Welcome!

Cloud Security Authors: Elizabeth White, Liz McMillan, Derek Weeks, Darren Anstee, Mark Hoover

Related Topics: Cloud Security, Mobile IoT, @CloudExpo

Cloud Security: Article

Top Four IT Trends to Master in 2012

Organizations that get their Windows migrations wrong, could suffer the consequences for many years to come

Last year saw some of the biggest security breaches to date, and some large organizations are feeling the heat. Anonymous and LulzSec made their presence known, taking on a large number targets. RSA suffered a massive breach, inadvertently putting the security of its many customers in jeopardy. The Sony Playstation Network had to be shut down following a breach. Even Apple cracked under an attack from malware writers.

Whether this year will be as eventful remains to be seen but what we can predict is cybercriminals will continue to look to profit from their illicit activities, albeit with evolving tactics. Rather than wait for them to strike, a little foresight can help prepare to fight back. So, with this in mind, this article draws on the author's experience of the corporate security landscape to predict four key threats he believes organizations will have to face in this Olympic year and how to mitigate them. Perhaps more important he also looks at the equally Olympic battle organizations face as they migrate away from Windows XP to Windows 7.

1. Mobile Security
The explosion of mobile computing, for example, the various tablets that stormed the enterprise during 2011, shows no sign of slowing down. However, for too long, the security of these devices has continued to lag behind that of traditional desktops and laptops. Many enterprises have struggled with pressure from the workforce to allow these technological marvels, and the precarious balancing act to do so securely.

While many argue that Microsoft has ground to catch up in the tablet market, I think 2012 could see Microsoft gaining mindshare, as Windows 8 will be more appealing to the corporate world. Expected to go into beta in 2012, it is widely anticipated to provide superior integrated security features. In combination, Microsoft is following Apple's lead of having a dedicated App Store, but it's expected to include corporate controls, which will give companies a more ‘corporate friendly' tablet. The ability to connect Windows 8 tablets to a domain will ensure that these devices can be secured just like any other Windows endpoint. For this reason I think Microsoft tablets will be viewed favorably in the corporate environment.

2. Bring Your Device to Work
But it's not just tablets - smartphones too pose a serious security concern to the enterprise, especially with the growing trend for people to use their own personal devices to improve their work life balance. Lured by aesthetics and functionality, little regard is given to their corporate security offering. Personal laptops are of even greater concern as the specification could present the organization with a rather large liability headache.

One of the major concerns is that the apps users download to these devices could introduce vulnerabilities. In addition, users, wanting to take advantage of the flexibility and freedom their device can deliver, will be looking to transfer corporate data on to them. The technology-savvy users will use external cloud storage accounts, such as Dropbox, or even email it out of the network to access it externally. The biggest risk here is data loss so, naturally, this is where we will see the big investment, as companies battle to control corporate data.

A fairly new advancement on the block that could gain traction in 2012 is the hypervisor for smartphones, which will allow a phone to be effectively split into two distinct profiles, which are securely isolated from one another. The corporate side could be managed by the enterprise, complete with enhanced security solutions and controls, with the users having a personal side for their apps, music, contacts, etc.

3. Endpoint Security
That leads us nicely to my next point. With the explosion of endpoint devices and the resultant mobility, naturally we've also seen an increased focus on endpoint security.

Solutions that are able to detect the criminals' increasingly diverse arsenal of threats will become crucial in the battle against stealthy and persistent malware. As a result, the adoption of application control and privilege management solutions within the operating system will increase in order to provide a more proactive approach to endpoint security. Many malware attacks can be mitigated, and even eliminated, with better control over application execution and user privileges. Both of these solutions will become more relevant on the server-side too, as organizations look to comply with external or internal compliance initiatives, and demonstrate that servers are secured and administrator activity is strictly controlled and monitored.

4. Cloud Security
Finally, no 2012 prediction would be complete without a look to the sky. My belief is compliance could be the key differentiator here.

While smaller organizations will continue to adopt cloud-based offerings more readily, larger organizations, especially those governed by regulatory compliance, will continue to tread more carefully and stick to more mature cloud offerings, such as CRM solutions.

