Welcome!

Cloud Security Authors: Pat Romanski, Elizabeth White, Liz McMillan, Yeshim Deniz, Ed Featherston

Related Topics: Cloud Security, Mobile IoT, @CloudExpo

Cloud Security: Article

Top Four IT Trends to Master in 2012

Organizations that get their Windows migrations wrong, could suffer the consequences for many years to come

Last year saw some of the biggest security breaches to date, and some large organizations are feeling the heat. Anonymous and LulzSec made their presence known, taking on a large number targets. RSA suffered a massive breach, inadvertently putting the security of its many customers in jeopardy. The Sony Playstation Network had to be shut down following a breach. Even Apple cracked under an attack from malware writers.

Whether this year will be as eventful remains to be seen but what we can predict is cybercriminals will continue to look to profit from their illicit activities, albeit with evolving tactics. Rather than wait for them to strike, a little foresight can help prepare to fight back. So, with this in mind, this article draws on the author's experience of the corporate security landscape to predict four key threats he believes organizations will have to face in this Olympic year and how to mitigate them. Perhaps more important he also looks at the equally Olympic battle organizations face as they migrate away from Windows XP to Windows 7.

1. Mobile Security
The explosion of mobile computing, for example, the various tablets that stormed the enterprise during 2011, shows no sign of slowing down. However, for too long, the security of these devices has continued to lag behind that of traditional desktops and laptops. Many enterprises have struggled with pressure from the workforce to allow these technological marvels, and the precarious balancing act to do so securely.

While many argue that Microsoft has ground to catch up in the tablet market, I think 2012 could see Microsoft gaining mindshare, as Windows 8 will be more appealing to the corporate world. Expected to go into beta in 2012, it is widely anticipated to provide superior integrated security features. In combination, Microsoft is following Apple's lead of having a dedicated App Store, but it's expected to include corporate controls, which will give companies a more ‘corporate friendly' tablet. The ability to connect Windows 8 tablets to a domain will ensure that these devices can be secured just like any other Windows endpoint. For this reason I think Microsoft tablets will be viewed favorably in the corporate environment.

2. Bring Your Device to Work
But it's not just tablets - smartphones too pose a serious security concern to the enterprise, especially with the growing trend for people to use their own personal devices to improve their work life balance. Lured by aesthetics and functionality, little regard is given to their corporate security offering. Personal laptops are of even greater concern as the specification could present the organization with a rather large liability headache.

One of the major concerns is that the apps users download to these devices could introduce vulnerabilities. In addition, users, wanting to take advantage of the flexibility and freedom their device can deliver, will be looking to transfer corporate data on to them. The technology-savvy users will use external cloud storage accounts, such as Dropbox, or even email it out of the network to access it externally. The biggest risk here is data loss so, naturally, this is where we will see the big investment, as companies battle to control corporate data.

A fairly new advancement on the block that could gain traction in 2012 is the hypervisor for smartphones, which will allow a phone to be effectively split into two distinct profiles, which are securely isolated from one another. The corporate side could be managed by the enterprise, complete with enhanced security solutions and controls, with the users having a personal side for their apps, music, contacts, etc.

3. Endpoint Security
That leads us nicely to my next point. With the explosion of endpoint devices and the resultant mobility, naturally we've also seen an increased focus on endpoint security.

Solutions that are able to detect the criminals' increasingly diverse arsenal of threats will become crucial in the battle against stealthy and persistent malware. As a result, the adoption of application control and privilege management solutions within the operating system will increase in order to provide a more proactive approach to endpoint security. Many malware attacks can be mitigated, and even eliminated, with better control over application execution and user privileges. Both of these solutions will become more relevant on the server-side too, as organizations look to comply with external or internal compliance initiatives, and demonstrate that servers are secured and administrator activity is strictly controlled and monitored.

4. Cloud Security
Finally, no 2012 prediction would be complete without a look to the sky. My belief is compliance could be the key differentiator here.

