Welcome!

Linux Containers Authors: Pat Romanski, Yeshim Deniz, Liz McMillan, Elizabeth White, Stackify Blog

Related Topics: @DXWorldExpo, Mobile IoT, Linux Containers, Containers Expo Blog, @CloudExpo, Cloud Security

@DXWorldExpo: Blog Post

The Major Cloud Security Threat By @Intermedia_Net | @CloudExpo [#Cloud]

Eighty-nine percent of knowledge workers retain access to the sensitive corporate applications and files of former employers.

The Major Cloud Security Threat Most IT Departments Overlook

Eighty-nine percent of knowledge workers retain access to the sensitive corporate applications and files of former employers.

Earlier this year, a member of the team at Site-Eye, one of the top time-lapse film companies in the UK, noticed a disturbing problem with one of its client's feeds. A deeper investigation revealed that of the 200 cameras it had installed at construction sites around the world, 120 had been remotely disabled. In order to restore service to these cameras, engineers needed to be dispatched to each location, setting Site-Eye back $80,000.

The cause behind the problem? A single disgruntled former employee who walked away from his job with the passwords to the company's services in-hand.

This is an issue that is far from isolated to the time-lapse film industry: it's actually a risk for any business that embraces the cloud.

A not-so-silver lining
Cloud services do more than just increase flexibility and scalability: they level the playing field by enabling small and medium-size businesses to leverage the same technology as enterprise companies. Businesses are showing increasing comfort with cloud-based services, and so are users. This has created the "Bring Your Own Service (BYOS)" trend, in which employees deploy the cloud services that they're most familiar or comfortable with, sometimes without IT's permission and often without IT's awareness.

This is one reason why it's becoming increasingly difficult for IT to control who has access to what data-and why stories like the Site-Eye sabotage are becoming increasingly common.

14.3 apps per company

According to Osterman Research, the average company has deployed 14.3 apps. (To me, that number sounds too small, even if it doesn't include apps provisioned without IT's knowledge.) Regardless, it's no surprise that employee turnover is now introducing a new IT risk: ex-employees that retain continued access to their former employer's sensitive cloud apps.

In fact, a separate study from Osterman Research found that a staggering 89% of knowledge workers retained at least one login and password to a former employer's cloud service, including Salesforce, PayPal, Dropbox, and others.

To make matters worse, 45% of the respondents to the Osterman Research survey considered the information they could access from their former employers to be "confidential" or "highly confidential." And 49% admitted to logging into one of these accounts after leaving a company.

I call this "rogue access." The FBI calls it "insider threat cases": they recently announced that this risk poses "a significant cyber threat to US businesses," noting that "...victim businesses incur significant costs ranging from $5,000 to $3 million due to cyber incidents involving disgruntled or former employees."

Three ways to mitigate your risk

This vulnerability creates risks that are potentially devastating for a business. These include the potential for stolen secrets, loss of data, data breaches, regulatory compliance failures, and, as in the case of Site-Eye, out-and-out sabotage.

However, there are three steps companies can take to regain control over their data and their access:

1. Establish stringent access management and IT off-boarding practices. Osterman Research found that 60% of the employees that participated in its survey were not asked for their cloud logins by their employers. Formal on-boarding and off-boarding policies are critical and must be implemented for every employee and every app.

2. Offer cloud storage services that are more attractive than personal alternatives. IT obviously is unable to revoke access to data on personal storage. However, 68% of the employees in Osterman Research's study reported using personal file storage services-including Dropbox and Google Drive-to store corporate files or transfer them to other devices.

Not only does this enable employees to retain access to these files after leaving the company, it also creates the risk of losing the only copy of a critical file if the former employee simply purges their personal file storage folders.

If companies offer easy to use options that also provide IT with full access and control, employees will be less likely to sidestep it, and employers can avoid these serious risks.

3. Leverage a single sign-on (SSO) service to improve visibility into employee access. An SSO portal allows employees to securely access all of their apps with just one click, using one strong password. This improves security because employees are more likely to use strong passwords if they don't have to commit them to memory. In addition, SSO gives IT visibility into which apps a departing employee had been using, providing a much better picture of which accounts need to be transferred or terminated.

The "ex-employee menace" is a very real problem, but also a preventable one. If IT departments institute and adhere to these three crucial steps, they can enjoy the benefits of cloud applications without incurring the potential risks.

More Stories By Michael Gold

Michael Gold is the President of Intermedia, a leading one-stop shop for cloud IT. You can learn more about the dangers of rogue access in Intermedia’s report, The Ex-Employee Menace. You can also download their IT off-boarding checklist and best practices for IT access. Follow Intermedia at @intermedia_net.

