Welcome!

Security Authors: Trevor Parsons, Vormetric Blog, Chirag Bakshi, Adam Vincent, Liz McMillan

Related Topics: Cloud Expo, SOA & WOA, Virtualization, Security, Big Data Journal, SDN Journal

Cloud Expo: Article

2014 Trends – The Year of the Insider Threat

As more and more organizations are adopting cloud strategies, there is now an added layer of complexity and sophistication

If last year underscored anything, it was the significant and far-reaching impact of breaches by trusted insiders - case in point, the Edward Snowden affair. What makes this such a critical trend for 2014 is the fact that as more and more organizations are adopting cloud strategies, there is now an added layer of complexity and sophistication when it comes to protecting who can access what types of sensitive data. The cloud makes it easier for organizations to conduct business, but that simplicity also translates into easier ways for insiders or un-trusted individuals to steal data - identity has become the new perimeter.

The number of organizations around the globe turning to a combination of traditional computing, virtualization, and public-cloud infrastructure to deliver business applications quickly, efficiently, and cost effectively is growing exponentially. As they migrate systems to the cloud, or leverage the scalability and elasticity of cloud computing to deliver entirely new applications, they can run headlong into security and compliance issues that must be solved to protect systems and make auditors happy. In addition to protecting privileged access to servers and network gear, virtualization and cloud computing add important new items that need to be locked down. First, organizations need to protect virtualization and cloud management consoles that provide unprecedented administrative power to create, configure, delete and copy network and server resources. Second, organizations must ensure the cloud management application programming interfaces (APIs) that transfer enormous administrative power to scripts, programs and DevOps tools are adequately controlled. Companies that want to ensure their data remains safe regardless of whether it is in a traditional database, in the cloud, or some variation of both, now need to seriously consider the security ramifications of having a lax privileged user policy - especially in an era where a few clicks of the mouse in the console, or a few commands in a script can wreak havoc.

The Snowden breach is a perfect example of the ramifications organizations typically overlook when they consider the negatives of a breach. According to different reports, the NSA has spent millions of dollars replacing software and hardware systems to mitigate the risk of undetected compromises on resources to which Snowden had access. These sorts of costs - forensic analysis, re-imaging, and repairing or replacing compromised systems - are frequently overlooked when assessing the potential value of privileged identity management programs. Harder to measure are the impacts arising from the disclosure or theft of sensitive and confidential information. Not to mention the potential for embarrassment and loss of trust from essential stakeholders including partners, customers, and others.

Another factor we see catapulting privileged users and insider threats as a key trend in 2014 is the increased attention toward regulations and compliance. Regulators are extending security and privacy mandates to cover the risks posed by privileged users and administrative accounts. High-profile insider breaches (e.g., Snowden, Wikileaks), plus increasingly advanced spearfishing and APT-based attacks, have heightened regulator and auditor attention to privileged user threats. And there are specific regulations that apply to specific industries. Some of the regulations include penalties for non-compliance, and many of these mandates continue to be updated to contend with the latest threats. A good number of them have been updated with specific requirements relevant to privileged identity management.

Privileged identity management protects organizations from the risks privileged users pose to systems and data. Privileged users - people like systems administrators, contractors, and third-party vendors - have routine access to the most sensitive IT resources. It's no wonder studies consistently show the largest and most damaging breaches are often traced to these individuals. Privileged identity management software supports and enforces the policies and controls needed to mitigate risks created by privileged users, those with elevated rights and access to administrative accounts, credentials, and systems.

Privileged identity management isn't just about privileged identities, though being able to positively identify powerful users and vault and manage their passwords is a key part of the equation. Next generation privileged identity management platforms also control, monitor and audit privileged users, ensuring they can access only explicitly authorized resources. Comprehensive privileged identity management tools also record privileged sessions so you know exactly what happens during each session - and you can prove it to your auditor. These tools also enable you to lock down virtual and cloud "super-user" administrative consoles, such as VMware's vCenter Server and the Amazon Web Services Management Console.

