Microsoft has just released volume 9 of it's bi-annual Security Intelligence Report (SIR) covering the evolving threat landscape for the first half of 2010. According to Microsoft, they analyze data from more than 600 million systems worldwide and Internet services to create the report.
As I've written about here many times, issues surrounding security and privacy are among the top concerns that businesses looking at cloud computing express. This is only natural - we hear about Internet security threats in the media every day - so it's perfectly natural to wonder whether cloud computing is safe.
So with the explosion of Internet services, SaaS and cloud computing, what do you think the top real-world security threats are so far in 2010?

According to Microsoft, the largest single category of security incidents in 2010 - just like they are in every other year - involve stolen equipment, with 30.6 percent of the total. Negligence and improper disposal of business records make up the bulk of the rest. This matches my real world experience - think how many times every day that someone has a laptop, hard drive, USB stick or CD ROM stolen with valuable, proprietary of confidential information stored on it.
So what does this mean for cloud computing ?
It shows how cloud computing is inherently more secure than on-premises software.
In the cloud computing world, information is never stored on your servers or laptops or hard drives or CD ROMs where it can eventually be misplaced or stolen. Instead it is physically stored in secure, Fortune 100-class data centers where the bulk of the categories of security threats above (stolen hardware, improper disposal, lost hardware, etc) are vanishingly unlikely to occur. Your information is encrypted when it travels across the network and then it is displayed in your web browser. Your data is not ever actually stored on your PC - so if you are using cloud computing and your laptop gets stolen, that's all you have lost.
So while people are right to be concerned about privacy and security, I think this new report from Microsoft really shows clearly that if you adopt cloud computing, you become much less likely to experience many of the most common real-world security threats.
Microsoft has a second, interesting chart showing where software-related vulnerabilities come from.

While I presume that the reason Microsoft included this data is to try to make the point here that the Windows operating system doesn't really have that many vulnerabilities compared to software applications (the counter argument is of course that Windows is so ubiquitous that any vulnerability is a huge deal) there is another gem around cloud computing in this information.
If we take Microsoft's data at face value that application vulnerabilities make up the majority of software risks, then I think it's also easy to conclude that cloud computing is a great way of reducing this risk as well.
Why - because in the cloud computing world the vendors and not the client are responsible for application security. And the vendors tend to have mature security capabilities, audited practices and 24x7 operations and security teams. They have more focus on security and more resources and expertise than nearly any of the individual users of their systems.
Which is more likely - an individual business staying up to the minute on all of the latest security issues for all of their business applications, or a cloud computing vendor doing the same for a single application on behalf of thousands of businesses? Seems pretty obvious to me that it is going to be far easier for the cloud computing vendor to stay ahead of the bad guys.
I thought this was a nice piece of research from Microsoft (lots of pretty pictures by the way if you read it) - but more importantly I think that the real-world data in the report makes a nice point that leveraging cloud computing in 2010 is likely to be far more secure than running your own business applications on-premises.
