Sunday, May 30, 2010

Cloud Security - A Pleonasm?

The IT industry successfully generates billions of dollars each year by selling us security products and services. Security always plays a major role in any corporate IT purchasing decision. But, we are still a very long way from securing our IT environments.

Most security breaches are caused internally by employees or other authorized users of corporate systems such as contractors. It is these groups that are most likely to compromise the integrity of our systems, not external hackers. In spite of this, much more focus tends to be placed on external threats. Each time I work on a client’s site, I am struck by how easy it would be for me to compromise their systems. All I would need to do is insert a thumb drive with malicious code into a USB port and, hey presto, I’ve undermined hugely expensive security investments.

It is reckless to allow employees and contractors to carry highly sensitive data around with little consideration of the consequences of losing the laptops and smart phones that house the data. Amazingly little focus is placed on addressing this particular security threat.

Indeed, enterprises do not sufficiently focus on changing the behavior of their users by making them aware of security policies and the reasons for those policies. Few ensure adequate control of basic access to their physical premises and to end points that form part of their network. As mentioned earlier, it also seems as though few enterprises track the location of sensitive data that physically moves around with employees and contractors.

Ensuring that everybody who accesses enterprise networks is trained to follow appropriate security policies is an extremely challenging task. For this reason, it is necessary to consider other ways of mitigating the risk of an employee or contractor from compromising security.
One way of doing this is to source as much of the enterprise’s computing resources from the cloud as possible. Managing the security of heterogeneous on-premise IT environments is a highly complex and almost impossible task. Minimising the amount of on-premise resources that a corporation manages mitigates risk associated with security breaches enormously. Ensuring that data is stored in a secure environment (in the cloud) rather than on portable devices such as laptops and smart phones also enables corporations to reduce risk.

Cloud computing, and I mean public cloud computing, allows us to mitigate risk and in many cases offer greater security that can be provided by spending millions of dollars in an attempt to secure on-premise resources.

Multitenancy and virtualization do indeed add a lot of complexity to providing levels of security that many enterprises require. However, public cloud services providers such as Google, Amazon, Microsoft and Salesforce.com focus heavily on ensuring that their datacenters follow best practice security policies and are using the most up to date security tools. Security can also be tied into service levels.

So, using public cloud services can offer more security than keeping data and other computing resources on-premise. These services can also reduce the amount spent on security massively. Perhaps this is the reason why many in the IT industry are keen to dissuade us from using cloud computing.

Security is always a challenge. But, there is little evidence to suggest that using the public cloud is less secure than the traditional on-premise form of computing. In fact, there is more evidence to suggest that using public cloud services can, in many cases, eliminate security risks that exist with on- premise computing alternatives.

The cloud model of computing is much better positioned to address today’s security challenges and concerns than alternative models. So, will the term cloud security soon be considered to be a pleonasm? In other words, will the cloud soon become synonymous with security?

Sunday, May 2, 2010

The Myth of Enterprise Social Networking

One of the most attractive concepts I have ever come across is that of crowdsourcing. At no time in history have ordinary individuals possessed the tools that enable them to engage with such a huge variety of people and to tap such a vast amount of knowledge. Many of today’s emerging business titans such as Facebook have used ‘the crowd’ to build their businesses and to build fortunes for their founders.

For knowledge based workers, the use of these tools can increase their productivity enormously and engender innovation at a more rapid rate than would be the case for smaller, selected, teams and individuals.

In a traditional corporate environment, knowledge workers predominantly access corporate resources alone. Admittedly, in certain environments such as academic institutions, knowledge sharing and collaboration beyond a single institution has been the norm for centuries. However, today, knowledge workers within corporations as well as within academia have access to infinitely more resources than ever before by using social networking tools.

The massive benefit offered by social networking tools is obvious in some corporate functions such as human resources, marketing and customer care. But, for other activities, the benefits are also huge. For example, a specialist such as an engineer can potentially source best practices or solutions to challenges using social networking tools. These professionals can use these tools to ensure that they are fully aware of the latest developments in their profession and they can do this anywhere in the world. Clearly, these tools can offer huge benefits to professionals ranging from aerospace engineers to zoologists. In fact, those that do not use social networking tools will soon find themselves isolated from the rest of their profession and risk coming across as having a seriously outdated approach to work, a bit like refusing to use word processing software and preferring to write by hand.

