Sunday, November 25, 2012

Security and Convenience - The Balance Matters

In our world, where information is the ultimate strategic resource, security is important. Very important. But security usually stands in the way of productivity and convenience.

Take something like strong passwords and the need to change them regularly. We could significantly increase the system security if we mandated very long, strong passwords with 256 characters and if we mandated them to be changed every day. The data would be very safe with these passwords. Of course remembering such passwords would be highly inconvenient, if not impossible, and changing them daily would be annoying. Want even higher security? How about 1024 character long passwords that have to be changed every hour?

Practical security today has to reach a compromise; a balance between security and convenience. We have to keep pushing the barriers on security without annoying users so much that they either give up or develop behavior that actually compromises the security altogether. In my password example above, people would lose productive time every day and they would likely have no choice but to write the password down every morning on a piece of paper kept right next to their monitor. All of those passwords lying around would severely compromise the security of the system which would achieve exactly the opposite from the intended result. If you are interested in learning more about password related challenges, I recommend reading the recent Wired article titled Kill the Password: Why a String of Characters Can’t Protect Us Anymore.

Clearly, there is a constant tradeoff that we have to make between security and convenience. However, not every organization is the same in terms of how strong their security needs to be  and how much inconvenience they can impose on their employees. I often meet customers who are on very different points of the spectrum, from very casual to utterly paranoid.


Of course nobody will admit that they have a casual attitude towards security. However, consider the differences between retail, manufacturing, and, yes, many technology companies which often get by with relatively simple security (I know, there are always exceptions) versus organizations such as military installations, intelligence agencies, and nuclear facilities. These operate on a completely different security level and have no choice but to impose a lot of inconvenience on their employees.

Think about all of the employees working at Internet startups in Silicon Valley and about how much security hassle you could put them through - not much! James Bond, on the other hand, never tires of opening the cafeteria doors using his palm and voice print. Apparently, high security standards come with some jobs (or companies).

What’s important is that one size doesn’t fit all when it comes to security. Different organizations face different security problems and their solutions have to be adjustable. For example, a two-factor authentication may be appropriate in some environments while a biometrics based authentication is a good fit in others.  Getting the balance right between security and convenience is important - the balance matters!

Sunday, November 18, 2012

Social Is Now a Noun

Inspired by the tremendous growth of Facebook and its endless ability to compel users to share, communicate and engage, companies have been trying to convince their employees to do the same at work. They hope that the same type of technology will help employees to share, communicate and engage inside the enterprise just as they do in the consumer world. Sometimes it works, although many companies are learning that just because you build it, they won’t necessarily come.
Social software is a very hot space right now.
What’s interesting, though, is how the industry struggles to find the right way to describe what it is we are doing here. The idea is not new, actually. Collaboration has been around for well over a decade and the benefits this new breed of social software offers is very similar to what collaboration did back in the early days of eRoom and OpenText Livelink. Heck, Lotus Notes has been called collaboration - the history of collaboration goes back to 1989! But of course we can’t use the old name ‘collaboration’ for this new hip, social software, can we?
Dedicated collaboration/social software is becoming rare
So the industry went on a long journey, searching for the right term. We started with extended collaboration, extended enterprise collaboration, collaboration software for the enterprise, team collaboration, and content collaboration and that apparently wasn’t cool enough, even though all these terms are still being used by various vendors. Then we borrowed the term social networking since that was how we used to refer to the thing we did on Facebook back then. That didn’t last very long and new terms came along including social software, social communities, social workplace, social business, and social collaboration. At some point, the industry even briefly toyed with the idea to seriously call this software category the Facebook for the Enterprise.

That, thankfully, didn’t take hold and so the journey continues. The latest trend is using just the word ‘social’. Yeah, I know, it is an adjective but old rules like grammar shouldn’t stand in the way of progress and world domination. And so, social became a noun.