That said, the security of servers in the data centers of cloud providers will drive more innovative security offerings at the hypervisor level. This in turn will allow the security software to get a complete view of the hosted servers, especially when dealing with stealthy attacks.

If cloud providers are to appeal to customers in highly regulated industries, then administrator access, and their actions on servers in the data centers, needs to be better controlled and monitored.

Whether this year will see as many high profile incidents as 2011 remains to be seen. However, we are confident that across all industries and sector, one challenge this year will be a common one: organizations looking to migrate across to Windows 7 must ‘get it right' this year or it could all be over for the next few years as they struggle to regain control, if they can manage it at all. Don't wait to see what the criminals have in store for you - act now and get ahead of the game.

More Stories By Paul Kenyon

Paul Kenyon is co-founder and Chief Operations Officer at Avecto. He is responsible for driving the revenue and growing sales globally with a focus on North America and Europe.

Paul is a successful business executive with an outstanding 15-year track record in building, growing and leading high-performing, multinational high tech companies in North America, Europe and the Pacific Rim. In 1999, he started AppSense, the global leader in User Environment Management for businesses and service providers. With the lead role on global sales, AppSense quickly grew to profitability with revenues of over $30 million.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
SYS-CON Events announced today that Roundee / LinearHub will exhibit at the WebRTC Summit at @ThingsExpo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. LinearHub provides Roundee Service, a smart platform for enterprise video conferencing with enhanced features such as automatic recording and transcription service. Slack users can integrate Roundee to their team via Slack’s App Directory, and '/roundee' command lets your video conference ...
Digital transformation is too big and important for our future success to not understand the rules that apply to it. The first three rules for winning in this age of hyper-digital transformation are: Advantages in speed, analytics and operational tempos must be captured by implementing an optimized information logistics system (OILS) Real-time operational tempos (IT, people and business processes) must be achieved Businesses that can "analyze data and act and with speed" will dominate those t...
Information technology is an industry that has always experienced change, and the dramatic change sweeping across the industry today could not be truthfully described as the first time we've seen such widespread change impacting customer investments. However, the rate of the change, and the potential outcomes from today's digital transformation has the distinct potential to separate the industry into two camps: Organizations that see the change coming, embrace it, and successful leverage it; and...
There is growing need for data-driven applications and the need for digital platforms to build these apps. In his session at 19th Cloud Expo, Muddu Sudhakar, VP and GM of Security & IoT at Splunk, will cover different PaaS solutions and Big Data platforms that are available to build applications. In addition, AI and machine learning are creating new requirements that developers need in the building of next-gen apps. The next-generation digital platforms have some of the past platform needs a...
Almost two-thirds of companies either have or soon will have IoT as the backbone of their business in 2016. However, IoT is far more complex than most firms expected. How can you not get trapped in the pitfalls? In his session at @ThingsExpo, Tony Shan, a renowned visionary and thought leader, will introduce a holistic method of IoTification, which is the process of IoTifying the existing technology and business models to adopt and leverage IoT. He will drill down to the components in this fra...
SYS-CON Events announced today that Numerex Corp, a leading provider of managed enterprise solutions enabling the Internet of Things (IoT), will exhibit at the 19th International Cloud Expo | @ThingsExpo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Numerex Corp. (NASDAQ:NMRX) is a leading provider of managed enterprise solutions enabling the Internet of Things (IoT). The Company's solutions produce new revenue streams or create operating...
IoT is fundamentally transforming the auto industry, turning the vehicle into a hub for connected services, including safety, infotainment and usage-based insurance. Auto manufacturers – and businesses across all verticals – have built an entire ecosystem around the Connected Car, creating new customer touch points and revenue streams. In his session at @ThingsExpo, Macario Namie, Head of IoT Strategy at Cisco Jasper, will share real-world examples of how IoT transforms the car from a static p...
I'm a lonely sensor. I spend all day telling the world how I'm feeling, but none of the other sensors seem to care. I want to be connected. I want to build relationships with other sensors to be more useful for my human. I want my human to understand that when my friends next door are too hot for a while, I'll soon be flaming. And when all my friends go outside without me, I may be left behind. Don't just log my data; use the relationship graph. In his session at @ThingsExpo, Ryan Boyd, Engi...
