Showing posts with label cloud based services. Show all posts
Showing posts with label cloud based services. Show all posts

Mar 15, 2013

Megaupload and Equinix Make History in Canada (?)

Megaupload and Equinix are in the news today. Apparently the Attorney General of Canada applied to the Ontario Superior Court for an order requiring them to turn over "cloud servers" on behalf was US Government (as reported by Chris Bennett of Davis LLP on Mondaq.com).

What's not clear to me yet is what is actually meant by "cloud servers" and how this could impact cloud computing in particular. We all know how the term "cloud" has been used repeatedly in cases where the service is not actually cloud computing (see my previous posts on the topic of cloudwashing and other posts on nomenclature). Are the servers actually IaaS and fit the NIST definition of cloud computing or are they simply hosted web servers and databases?

It appears that the judicial system could use some clarification as to what cloud computing actually is and the difference between cloud computing and cloud based services.

More to come as this story develops.

Oct 15, 2012

Live Blog -- Cloud Launch: Ian Rae

Ian Rae put up a slide with a less than glowing endorsement on Canadian capabilities and self-worth (along with those of Australians, no judgement)... Can the cloud help fix that?

Rae's working to build Canada's cloud ecosystem by contributing to it directly with CloudOps and "...building long term supportable solutions for just in time, right-sized IT solutions."

CloudOps' goal is to provide Canadian organisations with a home grown alternative to cloud services based in other countries. It's up to Canadians to provide decent cloud based services otherwise the $$$ will just go elsewhere.

Aug 6, 2012

Open Letter to the Cloud Community

Over the past few years, there have been many advances in cloud computing and much effort is being made by consumers and vendors alike to make the best of what is widely considered to be the next step in e-business. However, like with every good thing, there are challenges to advancing the general knowledge and confusion largely due to misconceptions about cloud computing in Canada in general. 

There is a growing number of organizations that make use of the general lack of knowledge about cloud computing in Canada in an effort to enter the cloud computing market. The term cloudwashing has been bandied about to describe what these organizations do in their efforts to gain a share of mind with Canadian consumers. Some organizations have even taken the moniker "cloud provider" in order to describe the products and services they provide as being cloud computing; they typically offer some sort of product “as a service”. The litmus test here is whether these products and services adhere to the basic characteristics of cloud computing such as those published by the NIST. Making data available to citizens or allowing them to use that data to write an app under an open government initiative is a great idea. But those two things in and of themselves do not constitute cloud computing. Part of the blame lies with the industry at large. That said, we should concede that there are such things as "cloud based services" that have cloud computing-like properties but are not, strictly speaking, IaaS, PaaS, or SaaS. 

One thing to note, is that much of the content generated by these organizations borrows from cloud computing to justify how their offering really is cloud computing (hence the cloudwashing). This is not a problem, in and of itself, but when competing vendors approach the same customer with different definitions of cloud computing, there can be confusion resulting in a delay in the adoption of cloud computing. This, I submit is one reason (maybe low on the list behind security, GRC, vendor lock-in, and standards concerns) why adoption has lagged in Canada, economic issues notwithstanding.

Everyone is trying to move cloud computing forward in Canada. There is little doubt about its benefits, at this point. However, cloudwashing does not help the cause and results in confusion in the minds of consumers. It is this confusion that is causing the hesitation in the marketplace and hindering educational efforts. There has to be some consensus in the market about what cloud computing is, what a cloud based service is, and what is simply not within the realm.

Apr 2, 2011

Takeaway #5 from Cloud Connect 2011 - Security schmecurity?

Security remains an important issue for cloud adopters. But to what extent is security truly preventing them from adopting cloud based services? Is it really that big of a deal?

Of course security is a real issue in IT; as a company doing business on the Internet, security is one of those things that, if you get it wrong, your business can be seriously hurt by the consequences. Security threats range in complexity but all have one thing in common: people are the main security threat, always have been, and always will be, through ignorance, accidental misconfiguration, or malicious behavior.

So why, then, is security in the cloud such a big deal? Governance. There is a lack of visibility into the security of cloud based services generally due to the nature of the contracts and the remedies offered as well as the lack of regulation whether it be industry, government, or some combination of the two.  In Canada, privacy law requires that the owner of private information (the organization(s) to whom the individual has provided the information) ensure that the information is held in confidence by whatever vendor/service provider makes legal use of that information. This means that the Government has mandated industry to regulate itself by making the organizations liable for any disclosure of that information including that by a third party such as a cloud services provider.