More and more, social capabilities are built into enterprise applications
Well, maybe, the search will be over soon. It is becoming increasingly apparent that ‘social’  is becoming a feature rather than an industry. Social capabilities are increasingly becoming integrated into other enterprise software - from content management, business process management, customer experience management, to CRM and ERP. So, perhaps we don’t have to worry about what to call the space because it is not a space at all - it is an integral part of enterprise applications.

Wednesday, November 7, 2012

The Only Hope for Privacy?

In his interview with TechCrunch in early 2010, Facebook founder and CEO Mark Zuckerberg famously proclaimed that privacy is no longer the social norm. Well, not so fast, Mark. Some of us still think that privacy is important. But Mr. Zuckerberg has a point too. Protecting privacy is becoming increasingly difficult in the Facebook era.

It’s not just Facebook and the information that we voluntarily disclose. We are being increasingly tracked, often without knowing about it. From the websites we visit, our physical location via smartphone tracking, to the ubiquitous TV cameras on city streets - our moves are being recorded and the volume of information about us continues to grow.

So it appears, that our future will be - just like Mr. Zuckerberg predicted - devoid of any privacy. Every one of us will always be monitored by the modern incarnation of the Orwellian telescreen which will continue collecting huge quantities of information about us. Yet the growing volume of information may be our best hope for keeping some privacy after all. Let me explain.


From the film adaptation of Orwell's 1984
Powerful computers can be used by governments and corporations - the good guys and bad guys alike - to weed through all that information collected about you. Monitoring anyone particular is relatively easy but monitoring everyone to find someone or something particular is becoming increasingly difficult. There is just so much information! Finding anything is becoming a tough chore that requires some serious computing power. In other words, collecting a ton of information about you without the capacity to decode and analyse it is pointless.

In addition, the information is increasingly encrypted and comes in formats that are not easy to search and analyse. We all know that any encryption can - at least in theory - be decoded using a brute force attack. But we also know that the higher the level of encryption we apply, the harder it is to decode the data using brute force. This has been an ongoing cat-and-mouse game in which the larger and larger volume of data with increasingly stronger encryption demands more and more computing power to decode and analyse it.

Back in August  2011, I wrote about how the massive amount of recorded video surveillance was making it actually harder to apprehend the suspects after the Summer 2011 riots in London. Contrast that with the famous scene from the Philip Kaufman movie The Unbearable Lightness of Being where the secret police is indicting people based on a handful of photographs after the Prague Spring uprising of 1968. A couple of photos were relatively easy to analyse while terabytes of video have made it practically impossible.




Today, there are a few key choke points on the Internet, such as the intercontinental submarine cables, and it is feasible that a hostile foreign government could tap into them to capture and decode all the data. Back in 2010, China allegedly re-routed and hijacked a large portion of US Internet traffic. But to do anything meaningful with all that data, they’d need to build a really powerful supercomputer. By the time it’s built, that supercomputer will likely become obsolete - the volume of data is simply growing so quickly that the brute computing power is having a tough time keeping up.

So as it turns out, the growth of information volume could become an effective defense against spying and monitoring. Perhaps that works also on a smaller scale. One ‘bad picture’ on Facebook might cause you trouble for years to come, particularly if that’s the only picture of you there is. However, if it is one of 10,000 pictures of you, chances are the compromising one will not emerge during a cursory background check, provided that most of them are “good”.

This approach might even provide an effective defense strategy in an eDiscovery case, where the court subpoenas all information relevant to a given lawsuit. When complying with the subpoena results in a body of evidence comprised of 10 documents, the opposing party will have it easy to find what they need. If the court request, however, yields 10 million documents, the opposing party may need to reconsider whether or not they want to pay their lawyers $500 per hour to review all of that evidence.

Perhaps privacy does stand a chance afterall - when we drown the surveillance in a sea of data.

