IoT
IoT
IT Leadership // Security & Risk Strategy
News
2/24/2016
09:06 AM
50%
50%

Security Concerns Continue Amid Cloud Adoption

While most top IT executives at companies of all sizes continue to express concern about the security of data in the cloud, that hasn't slowed their move to embrace this new infrastructure as a home for corporate data. A new survey and report reveal their top security nightmares and provides some recommendations about how to protect data in the cloud.

8 Reasons Cloud Email Is A Smart Move Now
8 Reasons Cloud Email Is A Smart Move Now
(Click image for larger view and slideshow.)

The Internet of Things (IoT) generates a lot of data, which organizations can store in the cloud. But how are they keeping it all safe?

Many companies are realizing they face this challenge and are ramping up efforts to improve data security as they embrace new platforms, including IoT and cloud-based applications, according to a recent survey conducted by 451 Research.

The survey, sponsored by data and cloud security vendor Vormetric, polled 1,114 senior IT executives, representing companies ranging from $50 million to more than $2 billion in annual sales.

[What's the Apple vs. FBI fight over the encrypted and secured iPhone all about? Read Tim Cook vs. FBI: Why Apple Is Fighting the Good Fight.]

More than 80% of respondents said they plan to store data in "new technology environments," defined as cloud, big data, or IoT. Of those, the vast majority (85%) said they were "concerned" or "very concerned" about security in the cloud.

Over half of all respondents voiced similar concerns about the security of big data, while more than a third (36%) said that protecting IoT data was a major concern.

Still, report author and 451 Research senior analyst Garrett Bekker, said in a prepared statement that security is an afterthought "when it comes to adopting new technologies, often taking a back seat amidst the rush to stake a claim in a promising new market." 

(Image: Henrik5000/iStockphoto)

(Image: Henrik5000/iStockphoto)

Top data concerns for respondents were security breaches or attacks at the service provider (70%), increased vulnerabilities from shared infrastructure (66%), lack of control over the location of the data (66%), and lack of a data privacy policy or a privacy service level agreement (65%).

The 451 Research survey showed that clients see encryption as one solution to guarantee cloud security. By a three-to-two margin, clients preferred to manage their own encryption keys, the survey said.

"Encryption got a bad rap in the past 40 years," said Sol Cates, chief security officer at Vormetric, in an interview with InformationWeek. It was perceived as slow and complicated. "How do you apply it without breaking anything?" he asked.

Early adopters of encryption were paranoid, or sensitive and paranoid, or aware of regulatory compliance, Cates noted. All these factors may have impeded the wide implementation of encryption as a security solution. But attitudes have shifted again, as companies now seek encryption solutions. As more data is collected by organizations, the C-suite is experiencing more concern over its security. Customers also expect their data to be kept safe, Cates explained.

That collection of data is growing exponentially, as gigabytes pile into terabytes, finally adding up to petabytes. Do you protect it all?

"Don't try to encrypt or protect everything," Cates said. Companies have to identify the 10% to 20% of data that is absolutely crucial. "If we lose this, we're done," is how Cates described this category.

The burden rests on the chief security officer, who must understand the business in order to understand the value of the data and what is most important to protect, Cates explained. That person must be able to communicate that understanding in the same language used by the various departments in that business, he added. The CSO must do more than share statistics; the CSO must share understanding.

Parting of the Cloud

Encryption isn't the only technology undergoing a major shift. Security was once a factor that made companies reluctant to move their data to the cloud, sometimes opting for hybrid solutions where the "crown jewels" would remain on-premises.

"Something is shifting there," Cates said, as companies now pursue cloud-based solutions. "A lot of organizations started on the cloud," he said, while established companies are becoming comfortable once they've gained more control over their data environment. Cloud providers want no liability for storing client data, which pushes the responsibility for security back to the client, he added.

Forecasts and Recommendations

451 Research predicts encryption and security policy management will be part of all future cloud deployment, with encryption deployed either natively or via a third-party solution. Clients will find their best options for cloud security after sorting through internal policies, industry best practices, and compliance mandates.

For big data, 451 Research recommends finding broad-based encryption and access controls that can cover traditional as well as big data repositories.

When it comes to the Internet of Things, the report suggests that clients focus on device authentication and access controls, as well as encrypting data as it flows from the device to the database.

Are you an IT Hero? Do you know someone who is? Submit your entry now for InformationWeek's IT Hero Award. Full details and a submission form can be found here.

William Terdoslavich is an experienced writer with a working understanding of business, information technology, airlines, politics, government, and history, having worked at Mobile Computing & Communications, Computer Reseller News, Tour and Travel News, and Computer Systems ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Ashu001
50%
50%
Ashu001,
User Rank: Ninja
2/28/2016 | 8:50:41 AM
Re: Security concerns are abating, for good reason
Charlie,

Are you basically saying that Encryption/Security should just be bolted onto the Cloud and all is Okay?

I am not so sure.

Unless companies have built in Security/Encryption all across the entire Cloud Infrastructure,nothing much will change.

Still,I liked what the report had to say HERE-

451 Research predicts encryption and security policy management will be part of all future cloud deployment, with encryption deployed either natively or via a third-party solution. Clients will find their best options for cloud security after sorting through internal policies, industry best practices, and compliance mandates.

For big data, 451 Research recommends finding broad-based encryption and access controls that can cover traditional as well as big data repositories.

Just wondering how this plays in with the FBI &NSAs recent assertion that they can't wait for the IoT Wave!

It seems they have already let loose their Eavesdropping Solutions all across the chain and are just waiting for them to gain traction among Consumers.

LOL!!!


 
Charlie Babcock
50%
50%
Charlie Babcock,
User Rank: Author
2/24/2016 | 7:18:08 PM
Security concerns are abating, for good reason
Encryption and security policy management are a future, automated feature of cloud computing and will help make the cloud more secure than the enterprise data center. Another factor: the cloud is a highly uniform environment with patching done regularly and routinely through automated procedures. Only among the fortunate is this true in the enterprise data center.
Register for InformationWeek Newsletters
White Papers
Current Issue
Top IT Trends to Watch in Financial Services
IT pros at banks, investment houses, insurance companies, and other financial services organizations are focused on a range of issues, from peer-to-peer lending to cybersecurity to performance, agility, and compliance. It all matters.
Video
Slideshows
Twitter Feed
InformationWeek Radio
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.