SlideShare a Scribd company logo
1 of 157
416style
Cloud?
Justin Pirie
@justinpirie
blog.mimecast.com
jpirie@mimecast.com
CLT Law London
February 15th 2010
Analyst Blogger
Community Manager
Social Media Influence
Where I work
Cloud Services for Microsoft Exchange
tipiro
Cloud Wrapper
For Microsoft Exchange
matthewbradley
Email Security
neilalderney123
Email Continuity
dolescum
Email Archive
How the problem used to be solved...
Benefits of Google Apps
For Microsoft Exchange
What do users get?
minifig
mescon
Unlimited Storage
Ronan_C
Fast Search
Uptime
szeke
Over 600,000 users can’t be wrong!
416style
Cloud?
What they don’t tell you...
nccarf_au
Which Cloud?
tipiro
William Vambenepe
SPI stack
IaaS- Infrastructure as a Service
IaaS ROI is about Utility Premium
PaaS- Platform as a Service
Paas = Place to execute code
SaaS- Software as a Service
SaaS = Software
Look back
Carrick
Mainframe era
Mess of Pottage
PC Era
Store and search text!
ThisIsIt2
Guess who?
Yes, them
Cloud Paradigm Shift
tipiro
Current Cloud Landscape
zoutedrop
bionicteaching
Lets have some data
russelldavies
To Understand
2009 = 36%
US Cloud Adoption
2010 = 56%
US Cloud Adoption
70%
US Businesses Considering Adopting
6%
UK lags behind US attitudes
2010 Hype Cycle
2010 Hype Cycle
What are the secrets?
aturkus
Paul Wicks
How did I get here?
Not the train
Andrew®
Or my Brompton
Ben Cooper
nep
It was...
ParaScubaSailor
and...
To understanding Cloud
Wen Nag (aliasgrace)
LIVING_BY_THE_MOMENT
At the beginning...
It was about money...
wwarby
Ian Muttoo
From CapEx
To OpEx
It’s not about money...
wwarby
What is IT for?
le niners
What do we do?
Daniel Mohr
Production Function of IT?
bewarenerd
Sound Academic?
a_sorense
Combination of Inputs
edwin.11
To produce Outputs
IT’s are hard to find
ilovememphis
labanex.com
Sales: Prospects into Orders
jamesjyu
Supply Chain: Orders into Invoices
Finance: Invoices into Cash
alancleaver_2000
What does IT do?
Daniel Mohr
IT Production Value #1 = Speed
TexasEagle
Jeffrey Barke
Strategy into execution
Fast as Possible
Warren D
IT needs to be Responsive
Chris Devers
Domingos Soares Neto
Not a bottleneck
IT Production Value #2 = Scale
....Tim
Take Operations
Detroit Public Library
Increase Capacity, Reduce Cost
ABB
IT Should Equal Agility
Picture Taker 2
Traditional IT Dept.
@appirio
Idea = Agile
Picture Taker 2
Reality for IT = Quicksand
sasamaster
xetark
What users got...
Business feeling about IT
Outsourced IT Dept.
@appirio
Cheaper Labour...
stev.ie
Contracts, Change Requests
Kevin H.
Business feeling about IT
IT using Managed services
@appirio
CarbonNYC
In Control?
Getting on better...
Arno & Louise
Cloud Utopia
@appirio
Reality
Picture Taker 2
Align IT and business
technicallyCreative
How can Cloud Help?
tipiro
Don’t worry about Scale
Dru!
Less Meetings
thinkpanama
Less Technical Detail
Rev. Xanatos Satanicos Bombasticos (ClintJCL)
Continuous Updates
The Doctr
No More Upgrades or Migrations
Bert Kommerij
More functionality- same cost
Seven Morris
Loosely Coupled Systems
ElenahNeshcuet
Separated Config and Code
sadashotit
Fewer Dependencies
Dave ®
Phillie Casablanca
Reconfigure Faster
Faster Gratification
lisatozzi
Grand Canyon between adopters
James Marvin Phelps (mandj98)
57%
Adopters: Cloud Improved Security
62%
Non Adopters: Cloud = Security Risk
Unsure about Cloud Security?
jessicafm
Security Presented as Binary
MarkOMeara
Reality...
cdw9
Cloud = Outsourcing
stev.ie
BUT with Technical Detail Abstracted
Rev. Xanatos Satanicos Bombasticos (ClintJCL)
Which makes Clouds Opaque
Andrew Coulter Enright
The reason Cloud is powerful
dok1
Is also it’s Achilles Heel
Moff
Need for Transparency
salmannas
While Protecting Vendor IP...
schoschie
viralbus
AND Cloud is embryonic
Standards just emerging
mayakamina
jeffc5000
So.... Caveat Emptor
And why it sometimes feels like this...
gxdoyle
Independent Audit?
ScottMJones
No Standards!!!
Leo Reynolds
Independent 3rd Parties: SAS70, CESG
wallyg
Missing Piece?
Mykl Roventine
ISO 27001...
Leo Reynolds
massdistraction
Should you adopt ISO 27001?
Best Practice Policy: ENISA
TheTruthAbout
Investigate Availability Guarantees
Yukon White Light
IXQUICK
Data Jurisdiction: clarify
Who has control of your data?
Duminda Jayasena
Baseline Current Risks
Chuck “Caveman” Coker
i.e. Where are we today?
Chris D 2006
Trusting Users....
Thai Jasmine (Take good care :-))
And Sysadmins....
leftcase
Others...
Tambako the Jaguar
Permissions Nightmare
marimoon
Managing those risks?
Patrick Q
jo'nas
Is expensive
Got the budget?
The Prime Minister's Office
“Quis custodiet
ipsos custodes?”
Cloud: Guards Guard
Cloud Security?
matt.hintsa
#1. It’s their Business
Esthr
#2. Financially Responsible
wwarby
#3. Scale
laffy4k
#4. Specialised Skills
SarahMcD ॐ
Leo Reynolds
#5. Cumulative Effect of Multiple Customers
Lars Plougmann
#6. Best Practice: Embedded, Distributed
#7. Focus
Chris Campbell
Want to be the Guards Guard?
jeffc5000
Remember: Caveat Emptor
But proportional to Risk
gxdoyle
nathansnostalgia
Contracts: Birth
Contracts: Marriage
Contracts: Divorce
DrJohnBullas
416style
Questions?
CLT Law London
February 15th 2010
Justin Pirie
@justinpirie
blog.mimecast.com
jpirie@mimecast.com

