Showing posts with label cloud stores. Show all posts
Showing posts with label cloud stores. Show all posts

Tuesday, 22 May 2018

Why a Cloud Consumption Model Should Replace Pay as You Go for Data Storage



- Alan Jamieson, VP of Business Development


In a previous blog, we highlighted why planning your Cloud storage requirements is the only way to ensure your company achieves operational savings moving to the cloud.  Today, we are going to look at the various consumption options:

Pay as you Go

Subscription (fixed term, monthly fee per user or unit) based commercial models have been around for several years driven by Customer Relationship Management vendors such as Salesforce, Infrastructure as a Service (IaaS) vendors such as VMware, and Information Technology Service Management (ITSM) vendors such as ServiceNow, who all enable us to pay for services we use, typically based on user number pricing bands. This pay as you go approach has also been widely adopted by the leading Cloud vendors who companies are turning to streamline operations and offerings.  However, this approach is more limited when you look at Cloud data storage. Typically Cloud vendors look to companies to their Cloud infrastructure by charging them lower rates for storing historic or archived data in their infrastructure as opposed to in the company’s own data center. This often means recent data or even just 12-months old data get archived. The problem with this is, once the data is stored, how are companies easily able to access this data to extract business value or analytical insight to help businesses remain competitive? This is a big need!

Research also shows that companies are paying money for storage that they currently don’t need, as they either have too much in-house storage capacity or they have estimated and invested more than their businesses need today for Cloud storage. Regulation is often the main driver for companies to retain transaction data and customer data for a defined number of years, but unless there is a data retention policy, storage investments in this area can be an unnecessary expense. Companies should only retain data for specific periods of time, exceeding these period is an overhead to the business.
It’s clear there is a struggle to find the right balance of leveraging the Cloud to streamline the collection and storage of a company’s increasingly growing data without wasting money. As detailed above, the current standard method of pay as you go is not setup to help companies cost-efficiently move their storage to the Cloud. 

So, what is the solution?

BOHH Labs believes introducing a consumption-based model to the storage market can help companies maximize the benefits of moving storage to the Cloud without paying for resources they don’t actually need. Subscription (consumption-based) fixed term agreements are paid monthly or quarterly and can help businesses to start achieving operational savings with small initial investments that grow through greater use of the service and increased user adoption over time. This approach allows companies to pay for the resources they need without overestimating on resources that roll in to wasted costs, yet still allows them to expand as they grow. This model will be beneficial for all companies – those with a small number of employees to global enterprises with hundreds of thousands to benefit from the same services. 

Within the consumption model, we believe it needs to be split into two areas:

  1. Data storage:
    As discussed above, companies should choose the right data storage period and commercial model to support their individual businesses, and thus pay for storage based on volume or data retention period.
  2. Data acces
    This is an area that is included in user subscription agreements such as CRM, but if not, it is an area that all companies need to explore to understand how they can gain business value from data they store. Stored data serves companies no purpose if it cannot be accessed easily to leverage insight and analytics from it t apply to their business decision-making. 

What Does this Look Like? 

When companies run a marketing campaign, they typically include all their active target customers to help ensure that they gain the maximum return from the planned campaign.  However, when a global financial services or health provider needs to make longer term investment decisions based on historic data over several years, securely accessing this stored data, which often contains confidential data such as PHI (Personal Health Information), PII (Personal Identifiable Information) is not available, as they cannot guarantee the security of sensitive data accessed by business users.

BOHH Labs has identified this business challenge and has a created a Secure Storage as a Service solution that ensures that all stored sensitive data remains secure and confidential.  If you know which data fields or rows contain sensitive data, BOHH Labs protects these fields to ensure business compliance. As such, the BOHH service leverages a consumption model to provide a secure way to enable your noncompliant data to be utilized and have the cost of storage recovered from it as its value is extracted. By protecting the compliant data, securing it and only providing access to those who have the correct privileges to see it, allows longer period (often years) non-compliant and non-corporate sensitive data to be utilized by a wider audience to extract greater business value or insight.


Tuesday, 10 April 2018

How to Flip Data Security into a Driver for Cloud Adoption, Not an Inhibitor


It’s no secret the Cloud brings enormous advantages to companies and the way they interact with data. Cloud environments offer companies the ability to share, store and access data from anywhere on any device at any time. As such, more companies are embracing digital transformation and integrating cloud services to their architecture strategies to enhance business agility, efficiency a new revenue stream, and let’s not forget the cost savings in terms of operations, personnel and technology updates.

To meet these demands, big data centers want to be able to open data access to the Cloud, yet organizations hold sensitive and protected personal information in their databases that they have a responsibility to keep protected, such as PHI (Protected Health Information), PII (Personally Identifiable Information) and GDPR (Global Data Protection Regulation) data that is held within them. Unfortunately, current database systems can encrypt stored data, but this encryption is carried out in a way that anyone (human or machine) that has access to the system at any administration level generally also has access to the plain unencrypted data. This design flaw leaves a “come get me” sign that has led to many diverse organizations becoming victims to data theft and losing millions of dollars.

This puts current data centers at a conundrum – Cloud-based data storage will help facilitate better use and collaboration of data housed, but the sensitive nature of the data and risk of breaching these compliance regulations is challenging adoption.

Security is still the most important concern for customers wanting to give Cloud access to their data stores. Now that we’ve seen how important data security is, what if you flip the switch and provide complete protection of Cloud data storage?

Strong risk management and data integrity systems can help companies avoid breaches and better manage disruption to operations, turning strong data security into a driver not an inhibitor for embracing Cloud environments.

But how does this work?