Horses for Sources has used social networking to build a business and to engage with a large community of professionals that share an interest in outsourcing. There are no restrictions on who can read the blog or follow Horses on Twitter. Provided, external content does not offend Phil Fersht, it can be added to the blog. But, the main point is that it is open to anybody, anywhere, who wishes to engage.

So what is enterprise social networking? Well, it is collaboration within the enterprise and with selected external stakeholders. To me, this is not social networking given that if I use these tools, the people with whom I can interact and the content with which I can engage are restricted by the enterprise. For example, it is much easier for an IBM employee that I have never met to connect with me using Twitter than using Yammer. Enterprise social networking tools are the next generation of collaboration tools that are designed to overcome the thorny issue of insufficient collaboration within most enterprises. Intranets were, and in many cases, still are used to engender greater collaboration within the enterprise.

In order to improve performance within many functions within their organisations, management must embrace open, public social networking tools such as Twitter, Linkedin and yes, Facebook. They should not seek to use enterprise social networking tools as more secure or manageable substitutes of the open, public tools. They have very different benefits. Instead, they should use enterprise social networking to help them to address that on-going challenge that they face, namely getting people, within different teams (or within the same team), to work together more closely.

Monday, April 12, 2010

UnGreen IT

In Australia, most industries have been addressing sustainability issues, at least to some extent, for several years. For example, energy companies and miners have had to, at the very least, address sustainability issues for many years, as have financial services companies, government, retailers and manufacturers.

IT, however, has traditionally perceived itself to be a clean industry and has been late to focus on sustainability. Over the last couple of years, IT’s carbon footprint and ways of reducing it have become more of a focus.

Sustainable IT is made up of two components. Firstly, it consists of ways of reducing IT’s carbon emissions through activities such as datacentre consolidation or even small operational changes like power management for PCs. Secondly, and perhaps more importantly, it comprises ways in which IT and IT suppliers can enable whole organisations to reduce carbon emissions in non-IT specific activities such as by developing smart grids for utilities firms or by enabling video conferencing.
In a recent survey undertaken by Frost & Sullivan, it was revealed that, despite the global financial crisis, IT professionals, in Australia, are placing more emphasis on sustainability initiatives than was the case a year ago.

Over time, Frost & Sullivan expects sustainability to be embedded within every IT process and purchase. It will become a much more significant choice determinant for products and services over the coming years along with other determinants like price, performance and references. It will be assumed that sustainable IT offers cost benefits. This will lead organizations to seek accurate ways of determining payback periods, net present values and returns on investment. Passing on the cost of carbon usage and of recycling to the consumer will result in the benefits of sustainable IT investments being realized sooner and offering greater financial benefits. It should be noted that this is not a hypothetical comment. Incorporating carbon costs and the cost of recycling into products and services is not just a possibility. Frost & Sullivan believes that organisations will incorporate these costs and pass them onto their customers within the next three to five years, if not before.

Of course, no investment is made that does not offer clear financial benefits within a reasonable timeframe. As a technology or business activity matures, buyers start to look beyond financial benefits and more to the strategic benefits that can be offered. Foresighted IT buyers are now making sustainable IT purchases not only for financial benefits but also to differentiate themselves from their competitors. This has parallels with the evolution of outsourcing. In the early days of outsourcing, cost reduction was the dominant and often the only driver for outsourcing decisions. However, today, outsourcing buyers assume that there will be measurable cost benefits associated with an outsourcing purchase. Cost reduction is no longer the sole driver. Instead, outsourcing buyers are increasingly interested in ways that outsourcing can differentiate them from their competitors. For example, an outsourced contact centre may not only offer cost benefits but also enable an organization to fully integrate its channels to market. Multichannel integration allows many organizations to offer vastly improved customer care and hence differentiation from their competitors.