More Related Content

What's hot

Lean Cloud - Amazon Web Services
Lean Cloud - Amazon Web ServicesLean Cloud - Amazon Web Services
Lean Cloud - Amazon Web ServicesSimone Brunozzi
 
Why minio wins the hybrid cloud?
Why minio wins the hybrid cloud?Why minio wins the hybrid cloud?
Why minio wins the hybrid cloud?Tyrone Systems
 
CMG White Paper
CMG White PaperCMG White Paper
CMG White PaperLen Jejer
 
CloudComputing - The future is in the sky
CloudComputing - The future is in the skyCloudComputing - The future is in the sky
CloudComputing - The future is in the skySteinar Ardal
 
Cloud Computing is not simple - The complexity is in the details
Cloud Computing is not simple - The complexity is in the detailsCloud Computing is not simple - The complexity is in the details
Cloud Computing is not simple - The complexity is in the detailsRene Buest
 
From Cloud Computing to Edge Computing
From Cloud Computing to Edge ComputingFrom Cloud Computing to Edge Computing
From Cloud Computing to Edge ComputingJulien SIMON
 

What's hot (10)

Staff presentation
Staff presentationStaff presentation
Staff presentation
 
Lean Cloud - Amazon Web Services
Lean Cloud - Amazon Web ServicesLean Cloud - Amazon Web Services
Lean Cloud - Amazon Web Services
 
Cloud technology 10 years from now
Cloud technology 10 years from nowCloud technology 10 years from now
Cloud technology 10 years from now
 
Why minio wins the hybrid cloud?
Why minio wins the hybrid cloud?Why minio wins the hybrid cloud?
Why minio wins the hybrid cloud?
 
CMG White Paper
CMG White PaperCMG White Paper
CMG White Paper
 
CloudComputing - The future is in the sky
CloudComputing - The future is in the skyCloudComputing - The future is in the sky
CloudComputing - The future is in the sky
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
What the heck is cloud?
What the heck is cloud?What the heck is cloud?
What the heck is cloud?
 
Cloud Computing is not simple - The complexity is in the details
Cloud Computing is not simple - The complexity is in the detailsCloud Computing is not simple - The complexity is in the details
Cloud Computing is not simple - The complexity is in the details
 
From Cloud Computing to Edge Computing
From Cloud Computing to Edge ComputingFrom Cloud Computing to Edge Computing
From Cloud Computing to Edge Computing
 

Viewers also liked

Cloud Security- In Perspective
Cloud Security- In PerspectiveCloud Security- In Perspective
Cloud Security- In PerspectiveJustin Pirie
 
Microsoft Worldwide Partner Conference Session
Microsoft Worldwide Partner Conference SessionMicrosoft Worldwide Partner Conference Session
Microsoft Worldwide Partner Conference SessionJustin Pirie
 
Cloud Adoption Secrets
Cloud Adoption SecretsCloud Adoption Secrets
Cloud Adoption SecretsJustin Pirie
 
Effective Transitions for New IT Leaders
Effective Transitions for New IT LeadersEffective Transitions for New IT Leaders
Effective Transitions for New IT Leaderstlhausmann
 
Swindon- Talk on Cloud
Swindon- Talk on CloudSwindon- Talk on Cloud
Swindon- Talk on CloudJustin Pirie
 
Jenzabar Lms Adoption Strategy
Jenzabar Lms Adoption StrategyJenzabar Lms Adoption Strategy
Jenzabar Lms Adoption Strategytlhausmann
 
Adoption Trends for SaaS- Cloud Computing World Forum 2012
Adoption Trends for SaaS- Cloud Computing World Forum 2012Adoption Trends for SaaS- Cloud Computing World Forum 2012
Adoption Trends for SaaS- Cloud Computing World Forum 2012Justin Pirie
 
CLT Law Conference Cloud intro
CLT Law Conference Cloud introCLT Law Conference Cloud intro
CLT Law Conference Cloud introJustin Pirie
 
Landasan teoritis asuransi syariah
Landasan teoritis asuransi syariahLandasan teoritis asuransi syariah
Landasan teoritis asuransi syariahUlfi Oktaviana
 
Bristol Tech Startup School: Lean Startup
Bristol Tech Startup School: Lean StartupBristol Tech Startup School: Lean Startup
Bristol Tech Startup School: Lean StartupJustin Pirie
 
The Hidden Security Danger – Don’t Let Email Be Your Downfall
The Hidden Security Danger –  Don’t Let Email Be Your Downfall The Hidden Security Danger –  Don’t Let Email Be Your Downfall
The Hidden Security Danger – Don’t Let Email Be Your Downfall Justin Pirie
 
Email: The Future Direction
Email: The Future DirectionEmail: The Future Direction
Email: The Future DirectionJustin Pirie
 
Rackspace Feb 2010 with Text
Rackspace Feb 2010 with TextRackspace Feb 2010 with Text
Rackspace Feb 2010 with TextJustin Pirie
 