At its core, this is an issue of risk tolerance; how tolerant is an organization to risk. The answer to this question is not complete without considering the tolerance to the magnitude of the impact to the organization (say $ for argument's sake). Basically, The greater the risk and the greater the impact, the more reluctant organizations will be. This is the basis for a basic risk response matrix.
(There are obviously more complex risk tolerance matrices, but it is sufficient for the purposes of this posting. Accept=make use of cloud based services as is. Mitigate=take measures to offset risks such as including remedies in contracts. Avoid=don't make use of cloud based services.)

There are those, even some at Cloud Connect 2011, that are claiming that security is a non issue. Unfortunately, most organizations are still worried about it and beg to differ. Countless polls prove this point. That said, this shouldn't be anything new to us. This very same argument/concern/issue has been dealt with before. At least twice: during the rise of e-commerce as we know it and again around the increase in outsourcing. Why is cloud any different? Let's figure out a way to secure our services, federate them, govern them, and then let's move on!

OK, so I oversimplified. The point is, there is too much discussion and not enough action. SaaS vendors have caught on. Their contracts address the issue of security. So, if customers want it, why aren't more vendors providing it, and why are yet others claiming that it's not a big deal?

Mar 25, 2011

Takeaway #4 from Cloud Connect 2011 - eBay and Cost Savings

By now, everyone has looked at Neal Sample's presentation from Cloud Connect 2011 (arguably the most important keynote as far as I am concerned) of how eBay makes use of the public cloud. I dare say, that they have shown significant and very real cost savings.

Up until early March, the best we could do was theorize and sort of guesstimate at how much could be saved on costs by making use of a cloud based architecture; how much were servers costing, what was their utilization, how many person hours were spent managing them, etc. vs. spinning up AWS instances and shunting excess or unplanned workload into the public cloud. Many vendors offer their own version of cost/benefit calculators and "financial checklists" but they mostly miss the point: consumers of cloud based services need to be honest with themselves about how they consume IT assets and services before they can really estimate their cost savings. eBay did that. They looked at the whole enchilada, discovered where their efficiencies or inefficiencies lie and showed huge cost savings.

I have no doubt that eBay's model has inspired at least a few organizations to look at their utilization. The trick is for them to decide what is right for the organization. eBay's model certainly isn't a one-size-fits-all. It is up to individual organizations to understand their asset utilization profile, their tolerance to risk, and to see how cloud based services fit into their governance model before making such a leap, however compelling it may be.

Mar 15, 2011

Takeaway #2 from Cloud Connect 2011

On our pre-panel and panel discussion at Cloud Connect, Krishnan Subramanian of CloudAve brought up an interesting point about cloud adoption in Africa and India and even discusses it in his blog. To these I would also add China. Given their populations, there is a massive business opportunity there that may yet be untapped.

Essentially, the masses in Africa, China, and India are well versed in mobile communication due to its relative affordability and even prefer mobile phones over personal computers and laptops. As Krishnan points out, this platform is well suited to the delivery of cloud based services.

However, it is not the mobile end user that will increase adoption/utilization of cloud based services; it is the startups and innovators that recognize the opportunity to deliver mobile applications, and who will leverage cloud based services themselves in such delivery, who will do so.

That said, there is still a major barrier on the path to widespread use of cloud based services in Africa and India: latency (see Cedexis' analysis of cloud latency presented at Cloud Connect 2011 for details). Internet access to the African continent, Chine, and India is generally slow (in the 400ms+ range) due to the high costs of provisioning bandwidth and delivering telecommunications infrastructure, especially in the interior of Africa. This, in effect, is one of the reasons that mobile devices have proliferated: transmission towers only require power and line of sight to transmit data over long distances.

There were over 850 million mobile phones in China and 771 million mobile phones in India in January, 2011, and another 250 million more in Africa at the end of 2008. This should give some idea as to the size of the opportunity.

Mar 11, 2011

Takeaway #1 from Cloud Connect 2011

Cloud Connect this year was excellent and brought with it some maturity to cloud computing.