The fallout of the NSA/Snowden leak and other "insider threat" and "privileged user" incidents has significantly broadened interest in privileged identity management tools, and we expect that to only increase as cloud and virtual technologies continue to evolve. Inbound inquires to Xceedium, and likely other PIM vendors, have increased beyond the usual suspects, such as the traditional security leaders in banking and financial services or organizations with critical infrastructure and those other markets governed by strict security regulations. We're now seeing a big increase in interest across numerous industries and geographic regions.

As insider threats continue to shine a light on the need for next generation privileged identity management solutions, the important thing to remember is to focus on solutions that go beyond simple password management. The ability to attribute actions taken to specific individuals, as well as real-time logging and session recording, make it easier to proactively alert security teams to issues and conduct forensic analysis. If questions arise about an individual's activities, it's a straightforward task to determine exactly what they did and when. Cloud computing introduces important new administrative systems that need to be controlled and monitored. While security breaches are bound to happen, a modern privileged identity management system can make sure you are in a position to appropriately investigate what happened and keep the fallout to a minimum.

More Stories By Dale R. Gardner

Dale R. Gardner is Director of Product Marketing at Xceedium. He's developed and launched multiple network, systems, and security management products for the enterprise market. A former META Group analyst, he started his career as a programmer and networking specialist.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
The Internet of Things (IoT) promises to evolve the way the world does business; however, understanding how to apply it to your company can be a mystery. Most people struggle with understanding the potential business uses or tend to get caught up in the technology, resulting in solutions that fail to meet even minimum business goals. In his session at @ThingsExpo, Jesse Shiah, CEO / President / Co-Founder of AgilePoint Inc., showed what is needed to leverage the IoT to transform your business. He discussed opportunities and challenges ahead for the IoT from a market and technical point of vie...
IoT is still a vague buzzword for many people. In his session at @ThingsExpo, Mike Kavis, Vice President & Principal Cloud Architect at Cloud Technology Partners, discussed the business value of IoT that goes far beyond the general public's perception that IoT is all about wearables and home consumer services. He also discussed how IoT is perceived by investors and how venture capitalist access this space. Other topics discussed were barriers to success, what is new, what is old, and what the future may hold. Mike Kavis is Vice President & Principal Cloud Architect at Cloud Technology Pa...
Dale Kim is the Director of Industry Solutions at MapR. His background includes a variety of technical and management roles at information technology companies. While his experience includes work with relational databases, much of his career pertains to non-relational data in the areas of search, content management, and NoSQL, and includes senior roles in technical marketing, sales engineering, and support engineering. Dale holds an MBA from Santa Clara University, and a BA in Computer Science from the University of California, Berkeley.
The Internet of Things (IoT) is rapidly in the process of breaking from its heretofore relatively obscure enterprise applications (such as plant floor control and supply chain management) and going mainstream into the consumer space. More and more creative folks are interconnecting everyday products such as household items, mobile devices, appliances and cars, and unleashing new and imaginative scenarios. We are seeing a lot of excitement around applications in home automation, personal fitness, and in-car entertainment and this excitement will bleed into other areas. On the commercial side, m...
The Industrial Internet revolution is now underway, enabled by connected machines and billions of devices that communicate and collaborate. The massive amounts of Big Data requiring real-time analysis is flooding legacy IT systems and giving way to cloud environments that can handle the unpredictable workloads. Yet many barriers remain until we can fully realize the opportunities and benefits from the convergence of machines and devices with Big Data and the cloud, including interoperability, data security and privacy.
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is now open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
"People are a lot more knowledgeable about APIs now. There are two types of people who work with APIs - IT people who want to use APIs for something internal and the product managers who want to do something outside APIs for people to connect to them," explained Roberto Medrano, Executive Vice President at SOA Software, in this SYS-CON.tv interview at Cloud Expo, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