Does the Cloud ROI Stack up- or does it fall?
Does the Cloud ROI Stack up- or does it fall?Does the Cloud ROI Stack up- or does it fall?
Does the Cloud ROI Stack up- or does it fall?Justin Pirie
 

Viewers also liked (17)

Cloud Security- In Perspective
Cloud Security- In PerspectiveCloud Security- In Perspective
Cloud Security- In Perspective
 
Microsoft Worldwide Partner Conference Session
Microsoft Worldwide Partner Conference SessionMicrosoft Worldwide Partner Conference Session
Microsoft Worldwide Partner Conference Session
 
Cloud Adoption Secrets
Cloud Adoption SecretsCloud Adoption Secrets
Cloud Adoption Secrets
 
Effective Transitions for New IT Leaders
Effective Transitions for New IT LeadersEffective Transitions for New IT Leaders
Effective Transitions for New IT Leaders
 
Family Tree
Family TreeFamily Tree
Family Tree
 
Swindon- Talk on Cloud
Swindon- Talk on CloudSwindon- Talk on Cloud
Swindon- Talk on Cloud
 
Favorite Photos
Favorite PhotosFavorite Photos
Favorite Photos
 
Jenzabar Lms Adoption Strategy
Jenzabar Lms Adoption StrategyJenzabar Lms Adoption Strategy
Jenzabar Lms Adoption Strategy
 
Adoption Trends for SaaS- Cloud Computing World Forum 2012
Adoption Trends for SaaS- Cloud Computing World Forum 2012Adoption Trends for SaaS- Cloud Computing World Forum 2012
Adoption Trends for SaaS- Cloud Computing World Forum 2012
 
CLT Law Conference Cloud intro
CLT Law Conference Cloud introCLT Law Conference Cloud intro
CLT Law Conference Cloud intro
 
Landasan teoritis asuransi syariah
Landasan teoritis asuransi syariahLandasan teoritis asuransi syariah
Landasan teoritis asuransi syariah
 
Bristol Tech Startup School: Lean Startup
Bristol Tech Startup School: Lean StartupBristol Tech Startup School: Lean Startup
Bristol Tech Startup School: Lean Startup
 
The Hidden Security Danger – Don’t Let Email Be Your Downfall
The Hidden Security Danger –  Don’t Let Email Be Your Downfall The Hidden Security Danger –  Don’t Let Email Be Your Downfall
The Hidden Security Danger – Don’t Let Email Be Your Downfall
 
Cloud. Why? How
Cloud. Why? HowCloud. Why? How
Cloud. Why? How
 
Email: The Future Direction
Email: The Future DirectionEmail: The Future Direction
Email: The Future Direction
 
Rackspace Feb 2010 with Text
Rackspace Feb 2010 with TextRackspace Feb 2010 with Text
Rackspace Feb 2010 with Text
 
Does the Cloud ROI Stack up- or does it fall?
Does the Cloud ROI Stack up- or does it fall?Does the Cloud ROI Stack up- or does it fall?
Does the Cloud ROI Stack up- or does it fall?
 

Similar to CLT Legal Cloud Conference

Cloud Security: Is My Data Safe?
Cloud Security: Is My Data Safe?Cloud Security: Is My Data Safe?
Cloud Security: Is My Data Safe?Justin Pirie
 
Cloud Expo May 09 Richard Britton, Cloud Computing for SMEs
Cloud Expo May 09 Richard Britton, Cloud Computing for SMEsCloud Expo May 09 Richard Britton, Cloud Computing for SMEs
Cloud Expo May 09 Richard Britton, Cloud Computing for SMEsEasynet Connect
 
OIT Technology, Communications, Japan
OIT Technology, Communications, JapanOIT Technology, Communications, Japan
OIT Technology, Communications, JapanChristos Makiyama
 
Quotables Quotes
Quotables QuotesQuotables Quotes
Quotables Quotesmat f.
 
Are you ready? Introduction to Cloud Computing and Windows Azure
Are you ready? Introduction to Cloud Computing and Windows AzureAre you ready? Introduction to Cloud Computing and Windows Azure
Are you ready? Introduction to Cloud Computing and Windows AzureThomas Robbins
 
Beyond the Cloud - Click Digital Expo 2016 - Jamin Andrews
Beyond the Cloud -  Click Digital Expo 2016 - Jamin AndrewsBeyond the Cloud -  Click Digital Expo 2016 - Jamin Andrews
Beyond the Cloud - Click Digital Expo 2016 - Jamin AndrewsJamin Andrews
 
Constructing the Case for Cloud
Constructing the Case for CloudConstructing the Case for Cloud
Constructing the Case for CloudJustin Pirie
 
Building Data Intensity with AWS MSK & Lenses.io
Building Data Intensity with AWS MSK & Lenses.ioBuilding Data Intensity with AWS MSK & Lenses.io
Building Data Intensity with AWS MSK & Lenses.ioLenses.io
 
Digital Transformation - ARC219 - re:Invent 2017
Digital Transformation - ARC219 - re:Invent 2017Digital Transformation - ARC219 - re:Invent 2017
Digital Transformation - ARC219 - re:Invent 2017Amazon Web Services
 
Loudoun chamber virtacore final-revised
Loudoun chamber virtacore final-revisedLoudoun chamber virtacore final-revised
Loudoun chamber virtacore final-revisedVirtacore Systems
 
Keynote Roberto Delamora - AWS Cloud Experience Argentina
Keynote Roberto Delamora - AWS Cloud Experience ArgentinaKeynote Roberto Delamora - AWS Cloud Experience Argentina
Keynote Roberto Delamora - AWS Cloud Experience ArgentinaAmazon Web Services LATAM
 
Glue con2011 future_of_net_systems
Glue con2011 future_of_net_systemsGlue con2011 future_of_net_systems
Glue con2011 future_of_net_systemsJames Urquhart
 
