Fear Hackers? First invest in an IT security culture change

VMware lays out roadmap to the clouds.

By G C Network | June 10, 2008

Earlier this year, Diane Greene, VMware President and Co-Founder, described cloud computing as the final evolutionary step for virtualization. Reza Malekzadeh, Senior Director of Products and Marketing reinforced that view…

Mario Dal Canto at Virtualization Conference & Expo 2008 East

By G C Network | June 9, 2008

According to Mario Dal Canto, “Virtual Cloud Computing represents the next wave of virtualization and offers significant market opportunities by providing a new, simpler, and much more pervasive platform for…

Microsoft cloud fits and starts.

By G C Network | June 9, 2008

Microsoft’s dance with cloud comuting is very puzzling. Point 1: The June 5th Wall Street Journal article discusses the friction between Steve Ballmer and Bill Gagtes over NetDocs, described by…

Salesforce.com & Google

By G C Network | June 6, 2008

A short promotional video on Salesforce and the Google cloud. Follow me at https://Twitter.com/Kevin_Jackson

Gamers now have their own cloud.

By G C Network | June 5, 2008

Valve, a Bellevue, Washington based entertainment software and technology company, recently announced that they will use the cloud computing paradigm as their next major update. Called “Steam Cloud” the service…

Is IBM serious about cloud computing?

By G C Network | June 5, 2008

Last week in Eye on the Enterprise, Joe McKendrick, highlighted IBM VP Steve Mills’ apparently less than enthusiastic statement regarding cloud computing. In an April 30th interview with CNET’s Dan…

VMware and Cloud Computing

By G C Network | June 3, 2008

VMware President and Chief Executive Officer Diane Greene,in her keynote address at the JP Morgan Technology Conference in Boston, described cloud computing as the final evolutionary step for virtualization. In…

DISA Cloud Computing Plans

By G C Network | June 3, 2008

During last month’s Defense Information Systems Agency (DISA) Partnership Conference, cloud computing debuted as a “top priority” for senior leadership. Speakers described a future state when users would access computing…

The Cloud Computing Portal

By G C Network | May 30, 2008

The Cloud Computing Portal is a community edited database that makes the cloud vendor selection process easier, by helping you find a cloud provider who supports the environment you need.…

HP in the Cloud

By G C Network | May 29, 2008

In “HP weds cloud…” , Hewlett-Packard has apparently outlined their approach to cloud computing. They are merging their high-performance computing unit with the Web 2.0 and cloud computing infrastructure businesses.…

by
Kevin L.Jackson

 With all the news these days about cyberterrorism and hacking the cloud may seem like the last place you would want to put your precious information. Pew Research has even suggested that cyber-attacks are likely to increase. Some 61% of over 1600 security expert respondents to a recent survey said “yes” that a major attack causing widespread harm would occur by 2025,according to the Pew Research study. The cold hard fact, however, is that fear of the cyberterrorist and hackers, while definitely valid, is mostly misplaced.  I hold this contrarian view, because when you pull back the curtain on many of the recent breaches, you’ll likely see a mirror!

In a recent case, sensitive data including passwords seem to have been stored in the clear which is against all recommended best practices. There also may have been significant involvement from a company insider.  Focusing on application hacks, some of the most devastating have been due to a failure of the application developers to follow some basic best practices for application development.  Another important fact is that most of these breaches were not on cloud service providers.  These successful attacks were on enterprise built and managed IT infrastructures.

Our failure to protect our information and data is mostly due to our less than focused attitude towards cybersecurity.  Policies, procedures and processes play an important part in preventing security incidents but more is needed.  Every organizational employee must realize that they could be an entry point for hackers and be aware of their individual actions.  IT professionals must follow industry standard best practices for application development, network configuration, system configuration, etc. Many of which have gone through multiple iterations over the years. Everyone must also be proactive in their identification and response to cyber threats.  What I am describing is the need for a cultural change.

Creating a risk-conscious and security-aware culture is key to protecting an organization’s information infrastructure and data assets, risk management expert John P. Pironti wrote in 2012 ISACA Journal article. Business leaders must begin viewing information security as a benefit, rather than as an obstacle, and employ threat and vulnerability analysis – rather than fear and doubt – to drive adoption of points of view and controls

So let us first focus on changing our IT security culture. That will give us the edge we need in order to prevail over the cyber underworld.  We also must adopt a “trust-but-verify approach to monitoring and oversight of organizational and employee activities”. This would involve the adoption and expansion of automated security control point monitoring and reporting.  This, in fact, is a strength of any well designed and implemented cloud computing platform.

(This post was written as part of the Dell Insight Partners program, which provides news and analysis about the evolving world of tech. To learn more about tech news and analysis visit Tech Page One. Dell sponsored this article, but the opinions are our own and don’t necessarily represent Dell’s positions or strategies.)

Cloud Musings

( Thank you. If you enjoyed this article, get free updates by email or RSS – © Copyright Kevin L. Jackson 2012)

Follow me at https://Twitter.com/Kevin_Jackson
Posted in

G C Network