Security in the cloud. This is the re-occurring theme when the technology conversation turns to cloud computing. Usually that's followed by "Where's my data?" or "Who can get access to my data?" or "Do I have complete control of my own data?" Security in the last twelve months has become the real deal breaker, & issues experienced by a high profile name in the technology world like Sony really made alot of people who have been on the fence about whether to take some of their business critical systems into the Cloud.
Recently, the Ponenmon institute conducted a study that revealed that 67% of the IT professionals questioned admitted that their respective organisations were vulnerable to hackers due to lax firewall security. Scarier was that 42% of those surveyed said that were they breached or attacked, they'd have no way of knowing what was compromised. And it got worse with over half saying they were of the opinion that their staff had no knowledge about the potential risks of open firewall ports.
The full insights of that study would appear shocking to those outside the Cloud Computing industry, but to those in it, it's not, but it also isn't the full story. The study neglects the real root of the issue; good security governance from the desktop upwards in any infrastructure. The truth is, there seems to be a general lack of knowledge about security & the implications of security issues from the receptionist to the CEO, with no-one seemingly taking full responsibility for it. No-one drawing a line in the sand about where the buck truly stops.
People leaving their screens unlocked, downloading software, or opening e-mail attachments without care, providing the opportunity for those out there to re-enact a digital version of the siege of Troy. There's even less of a responsibility taken by those who code websites, or are designers-for-hire. Many don't seem to understand the platforms they are building for, or understand how the applications they design & build for clients work in the cloud.
The issue really comes down to one single fundamental questions; would any of us leave our wallet down for anyone to peruse at will or take? The answer is no, we wouldn't. Data in any business IS the wallet of the company. It has to be given the same reverence, respect & care. Sure, the questions about where your data is, or who has access to it are valid, but the real question any organisation must ask is simple & stark; do WE ourselves treat our data the way we expect our service providers to treat it?
As sure as you could establish a cloud solution with a cloud service provider, then pen test that to within an inch of its life, the more important pen tests need to be done within your own organisation. One of the continually growing areas of access compromise is people taking advantage of social engineering; the process of obtaining information and or access through deceit.
People are still taking calls from people claiming to be from well known technology companies to run pieces of software on their machines, only to later find themselves compromised, exploited and or defrauded. People are still clicking on links in e-mails telling them to log on & confirm passwords. Ask any online gamer how often they've heard of someone getting compromised.
The simple truth of this is, no matter how good the hardware platform is, how good the process is from the service provider, & how good you think your staff is, the real threat to the security of your business comes from within. Your service provider is only as good as your own instructions, your own knowledge & understanding, & your own ideals, & those ideals being kept rigidly.
A degree of suspiciousness, caution & paranoia is not only healthy, but acceptable as well as needed in today's Digital Age. The level of concern about security in the cloud is really to do with business' own insecurity over its own processes, data handling ideals than what the service provider's level of security offers. If you can sleep well at night knowing your wallet is safe, shouldn’t your data in your business be able to feel the same?
Blog discussing the issues facing Cloud Adoption & Cloud usage in the Irish market, as well as the progression of the Cloud computing & SAAS/IAAS in Ireland. This blog is authored by an actual Cloud Computing services evangelist (yes, really!) who has been part of the forefront of 'the Cloud' in Ireland.
Showing posts with label Risk Management. Show all posts
Showing posts with label Risk Management. Show all posts
Wednesday, November 16, 2011
Monday, November 14, 2011
Episode 15: The one where Ireland leaves the front door unlocked
Ireland is at an incredible juncture in its history. Our national debt is of gargantuan proportions, we're in a harsh period of austerity, & the real economy is on the verge of complete collapse with barely any growth, & things are looking to only get worse for the citizens. Our exports however are the only thing that's saving our bacon. Richard Bruton, the Minister for Jobs, Enterprise & Innovation stated last month in the Dail that "Ireland is well placed to exploit opportunities in new sectors such as Cloud Computing & Digital Gaming, Life Sciences & Clean-tech". He went further to state that "Ireland’s services sector continues to grow & in 2010 accounted for 45.3 per cent of total exports."
One of the growing areas of concern in the tech sector continues to be security. Major gaming hubs from Sony, Nintendo, Enix, Sega Pass, Nintendo & Steam have in recent months come under attack to be compromised, as have Nokia, The Sun, CitiBank to name but a few. When you look through the major gaming names previously mentioned, you realise that these guys are in the top tier of that sector, & with their millions, they got their security totally wrong.