AWS Customer Presentation - Autodesk
AWS Customer Presentation - AutodeskAWS Customer Presentation - Autodesk
AWS Customer Presentation - AutodeskAmazon Web Services
 
How Autodesk uses Amazon VPC
How Autodesk uses Amazon VPCHow Autodesk uses Amazon VPC
How Autodesk uses Amazon VPCguestda111d9
 
AWS Customer Presentation - Autodesk
AWS Customer Presentation - AutodeskAWS Customer Presentation - Autodesk
AWS Customer Presentation - AutodeskAmazon Web Services
 
How to prevent cyber terrorism taragana
How to prevent cyber terrorism  taraganaHow to prevent cyber terrorism  taragana
How to prevent cyber terrorism taraganaGilles Sgro
 
Moving enterprise IT to the cloud
Moving enterprise IT to the cloudMoving enterprise IT to the cloud
Moving enterprise IT to the cloudJan Wiersma
 
Sdwan webinar
Sdwan webinarSdwan webinar
Sdwan webinarpmohapat
 
The Security Of Cloud Computing
The Security Of Cloud ComputingThe Security Of Cloud Computing
The Security Of Cloud ComputingJulie May
 

Similar to CLT Legal Cloud Conference (20)

Cloud Security: Is My Data Safe?
Cloud Security: Is My Data Safe?Cloud Security: Is My Data Safe?
Cloud Security: Is My Data Safe?
 
Cloud Expo May 09 Richard Britton, Cloud Computing for SMEs
Cloud Expo May 09 Richard Britton, Cloud Computing for SMEsCloud Expo May 09 Richard Britton, Cloud Computing for SMEs
Cloud Expo May 09 Richard Britton, Cloud Computing for SMEs
 
OIT Technology, Communications, Japan
OIT Technology, Communications, JapanOIT Technology, Communications, Japan
OIT Technology, Communications, Japan
 
Quotables Quotes
Quotables QuotesQuotables Quotes
Quotables Quotes
 
Are you ready? Introduction to Cloud Computing and Windows Azure
Are you ready? Introduction to Cloud Computing and Windows AzureAre you ready? Introduction to Cloud Computing and Windows Azure
Are you ready? Introduction to Cloud Computing and Windows Azure
 
Beyond the Cloud - Click Digital Expo 2016 - Jamin Andrews
Beyond the Cloud -  Click Digital Expo 2016 - Jamin AndrewsBeyond the Cloud -  Click Digital Expo 2016 - Jamin Andrews
Beyond the Cloud - Click Digital Expo 2016 - Jamin Andrews
 
Constructing the Case for Cloud
Constructing the Case for CloudConstructing the Case for Cloud
Constructing the Case for Cloud
 
Building Data Intensity with AWS MSK & Lenses.io
Building Data Intensity with AWS MSK & Lenses.ioBuilding Data Intensity with AWS MSK & Lenses.io
Building Data Intensity with AWS MSK & Lenses.io
 
ARC219_Digital Transformation
ARC219_Digital TransformationARC219_Digital Transformation
ARC219_Digital Transformation
 
Digital Transformation - ARC219 - re:Invent 2017
Digital Transformation - ARC219 - re:Invent 2017Digital Transformation - ARC219 - re:Invent 2017
Digital Transformation - ARC219 - re:Invent 2017
 
Loudoun chamber virtacore final-revised
Loudoun chamber virtacore final-revisedLoudoun chamber virtacore final-revised
Loudoun chamber virtacore final-revised
 
Keynote Roberto Delamora - AWS Cloud Experience Argentina
Keynote Roberto Delamora - AWS Cloud Experience ArgentinaKeynote Roberto Delamora - AWS Cloud Experience Argentina
Keynote Roberto Delamora - AWS Cloud Experience Argentina
 
Glue con2011 future_of_net_systems
Glue con2011 future_of_net_systemsGlue con2011 future_of_net_systems
Glue con2011 future_of_net_systems
 
AWS Customer Presentation - Autodesk
AWS Customer Presentation - AutodeskAWS Customer Presentation - Autodesk
AWS Customer Presentation - Autodesk
 
How Autodesk uses Amazon VPC
How Autodesk uses Amazon VPCHow Autodesk uses Amazon VPC
How Autodesk uses Amazon VPC
 
AWS Customer Presentation - Autodesk
AWS Customer Presentation - AutodeskAWS Customer Presentation - Autodesk
AWS Customer Presentation - Autodesk
 
How to prevent cyber terrorism taragana
How to prevent cyber terrorism  taraganaHow to prevent cyber terrorism  taragana
How to prevent cyber terrorism taragana
 
Moving enterprise IT to the cloud
Moving enterprise IT to the cloudMoving enterprise IT to the cloud
Moving enterprise IT to the cloud
 
Sdwan webinar
Sdwan webinarSdwan webinar
Sdwan webinar
 
The Security Of Cloud Computing
The Security Of Cloud ComputingThe Security Of Cloud Computing
The Security Of Cloud Computing
 

More from Justin Pirie

Unifying Devices in the Cloud
Unifying Devices in the CloudUnifying Devices in the Cloud
Unifying Devices in the CloudJustin Pirie
 
Microsoft Hosters Sweden- Becoming a Trusted Advisor to Sell Cloud
Microsoft Hosters Sweden- Becoming a Trusted Advisor to Sell CloudMicrosoft Hosters Sweden- Becoming a Trusted Advisor to Sell Cloud
Microsoft Hosters Sweden- Becoming a Trusted Advisor to Sell CloudJustin Pirie
 
The end of IT as we know it.
The end of IT as we know it.The end of IT as we know it.
The end of IT as we know it.Justin Pirie
 
Empowering and Securing BYOD Email
Empowering and Securing BYOD EmailEmpowering and Securing BYOD Email
Empowering and Securing BYOD EmailJustin Pirie
 
