Welcome!

SDN Journal Authors: Pat Romanski, Liz McMillan, Stefan Bernbo, Elizabeth White, TJ Randall

Related Topics: @CloudExpo, Microservices Expo, Open Source Cloud, Containers Expo Blog, Cloud Security, @BigDataExpo, SDN Journal

@CloudExpo: Article

Cloud Is All About Security

An exclusive Q&A with Terry Woloszyn, Founder & CEO, Leeward Security Ltd.

"Open source has always provided a number of benefits, including easing adoption costs, propagating a better understanding of the technology, and allowing for faster evolution and commercialization of products and services based on it," noted Terry Woloszyn, Founder & CEO, Leeward Security Ltd., in this exclusive Q&A with Cloud Expo Conference Chair Jeremy Geelan. "This is clearly evident with the OpenStack and CloudStack," Woloszyn continued, "and others that have been quickly commercialized as offerings such as Rackspace."

Cloud Computing Journal: The move to cloud isn't about saving money, it is about saving time. - Agree or disagree?

Terry Woloszyn: It's actually both. Depending on the type of cloud - SaaS, PaaS, or IaaS, and whether it is private or public - the metrics that are used to determine the savings vary in weighting and importance. For example, the total cost of ownership in selecting, installing, configuring, managing, and ultimately replacing enterprise applications is quite large when compared to utilizing a public cloud SaaS equivalent. In this case, it's about saving time and money. On the other hand, utilizing a private cloud infrastructure as a host platform for enterprise applications is much more about saving time in provisioning, as the money difference is small, realized only in hardware utilization and platform management cost savings.

There are other metrics that factor into a selection decision as well, such as security, redundancy, disaster recovery, scalability, and more. It all comes down to the individual requirements of the selector when determining what "it's all about saving."

Cloud Computing Journal: How should organizations tackle their regulatory and compliance concerns in the cloud? Who should they be asking/trusting for advice?

Woloszyn: Unfortunately, regulatory compliance is a moving target. Depending on the jurisdiction, there may not even be a way to become compliant, as legislation at different levels of government may actually conflict, resulting in a bun fight between them that only the courts can settle, and may take years to do so.

Furthermore, cloud exacerbates the problem by spreading the compliance requirements across a plurality of jurisdictions, which results in more conflicting legislation. Great examples have emerged wherein data privacy compliance dictated by one jurisdiction outside of the US is impossible to achieve, thanks to PATRIOT, to be complied with if a US cloud is utilized. It may even be impossible to comply if the network traffic itself simply transits US territory. Again, legislators and regulators are only starting to realize that they no longer can legislate within their borders - that there is a global economic and technology reality that they must account for if their constituents are to remain competitive in the global markets.

As a result, trying to achieve 100% compliance may be impractical, as it is virtually impossible to understand where every bit is located and where they travel during the usage of the cloud, and what compliance requirements are incumbent on the users and providers as a result. One approach to resolve this is similar to ring security employed by systems today, with the core representing the local jurisdiction regulatory and compliance requirements, and the risks and costs for non-compliance. Each subsequent ring around the core represents regulatory and compliance requirements of lessening importance, along with corresponding risks and costs for non-compliance. The final ring represents no regulatory or compliance requirements, and no risks. By creating this type of framework and taxonomy, with the assistance of technologists, cloud providers, and legal counsel, it allows the adopter to quickly make assessments for existing and future cloud adoption, and easily allows for impact analysis of ever-changing technology, regulatory, and compliance requirements.

Cloud Computing Journal: What does the emergence of Open Source clouds mean for the cloud ecosystem? How does the existence of OpenStack, CloudStack, OpenNebula, Eucalyptus and so on affect your own company?

Woloszyn: Open Source has always provided a number of benefits, including easing adoption costs, propagating a better understanding of the technology, and allowing for faster evolution and commercialization of products and services based on it. This is clearly evident with the OpenStack, CloudStack, and others that have been quickly commercialized as offerings such as Rackspace. It makes for more consistency, faster adoption, and more robust offerings as everyone works towards the same results in the open source community, rather than the competitive development model of the 1980s and 1990s that only resulted in a handful of expensive, proprietary, half-solutions.

Cloud Computing Journal: With SMBs, the two primary challenges they face moving to the cloud are always stated as being cost and trust: where is the industry on satisfying SMBs on both points simultaneously - further along than in 2011-12, or...?