Performance is the intersection of power, agility, control, and choice. If you value performance, and more specifically consistent performance, you need to look beyond simple virtualized compute. Many factors need to be considered to create a truly performant environment. In his General Session at 15th Cloud Expo, Harold Hannon, Sr. Software Architect at SoftLayer, discussed how to take advantage of a multitude of compute options and platform features to make cloud the cornerstone of your online presence.
SYS-CON Media announced that Splunk, a provider of the leading software platform for real-time Operational Intelligence, has launched an ad campaign on Big Data Journal. Splunk software and cloud services enable organizations to search, monitor, analyze and visualize machine-generated big data coming from websites, applications, servers, networks, sensors and mobile devices. The ads focus on delivering ROI - how improved uptime delivered $6M in annual ROI, improving customer operations by mining large volumes of unstructured data, and how data tracking delivers uptime when it matters most.
In this Women in Technology Power Panel at 15th Cloud Expo, moderated by Anne Plese, Senior Consultant, Cloud Product Marketing at Verizon Enterprise, Esmeralda Swartz, CMO at MetraTech; Evelyn de Souza, Data Privacy and Compliance Strategy Leader at Cisco Systems; Seema Jethani, Director of Product Management at Basho Technologies; Victoria Livschitz, CEO of Qubell Inc.; Anne Hungate, Senior Director of Software Quality at DIRECTV, discussed what path they took to find their spot within the technology industry and how do they see opportunities for other women in their area of expertise.
DevOps Summit 2015 New York, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that it is now accepting Keynote Proposals. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete at launch. DevOps may be disruptive, but it is essential.
Almost everyone sees the potential of Internet of Things but how can businesses truly unlock that potential. The key will be in the ability to discover business insight in the midst of an ocean of Big Data generated from billions of embedded devices via Systems of Discover. Businesses will also need to ensure that they can sustain that insight by leveraging the cloud for global reach, scale and elasticity.
The Internet of Things will greatly expand the opportunities for data collection and new business models driven off of that data. In her session at @ThingsExpo, Esmeralda Swartz, CMO of MetraTech, discussed how for this to be effective you not only need to have infrastructure and operational models capable of utilizing this new phenomenon, but increasingly service providers will need to convince a skeptical public to participate. Get ready to show them the money!
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is now open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
Connected devices and the Internet of Things are getting significant momentum in 2014. In his session at Internet of @ThingsExpo, Jim Hunter, Chief Scientist & Technology Evangelist at Greenwave Systems, examined three key elements that together will drive mass adoption of the IoT before the end of 2015. The first element is the recent advent of robust open source protocols (like AllJoyn and WebRTC) that facilitate M2M communication. The second is broad availability of flexible, cost-effective storage designed to handle the massive surge in back-end data in a world where timely analytics is e...
"There is a natural synchronization between the business models, the IoT is there to support ,” explained Brendan O'Brien, Co-founder and Chief Architect of Aria Systems, in this SYS-CON.tv interview at the 15th International Cloud Expo®, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
The Internet of Things will put IT to its ultimate test by creating infinite new opportunities to digitize products and services, generate and analyze new data to improve customer satisfaction, and discover new ways to gain a competitive advantage across nearly every industry. In order to help corporate business units to capitalize on the rapidly evolving IoT opportunities, IT must stand up to a new set of challenges. In his session at @ThingsExpo, Jeff Kaplan, Managing Director of THINKstrategies, will examine why IT must finally fulfill its role in support of its SBUs or face a new round of...
The BPM world is going through some evolution or changes where traditional business process management solutions really have nowhere to go in terms of development of the road map. In this demo at 15th Cloud Expo, Kyle Hansen, Director of Professional Services at AgilePoint, shows AgilePoint’s unique approach to dealing with this market circumstance by developing a rapid application composition or development framework.

ARMONK, N.Y., Nov. 20, 2014 /PRNewswire/ --  IBM (NYSE: IBM) today announced that it is bringing a greater level of control, security and flexibility to cloud-based application development and delivery with a single-tenant version of Bluemix, IBM's platform-as-a-service. The new platform enables developers to build ap...

“The age of the Internet of Things is upon us,” stated Thomas Svensson, senior vice-president and general manager EMEA, ThingWorx, “and working with forward-thinking companies, such as Elisa, enables us to deploy our leading technology so that customers can profit from complete, end-to-end solutions.” ThingWorx, a PTC® (Nasdaq: PTC) business and Internet of Things (IoT) platform provider, announced on Monday that Elisa, Finnish provider of mobile and fixed broadband subscriptions, will deploy ThingWorx® platform technology to enable a new Elisa IoT service in Finland and Estonia.