While smaller organizations will continue to adopt cloud-based offerings more readily, larger organizations, especially those governed by regulatory compliance, will continue to tread more carefully and stick to more mature cloud offerings, such as CRM solutions.

That said, the security of servers in the data centers of cloud providers will drive more innovative security offerings at the hypervisor level. This in turn will allow the security software to get a complete view of the hosted servers, especially when dealing with stealthy attacks.

If cloud providers are to appeal to customers in highly regulated industries, then administrator access, and their actions on servers in the data centers, needs to be better controlled and monitored.

Whether this year will see as many high profile incidents as 2011 remains to be seen. However, we are confident that across all industries and sector, one challenge this year will be a common one: organizations looking to migrate across to Windows 7 must ‘get it right' this year or it could all be over for the next few years as they struggle to regain control, if they can manage it at all. Don't wait to see what the criminals have in store for you - act now and get ahead of the game.

More Stories By Paul Kenyon

Paul Kenyon is co-founder and Chief Operations Officer at Avecto. He is responsible for driving the revenue and growing sales globally with a focus on North America and Europe.

Paul is a successful business executive with an outstanding 15-year track record in building, growing and leading high-performing, multinational high tech companies in North America, Europe and the Pacific Rim. In 1999, he started AppSense, the global leader in User Environment Management for businesses and service providers. With the lead role on global sales, AppSense quickly grew to profitability with revenues of over $30 million.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
Charles Araujo is an industry analyst, internationally recognized authority on the Digital Enterprise and author of The Quantum Age of IT: Why Everything You Know About IT is About to Change. As Principal Analyst with Intellyx, he writes, speaks and advises organizations on how to navigate through this time of disruption. He is also the founder of The Institute for Digital Transformation and a sought after keynote speaker. He has been a regular contributor to both InformationWeek and CIO Insight...
DXWorldEXPO LLC, the producer of the world's most influential technology conferences and trade shows has announced the 22nd International CloudEXPO | DXWorldEXPO "Early Bird Registration" is now open. Register for Full Conference "Gold Pass" ▸ Here (Expo Hall ▸ Here)
Join IBM November 1 at 21st Cloud Expo at the Santa Clara Convention Center in Santa Clara, CA, and learn how IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Cognitive analysis impacts today’s systems with unparalleled ability that were previously available only to manned, back-end operations. Thanks to cloud processing, IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Imagine a robot vacuum that becomes your personal assistant tha...
"MobiDev is a software development company and we do complex, custom software development for everybody from entrepreneurs to large enterprises," explained Alan Winters, U.S. Head of Business Development at MobiDev, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
I think DevOps is now a rambunctious teenager - it's starting to get a mind of its own, wanting to get its own things but it still needs some adult supervision," explained Thomas Hooker, VP of marketing at CollabNet, in this SYS-CON.tv interview at DevOps Summit at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
Recently, WebRTC has a lot of eyes from market. The use cases of WebRTC are expanding - video chat, online education, online health care etc. Not only for human-to-human communication, but also IoT use cases such as machine to human use cases can be seen recently. One of the typical use-case is remote camera monitoring. With WebRTC, people can have interoperability and flexibility for deploying monitoring service. However, the benefit of WebRTC for IoT is not only its convenience and interopera...
Cloud-enabled transformation has evolved from cost saving measure to business innovation strategy -- one that combines the cloud with cognitive capabilities to drive market disruption. Learn how you can achieve the insight and agility you need to gain a competitive advantage. Industry-acclaimed CTO and cloud expert, Shankar Kalyana presents. Only the most exceptional IBMers are appointed with the rare distinction of IBM Fellow, the highest technical honor in the company. Shankar has also receive...
It is of utmost importance for the future success of WebRTC to ensure that interoperability is operational between web browsers and any WebRTC-compliant client. To be guaranteed as operational and effective, interoperability must be tested extensively by establishing WebRTC data and media connections between different web browsers running on different devices and operating systems. In his session at WebRTC Summit at @ThingsExpo, Dr. Alex Gouaillard, CEO and Founder of CoSMo Software, presented ...
