With the exception of the iPhone ‘S’ versions;, The Cloud is perhaps the most irritating concept of the last decade.  It is the definitive re-branding of an existing service in order to drive new business in an era of doubt and uncertainty.

Security issues have become far more mainstream over the last few years, and lawmakers in every country are struggling to keep up with the demands for better protection of personal data.  So what we have now are hundreds of companies providing cybersecurity services ‘In the Cloud’. As though this is something new, and a must have for all organisations.

Breaking it down into its simplest terms, services in the cloud are services provided over the Internet.  Haven’t we had this for quite literally decades?  Why is the service to manage your firewalls suddenly a Cloud service, what’s wrong with simply calling it a MSS?

There are really only two valid ‘Cloud’ services;

1. Access to applications or resources you don’t have, and;

2. Distribution of functionality.

Everything else you do ‘In the Cloud’ is simply outsourcing, which is a perfectly valid, and often the best option.

Like everything else in security, never buy anything based on either a perceived need, what is the latest-and-greatest, and especially not a compelling sales pitch.  All capital expenditure, and moves toward outsourcing start with a business need, not external influences. This  includes compliance to regulatory standards.

You don’t need Cloud per se, you need a business process made cheaper, more efficient, or more competitive. HOW you get that done MAY include Cloud-esque services, but that will be determined by your Risk Assessment. Not by your CEO who read an article on his/her way to work, and certainly not by the fear of not having the latest toy.

Cloud services also add a layer of complexity that will generally be missing from most bespoke managed services; shared resources across multiple clients.  Who has access to your data?  How is your data kept separate from everyone else’s?  Because Cloud is a relatively new phenomena, SLAs and contract language has yet to catch up, so vendor due diligence takes on additional import.

In terms of providing a platform expertise that you don’t posses, or an operational resilience you simply can’t afford, Cloud may be an option. That said, you have best be sure your ‘Cloud’ provider has designed their service from the ground up, and not adjusted their marketing material. The latter, sadly, is by far the most prevalent.

Bottom line; do your homework, and run your needs by a security expert before taking the plunge.

Wikipedia describes big data as; “…a collection of data sets so large and complex that it becomes difficult to process using on-hand database management tools or traditional data processing applications.

So why complicate the already difficult concept of developing an effective security program with a huge lump of data you can neither store, nor put to good use yourself?

I’m not against big data per se, there are some very relevant areas where it’s actually required; weather forecasting, social analytics, brain mapping, economics etc, but in security?  I don’t think so.

Security must be simple to be effective, and less is almost always more.  Good security is baselined, white listed, known good and so on, big data can only be effective when your end goal remains somewhat static.  I very much doubt either the bad guys, or your business will stay still long enough put the results of the big data mining efforts to good effect.

Also, and I’m far from being a conspiracy theorist (I’m just not suspicious enough), but I can’t help but think the ones who really benefit are the those who already have the storage, the bandwidth, and the exiting data mining tools to make it effective, AND are looking for more business.  Security must begin with a business need, then a requirement for specific functionality, it is not falling for a sales pitch or a perceived competitive edge based on the latest buzz-phrase.

Instead of trying to understand your security posture with big data, consider the following;

  1. What kind of sensitive or business relevant data do you have?
  2. Where is it?
  3. Which applications or people access this data?
  4. Do you REALLY need all of the data you have?
  5. Is your EXISTING security programme as effective as it could be?

If you don’t know the answer to ALL of these questions, you should start there.  This doesn’t even qualify for ‘You can’t manage what you can’t measure.’, this is ‘You can’t protect what you don’t even know you have.’

Maybe, years down the road, when your security programme is a well oiled machine, and your Governance department is the paragon of business-to-IT communications, then, and only then, should you consider something as advanced as this.  Though I seriously doubt it even then.

[If you liked this article, please share! Want more like it, subscribe!]

First, an admission; this is NOT all about Fraud, it’s about data security in general …very general. I chose ‘Fraud’ because every spell check I’ve ever used autocorrects my name to it, people even pronounce my name as it, and it’s considerably more catchy that ‘Froud on Data Loss Risk Mitigation in Line With Business Goals’, which is actually more accurate.

My vision for this blog is; “To translate security concepts into a language usable to the business.” In other words, to simplify its application to help businesses grow responsibly.

The security industry is fast becoming as complex and specialised as the law, making the business saving techniques it can provide inaccessible to the people and organisation who need it the most. While this is good for the security professional, and the bad guys, it’s not good for the businesses struggling to keep everyones data safe.

The best analogy I’ve heard is [paraphrased]; “Why do cars have brakes?” The answer; “So you can go faster.”

While paradoxical, it’s absolutely true, and the perfect analogy for how security is perceived. The security professional is not there to stop the business from doing something, it’s there to help the business do something properly. Too often security is compared to buying insurance; you don’t want to spend the money, but you know you have to. The true benefits of security are subsequently lost.

This blog will attempt to bring to light as many of the latest security mis-concepts, and hot topics, and put them into a manageable perspective. This will include; PCI, EU Data Privacy Directive, BYOD, Cloud, Big Data and so on.

While I am an inch deep and a mile wide in my approach, I will bring to bear others’, far more profound knowledge on these and other subjects, so that the end consensus is not driven by my own [far from] humble opinions. I will moderate, and translate, I will not dictate.

The forum will only be as successful as the input from you, the audience, so I will also be posting ‘Guest Blogs’ to keep things interesting, and to delay the day when you all realise I have no idea what I’m talking about.

I am composing a Glossary of Terms so that we can all speak the same language. Security professionals all seem to derive tremendous pleasure from coining a new phrase, or the next ubiquitous acronym, but all this does is confuse. We all need to start dealing with concepts, not labels, or our message will either be lost, or worse, misinterpretted.

And finally, in words attributed to Aristotle; “Those who can, do. Those who understand, teach.”, it is our duty as security professionals to show our clients HOW we do what we do, and not to just do it for them, only then can we ever truly call ourselves trusted advisors.

I welcome any and all feedback, comment, suggestions, so please be as active as your time allows.