Thursday, October 25, 2012

Managing Paper in the Enterprise

Today, we observe the World Paper-Free Day to remind ourselves that we all are on a mission to get rid of the paper waste in the enterprise. I am a strong proponent of reducing the use of paper, even if I sometimes struggle. I read most of my books and magazines on my iPad, I use tools such as Evernote to take notes, and I have pretty much never any cash on me. If you look around my office, you’d probably score me as an 8 out of 10 on being paper-free except for my bookcase full of books. I really like books...
Many of our customers, however, struggle going paper-free. Indeed, flipping the switch from one day to another might be a little daunting. In reality, this transition has to be made easy to be realistic - this is more often a paper evolution than a revolution. That reminds me of some of the scenarios where our customers manage paper in the enterprise today:

1. Inbound
This is the most obvious situation where our customers deal with paper. This is the front-line in the war on paper. Many of our customers still receive paper-based information via snail mail and fax. They use our capture software to scan the paper documents right in the mailroom and to automatically extract as much information out of the scans as possible via optical character recognition (OCR) and data extraction which recognizes important data in the document (i.e. address, date, PO number etc.) to extract the metadata. Same thing happens with faxes that are captured using our fax software where the same OCR technique can be applied.

2. Outbound
At the tail end of many business processes is a new piece of content that has been produced to communicate to the stakeholders. This communication comes in two forms:
- Publishing - which is a form of communication using the same content asset(s) for a given target audience (more than one person). Publishing can occur online, on a portal, via mobile devices, email, etc. but it can also happen using paper - for example as a book or a marketing brochure.
- Customer Communication Management (also known as Output Management) which is a communication that has been personalized for a single individual. An example of such communication can be a utility bill which contains data about your monthly charges but it can also include useful, personalized tips on how to lower your next bill. This type of communication can again occur via a multi-channel delivery, one of which is often paper.

3. Physical Records
Managing records involves often the capability to manage physical records as well. The physical records - usually pieces of paper, but sometimes also objects such as police evidence - need to be kept the same way as electronic records, except that they don’t fit into a digital content repository. With physical records, the cost of storage is a major issue and records disposition usually means freeing up physical space on a shelf in a warehouse where those boxes of physical records are stored. The physical warehouse space is a major cost factor and many customers are approaching us today with projects to convert existing physical records stores into electronic records en masse.

4. Paper Processes
Yes, I know that the main idea of business process management (BPM) is to route information quickly from step to step and task to task - which is ideally done in an electronic form. But a few of our customers have to live with the paper-based process for now and yet they find inefficiencies in using BPM to track the status of each process instance. The workers complete their tasks on paper and then they “check off” the task in the BPM system to alert the next person that a task is coming. I know, I know...this is not the kind of BPM I usually recommend to our customers but I’ve seen it happen. Actually, this approach still delivers many of the BPM benefits. The manager can monitor the status of all the workers and processes, the processes can be optimized, the bottlenecks can be identified and the work teams can be re-aligned as needed. Those are some really cool benefits of BPM. Still, the plan is usually to add the capture software to get rid of paper altogether!

These are some of the use cases where our customers deal with paper - often as an intermediate step on the way to a paper-free enterprise. The paper-free vision is a great one but we will be probably dealing with paper for a long time. Any step that moves us in the right direction deserves a credit.

Here is to a Paper-Free World! 

Tuesday, October 16, 2012

These Filler Words

We marketers live by making up names - names of markets, products, and technologies. In the English language, names are easily created by chaining words together. New terms can be created very easily: mountain standard time (MST), automated teller machine (ATM), and Securities and Exchange Commission (SEC) are just a few examples of how nouns and adjectives can be strung together in English to create smart sounding new terms and names. Acronyms such as NBC, CIA, NFL, LAX, JFK, SAT, BTW, CEO, and USA are part of our everyday language.
Technology marketing often resembles the Alphabet Soup. (Source)
The problem is that technology marketers like to fall in love with three letter acronyms. Consequently, the terms and names they coin have to consist of three words. Random Access Memory, Content Distribution Network, Subscriber Identity Module are just a few examples of such three word names. Consequently, we have three letter acronyms such as RAM, CDN, SIM that dominate our technology language. We love it so much that we even have an acronym for the term ‘three letter acronym’: TLA.