If we're going to engage digital gaming as a means to increase our exports alongside cloud computing, we must place an incredible amount of attention on us having a strategy for cyber security in Ireland. In the area of cloud computing, as each market around the world begins the embrace, the first question is always around security, & it continues to be a question even in further developed cloud computing markets.
Ireland is one of the more mature markets for cloud. The sales penetration levels wouldn't tell you that, but it is much further along over four years later from when Ireland's first indigenous cloud computing provider entered the market. Back then, security was a huge issue, & there was alot of scaremongering about the security of the cloud versus traditional managed or collocated I.T. infrastructure services. So, with the market being more mature & over a hundred cloud computing services providers in Ireland, the tech exports market being so crucial to our economy you'd assume Ireland had a cyber security strategy already in place.
You'd be wrong. According to a question posed by Clare Daly last week to Pat Rabbitte, our Minister for Telecommunications, Energy & National Resources, that framework document doesn't yet even exist. His department are only in the process of developing it for publishing some time in 2012. We're hedging our survival as a country on I.T. services, & the digital economy & we have absolutely no framework as a country on the single biggest threat & concern to that sector?
Coincidentally, my collegue over at CloudBook, Thu Pham, wrote a great article about the concerns of security in the Cloud for SMB's (or, SME's to us in Ireland). While this article does discuss things from a US market standpoint, we're trying to attract US cloud market players to Ireland. So this does provide some viewpoint into what kind of market expectations these players have to work in back home.
Yes, you could revert to type & cast that off as a typically Irish response to a problem, & that it is the same slip-shod approach that was taken to our banking sector; "we'll worry about those problems after the fact." But that's not acceptable. It can't be. If we're spending huge resources on trying to attract direct foreign investment from technology based services companies, positioning Ireland to take advantage of cloud & digital gaming opportunities, this legislation must be of absolute priority.
Four years ago under the previous government, the question was asked about the Irish Governments shift to cloud computing, & the then-Minister for Communications, Eamon Ryan stated that only one department had engaged in looking at a virtualisation or cloud computing strategy so far, & that was his own department. It may be of interest to know that Cloud Computing has been part of Dail discussion 37 times since this present administration has come to power. In seven months, that is approximately five times a month without an exclusion on parliamentary breaks. Thirty seven discussions, with no sign or mention of a government strategy for Cloud Computing to address the costs & inefficiencies of the Government I.T. infrastructure.
There has also been no real approach made to the Cloud Computing industry in Ireland by Government. Discussions behind closed doors with the big five about direct foreign investment don't count. They're not the real players. Had the Government made approaches to companies like Hibernia-Evros, Network Recovery (who recently achieved ISO certification on their cloud), SunGard AS Ireland, DigiWeb, DediServe, DEG-Telecity-Redbus (recent merger of Telecity Redbus & DEG), Eircom, or the any of the other players, any of these players would have made alot of PR hay from the opportunity without any hesitation.
There needs to a proper industry working group, which would help understand the size of the Irish Cloud Computing market, its potential value to the Irish economy from service exports, & its potential for growth, market penetration & adoption throughout the business chain. This group needs to work with the department of trade, the department for public finance & expenditure, as well as the department of communications to help it understand what is needed from a national cyber strategy.
Ireland asked & got its change of leadership earlier this year, it is now time that changed leadership acted like leaders, instead of dithering like a deer in the headlights, reach out to those in the Irish Cloud market, reach out to those in the Digital arts markets (gaming/entertainment etc.), form some proper advisory working groups, & get on with helping to make the push behind a group of industries that form the tech sector that helps support our exports to allow us to fix our real economy, or are they going to continue to bet the farm on those who will move at a moments notice for tax & cost sakes premiums?
One of the growing areas of concern in the tech sector continues to be security. Major gaming hubs from Sony, Nintendo, Enix, Sega Pass, Nintendo & Steam have in recent months come under attack to be compromised, as have Nokia, The Sun, CitiBank to name but a few. When you look through the major gaming names previously mentioned, you realise that these guys are in the top tier of that sector, & with their millions, they got their security totally wrong.
If we're going to engage digital gaming as a means to increase our exports alongside cloud computing, we must place an incredible amount of attention on us having a strategy for cyber security in Ireland. In the area of cloud computing, as each market around the world begins the embrace, the first question is always around security, & it continues to be a question even in further developed cloud computing markets.