@ThingsExpo Stories
The best way to leverage your CloudEXPO | DXWorldEXPO presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering CloudEXPO | DXWorldEXPO will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at CloudEXPO. Product announcements during our show provide your company with the most reach through our targeted audienc...
@DevOpsSummit at Cloud Expo, taking place November 12-13 in New York City, NY, is co-located with 22nd international CloudEXPO | first international DXWorldEXPO and will feature technical sessions from a rock star conference faculty and the leading industry players in the world.
Everything run by electricity will eventually be connected to the Internet. Get ahead of the Internet of Things revolution. In his session at @ThingsExpo, Akvelon expert and IoT industry leader Sergey Grebnov provided an educational dive into the world of managing your home, workplace and all the devices they contain with the power of machine-based AI and intelligent Bot services for a completely streamlined experience.
DXWorldEXPO | CloudEXPO are the world's most influential, independent events where Cloud Computing was coined and where technology buyers and vendors meet to experience and discuss the big picture of Digital Transformation and all of the strategies, tactics, and tools they need to realize their goals. Sponsors of DXWorldEXPO | CloudEXPO benefit from unmatched branding, profile building and lead generation opportunities.
22nd International Cloud Expo, taking place June 5-7, 2018, at the Javits Center in New York City, NY, and co-located with the 1st DXWorld Expo will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud ...
In his keynote at 19th Cloud Expo, Sheng Liang, co-founder and CEO of Rancher Labs, discussed the technological advances and new business opportunities created by the rapid adoption of containers. With the success of Amazon Web Services (AWS) and various open source technologies used to build private clouds, cloud computing has become an essential component of IT strategy. However, users continue to face challenges in implementing clouds, as older technologies evolve and newer ones like Docker c...
"MobiDev is a software development company and we do complex, custom software development for everybody from entrepreneurs to large enterprises," explained Alan Winters, U.S. Head of Business Development at MobiDev, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
JETRO showcased Japan Digital Transformation Pavilion at SYS-CON's 21st International Cloud Expo® at the Santa Clara Convention Center in Santa Clara, CA. The Japan External Trade Organization (JETRO) is a non-profit organization that provides business support services to companies expanding to Japan. With the support of JETRO's dedicated staff, clients can incorporate their business; receive visa, immigration, and HR support; find dedicated office space; identify local government subsidies; get...
Dion Hinchcliffe is an internationally recognized digital expert, bestselling book author, frequent keynote speaker, analyst, futurist, and transformation expert based in Washington, DC. He is currently Chief Strategy Officer at the industry-leading digital strategy and online community solutions firm, 7Summits.
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: Driving Business Strategies with Data Science," is responsible for setting the strategy and defining the Big Data service offerings and capabilities for EMC Global Services Big Data Practice. As the CTO for the Big Data Practice, he is responsible for working with organizations to help them identify where and how to start their big data journeys. He's written several white papers, is an avid blogge...
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: Driving Business Strategies with Data Science," is responsible for setting the strategy and defining the Big Data service offerings and capabilities for EMC Global Services Big Data Practice. As the CTO for the Big Data Practice, he is responsible for working with organizations to help them identify where and how to start their big data journeys. He's written several white papers, is an avid blogge...
In past @ThingsExpo presentations, Joseph di Paolantonio has explored how various Internet of Things (IoT) and data management and analytics (DMA) solution spaces will come together as sensor analytics ecosystems. This year, in his session at @ThingsExpo, Joseph di Paolantonio from DataArchon, added the numerous Transportation areas, from autonomous vehicles to “Uber for containers.” While IoT data in any one area of Transportation will have a huge impact in that area, combining sensor analytic...
Charles Araujo is an industry analyst, internationally recognized authority on the Digital Enterprise and author of The Quantum Age of IT: Why Everything You Know About IT is About to Change. As Principal Analyst with Intellyx, he writes, speaks and advises organizations on how to navigate through this time of disruption. He is also the founder of The Institute for Digital Transformation and a sought after keynote speaker. He has been a regular contributor to both InformationWeek and CIO Insight...
Michael Maximilien, better known as max or Dr. Max, is a computer scientist with IBM. At IBM Research Triangle Park, he was a principal engineer for the worldwide industry point-of-sale standard: JavaPOS. At IBM Research, some highlights include pioneering research on semantic Web services, mashups, and cloud computing, and platform-as-a-service. He joined the IBM Cloud Labs in 2014 and works closely with Pivotal Inc., to help make the Cloud Found the best PaaS.
It is of utmost importance for the future success of WebRTC to ensure that interoperability is operational between web browsers and any WebRTC-compliant client. To be guaranteed as operational and effective, interoperability must be tested extensively by establishing WebRTC data and media connections between different web browsers running on different devices and operating systems. In his session at WebRTC Summit at @ThingsExpo, Dr. Alex Gouaillard, CEO and Founder of CoSMo Software, presented ...
I think DevOps is now a rambunctious teenager - it's starting to get a mind of its own, wanting to get its own things but it still needs some adult supervision," explained Thomas Hooker, VP of marketing at CollabNet, in this SYS-CON.tv interview at DevOps Summit at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
CloudEXPO New York 2018, colocated with DXWorldEXPO New York 2018 will be held November 11-13, 2018, in New York City and will bring together Cloud Computing, FinTech and Blockchain, Digital Transformation, Big Data, Internet of Things, DevOps, AI, Machine Learning and WebRTC to one location.
DevOpsSummit New York 2018, colocated with CloudEXPO | DXWorldEXPO New York 2018 will be held November 11-13, 2018, in New York City. Digital Transformation (DX) is a major focus with the introduction of DXWorldEXPO within the program. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of bus...
In his keynote at 19th Cloud Expo, Sheng Liang, co-founder and CEO of Rancher Labs, discussed the technological advances and new business opportunities created by the rapid adoption of containers. With the success of Amazon Web Services (AWS) and various open source technologies used to build private clouds, cloud computing has become an essential component of IT strategy. However, users continue to face challenges in implementing clouds, as older technologies evolve and newer ones like Docker c...
"Evatronix provides design services to companies that need to integrate the IoT technology in their products but they don't necessarily have the expertise, knowledge and design team to do so," explained Adam Morawiec, VP of Business Development at Evatronix, in this SYS-CON.tv interview at @ThingsExpo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.