WebRTC is great technology to build your own communication tools. It will be even more exciting experience it with advanced devices, such as a 360 Camera, 360 microphone, and a depth sensor camera. In his session at @ThingsExpo, Masashi Ganeko, a manager at INFOCOM Corporation, introduced two experimental projects from his team and what they learned from them. "Shotoku Tamago" uses the robot audition software HARK to track speakers in 360 video of a remote party. "Virtual Teleport" uses a multip...
Business professionals no longer wonder if they'll migrate to the cloud; it's now a matter of when. The cloud environment has proved to be a major force in transitioning to an agile business model that enables quick decisions and fast implementation that solidify customer relationships. And when the cloud is combined with the power of cognitive computing, it drives innovation and transformation that achieves astounding competitive advantage.
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at Cloud Expo, Ed Featherston, a director and senior enterprise architect at Collaborative Consulting, discussed the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
IoT is rapidly becoming mainstream as more and more investments are made into the platforms and technology. As this movement continues to expand and gain momentum it creates a massive wall of noise that can be difficult to sift through. Unfortunately, this inevitably makes IoT less approachable for people to get started with and can hamper efforts to integrate this key technology into your own portfolio. There are so many connected products already in place today with many hundreds more on the h...
When shopping for a new data processing platform for IoT solutions, many development teams want to be able to test-drive options before making a choice. Yet when evaluating an IoT solution, it’s simply not feasible to do so at scale with physical devices. Building a sensor simulator is the next best choice; however, generating a realistic simulation at very high TPS with ease of configurability is a formidable challenge. When dealing with multiple application or transport protocols, you would be...
Detecting internal user threats in the Big Data eco-system is challenging and cumbersome. Many organizations monitor internal usage of the Big Data eco-system using a set of alerts. This is not a scalable process given the increase in the number of alerts with the accelerating growth in data volume and user base. Organizations are increasingly leveraging machine learning to monitor only those data elements that are sensitive and critical, autonomously establish monitoring policies, and to detect...
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, provided an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settl...
In his session at @ThingsExpo, Dr. Robert Cohen, an economist and senior fellow at the Economic Strategy Institute, presented the findings of a series of six detailed case studies of how large corporations are implementing IoT. The session explored how IoT has improved their economic performance, had major impacts on business models and resulted in impressive ROIs. The companies covered span manufacturing and services firms. He also explored servicification, how manufacturing firms shift from se...
DevOpsSummit New York 2018, colocated with CloudEXPO | DXWorldEXPO New York 2018 will be held November 11-13, 2018, in New York City. Digital Transformation (DX) is a major focus with the introduction of DXWorldEXPO within the program. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of bus...
The Jevons Paradox suggests that when technological advances increase efficiency of a resource, it results in an overall increase in consumption. Writing on the increased use of coal as a result of technological improvements, 19th-century economist William Stanley Jevons found that these improvements led to the development of new ways to utilize coal. In his session at 19th Cloud Expo, Mark Thiele, Chief Strategy Officer for Apcera, compared the Jevons Paradox to modern-day enterprise IT, examin...
IoT solutions exploit operational data generated by Internet-connected smart “things” for the purpose of gaining operational insight and producing “better outcomes” (for example, create new business models, eliminate unscheduled maintenance, etc.). The explosive proliferation of IoT solutions will result in an exponential growth in the volume of IoT data, precipitating significant Information Governance issues: who owns the IoT data, what are the rights/duties of IoT solutions adopters towards t...
Amazon started as an online bookseller 20 years ago. Since then, it has evolved into a technology juggernaut that has disrupted multiple markets and industries and touches many aspects of our lives. It is a relentless technology and business model innovator driving disruption throughout numerous ecosystems. Amazon’s AWS revenues alone are approaching $16B a year making it one of the largest IT companies in the world. With dominant offerings in Cloud, IoT, eCommerce, Big Data, AI, Digital Assista...