Ireland is one of the more mature markets for cloud. The sales penetration levels wouldn't tell you that, but it is much further along over four years later from when Ireland's first indigenous cloud computing provider entered the market. Back then, security was a huge issue, & there was alot of scaremongering about the security of the cloud versus traditional managed or collocated I.T. infrastructure services. So, with the market being more mature & over a hundred cloud computing services providers in Ireland, the tech exports market being so crucial to our economy you'd assume Ireland had a cyber security strategy already in place.
You'd be wrong. According to a question posed by Clare Daly last week to Pat Rabbitte, our Minister for Telecommunications, Energy & National Resources, that framework document doesn't yet even exist. His department are only in the process of developing it for publishing some time in 2012. We're hedging our survival as a country on I.T. services, & the digital economy & we have absolutely no framework as a country on the single biggest threat & concern to that sector?
Coincidentally, my collegue over at CloudBook, Thu Pham, wrote a great article about the concerns of security in the Cloud for SMB's (or, SME's to us in Ireland). While this article does discuss things from a US market standpoint, we're trying to attract US cloud market players to Ireland. So this does provide some viewpoint into what kind of market expectations these players have to work in back home.
Yes, you could revert to type & cast that off as a typically Irish response to a problem, & that it is the same slip-shod approach that was taken to our banking sector; "we'll worry about those problems after the fact." But that's not acceptable. It can't be. If we're spending huge resources on trying to attract direct foreign investment from technology based services companies, positioning Ireland to take advantage of cloud & digital gaming opportunities, this legislation must be of absolute priority.
Four years ago under the previous government, the question was asked about the Irish Governments shift to cloud computing, & the then-Minister for Communications, Eamon Ryan stated that only one department had engaged in looking at a virtualisation or cloud computing strategy so far, & that was his own department. It may be of interest to know that Cloud Computing has been part of Dail discussion 37 times since this present administration has come to power. In seven months, that is approximately five times a month without an exclusion on parliamentary breaks. Thirty seven discussions, with no sign or mention of a government strategy for Cloud Computing to address the costs & inefficiencies of the Government I.T. infrastructure.
There has also been no real approach made to the Cloud Computing industry in Ireland by Government. Discussions behind closed doors with the big five about direct foreign investment don't count. They're not the real players. Had the Government made approaches to companies like Hibernia-Evros, Network Recovery (who recently achieved ISO certification on their cloud), SunGard AS Ireland, DigiWeb, DediServe, DEG-Telecity-Redbus (recent merger of Telecity Redbus & DEG), Eircom, or the any of the other players, any of these players would have made alot of PR hay from the opportunity without any hesitation.
There needs to a proper industry working group, which would help understand the size of the Irish Cloud Computing market, its potential value to the Irish economy from service exports, & its potential for growth, market penetration & adoption throughout the business chain. This group needs to work with the department of trade, the department for public finance & expenditure, as well as the department of communications to help it understand what is needed from a national cyber strategy.
Ireland asked & got its change of leadership earlier this year, it is now time that changed leadership acted like leaders, instead of dithering like a deer in the headlights, reach out to those in the Irish Cloud market, reach out to those in the Digital arts markets (gaming/entertainment etc.), form some proper advisory working groups, & get on with helping to make the push behind a group of industries that form the tech sector that helps support our exports to allow us to fix our real economy, or are they going to continue to bet the farm on those who will move at a moments notice for tax & cost sakes premiums?
Friday, April 22, 2011
Episode 4: The Day The Cloud Crashed & People Lost Their Minds
February 20th 2011 will be a date that cloud commentators, cloud zealots & the opportunists in the cloud will make sure is not forgotten. Amazon AWS had a colossal outage. This article from the BBC exemplifies the kind of coverage that went along with the event. Needless to say, alot of people directly affected as customers of AWS were miffed, as were users of those services hosted there in the affected area. And no, SkyNet did not begin its take-over starting with AWS for those who were concerned.
First off, one thing really needs clarifying about this event, as the reaction in social media circles, especially amongst twitterati was grossly out of of proportion. The reality of this is that a SINGLE region in Amazon's network was down. The rest of their services in the USA were fine, as were their European & their Asian services. The fact that the affected region services so many companies made the issue seem far greater than it was. Amazon AWS customers who engaged in deploying their cloud strategy across multiple regions in Amazon's EC2 system were completely unaffected.
The fact it went on for over ten hours yes is a concern. And rightfully so. But, did it violate Amazon AWS's 99.95% SLA which allows for '4 hours per year of downtime'? Nope. Not even in the slightest, even with their 10 hours of being unavailable to people who were screaming over lack of access to key services. But, screaming doesn't get around SLA's you agree to for services you take, or use. Always check the warranty.