SYS-CON Events announced today that Pulzze Systems will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Pulzze Systems, Inc. provides infrastructure products for the Internet of Things to enable any connected device and system to carry out matched operations without programming. For more information, visit http://www.pulzzesystems.com.
If you’re responsible for an application that depends on the data or functionality of various IoT endpoints – either sensors or devices – your brand reputation depends on the security, reliability, and compliance of its many integrated parts. If your application fails to deliver the expected business results, your customers and partners won't care if that failure stems from the code you developed or from a component that you integrated. What can you do to ensure that the endpoints work as expect...
The Internet of Things can drive efficiency for airlines and airports. In their session at @ThingsExpo, Shyam Varan Nath, Principal Architect with GE, and Sudip Majumder, senior director of development at Oracle, will discuss the technical details of the connected airline baggage and related social media solutions. These IoT applications will enhance travelers' journey experience and drive efficiency for the airlines and the airports. The session will include a working demo and a technical d...
SYS-CON Events announced today that Commvault, a global leader in enterprise data protection and information management, has been named “Bronze Sponsor” of SYS-CON's 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Commvault is a leading provider of data protection and information management solutions, helping companies worldwide activate their data to drive more value and business insight and to transform moder...
The Transparent Cloud-computing Consortium (abbreviation: T-Cloud Consortium) will conduct research activities into changes in the computing model as a result of collaboration between "device" and "cloud" and the creation of new value and markets through organic data processing High speed and high quality networks, and dramatic improvements in computer processing capabilities, have greatly changed the nature of applications and made the storing and processing of data on the network commonplace.
SYS-CON Events announced today that Bsquare has been named “Silver Sponsor” of SYS-CON's @ThingsExpo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. For more than two decades, Bsquare has helped its customers extract business value from a broad array of physical assets by making them intelligent, connecting them, and using the data they generate to optimize business processes.
Fact is, enterprises have significant legacy voice infrastructure that’s costly to replace with pure IP solutions. How can we bring this analog infrastructure into our shiny new cloud applications? There are proven methods to bind both legacy voice applications and traditional PSTN audio into cloud-based applications and services at a carrier scale. Some of the most successful implementations leverage WebRTC, WebSockets, SIP and other open source technologies. In his session at @ThingsExpo, Da...
The vision of a connected smart home is becoming reality with the application of integrated wireless technologies in devices and appliances. The use of standardized and TCP/IP networked wireless technologies in line-powered and battery operated sensors and controls has led to the adoption of radios in the 2.4GHz band, including Wi-Fi, BT/BLE and 802.15.4 applied ZigBee and Thread. This is driving the need for robust wireless coexistence for multiple radios to ensure throughput performance and th...
Enterprise IT has been in the era of Hybrid Cloud for some time now. But it seems most conversations about Hybrid are focused on integrating AWS, Microsoft Azure, or Google ECM into existing on-premises systems. Where is all the Private Cloud? What do technology providers need to do to make their offerings more compelling? How should enterprise IT executives and buyers define their focus, needs, and roadmap, and communicate that clearly to the providers?
SYS-CON Events announced today that SoftLayer, an IBM Company, has been named “Gold Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York, New York. SoftLayer, an IBM Company, provides cloud infrastructure as a service from a growing number of data centers and network points of presence around the world. SoftLayer’s customers range from Web startups to global enterprises.
There is little doubt that Big Data solutions will have an increasing role in the Enterprise IT mainstream over time. Big Data at Cloud Expo - to be held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA - has announced its Call for Papers is open. Cloud computing is being adopted in one form or another by 94% of enterprises today. Tens of billions of new devices are being connected to The Internet of Things. And Big Data is driving this bus. An exponential increase is...
DevOps at Cloud Expo, taking place Nov 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 19th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long dev...