Copenhagen Lean Startup
Copenhagen Lean StartupCopenhagen Lean Startup
Copenhagen Lean StartupJustin Pirie
 
The Great Migration- Cloud Circle
The Great Migration- Cloud CircleThe Great Migration- Cloud Circle
The Great Migration- Cloud CircleJustin Pirie
 
HostingCon 2011- How Not Just to Survive but Thrive in the Evolving Hosting M...
HostingCon 2011- How Not Just to Survive but Thrive in the Evolving Hosting M...HostingCon 2011- How Not Just to Survive but Thrive in the Evolving Hosting M...
HostingCon 2011- How Not Just to Survive but Thrive in the Evolving Hosting M...Justin Pirie
 
Cloud- A Technical or Organisational Challenge? Or Both?
Cloud- A Technical or Organisational Challenge? Or Both?Cloud- A Technical or Organisational Challenge? Or Both?
Cloud- A Technical or Organisational Challenge? Or Both?Justin Pirie
 
Cloud and The Channel- Where's the space?
Cloud and The Channel- Where's the space?Cloud and The Channel- Where's the space?
Cloud and The Channel- Where's the space?Justin Pirie
 
Cloud and the Channel- A Perfect Storm?
Cloud and the Channel- A Perfect Storm?Cloud and the Channel- A Perfect Storm?
Cloud and the Channel- A Perfect Storm?Justin Pirie
 
Lean Startup - A Primer for Entrepreneurs
Lean Startup - A Primer for EntrepreneursLean Startup - A Primer for Entrepreneurs
Lean Startup - A Primer for EntrepreneursJustin Pirie
 
Mimecast Partner Day
Mimecast Partner DayMimecast Partner Day
Mimecast Partner DayJustin Pirie
 
Lean Startup- a primer for Entrepreneurs
Lean Startup- a primer for EntrepreneursLean Startup- a primer for Entrepreneurs
Lean Startup- a primer for EntrepreneursJustin Pirie
 

More from Justin Pirie (13)

Unifying Devices in the Cloud
Unifying Devices in the CloudUnifying Devices in the Cloud
Unifying Devices in the Cloud
 
Microsoft Hosters Sweden- Becoming a Trusted Advisor to Sell Cloud
Microsoft Hosters Sweden- Becoming a Trusted Advisor to Sell CloudMicrosoft Hosters Sweden- Becoming a Trusted Advisor to Sell Cloud
Microsoft Hosters Sweden- Becoming a Trusted Advisor to Sell Cloud
 
The end of IT as we know it.
The end of IT as we know it.The end of IT as we know it.
The end of IT as we know it.
 
Empowering and Securing BYOD Email
Empowering and Securing BYOD EmailEmpowering and Securing BYOD Email
Empowering and Securing BYOD Email
 
Copenhagen Lean Startup
Copenhagen Lean StartupCopenhagen Lean Startup
Copenhagen Lean Startup
 
The Great Migration- Cloud Circle
The Great Migration- Cloud CircleThe Great Migration- Cloud Circle
The Great Migration- Cloud Circle
 
HostingCon 2011- How Not Just to Survive but Thrive in the Evolving Hosting M...
HostingCon 2011- How Not Just to Survive but Thrive in the Evolving Hosting M...HostingCon 2011- How Not Just to Survive but Thrive in the Evolving Hosting M...
HostingCon 2011- How Not Just to Survive but Thrive in the Evolving Hosting M...
 
Cloud- A Technical or Organisational Challenge? Or Both?
Cloud- A Technical or Organisational Challenge? Or Both?Cloud- A Technical or Organisational Challenge? Or Both?
Cloud- A Technical or Organisational Challenge? Or Both?
 
Cloud and The Channel- Where's the space?
Cloud and The Channel- Where's the space?Cloud and The Channel- Where's the space?
Cloud and The Channel- Where's the space?
 
Cloud and the Channel- A Perfect Storm?
Cloud and the Channel- A Perfect Storm?Cloud and the Channel- A Perfect Storm?
Cloud and the Channel- A Perfect Storm?
 
Lean Startup - A Primer for Entrepreneurs
Lean Startup - A Primer for EntrepreneursLean Startup - A Primer for Entrepreneurs
Lean Startup - A Primer for Entrepreneurs
 
Mimecast Partner Day
Mimecast Partner DayMimecast Partner Day
Mimecast Partner Day
 
Lean Startup- a primer for Entrepreneurs
Lean Startup- a primer for EntrepreneursLean Startup- a primer for Entrepreneurs
Lean Startup- a primer for Entrepreneurs
 

Recently uploaded

Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 

Recently uploaded (20)

Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 

CLT Legal Cloud Conference

Editor's Notes

  1. The Secrets of Successful Cloud Adoption: what they don’t tell you Cloud has a seemingly unstoppable momentum behind it- but is it clear at the outset what the benefits of Cloud are beyond the shift from cap-ex to op-ex? What exactly are these benefits and how do we access them to adopt Cloud successfully?
  2. To Microsoft Exchange
  3. Security
  4. Continutity
  5. Archive
  6. Bringing all the benefits of Google apps- horizontal scalability, reliability, etc
  7. To Microsoft Exchange
  8. What systems are your peers moving to the Cloud?- Present research from the Mimecast Cloud Survey
  9. Look back to see how we viewed previous paradigm shifts
  10. Mainframe – pc – ultimate benefits not forseen
  11. From the Mimecast Cloud Adoption Survey http://www.mimecast.com/events-press/press-releases/article/view/cloud-computing-delivering-on-its-promise-but-doubts-still-hold-back-adoption/462/
  12. From the Mimecast Cloud Adoption Survey http://www.mimecast.com/events-press/press-releases/article/view/cloud-computing-delivering-on-its-promise-but-doubts-still-hold-back-adoption/462/
  13. From the Mimecast Cloud Adoption Survey http://www.mimecast.com/events-press/press-releases/article/view/cloud-computing-delivering-on-its-promise-but-doubts-still-hold-back-adoption/462/
  14. From the Mimecast Cloud Adoption Survey http://www.mimecast.com/events-press/press-releases/article/view/cloud-computing-delivering-on-its-promise-but-doubts-still-hold-back-adoption/462/
  15. 2010 Gartner Hype Cycle for emerging technologies
  16. 2010 Gartner Hype Cycle for emerging technologies
  17. What’s the problem?
  18. How did I get here to be presenting in front of you about building the case for cloud?
  19. Not by first great western
  20. Or my brompton
  21. It was many years crawling under desks
  22. And fixing issues running a medium sized value added reseller. A VAR
  23. To my understanding of the cloud and the benefits it brings
  24. At the beginning of my journey I’m almost ashamed to say my attraction to Cloud was
  25. About money. The shift from
  26. Capital Expenditure, where the buyer took all the risk as to whether the software would work and fund the purchase, to
  27. Operational Expenditure, where you paid for what you used, and if it didn’t work you stopped paying- or sometimes didn’t even pay at all. But that only the first and probably the least important benefit of cloud- the real benefits are hidden
  28. About money. The shift from
  29. At a time of reinvention- it is really important to ask what IT is for?
  30. What do we do for the business? Or more specifically- what is the production function of IT??? http://blogs.gartner.com/mark_mcdonald/2010/06/27/what-is-the-production-function-of-it/ What is the Production Function of IT? by Mark McDonald  |  June 27, 2010  |  1 Comment Understanding IT’s role in the enterprise is complex and incomplete.  IT is the subject of great debate as some see it as the source of competitive advantage and others see it as an enabling function.  CIOs and IT professionals themselves have a tough time answering the question about IT’s role. Why?  because I believe we are asking the question in the wrong way. We need to ask, “What is the production function of IT?” Production function, sounds kind of academic right, but its simply the output you get for all the combination of inputs.   Its what you take and what you make. Every part of your enterprise has a production function.  So, when you ask different parts of the enterprise what they take and make you get answers like: SALES TOP LINE REVENUE: We take prospects and turn them into orders SUPPLY CHAIN PROFIT: We take orders and turn them into invoices FINANCE CASH: We take invoices and turn them into cash IT ?????? Silence  ?????? I know its silence because I have asked the question to dozens of IT leadership teams.  They look at each other and cannot put IT’s contribution in a simple answer.  It is not because IT is more complex than these other functions.  No its more that IT professionals have thought of themselves as something apart for the enterprise, something special and therefore not falling under the same rules. There are two production functions for IT that can be summarized in two words SPEED and SCALE. SPEED:  We take strategy plans and turn them into operational performance IT’s production function is to deliver speed of execution against the company’s strategy and plans.  Strategy execution involves change and change requires IT participation.  The faster IT is able to execute its processes, deliver results and accelerate strategy execution the better. IT drives speed when it concentrates on reducing its own internal cycle times for providing IT services, solution development and governance.  Concentrating internal operations on speed of execution makes IT more responsive and innovative.  IT organizations operating at speed give their business a steady stream of value that actually expands ITs role and enterprise flexibility. Without speed, IT is a bottleneck to strategic execution and operational performance.  It is the reason we cannot go faster.  This is the reason why change is expensive.  The reason why I have to control IT costs, because if they cannot go fast enough for me, then I had better make sure that they do not cost too much. SCALE:  We take operations and increase their capacity and reduce their average cost IT’s other production function is to create scale of operation across the enterprise.  Scale in this sense is the ability to IT to aggregate activities and deliver greater capacity at a lower average cost.  IT creates scale through its infrastructure and operations activities that make the modern enterprise possible.  IT is one of two scale functions in the enterprise.  The supply chain is the other scale function. IT drives scale through the infrastructure by constantly aggregating operations, virtualization and active contract management to gain the benefits of being bigger.  Without this scale, growing transaction volumes and the cost of operating disparate infrastructures would literally consume the company’s profit. Without scale, operations drown in a combination of complexity, duplicate cost and faltering service levels.  You see this with high growth companies that are heroes that suddenly fail – because they do not have scale. *** What is IT’s production function?  To deliver speed and scale to the enterprise. Speed and scale can seem as two different things, and that can be part of the reason why they are difficult for CIOs and IT leaders to articulate.  Most go “ah ha” when they think about their role in speed and scale. But, when you boil it down, we know why an enterprise has a sales function, a supply chain, a finance function, etc.  We had thought that IT existed to manage the technologies that these functions depend on. That is true in terms of the activities IT provides, but ‘to what end’ Speed of execution and Scale of operation.
  31. But it’s a question I didn’t ask myself seriously enough until recently- sounds academic though doesn’t it?
  32. It is a bit- but hopefully it’ll help you understand what we’re here for, just like it helped me. What does production function mean?
  33. It’s the combination of all the inputs
  34. Which create the outputs.
  35. The problem is, that in IT, they’re hidden. Hard to find. Let me contextualise it for you- What do Sales do?