And this is the real thing to remember; the fine print of your SLA's or terms & conditions of service are the last word in any comeback you have. Cloud Providers trying to win business from AWS to their own services around the world, especially in Ireland cried foul. What they neglected to tell those same Irish companies they were trying to win business from as a result of the outage was that their own SLA's & guarantees are in fact absolutely no better than Amazon's ones. In fact, some of them have in their terms & conditions that you have absolutely no comeback whatsoever in the event of an outage, & there are no guarantees on up-time at all, even at centre power/connectivity level, which some at least provide.
The companies who promote their uptime & their 'solid SLAs' if you dig into them are actually nothing more than guarantees against power & network connectivity to an actual hosting center itself, & unless both those fail for more than four hours in a year, you could lose access to your VPS or cloud for days on end due to a hardware, or virtualisation or internal networking issue & they would still not have violated their SLA with you.
Beware of service providers who are eager to bash the performance of their competitors openly. They'll mouth off quite happily about others lack of 'service', while at the same time not being so mouthy about what happens when (not a case of 'if' with technology, but 'when') their services fail on you. And believe me they will. If multi-billion dollar global companies like Amazon, Google, Microsoft, Apple & others have outages, your local provider who is less equipped staff-wise, financially & technically to be as able to deal with outages as efficiently as those corporations who have vast resources in all areas. It is also important to remember a very old adage when it comes to this, empty vessels make the most noise.
So, you're a company looking to engage a cloud strategy because you can see the benefits, but are scared by what happened with Amazon AWS from what you read on blogs & Twitter. You don't know what to do next. Firstly, the most important thing to do is ignore Twitter & the blogs decrying AWS. These are but a noisy few out of millions. Many of them are vested interests & vested interests should be ignored like the plague.
A good cloud service provider will be upfront with you when you engage them. They should be knowledgable enough to work with you in understanding your requirements, explain what risks there are to what you want to achieve, & provide advice on how to mitigate against the risks to what you want to do. Sure they're there to sell you services & gain your custom, but a good consultant will tell you that they are & should only be part of a solution to you. That as good as the company they represent may be, risk should always be spread.
Every company involved in risk management as a business will tell you that the absolute fundamental to risk management is spreading that risk around in a controlled manner to shore up your mitigation. Mitigating risk is not cheap. So don't fall for companies promising you to be the 'cheapest solution for your business' - they're not. They are if anything given their pricing, a small part of a solution to you. You also need to ensure that you have a communications plan in place in the event of any outages, as well as documented & tested internal procedures on how your teams & staff need to act, & what events need to be triggered if any to mitigate the circumstances or ease them as much as possible.
But this issue goes outside your cloud provider. It comes down to your choice in developer also. Your developer if they are worth their salt should have an application that allows for spread, that allows for redundancy. They should also be advising you to spread your system across at least two providers or two centers at the very least if your single provider can actually do this. Your cloud provider really should even do this. Single cloud services are single points of failure.
And the issue of disaster recovery or planning doesn't even stop at the developer or the service provider. You, as the business owner/operator leading your organisation are the absolute linchpin of it all. Fundamentally, being a good leader means being a good planner. As a leader of yours, it is incumbent upon you to plan, & plan well & properly.
'The Cloud' is not a solution to redundancy, or disaster recovery. It is a tool to help mitigate some aspects of risk at best in a cost effective manner for its part. It should never be the case of "Oh, it's in the cloud, no need to worry or care. It's taken care of already by my cloud provider." Just because it's easy to set up a business in the internet space, doesn't mean normal conventions for business disaster recovery, or 'battle-stations' planning doesn't apply. The fundamentals of good business planning apply to the Internet as much as the high-street. Most of the time, it's just cheaper. Shortcuts on these areas are just that, except to one day being caught proverbially with your pants around your ankles.
Remember; a blip in the operation of your business from an outage won't kill your business, but how you manage that blip, communicate & work towards the point of restoration will determine whether your business will recover when it happens. Another couple of adages worth closing this blogpost with is 'plan for the worst, hope for the best', 'expect the unexpected' & 'if you want peace, prepare for war'.
First off, one thing really needs clarifying about this event, as the reaction in social media circles, especially amongst twitterati was grossly out of of proportion. The reality of this is that a SINGLE region in Amazon's network was down. The rest of their services in the USA were fine, as were their European & their Asian services. The fact that the affected region services so many companies made the issue seem far greater than it was. Amazon AWS customers who engaged in deploying their cloud strategy across multiple regions in Amazon's EC2 system were completely unaffected.
