Showing posts with label Cloud. Show all posts
Showing posts with label Cloud. Show all posts

Saturday, March 26, 2016

CSA: IT Perception of Cloud Services Has Increased

An increasing number of enterprise employees are asking their IT security organizations to make the jump to cloud services, according to a recent studyfrom Cloud Security Alliance. The increase in positive perception toward cloud adoption could be indicative of a widespread change in public opinion regarding the safety and reliability of the cloud services market as a whole.
CSA’s survey, titled “The Cloud Balancing Act for IT: Between Promise and Peril” polled more than 200 IT and security professionals in the Americas, EMEA and APAC to gage their perception of the importance of cloud services and their willingness to make the jump from legacy services to the cloud. CSA found that 64.9 percent of IT trusts the cloud as much or more than their on-premise solutions. In fact, security professionals surveyed said they received 10.6 requests, on average, per month from employees looking for additional cloud services within their business.The survey also indicated that 71 percent of companies surveyed have set up a formal process for employees to request cloud services - a sure sign of the rapid-fire requests for virtual solutions being hurled at IT pros on a weekly basis.
So how has perception about the importance of cloud services changed over the past several years? In the past, business owners accustomed to utilizing legacy storage and in-house services struggled to see the benefits of cloud computing, especially in light of recent high-profile data leaks and controversy as to the effectiveness of remote solutions. Like any new technology, cloud services were strange and different from the norm, causing those adverse to change to shy away from their use for fear of exposing sensitive information.
But in recent years, cloud has become increasingly more prevalent in both consumer and enterprise use, and in doing so has demonstrated its worth as a replacement for both physical storage and traditional data center services. While many organizations still have their reservations about the reliability of the cloud, even those reluctant to change their ways are beginning to embrace these services.
“As a growing number of companies have become more confident in cloud security measures and, with that, are moving their systems of records to the cloud, the role of IT and its relationship to the line of business is changing,” said Jim Reavis, CEO of the CSA, in a statement. “This survey provides excellent insight into what security professionals are doing to minimize the risks and maximize the benefits of transforming their businesses into cloud-first organizations.”
The study, which was sponsored by Skyhigh Networks, also polled respondents on adjacent topics related to cloud security. The most interesting highlights included:
  • Customer relationship management (CRM) is the most widely used cloud-based system, according to respondents.
  • Having a Chief Information Security Officer, or CISO, in place generally makes employees feel more prepared to take on a potential cyber attack.
  • People, not programs, are the top barrier to stopping data loss in the cloud.
  • Nearly a quarter of companies surveyed said they would pay a ransom to a hacker to prevent a cyber attack. Of those, 14 percent said they would be willing to pay in excess of $1 million.
Of course, a company like Skyhigh Networks has a vested interest in convincing businesses to switch from legacy to cloud security solutions, but the findings in this study are solid in that virtual security can indeed be a safe alternative to physical systems. While we are unlikely to ever see a 100 percent migration to cloud services in terms of enterprise IT, the results are heartening for those who already know the benefit of taking their business processes beyond the confines of the data center.

Cato Networks Unveils NSaaS Platform, Assigns New Americas Channel Chief

Network security startupCato Networks is looking to provide channel partners with the ability to provide Network Security as a Service (NSaaS) to their customers with the launch of Cato Cloud, a managed services alternative to traditional network security solutions.
Like other “as a service” solutions of its class, Cato Cloud takes the concept of legacy network security solutions, which were traditionally expensive to utilize across businesses with distributed infrastructures, and allows IT administrators to virtualize their security for use across the entire network. The company said its approach to network security cuts down on the cost of distributing security to mobile devices and branch offices while eliminating the infrastructure strain typically associated with legacy solutions.“Network security must scale and adapt quickly to support new business requirements and the evolving threat landscape. However, the current appliance-based infrastructure can’t keep up and is too expensive and too complex to sustain, especially for mid-sized and resource-constrained companies,” said Shlomo Kramer, CEO and co-founder of Cato, in a statement. “Cato is creating the next chapter in the evolution of network security by unifying the network and security stack in the Cloud, addressing multiple enterprise challenges and use cases with one turnkey, service-based solution.”
Technically speaking, Cato Cloud consists of two layers, including the Cato Cloud Network and Cato Network Security Services, according to the announcement. Cato Cloud Network is a global network of Points of Presence, or PoPs, while Cato Network Security Services includes a suite of cloud-based network security solutions, the company explained in the official press release. The platform, which is managed by Cato’s Network and Security Operations Center, combines both WAN and Internet traffic in the cloud under a unified set of security services.
The launch of Cato Cloud comes in unison with the appointment of former Barracuda Networks (CUDA) executive Glenn Esposito as Cato’s vice president of Sales, Americas, responsible for overseeing the company’s sales and channel efforts in the Americas. Esposito joins the Israeli security company this month after spending five years in various positions at Barracuda, including his most recent stint as senior vice president of Sales for the Americas.
Cato also received $20 million in Series A funding as the company looks to build a name for itself in the IT security market.