Woloszyn: Certainly from a cost perspective, cloud has become very affordable as a technology. However, the skills and labor costs associated with cloud adoption and management are still relatively high, making it a barrier for SMB adoption. As cloud becomes more ubiquitous, the skills become more accessible and affordable. As a result, like any technology, it is the large, early adopters that start, and it slowly cascades down through SMB, and eventually down to SOHO and individuals.

As for trust, SMBs actually seem to trust more than the enterprise adopters. This is because more cloud vendors have succeeded in promoting security and trust of their brand through standards compliance, certification, and customer recognition. SMBs are aware that the cloud vendors are likely more secure an offering, for example, than the SMB themselves could provide.

Cloud Computing Journal: 2013 seems to be turning into a breakthrough year for Big Data. How much does the success of cloud computing have to do with that?

Woloszyn: Big Data, like other enterprise-scale technologies, would only be within reach of large enterprises without the support of cloud. Cloud has a democratization effect on new technology adoption, and allows for economies of scale that would otherwise be unaffordable by most organizations. This makes Big Data accessible by a much larger group of adopters, by virtue of cloud support.

Cloud Computing Journal: What about the role of social: aside from the acronym itself SMAC (for Social, Mobile, Analytics, Cloud) are you seeing and/or anticipating major traction in this area?

Woloszyn: There was a time when having a website was a requirement for organizations to be considered "real" and viable. Organizations without a website were viewed as either too small, or not viable, or not even trustworthy. Today, a website is mandatory for all organizations to do business. The same pattern is being followed for Social. Organizations now see an emerging requirement for social participation in order to be recognized as "real." The convergence of mobile and social and cloud has accelerated the growth of social as the primary and preferred interaction channels between the consumers and business, and between businesses themselves. Without a social presence, organizations today will simply not survive against those that actively exploit social media in their sales, marketing and other business functions.

Cloud Computing Journal: To finish, just as real estate is always said to be about "location, location, location", what one word, repeated three times, would you say Cloud Computing is all about?

Woloszyn: Cloud is all about "Security, Security, Security," where Cloud provides the security in cost savings, the security in access and availability, and the better security against present and future threats.

