Showing posts with label cloud computing. Show all posts
Showing posts with label cloud computing. Show all posts

Monday, August 27, 2012

Is Cloud More Secure Than On-Premises Software?

Security is the most common objection people - or companies - raise against the adoption of a cloud based solution. There have certainly been enough stories reported about compromised passwords and other security breaches at cloud based services such as Dropbox or iCloud. Emotionally, it feels like having our data stored somewhere where we can’t see it is just not very secure.

But let’s face it, we’ve had our money stored somewhere where we can’t see it for decades. Yet we seem to be completely trusting of our banks. Nobody is arguing that our money would be more secure under our mattresses. Quite the contrary, we rush to put our money into the banks knowing full well that the bank doesn’t actually keep the money. At the end of the day, it is just an entry in a computer database somewhere...somewhere...in a cloud. Or private cloud to be more precise. In any case, we consider banks highly secure today.

And so, the latest argument about cloud security goes in the opposite direction. We are beginning to realize that the cloud companies have more at stake, and so they are likely investing into security more so than a typical company ever would or could afford for its on-premises software.


Let’s take an example. Thousands of companies across North America have been using ADP to process their payroll for many years. ADP’s payroll processing is a cloud based application - it has been long before we knew what the cloud was all about. ADP even offers to outsource the service, not just the app.  Yet as far as security goes, nobody is screaming that it is preposterous having all the highly confidential personal data stored at ADP. In fact, most people think that it is probably safer at ADP than it would be if processed by their own employer.

Indeed, cloud companies are increasingly considered capable of providing more security features than companies running on-premises software. Just yesterday, Dropbox raised the bar by rolling out a two-factor authentication. How many of your on-premises applications have that?

But then again, the cloud companies are a much bigger and more attractive target for the bad guys. The hackers might never pay attention to your company and your data center but they sure know about Google Apps, Dropbox, Amazon EC2, Microsoft Azure, and Apple iCloud. Hacking a big name cloud company is just a very lucrative target that many hackers see as a challenge they can’t resist.

So what gives? Is our data more secure on-premises or in the cloud? Well, I suppose there is no black-and-white answer out there today. There are many considerations that need to go into software selection - on-premises or in the cloud. Security is certainly one of them. And we can be sure that the security debate will remain a hot one for quite a while.

Monday, November 28, 2011

Are You Ready for the Cloud?

Cloud computing has been the marketing topic of 2011. You could hardly attend a conference without being bombarded by predictions of how cloud computing is going to revolutionize our technology landscape. Indeed, having your data in the cloud is quickly becoming a necessity in the time when we are dividing our computer time among multiple devices.

Yet companies have been a bit more conscientious rushing to the cloud. Sure, there have been stories about many users and departments signing up for various cloud-based services such as collaboration, file-sharing, or project management. But not many enterprises have ripped out their existing on-premise solutions in favor of cloud-based offerings yet.

There are reasons why enterprises are careful. Security concerns are usually being mentioned as the top concern. The data in the cloud is not under your control and so it is less secure, right? Actually, I’m not sure I buy that argument. In fact, the cloud vendor most likely has better security in place than most enterprises could ever afford to deploy.

A much bigger issue is the data control and ownership. First, there is the issue with employee-owned devices that end up containing corporate data. In case of a device theft or employee departure, the company isn’t allowed to wipe the device and has no control over the data. That is a problem for corporate security and legal liability.

The second issue related to data ownership is the protection provided by the cloud service providers. Take Google Gmail, for instance, which is being used by many employees. The Section 11 of the Terms of Service contains the following paragraph:

By submitting, posting or displaying the content you give Google a perpetual, irrevocable, worldwide, royalty-free, and non-exclusive license to reproduce, adapt, modify, translate, publish, publicly perform, publicly display and distribute any Content which you submit, post or display on or through, the Services.

That clause alone made me think really hard about how much am I willing to use Gmail for communication with my tax accountant or investment advisor.  

And then there is the Patriot Act issue which forces US based companies to comply with law enforcement requests to hand over your data. Dropbox’s Privacy Policy, for example, includes the following passage:

We may disclose to parties outside Dropbox files stored in your Dropbox and information about you that we collect when we have a good faith belief that disclosure is reasonably necessary to (a) comply with a law, regulation or compulsory legal request; (b) protect the safety of any person from death or serious bodily injury; (c) prevent fraud or abuse of Dropbox or its users; or (d) to protect Dropbox’s property rights.