It seems that sometimes we even add an unnecessary word just to make a name consist of three words. For example, I think that Enterprise Content Management could do without the word ‘enterprise’. Since there is no Consumer Content Management (unless you count Picasa and iTunes), we could easily get by with just Content Management. Similarly, I don’t see much difference between Business Process Management and just Process Management. Indeed, the words ‘enterprise’ and ‘business’ are often being added without much reason. We say ‘business ethics’ where just ‘ethics’ would do perfectly fine.

But there are even worst transgressions of this kind. When I hear Advanced Case Management, I have to chuckle. ‘Advanced’ as opposed to Retarded Case Management? Or, how about Extended Data Processing? ‘Extended’ as opposed to Limited Data Processing? And then, there is the omnipresent word ‘Management’. Marketing Automation Management? Hmm... Marketing Automation would probably do. Customer Experience Management? I vote for Customer Experience!

Don’t take me wrong, I am not saying that all three letter names are wrong. Supply Chain Management is a perfectly good term and none of the three words can be dropped. Similarly, there is a difference between Asset Management and Digital Asset Management. There is definitely a place for three and even four letter names. But what I am suggesting is that we should examine the meaning before we get carried away by the language rhythm, melody, or whatever it is that makes us construct sometimes ridiculously sounding names.

Yet, there is hope. I see examples of new industry terms that consist of just two or even one word. Cloud Computing, Virtualization, Analytics - here are some very new industry terms we have settled on without messing them up. I’m sure that we could have coined Advanced Virtualization Management or Extended Information Analytics but we didn’t. Simplicity and logic have prevailed.

I know, it’s too late to reverse the course of history. The 10-year old terms such as Enterprise Content Management or Business Process Management will hardly be changed at this point. Although, if you follow my blog, I usually write just ‘content management’. Yes, with lower case characters because back in school I learned that only proper names should be capitalized. (Sigh...) Anyway, let’s create names and terms for new technologies that are simple, easily understandable, and free of redundant words!

Here is to good marketing!

Tuesday, October 9, 2012

Abstinence is not a Solution

Facebook just announced 1 billion active users last week. One BILLION is an incredible number. There is hardly any other product in the world that has 1 billion customers. OK, maybe Coca-Cola but I don’t drink coke, I do Facebook...
We all know that Facebook and other social media revolutionized the social interactions between people. Social media enabled us to be much more connected with friends and create relationships with new people. Facebook makes things possible and easy that were not possible before. The announcement, however, prompted me to think about a neglected factoid: There are 7 billion people on the planet and if only 1 billion are on Facebook, what the heck are the other 6 billion doing?


Yes, sure, among those 6 billion are many babies and other folks who are not using any computer. But still, there must be at least 3 billion people that have so far resisted Facebook. WHY???

I have many such Facebook abstinents among my friends and no amount of encouragement has moved the needle so far. Usually, they tell me that they don’t want to waste their time on frivolous conversations about what people had for dinner tonight. Another common argument is the narcissistic nature of many of the Facebook posts - it is more about advertising yourself than any other cause. Yet, the most frequent argument against Facebook is security and privacy. Disclosing any kind of information in such public forum will ultimately compromise your privacy and security. Won’t it?

Well, I have some news for you, dear Facebook abstinents. One of the greatest security threats that you can expose yourself to is not being on Facebook. Surprised? I’m serious!

If you don’t claim your own identity on Facebook (and other social sites), you expose yourself to someone else doing it in your name. It is really easy today to join Facebook as John Smith with a validated email address on Gmail or Yahoo Mail. The bad guys can establish a pretty decent profile with pictures, engage with your colleagues from remote locations, and collect a lot of personal data about you from others. Before you know it, they can pretend to be you. This is social engineering in the social media world.

With Facebook Connect, it gets even scarier. Facebook Connect is increasingly the preferred method of authentication to many other sites and services. Now, the perpetrator who has stolen your identity on Facebook gets access to many other sites on the Internet - as you!

The moral of the story is very simple. As much as a you may not be a fan of Facebook, it is important to establish your own identity online. Because if you don’t do it, someone else might do it for you...