Seeking business benefits beyond cost reductions can also be expected to occur when buyers examine sustainable IT options. For example, a utilities firm might invest in developing a smart grid, not only to manage costs over a period of time but also to differentiate its customer offerings from competitors. A utilities service that can provide information about energy use per device can differentiate that service and offer additional value to customers.

Key advances in technology use in Australia will complement the move to sustainable IT. The National Broadband Network will allow an increasing number of services to be provided over the Internet, further enabling service dematerialization such as the elimination of CDs.

The move to cloud computing together with server virtualization will also create greater efficiencies and economies of scale in the datacentre.

Another major sustainable IT issue is e-waste. Australia has yet to implement e-waste legislation which exists in many other mature economies. IT products contain comparatively large amounts of embodied energy yet, they have relatively short life spans. Questions are being raised about the life spans of IT products. For example, why do we dispose of all the components of a laptop computer each time we purchase a new one? Can’t we, for example, re-use our keyboards or monitors? As yet, there are no clear answers to these questions? This suggests that the bulk of the IT industry still has some way to go before sustainable practices are embedded into all parts of the IT supply chain.
Nevertheless, IT stakeholders are becoming increasingly aware of the benefits and challenges associated with sustainability issues and sustainability is becoming a key component of, at least some, critical IT-related decisions.

Tuesday, March 16, 2010

Private Cloud - An Oxymoron

Recently, IT vendors as well as IT buyers have been focusing on the impact of cloud computing on their businesses. The rapid growth in the use of cloud services in recent years massively disrupts traditional IT delivery models. But, there remains much confusion regarding the nature of cloud computing.

Attributes of cloud computing typically include, scalability, elasticity, multi-tenancy, payment models that are linked to usage, resources delivered from virtualized environments and the provision of all support and management tasks by a cloud services provider.

However, the emergence of the term, ‘private cloud’ is creating confusion around cloud computing. It is a term that is commonly used by those with vested interests in existing computing paradigms. In fact, is the term an oxymoron?

Surely the use of private clouds is not cloud computing since key attributes of cloud computing include, the use of computing resources that reside outside of the enterprise and that are delivered to multiple customers (multi-tenancy) by a third party (cloud services provider). Private clouds deliver IT resources from within the corporate firewall and to one customer. To me, the term private cloud is a misleading way of describing hosted services. Is it a term that is used by providers of hosted services in order to hold onto lucrative contracts and prevent the loss of customers to companies that provide public cloud services?

Companies that offer services from the public cloud such as Salesforce.com are undermining traditional on-premise business models. The business case for sourcing resources from public clouds will soon be indisputable. In the next few years, business unit and IT managers will need to provide business cases for not using public clouds and for keeping resources on-premise.

Services that share the attributes of public cloud computing, have, of course been with us for many years. For example, the Application Service Provider (ASP) model of computing was expected to deliver services from the Internet to multiple clients. The ASP model did not mature for a variety of reasons. However, the planets are now aligned for an explosion of public cloud activity. Today’s virtualization technology, application acceleration technology, the widespread use of OpenSource and faster average broadband speeds are enabling the rapid adoption of public cloud based services.

In many ways, the use of public cloud services is creeping up on us by stealth. Although, the use of platforms, infrastructure or/and applications delivered from public clouds may seem to be comparatively immature, most people are using public cloud services. Each time we use Google’s search engine or a social networking tool such as Facebook or LinkedIn, we are using public cloud services. From an enterprise perspective, payroll processing services offered by companies such as ADP, are also a form of cloud computing. Now, if companies can send the personal details of their employees, their salary details, their tax details and their identification details to a datacenter that is operated by a third party such as ADP, are privacy and security concerns legitimate reasons for not wishing to use public cloud services?

I believe that a mix of groupthink and conservatism is at play in many cases when objections to the use of cloud services are raised. These objections tend to be centered around security and privacy. It is argued that private clouds address these concerns. In my view, so called private clouds re-inforce the conservatism of many in business today by giving them an excuse not to use the public cloud. In a few years time, those that simply revamp their existing datacenters to provide private cloud services and those that refuse to use cloud services for security and privacy reasons, will give the impression that they simply cannot grasp their very straightforward and obvious business benefits of using public cloud services.