Good faith belief that disclosure is reasonably necessary” - that isn’t exactly the Swiss Banking Act, is it? While it may be the law in the US, it may also be beyond the tolerance threshold of many companies - particularly those from European countries that have a much less casual attitude towards data security and privacy.

As a result, companies are being very careful when taking advantage of cloud based services - particularly those that primarily cater to consumers. Such services will be likely supplemented by private-cloud based offerings that provide similar capabilities under the organization’s full control.

Also, a hybrid cloud approach might be used more often to address corporate concerns. One customer recently told me that they are moving their users to a cloud based email except for critical functions such as the financial and legal departments and their entire executive team.

This kind of approach may result in lower capital expenditures, but probably higher overall costs and complexity. Well, welcome to the Cloud Age!

Sunday, September 18, 2011

Consumarization of BPM

Business process management (BPM) is a high growth market that delivers significant return-on-investment to customers who deploy these solutions to improve their efficiency. Still, many people think that BPM is just a boring back-end technology. I know that hipness lies in the eye of the beholder but I’d argue that social media or gamification are getting more attention than back-end technologies such as data warehousing, archiving, or BPM.

There are several new trends in BPM that make it just as exciting as Jive Software except much more profitable. One of the trends is social BPM which employs social networking capabilities to allow for better decision-making in business processes. Long gone is the era of business processes that attempted to cover every single permutation of possible conditions to route the task in a predetermined path. Too many exceptions were typically the result and, in the end, the majority of decisions are best done by humans. It is the social software that can quickly help to identify and get together the right experts to help them make a decision.

Another important trend in BPM is mobility. As much as mobile devices are becoming the primary user experience, not everything we do in the office has the same appeal for a mobile user. Reviewing or editing documents works well on a tablet but it becomes pretty tedious on a smartphone. Interacting with a business process on a smartphone, however, makes a lot of sense and it is exactly here where a lot of customers realize the greatest benefits from mobility. So many process steps used to sit idle, waiting for the user to get back to the office since the email-based alert didn’t provide enough context to make a decision. By taking BPM mobile, the process apps are easily tailored to make users very effective to handle any process tasks.
Even submitting travel expenses can be pretty cool
Finally, BPM is also moving to the cloud. Besides the obvious appeal of shortening the deployment cycles by hosting the BPM software as a service, BPM can also benefit from making its functionality available to users easily. In any business process, it can happen that a particular expert needed for a specific task cannot participate since he or she doesn’t have access to the system. The cloud based approach makes BPM easily accessible. A good example of a cloud based activity is collaborative process design which frequently requires many stake holders to participate, even if some of them will not be involved in the actual process execution.

Clearly, the consumarization of the enterprise has reached BPM just like so many other disciplines of enterprise software. And who says that BPM is just a bunch of back-office technology? With the latest trends such as social BPM, mobility, and cloud, BPM is becoming rather hip. And it continues providing very compelling benefits such as higher efficiency, lower cost, or better quality.

Tuesday, August 9, 2011

The Cloud and the Asymmetric Patriot Act


USA PATRIOT Act of 2001
There have been numerous articles recently about cloud-based companies and their policies in regards to the Patriot Act. Most recently, Dropbox and Microsoft Office 365 have generated headlines when the press found out that their end user license agreement includes clauses that basically state that the company may have to hand the customer data over to the law enforcement authorities under certain circumstances – such as to comply with the Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 (in short USA PATRIOT Act).

Microsoft drew an additional dose of criticism as their policy apparently implies that they would repatriate and hand over data from European customers, even if the data resides on European soil. That, in turn, would be in violation with Europe’s data privacy and safe harbor laws which raised many eyebrows. Unlike the United States, the Europeans take personal privacy much more seriously. For example, an employee’s email belongs to the employee in many European countries and not to the company as it is the law in the US. By the way, am I the only one who finds the whole notion of cloud data residing on some country’s soil a little paradoxical? Since when do clouds care about borders?

My take is that the problem might not lie with the cloud based companies and their frivolous attitude towards their customers’ data. I believe that the challenge lies in the Patriot Act itself. The Patriot Act has been signed into law in October 2001 as a response to 9/11 and it was extended in May 2011. The Act grants the US government sweeping privileges to access private data in case of suspected terrorist threats. The US law enforcement agencies can apparently get your private data by requesting access to say Dropbox servers because suspected terrorists might be allegedly using Dropbox to plan their activities.