Sunday, September 30, 2012

The Family Album of the Facebook Generation

When I was a kid, my parents had a small camera and, like most parents, they took many pictures of their offspring. As a result, there are a couple of family albums and a shoebox full of family pictures somewhere in the basement. Among those pictures are a couple hundred photographs of me.

Now, fast forward to the present time. I have literally thousands of pictures of my children. Those pictures are easily shared with other family members on flash drives and via Dropbox and often uploaded to Facebook or Flickr. When our children are grown, they will live in a world where their lives are well documented in pictures. Really well.


Yep, I have thousands of pictures of my kids...and those pics last forever!
What’s more, all those pictures will be fairly broadly distributed - our kids will have limited control over where their pictures are used. The pictures will be in many hands - many people will have a copy. Being camera shy just won’t fly.

This development is the result of two major events. First, the advent of digital photography has made taking pictures significantly less expensive - almost free. They are not entirely free as we are paying for the storage and often for the transmission cost. But compared to what pictures used to cost, they are pretty much free today. Back in the days of negatives and prints, each picture had an explicit price. A roll of 35mm film used to cost about $8 and the development plus those 36 prints would cost about $12 - that means each picture came to approximately $0.50. That made even the most avid photographer quite selective about when to squeeze the trigger!

The second event was the convergence of cameras and mobile phones. For years now, most mobile phones and smartphones include a camera and since pretty much everybody has a mobile phone today, everybody is a photographer. There are over 6 billion mobile phones out there and a significant portion of them have a built-in camera (at least 50%). On top of that, millions of digital cameras from the point-and-shoot to the fancy digital SLR cameras are sold every year. In the days of film cameras, there were only very few photographers among any group of people: weddings, group travel, or sports events. Today, everybody is taking pictures at all times. Some events in front of large audiences (i.e. concerts) have been completely transformed by the constant flashes from thousands of cameras.

All of the sudden, photography is free and ubiquitous and the result is predictable. Our lives are being documented like never before. Approximately 250 million pictures are being uploaded onto Facebook every day which is almost 25% of all pictures taken worldwide. In 2011, an estimated 375 billion pictures were taken in the world. That’s over 52 pictures for every single human being each year - at least one picture each week. Given the likelihood that the picture taking is concentrated into a smaller percentage of the world population, the likely number of pictures is much higher. Every one of the 950 million Facebook users uploads almost 100 pictures per year. That’s right, “uploads”, not “takes”. I’m guessing that if one out of every 10 pictures taken ends up on Facebook, the average Facebook user might be taking about 1,000 pictures a year. That’s 18,000 pictures before a child has a chance to hide in college from the parental picture taking.

That’s a pretty big shoe box. Our lives are documented way more than any generation before. And, we need to learn to live with it.

Tuesday, September 18, 2012

Darwin Meets the Innovator's Dilemma - in the Cloud

In his book Dealing with Darwin, Geoffrey Moore - the one of the Crossing the Chasm fame - has explained the difference between the complex systems and volume operations. According to this concept, technology vendors fall into one of two categories. The complex systems vendors focus on a relatively small number of high-value, high-touch transactions that are delivered in the form of sophisticated, customized solutions, usually integrated with other systems.
Geoffrey Moore's model for Complex Systems vs Volume Operations
The volume operators are doing exactly the opposite. They deliver relatively simple, inexpensive solutions through low-touch transactions - no direct sales force but resellers, retailers or online sales. These solutions come with no customization, no integration with other systems, and a limited feature set - one size fits all. While there are many scenarios in between (i.e. small business offerings), Geoffrey Moore suggests the the more a vendor is focused on one or the other extreme, the more effective the business model. IBM and Oracle are examples of complex system vendors while Apple and Google are volume operators.

The most important point that Moore makes is that vendor business models become so optimized for one or the other business architecture that crossing from one side to the other is impossible. Having started on one side of the model, the vendor’s business model, business processes, and key performance metrics are completely hard-wired towards the particular model that makes switching practically impossible.