More Stories By Pat Romanski

News Desk compiles and publishes breaking news stories, press releases and latest news articles as they happen.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@CloudExpo Stories
Machine Learning helps make complex systems more efficient. By applying advanced Machine Learning techniques such as Cognitive Fingerprinting, wind project operators can utilize these tools to learn from collected data, detect regular patterns, and optimize their own operations. In his session at 18th Cloud Expo, Stuart Gillen, Director of Business Development at SparkCognition, discussed how research has demonstrated the value of Machine Learning in delivering next generation analytics to impr...
Join Impiger for their featured webinar: ‘Cloud Computing: A Roadmap to Modern Software Delivery’ on November 10, 2016, at 12:00 pm CST. Very few companies have not experienced some impact to their IT delivery due to the evolution of cloud computing. This webinar is not about deciding whether you should entertain moving some or all of your IT to the cloud, but rather, a detailed look under the hood to help IT professionals understand how cloud adoption has evolved and what trends will impact th...
More and more brands have jumped on the IoT bandwagon. We have an excess of wearables – activity trackers, smartwatches, smart glasses and sneakers, and more that track seemingly endless datapoints. However, most consumers have no idea what “IoT” means. Creating more wearables that track data shouldn't be the aim of brands; delivering meaningful, tangible relevance to their users should be. We're in a period in which the IoT pendulum is still swinging. Initially, it swung toward "smart for smar...
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
Businesses and business units of all sizes can benefit from cloud computing, but many don't want the cost, performance and security concerns of public cloud nor the complexity of building their own private clouds. Today, some cloud vendors are using artificial intelligence (AI) to simplify cloud deployment and management. In his session at 20th Cloud Expo, Ajay Gulati, Co-founder and CEO of ZeroStack, will discuss how AI can simplify cloud operations. He will cover the following topics: why clou...
Internet of @ThingsExpo, taking place June 6-8, 2017 at the Javits Center in New York City, New York, is co-located with the 20th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. @ThingsExpo New York Call for Papers is now open.
"ReadyTalk is an audio and web video conferencing provider. We've really come to embrace WebRTC as the platform for our future of technology," explained Dan Cunningham, CTO of ReadyTalk, in this SYS-CON.tv interview at WebRTC Summit at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
When it comes to cloud computing, the ability to turn massive amounts of compute cores on and off on demand sounds attractive to IT staff, who need to manage peaks and valleys in user activity. With cloud bursting, the majority of the data can stay on premises while tapping into compute from public cloud providers, reducing risk and minimizing need to move large files. In his session at 18th Cloud Expo, Scott Jeschonek, Director of Product Management at Avere Systems, discussed the IT and busin...
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at Cloud Expo, Ed Featherston, a director and senior enterprise architect at Collaborative Consulting, discussed the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
Successful digital transformation requires new organizational competencies and capabilities. Research tells us that the biggest impediment to successful transformation is human; consequently, the biggest enabler is a properly skilled and empowered workforce. In the digital age, new individual and collective competencies are required. In his session at 19th Cloud Expo, Bob Newhouse, CEO and founder of Agilitiv, drew together recent research and lessons learned from emerging and established compa...
Everyone knows that truly innovative companies learn as they go along, pushing boundaries in response to market changes and demands. What's more of a mystery is how to balance innovation on a fresh platform built from scratch with the legacy tech stack, product suite and customers that continue to serve as the business' foundation. In his General Session at 19th Cloud Expo, Michael Chambliss, Head of Engineering at ReadyTalk, discussed why and how ReadyTalk diverted from healthy revenue and mor...
Effectively SMBs and government programs must address compounded regulatory compliance requirements. The most recent are Controlled Unclassified Information and the EU's GDPR have Board Level implications. Managing sensitive data protection will likely result in acquisition criteria, demonstration requests and new requirements. Developers, as part of the pre-planning process and the associated supply chain, could benefit from updating their code libraries and design by incorporating changes. In...
"Coalfire is a cyber-risk, security and compliance assessment and advisory services firm. We do a lot of work with the cloud service provider community," explained Ryan McGowan, Vice President, Sales (West) at Coalfire Systems, Inc., in this SYS-CON.tv interview at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
CloudJumper, a Workspace as a Service (WaaS) platform innovator for agile business IT, has been recognized with the Customer Value Leadership Award for its nWorkSpace platform by Frost & Sullivan. The company was also featured in a new report(1) by the industry research firm titled, “Desktop-as-a-Service Buyer’s Guide, 2016,” which provides a comprehensive comparison of DaaS providers, including CloudJumper, Amazon, VMware, and Microsoft.
"We are an all-flash array storage provider but our focus has been on VM-aware storage specifically for virtualized applications," stated Dhiraj Sehgal of Tintri in this SYS-CON.tv interview at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
The 20th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held June 6-8, 2017, at the Javits Center in New York City, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Containers, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal ...
We are always online. We access our data, our finances, work, and various services on the Internet. But we live in a congested world of information in which the roads were built two decades ago. The quest for better, faster Internet routing has been around for a decade, but nobody solved this problem. We’ve seen band-aid approaches like CDNs that attack a niche's slice of static content part of the Internet, but that’s it. It does not address the dynamic services-based Internet of today. It does...
You have great SaaS business app ideas. You want to turn your idea quickly into a functional and engaging proof of concept. You need to be able to modify it to meet customers' needs, and you need to deliver a complete and secure SaaS application. How could you achieve all the above and yet avoid unforeseen IT requirements that add unnecessary cost and complexity? You also want your app to be responsive in any device at any time. In his session at 19th Cloud Expo, Mark Allen, General Manager of...
Major trends and emerging technologies – from virtual reality and IoT, to Big Data and algorithms – are helping organizations innovate in the digital era. However, to create real business value, IT must think beyond the ‘what’ of digital transformation to the ‘how’ to harness emerging trends, innovation and disruption. Architecture is the key that underpins and ties all these efforts together. In the digital age, it’s important to invest in architecture, extend the enterprise footprint to the cl...
Bert Loomis was a visionary. This general session will highlight how Bert Loomis and people like him inspire us to build great things with small inventions. In their general session at 19th Cloud Expo, Harold Hannon, Architect at IBM Bluemix, and Michael O'Neill, Strategic Business Development at Nvidia, discussed the accelerating pace of AI development and how IBM Cloud and NVIDIA are partnering to bring AI capabilities to "every day," on-demand. They also reviewed two "free infrastructure" pr...