Security technologies delivered via the SAAS (software-as-a-service) business model may still be in their nascent stage, but some early adopters are already piecing together multiple offerings to outsource a significant portion of their IT systems defense infrastructure.
One such company is Imperial Chemical Industries, the massive London-based maker of paints and chemicals that is in the process of being acquired by industrial conglomerate Akzo Nobel to the tune of US$16 billion (AU$19.6 billion).
With worldwide business operations and an annual research and development budget approaching US$60 million, the chemicals giant is spending more effort than ever before in securing its assets and data, company officials said.
However, utilizing a handful of SAAS applications -- including vulnerability scanning tools offered by Qualys, e-mail and anti-spam filtering from MessageLabs, and Web filtering provided by ScanSafe -- IT executives at ICI claim they are maximizing personnel and budget in a manner that traditional on-premise security products wouldn't allow.
"We're pushing the envelope in terms of what's out there with security SAAS, but so far, it's been a fantastic success; SAAS can only be employed where IT truly benefits from doing something once centrally, but there are a number of sweet spots where that approach fits today," said Paul Simmonds, global information security director at ICI. "Over time we'll likely see a mix with SAAS being used more heavily where it can offer benefits of cost and management, just as with general outsourcing."
Having used Qualys' vulnerability scanning services for over five years, ICI is at the cusp of large enterprises that have begun replacing some in-house security tools with subscription-based services.
The company is currently considering use of hosted applications binary code scanning tools offered by Veracode, a relatively new start-up, under the idea that it can begin integrating multiple SAAS technologies to offload larger parcels of its security infrastructure to outside specialists, Simmonds said.
With five years of security SAAS experience under its belt, ICI is beginning to see the long-term promise of the services offerings, according to the executive. But the company is also cognizant that despite the benefits of moving to SAAS services, some elements of its network and data security must always remain on-site.
"The combination of outsourced vulnerability and binary code analysis through combining Qualys and Veracode is the type of thing that could be very significant as it's the kind of work that can truly benefit from being done once, centrally, in terms of running samples through tests. There's a huge opportunity there, and this type of scanning is very complex to do on your own," Simmonds said.
"At the same time, like everything else, you need to be selective in what you move into the cloud," he said. "Some things are a natural fit, but others will never work for this model; there's always a danger that when something like SAAS becomes an industry trend, like security appliances today, that the market tends to go overboard."
Emerging security tools like NAC systems and endpoint-oriented products, including data leakage prevention software, are among the types of technologies the ICI security chief said wouldn't ever likely be provided via SAAS.
In the meantime Simmonds said that the chemicals behemoth will continue to seek out new SAAS security alternatives as they come to market.
Philippe Courtot, chief executive of Qualys, is recognized as one of the chief evangelists of security SAAS in general, just as Salesforce.com CEO Marc Benioff has become associated with pushing the hosted applications model into the enterprise software space.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. How to improve employee productivity in small and medium businesses
Delivering the Power of Choice with Microsoft Dynamics CRM
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Strategies for Eliminating .PST Files
Email Archiving Implementation: Five Costly Mistakes to Avoid
Solve Exchange Mailbox Storage Issues Once and for All
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Discover the advantages of an open architecture multi-vendor network solution
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
AOC Launches 18.5” Widescreen Green 16:9 LCD Monitor in Australia and New Zealand 2008-12-03 15:30:00+11
FrontRange Solutions eases software license management with new License Manager 3.0 2008-12-03 14:56:00+11
Progress Software's Cure for Managing Services-based Applications 2008-12-03 14:42:00+11
S3 Graphics Unleashes Full OpenGL® 3.0 API Support with Beta Driver for Chrome 500 Series GPUs 2008-12-03 14:08:00+11
Informatica Powercenter added to Nec Infoframe Solution Suite 2008-12-03 11:36:00+11
IT Service Management Needs and Adoption Trends: An Analysis of a Global Survey of IT Executives
IT executives face the need to improve service delivery with limited resource increases. Two common strategies for achieving this are network and systems management tools and datacenter consolidation. Read on to disocover how you can make a strong business case for IT Consolidation.