Geoffrey Moore at an AIIM project
Now, let’s mesh the Moore model with another one - the Innovator’s Dilemma by Clayton Christensen. Professor Christensen suggests that disruptive innovations will always be attacking the incumbents from the bottom up - by providing low-end solutions for the less demanding customers and thus flying under the radar of the incumbent market leaders - until they gain the critical mass and sufficient functionality to challenge the incumbents.

Clayton Christensen's Innovator's Dilemma model 
OK, time to put the two models to work - in enterprise software. The established vendors including IBM, Microsoft, and Oracle are supposedly being challenged by the disruptors coming from the lower end of capabilities - just like the Innovator’s Dilemma predicted. Those disruptors are companies such as Salesforce, Google, Dropbox and others. They all have one thing in common - they are cloud based. But how do they do it when we look through the Geoffrey Moore lense?

Salesforce is a cloud based disruptor that has initially targeted the sales force automation (SFA) market and later the customer relationship management (CRM) market with a cloud based solution. Salesforce has clearly started as a complex system from day one and they have continued evolving in that direction. Their initial customer base were mostly smaller companies and departments but they continued focusing on complex systems - evolving towards more valuable and more complex deployments. Salesforce never had to shift from one side to another on the Geoffrey Moore model. Today, a typical Salesforce deployment involves integration to marketing automation and enterprise resource planning systems.

Microsoft started as a complex systems vendor with enterprise on-premise offerings such as Exchange and SharePoint (note: I’m discussing the enterprise software here, not their Xbox business). To take on the cloud challenge seriously, Microsoft created Office 365 - a cloud based offering that is clearly going in the direction of volume operations on the Moore model. That actually explains why Microsoft uses different branding for the cloud based solution and why they are not particularly worried about the integration between Office 365 and the on-premise offerings. While Microsoft shouldn’t be able to switch from the complex systems model to a volume operations model, they are applying their considerable financial resources to power through those challenges, ignoring the business model altogether.

Clayton Christensen during his visit in Waterloo, ON
Google and Dropbox started as cloud-based offerings focused purely on volume operations - on the consumers. The consumer focus and free price helped them to grow their user base quickly, often infiltrating the enterprise. But the offerings have been clearly designed as consumer software aiming to attract as many eyeballs as possible at the least possible cost. That means basic feature set, no customizations, no integrations, no direct sales force - simply one size fits all service.

While vendors such as Google, Dropbox - and also Apple, Amazon, Evernote, etc. - have a good formula to drive user adoption and even penetrate the enterprise, their business model has been designed to cater to the consumer and not to the enterprise. Enterprises need, I repeat “need” customization and integration with other systems. Just think of managing user lists and groups. Sharing content on Dropbox with your friends might be easy, sharing something with all the employees in Sales or Marketing in your company is much less trivial. You can’t manage all the user groups by hand and thus you need to integrate with other existing systems - i.e. directory services and HR Management system. Enterprise software can do that. Consumer software can’t.  

The consumer vendors might be penetrating the enterprise but today, they don’t have any enterprise offerings.

PS: This post has been inspired by a spirited discussion during the last AIIM Board meeting. I love these conversations with my fellow Board members!

Tuesday, September 11, 2012

Your Digital Shadow Won't Matter That Much

The 2012 US presidential elections are in full swing and the campaigns on both sides are doing the best they can to attract voters. Well, their best and sometimes not so best mud-slinging is today an integral part of the presidential show. Those constant questions about who’s done what at some point in their lives as both sides hope that they can dig out something bad. Something that will swing those undecided voters who seem to be making up their mind based on what they hear in a late night commercial sponsored by a presidential candidate.

But don’t despair, it won’t always stay like this. The time is coming, where the digging won’t be necessary any longer. Thanks to the Internet, our lives are becoming more and more transparent. Increasingly, the information about our work, hobbies, networks, likes and dislikes is being documented. You want to know what I’m doing for living? Well, just Google my name and see what comes up. Are you the member of a club? Do you compete on weekends? Are you associated with people in a particular organization? Have you taken part in a fundraiser? All of that is out there. For posterity.