Contributors
Taylor Macdonald
Vice President, Intacct
Peter Olson
Senior Corporate Communications Manager, Intacct
Amy Vetter
CPA Programs Leader, Intacct
Bob Green
Partner, Information Technology Advisory Services/ERMS, SingerLewak, LLP
Jim Hart
Practice Manager, SingerLewak Systems
Vice President, Intacct
Peter Olson
Senior Corporate Communications Manager, Intacct
Amy Vetter
CPA Programs Leader, Intacct
Bob Green
Partner, Information Technology Advisory Services/ERMS, SingerLewak, LLP
Jim Hart
Practice Manager, SingerLewak Systems
Labels
- SaaS (62)
- Cloud (61)
- Innovation (51)
- Accounting (45)
- Best of Breed (31)
- Customer Satisfaction (26)
- ERP (26)
- ROI (25)
- financial management (25)
- Adoption (22)
- Channels (19)
- Customers (17)
- CPA Firms (15)
- Intacct (14)
- QuickBooks (14)
- TCO (14)
- Value (14)
- Flexibility (13)
- Video (13)
- Innovator's Dilemma (12)
- Best Practices (10)
- Internet (10)
- Partners (10)
- Predictions (10)
- Visibility (8)
- CFO (7)
- Efficiency (7)
- Reporting (7)
- Sage (7)
- Salesforce.com (7)
- Ease of Use (6)
- SAP (6)
- Adaptability (5)
- Google (5)
- Great Plains (5)
- Maintenance (5)
- Integration (4)
- Revenue Recognition (4)
- SLA (4)
- Awards (3)
- IBM (3)
- Industry Insights (3)
- Microsoft (3)
- Multi-entity (3)
- NetSuite (3)
- PaaS (3)
- VAR (3)
- Advantage (2)
- Analytics (2)
- Lawson (2)
- Security (2)
- VSOE (2)
- software (2)
- AICPA (1)
- ASAE (1)
- Dashboards (1)
- Franchise (1)
- GAAP (1)
- Global Consolidation (1)
- Healthcare (1)
- IPO (1)
- Multi-currency (1)
- Nonprofit (1)
- Professional Services (1)
- Project (1)
- Project Accounting (1)
- Small Business (1)
- Softrax (1)
- Superior Global (1)
- momentum (1)
- public companies (1)
Blog Archive
-
►
2012
(31)
-
►
March
(12)
- Gain the Power to See Your Business in New Ways
- The Need for Flexible Financial Applications
- The Outstanding ROI from Cloud Financials
- From QuickBooks to Successful IPO and Beyond with ...
- The Power of Multi-Dimensional Reporting for Finan...
- Intacct Customer Spotlight: Mozilla
- How to Buy Cloud Financials: Step 5 – Go Live and ...
- How to Buy Cloud Financials: Step 4 – Deploy Your ...
- How to Buy Cloud Financials: Step 3 – Choose the R...
- How to Buy Cloud Financials: Step 2 – Define Your ...
- How to Buy Cloud Financials: Step 1 – Embrace the ...
- Managing Your Global Business with Intacct
-
►
February
(10)
- Maximizing Business Value with Cloud ERP
- The Power of Intacct's Adaptability
- Taking Back Control of Your Accounting Engagements...
- Why Healthcare Companies Should Switch to Cloud Fi...
- The Value of Intacct for Multi-Entity Businesses
- The Marriage of Front Office and Back Office Appli...
- The Cloud Financial Accounting Software ROI
- Intacct Customer Spotlight: Savory Sandwiches, Inc...
- Intacct Voice of the Customer Videos - FlightWorks...
- Intacct Customer Spotlight: Superior Global Soluti...
-
►
March
(12)
-
►
2011
(21)
-
►
September
(6)
- The Intacct Advantage in Professional Services and...
- Silverlight debacle coming to the cloud applicatio...
- Intacct Revenue Management and Vertical Offerings
- The IRS wants your data file - That's so 1980's......
- A brand-new data center for 5,000 companies - and ...
- Intacct Chosen by Indiana-based Software Developer...
-
►
September
(6)
Blog Roll
- A Software Insider’s Point of View – Ray Wang
- Accman - Dennis Howlett
- Accounting Software World
- Anshu Blog
- Appirio Blog - Apps in the Cloud
- Avalara Blog
- Bill.com Blog
- CFO Magazine – Growth Companies
- Cloud Accounting Institute Blog
- Cloud Computing Showcase
- Cloud Topics – Sand Hill
- Constellation Research Blog
- CPA Firm Technology
- Deal Architect - Vinnie Mirchandani
- Enterprise Irregulars
- Inspired Ideas – Convergence Coaching
- Intacct Home Page
- Irregular Enterprise
- Laurie Mccabe
- OnStrategies Perspectives - Tony Baer
- Sanjeev Aggarwal
- Small Business Matters – Heather Clancy
- Software & Services Safari – Brian Sommer
- Software as Services - Phil Wainewright
- Technology Best Practices
- ThinkIT Services - Jeff Kaplan
- Totally Paperless
- Venture Chronicles - Jeff Nolan
- ZDNet – Between the Lines
- Zuora Blog
Monday, October 18, 2010
New Microsoft Security Report - Implications for Cloud Computing
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment