GoGrid Security Breach
March 30, 2011 by Craig Balding
GoGrid Security Team discover an unauthorized party accessed customer records. Here is a copy of the breach notification I received.
Articles, interviews and insights about cloud security
March 30, 2011 by Craig Balding
GoGrid Security Team discover an unauthorized party accessed customer records. Here is a copy of the breach notification I received.
May 18, 2010 by Craig Balding
Marketers of cloud services and software as a service continue to find ever more creative ways to get targeted exposure to their offerings. I experienced this first hand when a blog post I wrote was turned into a video with professional actors.
February 23, 2010 by Craig Balding
The Cloud Security Alliance is running a survey to find out which cloud security threats security professionals are most concerned about.
January 25, 2010
When it comes to security due diligence and on-going operational security visibility of cloud services, enterprise security pros are acting out the childrens game, Pin the Tail on the Donkey.
December 04, 2009 by Craig Balding
November 20, 2009 by Craig Balding
August 31, 2009 by Craig Balding
Research team publish paper analyzing potential security weaknesses in Infrastructure a a Sercice cloud environmentsl
July 31, 2009 by Craig Balding
July 08, 2009 by Craig Balding
June 28, 2009 by Craig Balding
Vulnerability scanning of cloud services may be against cloud providers Terms and Conditions. How can we digitize requests to scan?
June 16, 2009 by Craig Balding
Cloud providers are suffering an Audit Denial of Service as customer security teams conduct reviews. How can we eliminate unncessary duplication and gain digital trust of claims?
May 08, 2009 by Craig Balding
Legal Cloud caters to the specific security, compliance and audit needs of Law firms. Will vertical specific clouds drive greater cloud adoption by enterprises?
May 04, 2009 by Craig Balding
Cloud terminology can be confusing. Learn the difference between cloud security and security in the cloud.
May 04, 2009 by Craig Balding
The slides from my talk at Black Hat Europe 2009 are now available
April 27, 2009 by Craig Balding
April 10, 2009 by Craig Balding
April 09, 2009 by Craig Balding
Amazon introduces fine grained access control using new policy language. Learn how you can limit access to your cloud services.
April 08, 2009 by Craig Balding
Always read the terms and conditions before signing up for a cloud service. Especially if you are a weapons developer.
April 08, 2009 by Craig Balding
Google App Engine introduces the Google Secure Data Connector to help organisations connect their network to the Google public cloud.
April 08, 2009 by Craig Balding
Amazon Web Services claim their cloud platform can be used to create HIPAA compliant applcations. cloudsecurity.org challenges that claim...
March 27, 2009 by Craig Balding
Compliance as a Service could provide a means to bind your company security policy and regulations to your use of cloud services and APIs
March 18, 2009 by Craig Balding
What happens when a popular privacy group takes on the worlds largest cloud provider? EPIC files compliant with the FTC citing concerns with Googles' privacy and security.
March 17, 2009 by Craig Balding
Who are the cloud providers and what cloud services do they sell? Find out with this cloud ecosystem map.
March 15, 2009 by Craig Balding
The Microsoft Azure Technology Preview suffered a major outage that lasted 22 hours.
March 15, 2009 by Craig Balding
Amazon Reserved Instances provide a customer with a cheap way to reserve computer capacity in advance for Business Continuance (for example). But what are the Terms and Conditions?
March 14, 2009 by Craig Balding
What is a PCI compliant cloud service? Learn how to separate the hype from reality in cloud providers compliance claims.
March 13, 2009 by Craig Balding
How does your cloud provider handle vulnerability reports and how quickly do they inform you so you can assess retrospective risk? Baynote case study.
March 11, 2009 by Craig Balding
Share your cloud security startup and get free security consulting to help your startup prepare for 'Under The Radar'.
March 07, 2009 by Craig Balding
A vulnerability in the sharing feature in Google Docs led to unauthorized disclosure of private customer data. How did the Google Security Team handle it?
March 06, 2009 by Craig Balding
Large cloud providers employ evangelists to market their cloud services. But where are the security evangelists?
March 04, 2009 by Craig Balding
NIST creates a Cloud Computing Security Group to identify risks and develop standards for government agencies to safely use cloud services.
January 16, 2009 by Craig Balding
Craig Balding talks about the security challenges of cloud computing at the IGT2008 World Cloud Computing Summit [video]
December 18, 2008 by Craig Balding
Cloud security vulnerability in Amazon EC2 and SimpleDB fixed after 7.5 months. Customers notified by a forum post.
December 17, 2008 by Craig Balding
Web browsers may cache or store sensitive infoatmion, exposing your cloud credentials and data to risk.
October 14, 2008 by Craig Balding
A recent survey suggests IT decision makers consider cloud security the biggest challenge. What is your cloud provider doing to address your concerns?
October 12, 2008 by Craig Balding
Cloud Computing raises privacy concerns. A recent Pew Internet study highlights the growing use of cloud sercice. What is your privacy worth?
July 21, 2008 by Craig Balding
July 17, 2008 by Craig Balding
When collaboration technologies meet Virtual Worlds, what are the security implications?"
July 14, 2008 by Craig Balding
Amazon posted a forum message stating they had fixed a vulnerability in their cloud copmuting environment.
July 01, 2008 by Craig Balding
Interview with Guido van Rossum from Google talking about the security of Google App Engine and the Python programming language.
June 25, 2008 by Craig Balding
How do you know that the data you pushed to a cloud storage provider is the same as what you get back? An example is provided showing a problem with Amazon S3 integrity checks.
May 05, 2008 by Craig Balding
Interview with Craig Balding on US National Public Radio (NPR). Topics include the definition of cloud computing, how consumers can benefit and security challenges.
May 01, 2008 by Craig Balding
Security API calls and audit log entries may be billable for cloud services. How does your choice of cloud security tools impact your budget?
April 25, 2008 by Craig Balding
A light-hearted look at the early tell-tale signs that your company is already using cloud services - regardless of what your security policy does or doesn't say.
April 24, 2008 by Craig Balding
What measures do you have in place to assess potential security gaps in cloud services and how do you mitigate the risks?
April 22, 2008 by Craig Balding
Security professionals often dismiss cloud computing as hype or a label for mainframe service models. Here are 5 reasons why you should pay attention.
April 21, 2008 by Craig Balding
A cloud service may be composed of multiple cloud provider offerings. Security reviews need to consider the risk posed by API mashups on supply chain security.
April 18, 2008 by Craig Balding
Thin clients offer less features and expose less attack surface. But cleartext and proprietary protocols combined with weak security controls undermine their overall security.
April 17, 2008 by Craig Balding
What is Cloud Computing? A simple definition covering virtualization, commodity hardware and software and utility billing.
April 17, 2008 by Craig Balding
Cloud providers share dashboards showing operational metrics including uptime and outages over time. To speed enterprise cloud adoption, providers should expose cloud security metrics.