Lot of information is out there about all of us
Today, it is still a novelty as we are discovering all these information sources - LinkedIn, Twitter, SlideShare, YouTube, Flickr, and other social media tell a lot about us and not just to our friends. Our property records were always public but now they are increasingly available - just check out Zillow. If you want to see how well Will Ferrell did in the 2003 Boston Marathon or how your neighbor did in last week’s race, just check out www.althlinks.com. It’s all there, online. Together with your employment history, info about your friends, your education, your phone number and so much more. All of us have a digital shadow that is already available today. And we are barely getting started.
Not to pick on Mr. Gates - do you know the value of his house?
I believe, that all this transparency will eventually lead to a profound change in our attitude. Simply said, we won’t care as much. I don’t mean that we won’t care about what people do. Sure, it will always be interesting finding out about our friends’ recent travel or about some unexpected hobbies of a celebrity. And we might even care about what the politicians have done in the past. But we won’t care about finding out. Right now, it is still a novelty finding something out about somebody - a friend, a colleague or a presidential candidate. Finding out something is surprising and thus fascinating. But that novelty will wear off.

Pretty soon, our life story will be just a mouse click away. Everybody’s past will be well documented. The story will be right in front of us if we chose so. We might walk around with  “Google goggles” that will be applying augmented reality techniques to overlay the information about everything and everyone we look at. We will be used to it and it won’t matter by far as much. All this info will have about the same value as which town you live in today. Sure, that’s interesting for the first 5 seconds after you meet someone but 10 seconds later, it doesn’t matter anymore. Everybody lives somewhere and most of the time, it is not worth writing articles about. Even if it is a presidential candidate.

Your digital shadow won’t matter that much - because everybody will have one.


Monday, August 27, 2012

Is Cloud More Secure Than On-Premises Software?

Security is the most common objection people - or companies - raise against the adoption of a cloud based solution. There have certainly been enough stories reported about compromised passwords and other security breaches at cloud based services such as Dropbox or iCloud. Emotionally, it feels like having our data stored somewhere where we can’t see it is just not very secure.

But let’s face it, we’ve had our money stored somewhere where we can’t see it for decades. Yet we seem to be completely trusting of our banks. Nobody is arguing that our money would be more secure under our mattresses. Quite the contrary, we rush to put our money into the banks knowing full well that the bank doesn’t actually keep the money. At the end of the day, it is just an entry in a computer database somewhere...somewhere...in a cloud. Or private cloud to be more precise. In any case, we consider banks highly secure today.

And so, the latest argument about cloud security goes in the opposite direction. We are beginning to realize that the cloud companies have more at stake, and so they are likely investing into security more so than a typical company ever would or could afford for its on-premises software.


Let’s take an example. Thousands of companies across North America have been using ADP to process their payroll for many years. ADP’s payroll processing is a cloud based application - it has been long before we knew what the cloud was all about. ADP even offers to outsource the service, not just the app.  Yet as far as security goes, nobody is screaming that it is preposterous having all the highly confidential personal data stored at ADP. In fact, most people think that it is probably safer at ADP than it would be if processed by their own employer.

Indeed, cloud companies are increasingly considered capable of providing more security features than companies running on-premises software. Just yesterday, Dropbox raised the bar by rolling out a two-factor authentication. How many of your on-premises applications have that?

But then again, the cloud companies are a much bigger and more attractive target for the bad guys. The hackers might never pay attention to your company and your data center but they sure know about Google Apps, Dropbox, Amazon EC2, Microsoft Azure, and Apple iCloud. Hacking a big name cloud company is just a very lucrative target that many hackers see as a challenge they can’t resist.

So what gives? Is our data more secure on-premises or in the cloud? Well, I suppose there is no black-and-white answer out there today. There are many considerations that need to go into software selection - on-premises or in the cloud. Security is certainly one of them. And we can be sure that the security debate will remain a hot one for quite a while.