Welcome!

SDN Journal Authors: Elizabeth White, Liz McMillan, Jeremy Geelan, Pat Romanski, Patrick Pushor

Related Topics: Cloud Expo, SOA & WOA, Virtualization, Web 2.0, Security, Big Data Journal, SDN Journal

Cloud Expo: Article

Moving Your Company’s Application or Service into the Cloud?

Beware of what your customers will expect

A number of studies I’ve recently read indicate that more enterprises will use cloud services in 2013 than ever before.  This fact is not lost on many of my software vendor clients, who are transitioning many of their on-premises products into cloud-based offerings.

The problem many of these vendors are facing is the inability to address data privacy and security demands placed upon them by their customers due to the weak contractual protections offered by the vendor’s hosting providers.  As a result, the time and cost savings expected by leveraging the cloud model are lost by extended contract negotiations between the vendor, customer, and hosting provider.

Here is a typical example:

  1. Software vendor wishes to offer its cloud-based service to a financial services company.
  2. The financial services company sends the software vendor its detailed requirements for information security controls, data privacy, breach detection and response, security program details and systems, disaster recovery, encryption, physical security, and data destruction and certification.
  3. Software vendor reviews the contract with its hosting provider to determine whether the financial services company’s security requirements can be met.
  4. Software vendor discovers that its hosting provider only commits to something like “we will implement reasonable and appropriate measures designed to help you secure your content against accidental or unlawful loss, access or disclosure.”  (See, for example, Amazon’s Web Services Agreement, Section 3.1.)
  5. Panic ensues.

Generally, at this point the software vendor is left with a couple of options:  One, attempt to renegotiate its hosting provider contract to incorporate the voluminous information security controls demanded by its financial services company customer, or two, convince the financial services company to drop its demands and accept language similar to Amazon’s above.  You can guess how well each of these options will work out.

So what is a software vendor to do?

Before accepting a hosting provider’s contract, know your target customer base.  Are your customers regulated by laws like Gramm-Leach-Bliley or HIPAA?  Is your service likely going to be storing sensitive information of your customers?  If the answer to these or similar questions is yes, then selecting a hosting provider willing to accommodate and contractually commit to specific data security protocols is paramount.  Many enterprise users are feeling both internal and external pressure to shave costs and move certain services and data into the cloud – even if doing so creates heightened risks and liabilities.  But simply explaining to these users that “our hosting provider doesn’t provide these assurances” usually won’t cut it.

In my next post, I’ll discuss certain tactics software vendors can use with their hosting providers to create more robust and meaningful protections for them, and their customers.

More Stories By Dan Pepper

Dan Pepper is the managing member of Pepper Law Group, LLC, a boutique technology law firm, and has spent nearly 20 years in the information technology law field, including acting as in-house counsel for Oracle Corporation. He presents at conferences worldwide on the legal risks associated with cloud computing.

Cloud Expo Breaking News
“Cloud has everything to do with what has happened with Big Data,” explained Jason Deck, Director of Strategic Alliances at Logicworks, in this exclusive Q&A with Cloud Expo Conference Chair Jeremy Geelan. “Big Data doesn’t exist in its easily accessible way without cloud. From reduced startup costs, to cheap storage, to fast processing, to adequate security, to the easy incorporation of third-party analytics tools, cloud made Big Data accessible to customers of all sizes, with all different bud...
“Social, mobile, analytics and cloud can’t be looked at as distinct technology trends; they are facets of the same movement and an everyday reality for consumers and businesses alike,” said Craig Sowell, IBM VP of SmartCloud Marketing, in this exclusive Q&A with Cloud Expo Conference Chair Jeremy Geelan. “This means that businesses need to start looking at trends as one: cloud is the delivery, analytics is the unique insight, social is a shareable service, and mobile is the ubiquitous access.” ...
The new open source cloud orchestration platform called OpenStack is the promise of flexible network virtualization, and network overlays are looking closer than ever. The vision of this platform is to enable the on-demand creation of many distinct networks on top of one underlying physical infrastructure in the cloud environment. The platform will support automated provisioning and management of large groups of virtual machines or compute resources, including extensive monitoring in the cloud.
In his session at the 12th International Cloud Expo, Dave Eichorn, Global Data Center Practice Head at Zensar, will share a case study describing how a utility services company handled the migration of its Microsoft platform to the cloud. Challenged with the time-consuming task of opening operations out of temporary offices, this company struggled with the need to simultaneously access data that was accumulated from a vast amount of data-intensive jobs. Zensar migrated the company’s application ...
With Cloud Expo New York | 12th Cloud Expo [June 10-13, 2013] hurtling towards us, let's take a look at the distinguished individuals in our incredible Speaker Faculty for the technical and strategy sessions at the conference coming up June 10-13 at the Jacob Javits Center in New York City. We have technical and strategy sessions for you all four days dealing with every nook and cranny of Cloud Computing and Big Data, but what of those who are presenting? Who are they, where do they work, wha...
SYS-CON Events announced today that Wowrack will exhibit at SYS-CON's 12th International Cloud Expo, which will take place on June 10–13, 2013, at the Javits Center in New York City, New York. Wowrack’s core expertise lies in high-availability Private and Public Cloud IaaS Hosting Solutions. Wowrack provides a true Hybrid service – where business release all IT management and hardware provisioning – taking the data center and server system administrative headaches off our customer’s shoulders. ...
At pennies per virtual machine-hour, the economics of cloud computing are both compelling and daunting to replicate. Whether you are building your own cloud infrastructure, building a public cloud or choosing a cloud service, there are key strategy and technology decisions that make the difference between success and failure. In his General Session at the 12th International Cloud Expo, Jason Waxman, VP in the Intel Architecture Group and general manager of the Cloud Platforms Group within Inte...
You're getting pitched every day from your legacy enterprise software and hardware vendors about "cloud." They're doing an amazing job of convincing your CIO and CTO about what cloud is and how you should use it. The reality is they're defending their shrinking market share and keeping you on the legacy treadmill for as long as they can by selling you solutions that aren't "cloud." In her session at the 12th International Cloud Expo, Niki Acosta, Cloud Evangelista for Rackspace, will talk thro...
The rise of cloud computing has exposed hard drive-based storage as the new data center bottleneck. Combating this, data center managers have deployed SSDs to gain the performance needed to provide real-time access to data. However, due to budget constraints, many have turned to consumer-grade SSDs without understanding that they wear out quickly when processing enterprise workloads. In this session, Esther Spanjer will discuss recent endurance advancements in SSD technology that enable usage of...
Organizations across the world are increasingly starting to see the benefits of moving more and more services to the cloud. The focus on the cost-saving potential of cloud is rapidly shifting to completely transforming the business with cloud. As organizations are investing enormous sums on technology they are starting to realize that in order to maximize the return on investment and accelerate the business transformation process the first area of focus should be people. By ensuring the organiza...