« Product Bistro: Love Developers, and Trust QA | Main | It Takes a Village.. ah, actually, being there first and tons of hard work »

April 10, 2008

Security Industry Missing Ride On The Cloud

Cloud One of the things I was interested to investigate at this week's RSA conference was whether SaaS and cloud services (compute, storage, etc.) had entered into the horizon of the security market. The answer is easy. NO. Not even close. Security doesn't get where the software market is headed and we need to get after it now.

There's two perspectives to assess this from; What are security vendors doing to build products for the On Demand, SaaS and cloud computing world we are rapidly moving into? And, are security vendors moving into offerings based in the cloud themselves? Again, with a very few exceptions this isn't something that even appears on the radar screen of RSA exhibitors.

Regarding the first question, the themes of RSA is still very much in the world of data protection, data lose prevention, network access control, USB storage containment, and infatuation with the latest 10 gigabit doodad appliance box.  Maybe its too early for security in the cloud to be the issue of the day - security in the virtualized world isn't even a topic for conversation. At least a few smart people like The Hoff are playing virtualization MythBuster, keeping us honest about what challenges and interesting problems need to be solved as virtualization continues its march into data centers, storage and applications.

How about those offering their security wares via the cloud? Clearly Qualys suffered the arrows of being an early SaaS security vendor but crazy frenchman Philippe Courtot is still riding high knowing the SaaS market is doing well within other segments of IT and security will eventually get there. But they are still pretty much a lone SaaS delivered security player. Another company doing SaaS delivered security products is Alertlogic, providing log management, analysis, and compliance software On Demand. I spent some time with Alertlogic CTO Misha Govshteyn, someone who has been through the transition to SaaS and learned the lessons needed to scale a multi-tenant product. (Misha's a smart guy, btw. You sooooo need to start blogging dude!)

I think Misha's approach also shows some insight into where we'll see SaaS enter into security - in the mid-enterprise and SME markets. Those are buyers who don't necessarily have access to full time security, storage or other specialized resources. They also are more accepting and can get over the perceived privacy concerns that surface when considering an On Demand service, especially private companies who don't fall under SOX compliance. I still recall selling against Qualys and pushing the issue of your vulnerability data being stored in the cloud - many saw the advantages and convenience from an On Demand offering, and for yet many others it was a no-op. But mid-enterprise and SME's adoption of On Demand software solutions could show us this is where security will make it's first SaaS market beachhead.

As security professionals, we can't wait for the market and vendors to catch up. We need to be creating the security dialog and debates about virtualization, on demand and cloud based services. While Microsoft may be trumpeting the call of End-To-End Trust, trying to get the other elephants to tap dance with them, we've got to working ahead of the curve on the tough problems, vocalizing the security needs while services are being created and moving into the cloud, not after. I'm glad that Hoff, Misha and others are thinking ahead of the curve.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e54d69e200e551dafa938834

Listed below are links to weblogs that reference Security Industry Missing Ride On The Cloud:

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

What I Do

  • create and grow businesses
        social media and blogger
        product creator and developer
        business development
    convergence
        software and networking,
        microsoft, mobility,
        collaboration, cloud services,
        virtualization, security,
        open source
    music
        guitarist, performer, writer
    video
        production, editing

  • Contact me about the consulting services offered by Converging Network LLC.
    Learn more about social media and how its leveling the playing field in business and thought leadership.

Social Networks

Twitter Updates

    follow me on Twitter

    Blogs & Podcasts



    Featured On

    • MVP blogger at MyVenturePad.com


    • Find the best blogs at Blogs.com.


      Top 10 Security Blogs at Blogs.com.

    Book Quote

    Disclaimer

    • Everything on this blog and my podcast are only my views and opinions, and are not those of my current or past employers, investors, customers or anybody else. I make no representations as to the accuracy, validity, relevance or importance of anything I say here. Some of what is said here could very well be true (most likely by accident), a lot of it is obviously made up, and all of it is only one man's opinion. All spelling and grammatical errors are purposefully placed to throw any lawyers off the trail. And if you are a lawyer, "move along... this isn't the blog you're looking for". Read and listen entirely at your own risk, and please, don't try any of this at home (work or school.) Now, get back to work - before somebody catches you reading blogs all day instead of doing something productive. And yes, consider yourself notified.

    Misc

    Blog powered by TypePad

    Enter your email address:

    Delivered by FeedBurner

    Relevant Info