Enter Secure Storage as a Service. While the market has various related offerings: public Cloud, IaaS, PaaS, etc., secure data storage is not available. BOHH Labs is introducing a Bring your own storage (BYOS) capability which offers databases or specific file security that businesses desperately need. This enables on premise deployments to actively prioritize applications, databases or infrastructure to a lower cost, and secure cloud deployment without impacting user access.  Companies can choose which data to store with full knowledge of data confidentiality/ sensitivity.

Our solution removes the sensitive data from the source, storing it separately, enabling prioritization and control over sensitive data storage. This kills the flaws within the current storage market and enables stored data to be securely opened to the Cloud, without putting it at risk of breach, flipping the switch on data security making it a driver, not an inhibitor. 

Friday, 9 February 2018

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Over 19 Million Californian Voter Records Held for Ransom Again

A database containing the voter records of over 19.5 million Californians was exposed to the public internet before being locked down and held for ransom by cyber-criminals, just months after a similar incident, according to reports. Read more…

Cisco: Severe bug in our security appliances is now under attack

Cisco's Adaptive Security Appliance (ASA) flaw with a CVSS score of 10 is now being exploited by attacks. Cisco has updated its advisory for vulnerability CVE-2018-0101 for the second time since warning customers of the critical flaw on January 29. The bug affects its ASA and Firepower security appliances. Read more…

New POS Malware Steals Data via DNS Traffic

Researchers have discovered new point-of-sale (POS) malware disguised as a LogMeIn service pack that is designed to steal data from the magnetic stripe on the back of payment cards. Read more…

Bitcoin's Reign on the Dark Web May Be Waning
For online scams and schemes, bitcoin changed the landscape. It became possible to obtain quick and secure payment in virtual currency for extortion schemes without touching conventional banking systems or wire transfer services. But, it may be losing its rein. As wider use of Litecoin, Monero and Dash signals a cryptocurrency shift. Read more…

Friday, 29 September 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Deloitte hit by data breach

Corporate finance giant Deloitte suffered a cyber-attack that compromised confidential data, including the private emails of some of its clients, the company has confirmed. Its system had been accessed via an email platform and "very few" clients had been affected, Deloitte said. Read more…

Russian hackers targeted election systems in 21 U.S. states

The Department of Homeland Security (DHS) finally notified election officials in 21 U.S. states about Russia trying to hack their election systems before the 2016 election. Read more…

Whole Foods Market Investigates Hack Attack

Upscale supermarket chain Whole Foods Market says it's investigating an apparent payment card data breach that affects facilities located in some of its stores, although none of its checkout lanes. Payment card data stolen from taprooms and restaurants, the supermarket chain says. Read more…

Sonic hit with class action suit over POS data breach

Two Sonic Drive-In customers are taking legal action against Sonic for allowing their payment card data to possibly have been compromised when the fast-food chain's POS system was hacked and are demanding the company pay for credit monitoring services for those affected. Read more…


Thursday, 29 December 2016

Do You Know Who Actually Owns Your Data in the Cloud?



As stories of breaches continue hitting the headlines, especially targeting cloud stores and user’s data, passwords, credit cards, and email addresses have become the prized target for cyber criminals all over the world.
In a lot of these cases the information was encrypted, as industry standards recommend. This doesn’t mean hashed, but truly encrypted, with keys that means unless a would-be thief also manages to access the key store then your information is safe. Or at least it should be!
However, when we take closer look in to the statement, “then your information is safe,” there are two parts we need to understand. The first is a relatively simple one. Safe from whom? If a thief, then yes. If your keys themselves are secured, then your information should be safe. However, a lot of hacks seem to come from an internal source to where the information is being held, such as from an unhappy employee, an ex employee who was recently let go, or even an employee who has an axe to grind. The disgruntled employee can use inside knowledge to share a virus, share documents with rivals or misuse company and personnel data. If this organization is a cloud store or service provider that also holds and owns your encryption keys, then in any one of these cases your information is far from safe.
For example, there have been many stories about the sharing of celebrity nude photos in the past couple of years that have made individuals and companies wonder about the security of data stored in the cloud and ask such questions as: Is the data encrypted at the server, while in transport? What level of encryption is used and how much authentication is performed? Because another employee could also have access to the keys to the cloud store your information is in, then your data is no longer encrypted. This is not as far-fetched as it may seem. This has been the case for many breaches over the past few years.
The above scenario is about data theft, when an individual or individuals go out to steal data for their own gain. But what about those scenarios when a government or legal authority decides that they need access to your corporate information? This is not necessarily theft, but it can be unwanted access despite being in the public interest. According to the US’s Communications Assistance for Law Enforcement Act (CALEA), a “communications provider” of any size must allow government agencies access to data. The service providers are not told why the data is needed, only that they must comply.
Government should have the right to do this, as this often has secured us all from many security threats. The question here though is one of accountability. If your supplier owns your security, then they are obliged to pass over not just the documents, but also the keys that allow this information to be decrypted. All of this is happening without your corporate knowledge! The issue is not that the government has access; the bigger threat is lack of knowledge about where corporate data is headed. That is why many tech companies are taking a strong stance on what user data they share with the government and it will continue to be heavily debated moving in to 2017. One possible solution would be if you, as an individual, had ownership of your security. Then the government department could come to you directly, giving you the opportunity to directly pass this information across with full knowledge and the accountability that goes with that.
In summary, if you pass your security to a third party, and they own and store your encryption keys, then you have lost control of your information. It is imperative that you own and store these separately from your cloud suppliers. If you do not, then your information can be stolen or subpoenaed without your knowledge.