Will Cloud improve Cyber Security?
Sometime future direction is based on learnings from past. I have always found great parallels between story of Electricity and Computer Industry.
For electrical bulbs to be ready for mass use, invention of bulb was not the only requirement. Problems of electricity generation, transmission, measurement had to be solved. Efficient electrical transmission meant in turn that electricity could be generated at centralized power stations, where it benefited from standardization and economies of scale.
Something similar is happening with Computer Industry. Invention of Internet and improvements in computer hardware and software has meant that everyone walks around connected and information rich. These are perfect ingredients to start reaping the benefits of centralization and economies of scale by moving to "Cloud".
Today in 2017 as we celebrate 10th anniversary for iPhone, we are at the start of a new era where every corporation having its own datacenter and an army of software professionals would just become a thing of past. Computer applications will be centrally developed and deployed in the "Cloud" by the specialists and rest of the world would only be users of these services.
Such centralization in any field has usual benefits of consistency, consolidation, and efficiency. However, the one that I am really excited about is potential benefits for Cyber Security. Here's how and why:
- Fortress - No matter how much anarchy is happening on rest of the Internet; the few cloud providers that will emerge eventual winners will be almost like impenetrable "forts". These cloud providers will have enough financial resources and business survival needs to deploy protection technologies to fight even military grade cyber weapons.
- More Secure Applications - Applications running within these forts will be all developed following uniform development structure, strict standards and best practices. Also, these applications will be purpose built to run on specific deployment platforms and would be tailored to be most secure for that particular platform rather than trying to be secure in all possible deployment scenarios.
- Country specific cloud providers - Due to physical world needs of law enforcement, surveillance, privacy etcetera ultimately country specific cloud providers will start to emerge. This will get us closer to Internet with country and geographical boundaries as I discussed in one of my earlier articles. Also, this will make attribution and law enforcement easier leading to less people having motivation to find vulnerabilities and carry out the attacks.
- More skilled resources and automation - Employees working at these Cloud providers should be better skilled and to satisfy the needs to do things more efficiently and at large scale operational automation would kick in. This will reduce human errors thereby further improving security.
- Help from country's Military - There could be potential for private sector and military partnership to ensure security of such critical Cloud infrastructure.
I am sure, I am missing few more ways that Cloud could improve security - add your ideas in the comment section.
Thanks, Ty. Good to hear from, hope you are doing well in your new role.
Manish, very well told, I appreciate your point of view.