The Register® — Biting the hand that feeds IT

Feeds

Is cloud data secure?

Because your datacentre probably isn't

5 ways to reduce advertising network latency

Hosted apps Would your data be more secure in the hands of Google or left where it is? Your answer to that depends on where you store business information at the moment and, of course, whether you feel Google can be trusted.

We’re picking on Google here because it is the “cloud” player that, rightly or wrongly, receives the most criticism about security and privacy. We could, however, ask the same question of Microsoft, Salesforce.com, Amazon, IBM or anyone else offering to host the business information that is so precious to us.

Before we discuss this issue of trust, let’s think about where your data resides right now. If you are a sizeable organisation, you might have a central datacentre or computer room that houses specialist servers and storage equipment. As well as that, research among Reg readers suggests that you are likely to have at least a few local servers and storage devices dotted about the business. Then there is all that stuff that sits on desktop and laptop PCs, not to mention smartphones and handhelds, or even in cloud services such as Dropbox or SkyDrive.

"Most businesses could never match the Fort Knox-style controls implemented by the big providers"

The result is that not everything is totally controlled and secure. In smaller organisations with limited manpower and money to spend on automation, this is even more true. There is no shame in this. IT professionals do what they can with what they have, and 100 per cent protection is not realistic anyway. Some of the most common threats arise from accidents or misuse of data by employees and partners.

Is it reasonable, then, to be so hung up on security when it comes to hosted service or cloud providers? Even setting aside the human element, most businesses could never match the Fort Knox-style controls implemented by the big providers to protect their datacentres. Nor would they be able to implement the same measures to defend against hacking or to manage access control.

So what are we scared of? And we are scared, if the research is anything to go by. Whether it’s in our Reg reader studies or surveys carried out elsewhere, security and privacy appear at or near the top of the list of reasons given for not moving stuff to a service provider’s datacentre.

Coming back to the question of trust, or lack of it as the case may be, one concern is that providers will abuse access to our data. Whether it’s selling "profiling" or "traffic" related information to third parties who want to advertise to us, or giving up our secrets to governments at the drop of a hat, we get nervous. The press has educated us not to believe that such activity is innocuous, even if the stories are about consumers, and even when data has been aggregated and anonymised before it was passed on. There is similar uncertainty over whether "delete" actually means "delete" (in the permanent sense) in the cloud.

Just as with on-premise systems, we then have the possibility of human error inadvertently creating a security hole to the outside world, but specifically with SaaS there may also be concern about leaks of information between customers. There is something inherently worrying to many businesses about their data sitting in the same infrastructure as that of their customers, suppliers and even competitors.

Lastly, we have a cultural dimension. Many of the big providers have their roots in the consumer sector, providing low-cost or advertising-funded services to the masses. The conventions in this space are perceived to be different, especially if the provider has anything to do with social media. It is often assumed that the spirit of “open by default, secure by exception” applies. This might not be fair but there remains the nagging question of whether the expectations of both consumers and businesses can be met via a shared infrastructure.

We would be interested in knowing what you think. What kinds of providers do you trust and which ones are you suspicious of? What can providers do to reassure you? Are contract terms and service level agreements good enough, or are there specific proof points you would look for? We would be particularly interested in hearing from those who have overcome their issues (or paranoia) and taken the plunge into cloud services.

5 ways to prepare your advertising infrastructure for disaster

Whitepapers

Microsoft’s Cloud OS
System Center Virtual Machine manager and how this product allows the level of virtualization abstraction to move from individual physical computers and clusters to unifying the whole Data Centre as an abstraction layer.
5 ways to prepare your advertising infrastructure for disaster
Being prepared allows your brand to greatly improve your advertising infrastructure performance and reliability that, in the end, will boost confidence in your brand.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Email delivery: Hate phishing emails? You'll love DMARC
DMARC has been created as a standard to help properly authenticate your sends and monitor and report phishers that are trying to send from your name..
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?

More from The Register

next story
Windows 8 fans out-enthuse Apple fanbois
Redmond allows 81 Win 8 devices to use one user ID, solving side-loading shemozzle
'200 million' fanbois using iOS 7 just a week after release - study
Plus: Most US iDevice users are drinking Cupertino's latest Koolaid
No luck at all for BlackBerry as Messenger apps launch stalls
Leaked Android build 'causes issues,' is withdrawn
App Store ratings mess: What do we like? Sigh, we dunno – fanbois
How do I know what to download if I don't know what everyone else is doing?
OUCH: Google preps ad goo injection for Android mobile Gmail app
Don't worry, fandroids, wallet-plumping serum won't hurt a bit
Launchpads, catapults... what a load of - WAIT, there's £15m for grabs?
Quango sprinkles cash on games, animation and trendy meeja types
Apple iOS 7 makes some users literally SICK. As in puking, not upset
'Eye candy really is as bad as classical candy is for the teeth,' writes one
Google reveals its Hummingbird: Fly, my little algorithm - FLY!
Update brings Googleplex one step closer to sentience
Oracle hides ExaLogic price cut
Old price lists prove price halved, so why has Big Red deleted the post announcing it?
prev story