  36. They turn prospects into orders. What does the supply chain do?
  37. They turn orders into invoices. What does finance do?
  38. The turn invoices into cash. So what does IT do?
  39. What do we do for the business? Or more specifically- what is the production function of IT??? http://blogs.gartner.com/mark_mcdonald/2010/06/27/what-is-the-production-function-of-it/ What is the Production Function of IT? by Mark McDonald  |  June 27, 2010  |  1 Comment Understanding IT’s role in the enterprise is complex and incomplete.  IT is the subject of great debate as some see it as the source of competitive advantage and others see it as an enabling function.  CIOs and IT professionals themselves have a tough time answering the question about IT’s role. Why?  because I believe we are asking the question in the wrong way. We need to ask, “What is the production function of IT?” Production function, sounds kind of academic right, but its simply the output you get for all the combination of inputs.   Its what you take and what you make. Every part of your enterprise has a production function.  So, when you ask different parts of the enterprise what they take and make you get answers like: SALES TOP LINE REVENUE: We take prospects and turn them into orders SUPPLY CHAIN PROFIT: We take orders and turn them into invoices FINANCE CASH: We take invoices and turn them into cash IT ?????? Silence  ?????? I know its silence because I have asked the question to dozens of IT leadership teams.  They look at each other and cannot put IT’s contribution in a simple answer.  It is not because IT is more complex than these other functions.  No its more that IT professionals have thought of themselves as something apart for the enterprise, something special and therefore not falling under the same rules. There are two production functions for IT that can be summarized in two words SPEED and SCALE. SPEED:  We take strategy plans and turn them into operational performance IT’s production function is to deliver speed of execution against the company’s strategy and plans.  Strategy execution involves change and change requires IT participation.  The faster IT is able to execute its processes, deliver results and accelerate strategy execution the better. IT drives speed when it concentrates on reducing its own internal cycle times for providing IT services, solution development and governance.  Concentrating internal operations on speed of execution makes IT more responsive and innovative.  IT organizations operating at speed give their business a steady stream of value that actually expands ITs role and enterprise flexibility. Without speed, IT is a bottleneck to strategic execution and operational performance.  It is the reason we cannot go faster.  This is the reason why change is expensive.  The reason why I have to control IT costs, because if they cannot go fast enough for me, then I had better make sure that they do not cost too much. SCALE:  We take operations and increase their capacity and reduce their average cost IT’s other production function is to create scale of operation across the enterprise.  Scale in this sense is the ability to IT to aggregate activities and deliver greater capacity at a lower average cost.  IT creates scale through its infrastructure and operations activities that make the modern enterprise possible.  IT is one of two scale functions in the enterprise.  The supply chain is the other scale function. IT drives scale through the infrastructure by constantly aggregating operations, virtualization and active contract management to gain the benefits of being bigger.  Without this scale, growing transaction volumes and the cost of operating disparate infrastructures would literally consume the company’s profit. Without scale, operations drown in a combination of complexity, duplicate cost and faltering service levels.  You see this with high growth companies that are heroes that suddenly fail – because they do not have scale. *** What is IT’s production function?  To deliver speed and scale to the enterprise. Speed and scale can seem as two different things, and that can be part of the reason why they are difficult for CIOs and IT leaders to articulate.  Most go “ah ha” when they think about their role in speed and scale. But, when you boil it down, we know why an enterprise has a sales function, a supply chain, a finance function, etc.  We had thought that IT existed to manage the technologies that these functions depend on. That is true in terms of the activities IT provides, but ‘to what end’ Speed of execution and Scale of operation.
  40. IT’s production value number 1 is Speed.
  41. Turning organisational strategy into execution
  42. As Fast as possible- to deliver results to the business
  43. And to do that IT has to be as responsive as possible
  44. Because without speed IT is a bottleneck to operational performance.
  45. Take operations
  46. increase their capacity and reduce their average cost to again deliver operational performance.
  47. IT should equal agility. Yet when we’re purchasing systems, rarely does agility factor heavily enough.
  48. Traditional IT department In the past, the only way for a company to maintain control of their business process was to completely own the technology supporting the process.  The rationale was that a company's most strategic, differentiating processes are unique and therefore have to built by the company either from scratch or by heavily customizing packaged applications.  This also meant owning the entire technology stack supporting the process and the application.  So, while the intent was to create differentiated processes that were agile and differentiating, the reality has become that the technology stack is an albatross around the IT team's neck that prevents them from moving as quickly and as efficiently as they would like to. The result is that while IT organizations are keen to support the business, they are unable to go much beyond providing basic services.  The solution to the problem of managing the entire stack was traditionally either hosted/managed server services or outsourcing, but each introduces its own problems. http://blog.appirio.com/2009/05/do-your-most-strategic-apps-belong-in.html
  49. Outsourcing In the case of outsourcing, the enterprise gains cost savings but relinquishes control of their business process and has to adhere to the provider's "best-practice" process.  This clearly means that outsourcing can only be applied to commodity processes rather than any differentiating processes or processes where innovation is needed.  The IT team's role shifts to primarily vendor management with little ability to innovate or drive the business.
  50. Hosted/Managed Servers Hosting gets a bit closer to solving the problem because it reduces some of the IT team's pain in terms of managing infrastructure.  However, the IT team still needs to spend a lot of their time maintaining the application and the middleware stack, i.e., applying patches and bug fixes, implementing upgrades, maintaining integrations, etc.  In addition, the team also needs to manage their relationship with the hosting vendor.  So, again, the main impact is some cost savings but no real gains in terms of agility or ability to innovate or support the business.
