices (μServices) are a fascinating evolution of the Distributed Object Computing (DOC) paradigm. Initial design of DOC attempted to solve the problem of simplifying developing complex distributed applications by applying object-oriented design principles to disparate components operating across networked infrastructure. In this model, DOC “hid” the complexity of making this work from the developer regardless of the deployment architecture through the use of complex frameworks, such as C...
TechTarget storage websites are the best online information resource for news, tips and expert advice for the storage, backup and disaster recovery markets. By creating abundant, high-quality editorial content across more than 140 highly targeted technology-specific websites, TechTarget attracts and nurtures communities of technology buyers researching their companies' information technology needs. By understanding these buyers' content consumption behaviors, TechTarget creates the purchase inte...
We've all had that feeling before: The feeling that you're missing something that everyone else is in on. For today's IT leaders, that feeling might come up when you hear talk about cloud brokers. Meanwhile, you head back into your office and deal with your ever-growing shadow IT problem. But the cloud-broker whispers and your shadow IT issues are linked. If you're wondering "what the heck is a cloud broker?" we've got you covered.
In today's enterprise, digital transformation represents organizational change even more so than technology change, as customer preferences and behavior drive end-to-end transformation across lines of business as well as IT. To capitalize on the ubiquitous disruption driving this transformation, companies must be able to innovate at an increasingly rapid pace. Traditional approaches for driving innovation are now woefully inadequate for keeping up with the breadth of disruption and change facing...
In his General Session at 16th Cloud Expo, David Shacochis, host of The Hybrid IT Files podcast and Vice President at CenturyLink, investigated three key trends of the “gigabit economy" though the story of a Fortune 500 communications company in transformation. Narrating how multi-modal hybrid IT, service automation, and agile delivery all intersect, he will cover the role of storytelling and empathy in achieving strategic alignment between the enterprise and its information technology.
Microservices are a very exciting architectural approach that many organizations are looking to as a way to accelerate innovation. Microservices promise to allow teams to move away from monolithic "ball of mud" systems, but the reality is that, in the vast majority of organizations, different projects and technologies will continue to be developed at different speeds. How to handle the dependencies between these disparate systems with different iteration cycles? Consider the "canoncial problem" ...
The rise of containers and microservices has skyrocketed the rate at which new applications are moved into production environments today. While developers have been deploying containers to speed up the development processes for some time, there still remain challenges with running microservices efficiently. Most existing IT monitoring tools don’t actually maintain visibility into the containers that make up microservices. As those container applications move into production, some IT operations t...