Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, August 21, 2013

The Future is Past: Cloud Services Come of Age for Banks

For some, the future lies behind.

by Randy Davis, VP Sales and Marketing Operations

Banks and bankers are not, I suppose, usually perceived as harbingers of trends in technology, but kudos go to +Michael Harte, CIO at Commonwealth Bank of Australia, for getting it right back in 2010.

In our blog post at the time, Putting the Kibosh on Soaring Software and Maintenance Costs, we noted that Michael had recognized that select cloud vendors had solved his hardware/software problem, and that he didn't need to:
"We're saying that we will never buy another data center. We will never buy another rack or server or storage device or network device again. I will never let any organization that I work for get locked into proprietary hardware or software again. I'll never tell my teams in the business that it will be weeks to get them hardware provision. I'll never pay upfront for any infrastructure and certainly would never pay for any, or rent any, infrastructure that I would never use. I will never implement an internal solution for a common problem that I could procure on subscription across the Web (emphasis mine)."
                                                                                                  (Reported by Finextra.)
Now we read in an article by Bank Technology News titled, "Banks Are Finally Embracing Cloud Computing," that "banks are warming to cloud computing after nearly a decade of hesitation about trusting their data to outsiders." Michael Harte might say, "Welcome to the past, boys and girls."

However, the Institute of Financial Operations just published a report on "2013 Trends in Cloud-based and Mobile Technology in Financial Services," sponsored by eGistics (click the link and look under Media>Brochures). This study shows that many financial services companies still have a long way to go in recognizing the benefits of cloud-based services. Concerns about security, perhaps based on misinformation or misplaced fears, still prevent some FS organizations from embracing cloud solutions that have been carefully vetted by other banks and or bank servicing companies. This is an example of "The Emperor's Clothes" in reverse.

Rather than "seeing" what's not really there (higher security risks in proven cloud service providers), many banks may be ignoring what's really in plain sight (higher security capabilities provided by cloud providers consumed with protecting data).

Our view, of course, as a provider of "hosted" or "cloud-based" solutions to banks for almost 20 years, is that carefully vetted and chosen cloud-providers can (and do) deliver superior security and data management services. In our blog post, "Cloud Security Concerns Are Dead..." we argued that just as we have come to trust third-parties (banks) with our money, we will also come to trust third-parties (data banks) with our most sensitive data. It is the way of things.

So what should you do if you are hesitating to use cloud services? Here are some suggestions:
  • Recognize that there are different kinds of cloud service providers. Understand the difference between general practitioners and specialists in handling financial services data
  • Determine your requirements: Tier 4 data centers, certifications, experience with banking practices and operations, regulatory compliance, SLAs, scalability, etc.
  • Visit the facilities and meet with the staff of prospective cloud service providers
  • Talk to banks and FS companies that are using cloud services
  • Don't focus just on high-profile cloud service providers. Consider that you may not want your cloud service provider to be "well known"
Post your comments about banks using cloud-services below.

Thursday, July 29, 2010

Beyond SAS 70

By R. Edwin Pearce (www.epearce@egisticsinc.com)

A new study from Gartner confirms something that eGistics (www.egisticsinc.com) has known for some time: there's a lot more to effective security, privacy and continuity than compliance with Statement on Auditing Standards (SAS) 70.

"SAS 70 is basically an expensive auditing process to support compliance with financial reporting rules like the Sarbanes-Oxley Act (SOX)," says French Caldwell, research vice president at Gartner. "Chief information security officers (CISOs), compliance and risk managers, vendor managers, procurement professionals, and others involved in the purchase or sale of IT services and software need to recognize that SAS 70 is not a security, continuity or privacy compliance standard."

Published by the American Institute of Certified Public Accountants (AICPA), SAS 70 provides a service provider's auditor with guidance on how it should report on process-related risks relevant to financial statements and transaction processing. Intended for use by the customer's auditor, the result of a SAS 70 is either a Type I attestation that the processes as documented are sufficient to meet specific control objectives, or a Type II attestation, which additionally includes an on-site evaluation to determine whether the processes and controls actually function as anticipated.

Gartner believes a SAS 70 Type II evaluation does provide a very high degree of assurance that the examined controls are effective. The performance of controls is evaluated over a period of time; it is not just a snapshot of control effectiveness. However, customers should never assume that the provider has implemented all the appropriate controls, Gartner says.

"To ensure that vendor controls are effective for security, privacy compliance and vendor risk management, SAS 70 ... and other national audit standard equivalents should be supplemented with self-assessments and agreed-upon audit procedures," Caldwell explains.

Interested in learning more? E-mail me at epearce@egisticsinc.com.

Tuesday, July 20, 2010

Cloudy with a chance of Microsoft


Microsoft CEO Steve Ballmer, known for his eyebrow raising antics at company-wide employee meetings, is raising eyebrows again with his provocative and far-reaching statements about Microsoft and the cloud. On July 12 Ballmer told 9,500 attendees at the annual partners’ conference that “if you don’t want to move to the cloud, we’re not your folks.” The cloud, he says, is “inevitable.” Whew.

Actually, even in the summer of 2008 Microsoft recognized that on-line delivery of critical business applications and services was, in fact, “a sea change” in the way businesses and corporations want to be served. On-line delivery was then and is now recognized as part of a “services wave” that is causing some to criticize the traditional software-based delivery model and on-premise execution of business applications as growing “antiquated.”

Maybe yes, maybe no.

Ballmer acknowledges what corporations have been concerned about since the cloud began to form: security and compliance. He implies that companies that get this right are “way ahead” in providing a viable offering to the market.

This brings up a good point in the use and selection of on-line services companies: Choosing one that provides an on-line service is one thing; choosing one that has invested the time, cost, expertise and infrastructure required to provide world-class security, and that supports a variety of compliance mandates, is quite another.

It is our experience that large, security- and compliance-conscious institutions are taking advantage of the growing maturity of cloud services, especially in the area of the management of documents, transactional data, payment images, and reports. As institutions become more comfortable with, and confident in, selective cloud providers, expectations will increase regarding the use of such information for fraud detection and prevention, data mining, analysis, legal discovery, research and customer service.

Is your company catching the wave, dipping its toes in the water, or staying high and dry? 

Thursday, July 8, 2010

Pressure is rising for data center managers

By R. Edwin Pearce (epearce@egisticsinc.com)

Just when data center and IT managers assumed things couldn’t get any worse, along comes a report from Gartner predicting that the critical issues facing data centers – namely, technology, space and energy challenges – will worsen in 2010. Coupled with the tremendous cost pressures brought on by the economic downturn, the Gartner report provides a heightened sense of urgency for data center and IT managers looking for pragmatic ways in which to deal with their operations issues. In its report, Gartner provides several tips for helping reduce data center costs:
  • Eliminate those systems that are underutilized or old
  • Consolidate multiple sites
  • Better manage energy and facilities costs
  • Better manage people costs
  • Delay the procurement of new assets
To be sure, these are all sound strategies. But savvy data center managers already have implemented (or at least considered) these strategies in response to the economic downturn. In other words, many data centers may have already squeezed as much savings as possible from their infrastructure.

However, the following challenges still remain:
  • Finding ways to implement a variable expense model to take advantage of reductions or slowdowns
  • Improving security and regulatory compliance
  • Staffing to support multiple hardware/software environments
  • Reducing excess capacity while maintaining the ability to grow
  • Managing the increasing need for backups and redundancy
None of this is new, of course. These are the normal and continuing requirements for doing business, perhaps "heightened," as Gartner says, by the subdued economy. 

How are you responding to your own data center information management challenges? If you had your way, what would you have your company do differently than they are doing today?