The fact it went on for over ten hours yes is a concern. And rightfully so. But, did it violate Amazon AWS's 99.95% SLA which allows for '4 hours per year of downtime'? Nope. Not even in the slightest, even with their 10 hours of being unavailable to people who were screaming over lack of access to key services. But, screaming doesn't get around SLA's you agree to for services you take, or use. Always check the warranty.
And this is the real thing to remember; the fine print of your SLA's or terms & conditions of service are the last word in any comeback you have. Cloud Providers trying to win business from AWS to their own services around the world, especially in Ireland cried foul. What they neglected to tell those same Irish companies they were trying to win business from as a result of the outage was that their own SLA's & guarantees are in fact absolutely no better than Amazon's ones. In fact, some of them have in their terms & conditions that you have absolutely no comeback whatsoever in the event of an outage, & there are no guarantees on up-time at all, even at centre power/connectivity level, which some at least provide.
The companies who promote their uptime & their 'solid SLAs' if you dig into them are actually nothing more than guarantees against power & network connectivity to an actual hosting center itself, & unless both those fail for more than four hours in a year, you could lose access to your VPS or cloud for days on end due to a hardware, or virtualisation or internal networking issue & they would still not have violated their SLA with you.
Beware of service providers who are eager to bash the performance of their competitors openly. They'll mouth off quite happily about others lack of 'service', while at the same time not being so mouthy about what happens when (not a case of 'if' with technology, but 'when') their services fail on you. And believe me they will. If multi-billion dollar global companies like Amazon, Google, Microsoft, Apple & others have outages, your local provider who is less equipped staff-wise, financially & technically to be as able to deal with outages as efficiently as those corporations who have vast resources in all areas. It is also important to remember a very old adage when it comes to this, empty vessels make the most noise.
So, you're a company looking to engage a cloud strategy because you can see the benefits, but are scared by what happened with Amazon AWS from what you read on blogs & Twitter. You don't know what to do next. Firstly, the most important thing to do is ignore Twitter & the blogs decrying AWS. These are but a noisy few out of millions. Many of them are vested interests & vested interests should be ignored like the plague.
A good cloud service provider will be upfront with you when you engage them. They should be knowledgable enough to work with you in understanding your requirements, explain what risks there are to what you want to achieve, & provide advice on how to mitigate against the risks to what you want to do. Sure they're there to sell you services & gain your custom, but a good consultant will tell you that they are & should only be part of a solution to you. That as good as the company they represent may be, risk should always be spread.
Every company involved in risk management as a business will tell you that the absolute fundamental to risk management is spreading that risk around in a controlled manner to shore up your mitigation. Mitigating risk is not cheap. So don't fall for companies promising you to be the 'cheapest solution for your business' - they're not. They are if anything given their pricing, a small part of a solution to you. You also need to ensure that you have a communications plan in place in the event of any outages, as well as documented & tested internal procedures on how your teams & staff need to act, & what events need to be triggered if any to mitigate the circumstances or ease them as much as possible.
But this issue goes outside your cloud provider. It comes down to your choice in developer also. Your developer if they are worth their salt should have an application that allows for spread, that allows for redundancy. They should also be advising you to spread your system across at least two providers or two centers at the very least if your single provider can actually do this. Your cloud provider really should even do this. Single cloud services are single points of failure.
And the issue of disaster recovery or planning doesn't even stop at the developer or the service provider. You, as the business owner/operator leading your organisation are the absolute linchpin of it all. Fundamentally, being a good leader means being a good planner. As a leader of yours, it is incumbent upon you to plan, & plan well & properly.
'The Cloud' is not a solution to redundancy, or disaster recovery. It is a tool to help mitigate some aspects of risk at best in a cost effective manner for its part. It should never be the case of "Oh, it's in the cloud, no need to worry or care. It's taken care of already by my cloud provider." Just because it's easy to set up a business in the internet space, doesn't mean normal conventions for business disaster recovery, or 'battle-stations' planning doesn't apply. The fundamentals of good business planning apply to the Internet as much as the high-street. Most of the time, it's just cheaper. Shortcuts on these areas are just that, except to one day being caught proverbially with your pants around your ankles.
Remember; a blip in the operation of your business from an outage won't kill your business, but how you manage that blip, communicate & work towards the point of restoration will determine whether your business will recover when it happens. Another couple of adages worth closing this blogpost with is 'plan for the worst, hope for the best', 'expect the unexpected' & 'if you want peace, prepare for war'.
Subscribe to:
Posts (Atom)