Showing posts with label May 2010. Show all posts
Showing posts with label May 2010. Show all posts

Thursday, May 27, 2010

The 5 Cs of Security as a Service

Conclusions

The 5 Cs finishes with our conclusions on why end users are quickly moving to Security as a Service.

Conclusions
Change, Compliance, Cost, Continuity, and Coverage; these are all basic considerations for an organization. For anyone challenged with evaluating and implementing technical solutions, these factors provide a useful lens through which available options can be viewed. With the past as our guide it is clear that the future will demand more flexibility, reach, and capacity more quickly and at lower costs. The Internet has already changed the way we live, the way we learn, and the way we communicate with each other. It is also changing the nature of software and how we interact with it. We are moving from static applications purchased in boxes to living cyber platforms shared with thousands of users, adopted as needed and discarded if not valued.

SaaS changes our relationship with software by allowing us to focus on what it does for us rather than the infrastructure required to make it work. This change allows business to invest more in their people and the technology that allows them to differentiate themselves from their competition and less on non-strategic functions.

SaaS also changes our relationships with software providers by creating a mutually dependant environment in which the seller of the service is fully committed to the customer’s outcomes. No one expects a customer to continuously pay for a solution that is not providing value to their organizations. The Software as a Service model creates a vendor vested relationship from the very start and places the consumer in a very powerful position. If your organization would be best served by rapid access to state of the art technology delivered with minimal internal resource requirements, tremendous scalability and predictable costs over time, you should consider a SaaS based option for your physical security.

-John Szczygiel

Thursday, May 20, 2010

The 5 Cs of Security as a Service

The 5th C...Coverage

Coverage
Organizations often find that the best way to accelerate profitable growth is through geographic expansion. Expansion comes with significant challenges, risks, and expenses. Management teams will be extended a bit further, along with scarce company resources. Solutions that provide good results in one location or at small campus can turn troublesome when multiplied for many geographically dispersed sites. Typically, these types of installations expose the vulnerabilities, complexities, and hidden expenses of traditional client/server solutions.

Security as a Service solutions provide very clear benefits for organizations with geographically dispersed sites. The low initial costs and wide scalability of SaaS solutions give organizations access to world-class technologies with an economic model that promotes expansion rather than restricting it. Securely using the public Internet as a communication medium greatly simplifies the deployment of remote sites for IT Departments. Best yet, the centrally hosted SaaS model provides all the central oversight and management that is needed in well run organizations without requiring costly investments in dedicated infrastructure.

It's a small world, but I wouldn't want to have to paint it, Steven Wright

A SaaS-based security platform gives you the power to drop an access control point anywhere in world and have it communicating, configured, and controlling your facility in a matter of hours. With complete synchronization to your master database and with total audit capability from wherever you happen to be. With the complexity of local software and hardware configurations removed from the equation, installers with modest training can successfully implement a SaaS based physical access control solution.

Illustration: SaaS in Physical Security Today
Brivo introduced SaaS into the security industry in 2001. The company offers a hosted Security Management System that provides centralized access control, video surveillance, notifications, and related services. As shown below, the SaaS applications connect to a variety of on-premise security equipment ranging from cameras to control panels and other sensors.


This architecture eliminates the need to have applications running at each secured property, which eliminates the expense and headaches of the local computing resources that have been the Achilles ’ heel of legacy security systems. Instead, it relies on a centrally hosted platform for identity, device, and asset management; as well as all alerts, alarms, email notifications, and general reporting. Multiple data centers throughout the US provide redundancy and disaster recovery capability, with SAS-70 audits to provide assurance on information security and compliance concerns.

-John Szczygiel

Thursday, May 13, 2010

The 5 Cs of Security as a Service

The 4th C…Continuity

The 5 Cs continues with yet another in our reasons why end-users are quickly moving to Security as a Service. The 4th C is for Continuity.

Continuity
Our collective experiences with events such as September 11 2001, Hurricane Katrina, and a host of other disasters and outages have brought into clear focus the need for redundancy and resiliency in the systems that support our organizations. It’s not enough to ask how well are we protected or how many back-ups exist, but also how fast can we resume operations if everything goes wrong?

Organizations routinely spend hundreds of thousands of dollars creating resiliency in their physical security platforms. This commonly includes hot-standby computers, back-up power sources, and disaster recovery locations. These measures are not only expensive; they are often reliant on internal computer networks that are likely to be challenged by any form of massive disaster. Further, if employees cannot get to the machines that operate the security platform, all the redundant measure may be fruitless. While security is certainly a high priority, if an organization’s core revenue generating capabilities are down, what will be addressed first?

Fortunately, the SaaS model provides numerous answers for these types of challenges. Multi-tenant SaaS services are normally hosted in highly reliable data centers with built-in redundancy. The best providers also employ separate disaster recovery centers to restore full operations if the primary center is disabled. Redundancy in the communication path is built into this model due to the Internet’s capability to send information via a large number of routes. Even if broadband service is down, it’s possible to establish the same communication paths via cellular cards and cellular equipped access panels. Since no special computers or software is required to operate a SaaS-based physical security application, any computer connected to the Internet can be placed into service during an emergency.

The redundancy and disaster recovery capabilities of the SaaS model are even more remarkable when you consider that it’s all part of the basic service and thus is available at the same level of quality for consumers with one reader or one thousand readers.

-John Szczygiel

Thursday, May 6, 2010

The 5 Cs of Security as a Service

The 3rd C…Cost  

Moving on through the 5 Cs of Security as a Service, let's examine the motivations for customers to seek cloud services. The 3rd “C” is for Cost.

Cost
The survival of every organization hinges on its ability to deliver value for its customers. It’s impossible to deliver high levels of value without addressing the cost for operating your organization. Referring back to the power example, what would it cost each of us to have a personal power generation plant for our homes? How much would the installation cost, how much labor would be required to operate it and maintain the equipment? While it seems quite obvious that a personal power generation plant wouldn’t make sense, most physical security applications are delivered exactly in this way. Software and hardware is purchased with sufficient capacity to handle present and some portion of future needs. The equipment is installed, powered, and maintained with internal resources. Very often excess resources exist in the host computers and within each machine that is operating the client software. When you add up the total cost of ownership, you will most likely be very surprised.

The SaaS-based Security as a Service model provides an excellent alternative to the traditional options, thus allowing organizations to focus on their core business. SaaS delivers outstanding economic value for the following reasons;
  1. All users share a common computing infrastructure, to the economic benefit of all.
  2. The cost model is scalable with users only paying for what they actually use.
  3. The consumers of an application are free of all “back-end” management and maintenance expenses.
  4. Up-front capital expenditures are replaced with flat, subscription-based operational expenses.
Beyond the excessive capital outlays for traditional options, recent studies have established that the largest part of application and server ownership costs actually exist in ongoing operational expenses, maintenance, and support agreements. This is particularly true of computer systems that provide infrastructure services like security, because they must be held to a higher standard of availability and performance than ordinary office equipment. In one representative study, the authors conclude that only 15% of the lifetime cost of server ownership is captured by the initial purchase price, which means that your $1,000 server can actually cost you over $6,600. [1]

In the case of physical security, our own study finds that for a typical branch office or managed property scenario, the SaaS model for security management offers significant operational and financial savings. This is due to both upfront cost reductions and the economies of scale of hosted application services. This study found that a Security as a Service solution enjoyed an advantage of nearly $26,000 (or 76%) over the server-based solution. [2]

- John Szczygiel


[1] Total Cost of Ownership Reduction with VMware,” VMware.com (March 10, 2008).
[2] Interested readers are referred to the full study, found here.