This kind of law would seem to violate the 4th Constitutional Amendment which protects citizens against unreasonable searches – law enforcement is supposed to get a court order and not many European courts would ever allow this. But the Patriot Act has been passed in the wake of 9/11 and anything to protect the US citizens from terrorists has a higher priority than protecting their civil liberties.

This reminds me of the speech that Sun co-founder and former Chief Scientist Bill Joy gave at TEDtalks back in 2006. Joy spoke about the asymmetric threats in the scary world we live in: “We can’t give up the rule of law to fight an asymmetric threat and we can’t fight the threat the stupid way we are doing because a million dollar act causes a billion dollar damage which causes a trillion dollar response which is largely ineffective and almost certainly has made the problem worse.”. If anything, Joy’s speech was understated as the 9/11 response has reached several trillions by now. The Patriot Act is part of that response and the cost keeps rising.


The effectiveness of the Patriot Act has been questioned many times but that’s not my point. The terrorists aren’t stupid and they know about it and they know about plenty of other data sharing services that are not run by American companies and are thus not subject to the Patriot Act. My point is that the generic and sweeping authority that the Patriot Act gave to the US government is scaring the good guys away from the Cloud.

At least 99.99% of people are not terrorists; they are people like you and me and we get all nervous about using online services that do not offer us sufficient privacy. Many countries have a culture and laws that demand a much higher privacy protection than the United States.  The customers are already worried about the hackers who could compromise their information. And now, even the government is snooping in my data?  Perhaps, my data is better protected if I use the online services of a company based in the Germany or Canada - countries that are not subject to the Patriot Act?

The US economy needs stimulation. We shouldn’t be scaring away the privacy-loving Europeans. The United States could easily be known as the country where your data is the safest – attracting business from the entire world. But that is not what people think today. Right now, the secure data hosting business is going elsewhere.

The press is crucifying US cloud companies for the alleged vagueness in their end user policies. But what if those companies just try to do business in an environment that effectively forces them to have such clauses in their policies? Is the media barking up the wrong tree?

I know that there is a lot of good that came out of the Patriot Act but I suggest that in the era of cloud computing, it may need to be reviewed and possibly amended.

Sunday, May 22, 2011

The Real Problem with the Cloud

I am a big fan of cloud computing. The idea of having software provided as a service without having to actually deploy it makes a lot of sense. But, I often encounter skeptics who keep bringing up what I think are the wrong anti-cloud arguments - security concerns, availability issues, or perhaps the lack of customizations. The troubles that Amazon, Sony or Twitter just recently experienced are only fueling such arguments.

While those are valid concerns today, they are just growing pains. They are often exaggerated by the media and the blogosphere. In time, the cloud offerings may be able to address these issues better than any on-premise deployment. Take security, for instance, which is perhaps the most common issue raised by the cloud skeptics. Every one of my employers in the US used a SaaS based solution for payroll. And since that particular vendor caters to millions of users, I trust their security more than I would have trusted any one of my employers.

The one thing, however, that worries me about the cloud-based solutions today is the ability of a customer to part ways with their cloud providers. Nothing lasts forever and it is very likely that every customer will come to a point where they will want to get their data, templates, process definitions, business rules, users profiles, permissions, and customizations off the cloud vendor and move them into some other cloud.

The reasons may be many. The vendor could go out of business - it’s not like all those cloud start-ups are widely profitable today and some of them will just not make it. The vendor could also decide to shut down the service just like Google discontinued Wave and Video. The vendor could be acquired by someone else who changes the business terms. Or, the customer’s requirements evolve and the vendor no longer meets them. In any case, getting off a cloud where you have invested a ton of data and work isn’t trivial.

Nobody is talking much about this today. Of course, all the vendors are keen to attract and keep customers. Nobody wants to advertise the ability to let customers go easily. But that’s exactly what they need to do to get serious enterprise customers. They need to provide the right APIs, tools, services and terms that make an easy farewell possible.

This is the one cloud challenge that has me worried. On-premise software is also tough to leave but at least the customer owns the system and the data and has usually a plenty of time to figure out how to dump their vendor. A 30 day notice is not what enterprise customers will be comfortable with.