  51. IT department in the cloud Cloud computing changes the decision process completely.  No longer do companies face a choice between relinquishing all control of their business process for cost savings or dealing with the high costs and complexity of supporting an entire software stack. Platforms like Force.com and Google App Engine give companies a way to control the parts of the stack that matter most, the application and business process layer and abstract away the management of the infrastructure.  This means that the IT team can focus their energies on driving innovation and supporting the business.
  52. #1 Not having to worry about scaling- the provider does
  53. Less meetings
  54. . #3 The provider is constantly updating its software,
  55. No more upgrades or migrations
  56. which means you get Richer functionality- for very little effort
  57. #4 Creating Loosely coupled systems enables greater integration for less cost and dependency
  58. . #2 By separating configuration and code, it enables IT to rapidly reconfigure operations
  59. Less dependencies
  60. Means you can Reconfigure faster
  61. Aligns cost to value- Which means time to value is much quicker
  62. From the Mimecast Cloud Adoption Survey http://www.mimecast.com/events-press/press-releases/article/view/cloud-computing-delivering-on-its-promise-but-doubts-still-hold-back-adoption/462/
  63. From the Mimecast Cloud Adoption Survey http://www.mimecast.com/events-press/press-releases/article/view/cloud-computing-delivering-on-its-promise-but-doubts-still-hold-back-adoption/462/
  64. Why are some People are unsure about Cloud Security
  65. Security is often presented as a binary object. It’s not.
  66. It’s much more complex than that.
  67. Technical details are abstracted
  68. Probably because of the relative opacity of Cloud compared to the transparency of a private network and the control you can exert on it
  69. Are it’s Achilles heel
  70. Without revealing to much intellectual property- the main differentiator in Cloud
  71. Standards are only just emerging
  72. Buyer Beware- http://en.wikipedia.org/wiki/Caveat_emptor Under the doctrine of caveat emptor, the buyer could not recover from the seller for defects on the property that rendered the property unfit for ordinary purposes. The only exception was if the seller actively concealed latent defects or otherwise made material misrepresentations amounting to fraud. Before statutory law, the buyer had no warranty of the quality of goods. In many jurisdictions now, the law requires that goods must be of "merchantable quality". However, this implied warranty can be difficult to enforce and may not apply to all products. Hence, buyers are still advised to be cautious.
  73. Which is why we in cloud feel like we’re being beaten up...
  74. Independent Audit?
  75. There are no standards... There is not a best practice independent security methodology for cloud. Clouds are opaque. Technical complexity is abstracted. Proper audit / DD requires transparency. But transparency would reveal IP.
  76. Independent 3rd party is so important to validate claims in depth SAS 70, CESG etc
  77. Spot the missing one?
  78. ISO 27001- ISO 27001 doesn’t fit the cloud- 5 year old standard currently- to be reviewed in 2012- CSA helping update controls for the Cloud
  79. ·          Should you adopt ISO 20071? What sort of protection will it grant you?   Yes. Because it’s a framework for managing security. A process. Set of Documentation. Set of controls.   Working out how much acceptable risk   What risk are you exposed to   Which are greater than the accpectable risck   What controls do you need to manage- taken from annex A   Deploy the controls in an auditable way- constantly approve   Compliance- testing   Governance   Risk   Complaince- testing to make sure your controls   It Scales
  80. Control and governance; what should be the basis of your Cloud Data Best Practice Policy- ENISA
  81. ·          Investigating availability guarantees and penalties and examining your supplier’s disaster recovery strategy   Important- they do what they say the do   The bar to what you set that at needs to be relevant to what you have already- BASELINE!!! Realistic expectation   Based on the data you’re going to outsource   Look at historical performance- not a predictor for the future- but relevant   Look at their DR strategy- if you have 2 data centres- that should be the expectation   Map your requirements to the provider
  82. ·          Data compliance; the importance of clarifying where your data will be stored and who will have access to your information   Jurisdiction   EU/ Patriot / RIPA / Safe Harbour
  83. ·          Ultimately, who has control over your data?   When you save your data- need to understand   Look at service providers to the same extent   MBTF- encryption look at service providers   Cloud should be architected differently   People shouldn’t be fooled by “cloud” technology   See behind the fog   Often it’s really hard because of the opaqueness       Integretity of Data Critical   End to end vs middleware   Designed to hook together     Managing service provider obligations   Asses the risk- make sure the risk you’re willing to accept is related in the SLA   Review- annually?   Any deviation look for recompense or additional controls   Blunt instrument   Make sure compliance and information governance are involved early on in the process of negotiating SLA- lawyers don’t know about GRC
  84. The key is to understand your current risks- baseline them
  85. i.e. Where are we today?
  86. Users Applications File shares Email Document management
  87. Sysadmins User based access Server access Database access
  88. Others: Internet VPN Extranet Customer/Partner portals API’s Suppliers Telco’s Tape warehousing Backup delivery personnel
  89. Ends up in a Permissions Nightmare- or a brittle infrastructure
  90. How are we managing those risks today?
  91. Are you given the budget / skills to do it?
  92. “Quis custodiet ipsos custodes?” Who will guard the guards themselves? Decimus Iunius Iuvenalis
  93. Cloud can be a way to become a guard’s guard, instead of the guard
  94. Reasons to go Cloud Security
  95. Reason to go Cloud security #1 It’s their business- and their reputation depends on it
  96. #2 Money - they are held financially responsible
  97. Reason #3 Scale- Cloud platforms have scale that customers could never achieve on their own- protecting against large scale attacks
  98. Reason #4 Specialised Skills- employ specific people to do specialised job. Cumulative effect of multiple customers
  99. Cumulative effect of multiple customers
  100. Best Practice embedded in organisation and distributed. Not dependent on one person
  101. Not just about competence and budget- but focus. It’s all they do.
  102. Cloud can be a way to become a guard’s guard, instead of the guard
  103. Buyer Beware- http://en.wikipedia.org/wiki/Caveat_emptor Under the doctrine of caveat emptor, the buyer could not recover from the seller for defects on the property that rendered the property unfit for ordinary purposes. The only exception was if the seller actively concealed latent defects or otherwise made material misrepresentations amounting to fraud. Before statutory law, the buyer had no warranty of the quality of goods. In many jurisdictions now, the law requires that goods must be of "merchantable quality". However, this implied warranty can be difficult to enforce and may not apply to all products. Hence, buyers are still advised to be cautious.
  104. But make it proportional to risk- especially to CURRENT RISKS