CipherCloud Announces Cloud Security Broker

CipherCloud has launched a solution designed to deliver cross-cloud visibility and data protection. 
The San Jose, California-based cloud security provider has released Cloud Security Broker, which "extends the CipherCloud platform with frictionless application programming interface (API) integration to entire categories of clouds such as cloud storage applications, CRM systems, HR applications and more."Cloud Security Broker delivers 360-degree user behavior analytics, threat detection compliance controls and encryption, according to CipherCloud.
In addition, CipherCloud noted Cloud Security Broker works across a range of applications across Microsoft Office 365OneDriveBox and other cloud applications through cloud APIs.
Other Cloud Security Broker features include:
  • Compliance scanning capabilities
  • Granular policy controls
  • Policy-based encryption
  • Multi-cloud collaboration controls
  • Activity monitoring and anomaly detection
"CipherCloud is the industry pioneer in enabling enterprise cloud adoption by protecting sensitive and regulated data," CipherCloud CEO Pravin Kothari said in a prepared statement. "Cloud Security Broker greatly expands the breadth of our cloud coverage."
Also, CipherCloud continues to explore ways to bolster its cloud security offerings. 
The company in June, for example, added tokenization to its cloud data protection portfolio.  
Tokenization allows businesses to retain the original data on premises while sending the tokenized forms into the cloud, CipherCloud said.
Kothari pointed out the offering was "tailor made for the EU's increasingly tougher regulatory environment for the cloud" as well. 
What are your thoughts on CipherCloud? Share your thoughts about this story in the Comments section below, via Twitter @dkobialka or email me atdan.kobialka@penton.com.​

Many Organizations Targeting Encryption Deployments, Study Shows

A new Thales e-Securitystudy of more than 5,000 IT professionals indicated the use of encryption continues to grow in response to cyber attacks, privacy compliance regulations and consumer concerns.
The "2016 Global Encryption Trends Study," released during this week'sRSA Conference in San Francisco, revealed the majority of organizations plan to transfer sensitive data to the cloud within the next two yearsIn addition, the study showed:
  • 56 percent of respondents said they are transferring sensitive or confidential data to the cloud, and this figure is expected to rise to 84 percent within two years. 
  • Support for both cloud and on-premise deployment was rated the most important consideration when deploying encryption solutions.
  • Employee and HR data was the most commonly encrypted data.
  • The number one perceived threat to data exposure was employee mistakes, followed by system or application malfunction rather than external attack or malicious insiders.
"As businesses increasingly turn to cloud services, we're seeing a rapid rise in sensitive or confidential data being transferred to the cloud and yet only a third of respondents had an overall, consistently applied encryption strategy," Peter Galvin, Thales' vice president of strategy, said in a prepared statement. "Encryption is now widely accepted as best-practice for protecting data, and a good encryption strategy depends on well-implemented encryption and proper key management."
The study also highlighted an increasing push for data protection. 
However, Thales noted that awareness alone is insufficient, and organizations must devote the necessary time and resources to identify and minimize IT security threats consistently. 
"Awareness is just the first step towards safeguarding sensitive or confidential information," Thales wrote in a blog post. "Once you know the information that needs protecting – and where it is located – placing well-implemented encryption, with strong key management, at the heart of your security strategy will help keep sensitive data safe."
What are your thoughts on the Thales study? Share your thoughts about this story in the Comments section below, via Twitter @dkobialka or email me atdan.kobialka@penton.com.​.

CoreOS's Container Security Scanner, Clair, Reaches Production Quality

CoreOS has taken another step toward distinguishing itself in the container ecosystem with the release of Clair 1.0, the production-quality version of its security scanner. But will this truly be enough for CoreOS to stand out from the likes of Docker?
As container companies go, CoreOS is a distant number two. Its name is well known and its software respected, but the company has followed an awkward trajectory -- first trying to distribute Docker containers, then producing its own container offering, Rocket (or rkt). The company has arguably done a poor job of moving outside Docker's shadow.
But the one area where CoreOS has been doing important things that Docker has not is security. In November, the company announced development of a container scanner called Clair, which is designed to detect security vulnerabilities in containers and help developers patch them automatically.On Friday, CoreOS announced that Clair is now ready for production use. Since November, Clair has evolved to offer better performance through recursive database queries, which CoreOS says improves response time by as much as three magnitudes. Clair 1.0 also features a more extensible RESTful JSON API.
Clair has certainly come far in a short time. Back when CoreOS announced the tool in the fall, it was easy to assume that this would be a simple security scanner, which might make some admins feel better about security, but not actually do much to improve cloud performance. It is now clear that that is not the case. By all indications, Clair 1.0 is a sophisticated, robust security tool that is easy to extend and to integrate into different types of environments.
Plus, CoreOS is making good on the biggest selling-point of Clair, which is that the scanner is able not only to detect security issues but also patch them. That's important, CoreOS says, because the whole point of using containers is to build a flexible, scalable infrastructure. If you have to update software manually whenever security vulnerabilities appear, you lose a lot of nimbleness. But if you can handle security in an automated fashion, you're getting the most out of your cloud.
Indeed, in a way, Clair is like a cloud orchestration platform, except instead of managing the cloud workload, it handles the security front.
This all said, it remains to be seen whether Clair will prove a compelling enough offering to convince cloud admins to consider CoreOS's container solution instead of Docker. The latter is much more established in the marketplace. It also has gobs more funding. Plus, you can use Clair to scan Docker containers just as well as you can CoreOS container images -- so Clair is not going to force companies to use the entire CoreOS platform just to get a better security and upgrade experience.
But Docker compatibility may be the factor that makes people actually use Clair and, in turn, assures that CoreOS gets its slice of the container space. Docker itself has yet to offer security tools like Clair, or even send a strong message that it takes container security seriously. By filling this gap through Clair, CoreOS is positioning itself to stay relevant -- although not to advance adoption of its entire container platform.

vCloud Air Hybrid Cloud Manager

VMware vCloud Air Hybrid Cloud Manager makes it even easier to migrate applications to and from the public cloud, and extend your network for a true hybrid environment.

Advertisement

Labels