It seems that there was some consensus about whether it's all about public or private clouds with proponents at both ends of the spectrum. To paraphrase, it's not really about the hardware any more.
  • A purely public cloud is somewhat of a holy grail - a "cloudtopia", to coin a term - and can only occur once all regulatory hurdles, such as privacy concerns, have been overcome. Will this ever happen? No one knows for sure.
  • Private cloud seems to be the solution for those organizations and industries that have a low tolerance to risk and prefer to control their environment. How can these organizations relax their governance?
In my opinion, cloud will converge on a hybrid model due to regulatory and confidentiality requirements. Consumers of cloud based services will make them what they need them to be with a mix of public and private as they see fit.

There is no doubt that adoption is gaining momentum (double and triple digit rates for the current leaders); regulatory authorities and industry must now engage each other to further advance the agenda instead of staring at each other and wondering who will blink first.

Mar 7, 2011

Breakdown of Amazon's cloud based services

Good basic overview of Amazon's cloud based services and how they interrelate. Graphical representation of:
  1. Infrastructure (compute, storage, network, database); includes global physical infrastructure
  2. Platform (parallel processing, payments, content delivery, workforce, messaing, email)
  3. Cross service features (authetication and autorization, monitoring, deployment and automation)
Jinesh also explained how ISPs can resell AWS instances with margin using DevPay. Wondering what the developer/channel/spot market dynamics will be.

Wonder how many of the services are home grown vs. COTS white labeled. Anyone know?

Sep 24, 2010

Two years on and SaaS is still around!

I came across an interview I read a while back (August, 2008) in which Harry Debes, CEO of Lawson, claimed that SaaS was a passng fad that would pass like its previous incarnations, "service bureaux" and "application service provider".

Well, here we are, two years later, and SaaS has picked up steam. The main strength of SaaS is the huge savings on CAPEX that Debes neglects to mention in his interview. It's true that, on the surface, SaaS appears to be a form of software license financing; a monthly charge per user that includes licensing and support/maintenance instead of an upfront license fee and annual maintenance fees.

That said, there are benefits for both the customer and vendor. The customer, obviously, benefits from the reduced investment in infrastructure required to run software on premises. The vendor, however, can leverage the same environment for multiple customers which increases the utilization rate of the infrastructure but lowers the monthly cost to its customers (or pockets the extra margin).

Organizations use SFDC because it works and it's relatively cheaper than installing servers and DBs to run a CRM application on premises. If it were not available in a SaaS format, would it be as popular? Possibly. But if it didn't work that well, would it be as successful as either a SaaS or on premise offering? Probably not. The market has a way of weeding out bad software.

Theoretically, all software that is offered on premises and as a service has a tipping point at which the decision to build or buy is made. This is why, regardless of what Harry Debes or Larry Elllison say, organizations need to evaluate the costs of each option, the total cost of ownership, and make an informed decision based on that information and not the hype.

Aug 31, 2010

Bill You, Bill Me

@benkepes tweeted about Aria Cloud Revenue Adapter for VMware vCloud Director which led me to his article on GIGAOM on the topic.

I agree with much that Ben says in his article (including the fact that the industry is perceived as commoditized, the erosion of revenue by third party services layered over top, and how utility based billing is an emergent market segment) and think that he's right on the market's movement.

What I can not agree with his assessment that billing is a "non-core function". This really shouldn't be the case; billing is core to every business' operations. Why, then, should cloud service providers have to rely on third parties to provide them with a solution?

The way I see it, there are three options:
1) License a complete solution that you will leverage to provide your services,
2) License a billing solution and develop the cloud offering (or vice versa),
3) Build your own solutions.

Of course, this is a classic 'build-or-buy' scenario. It is true that buying is sometimes cheaper. However, relying on a third party's services is not without risk and costs. By some accounts and from personal experience, vendor/partner/contract management often accounts for perhaps 25% additional costs that are often not captured correctly or understood completely. Not to mention switching costs when a cheaper alternative comes along.

In the end, the decision is a financial one that considers the costs involved in the development of such a tool, and I understand that. The bottom line for me is that the billing tools should be built alongside the product offering. Many organizations could be eligible for R&D and/or HR tax credits to offset the additional expense. For those organizations that have been around a while (like VMware) it probably makes more financial sense to buy than to build. Those organizations who are new to the market should consider building while their operating costs are relatively low. (No, billing spreadsheets are NOT the answer.)

To paraphrase and echo Ben, using tools from a third party is fine if you have high margins, but these costs, however low they may be, will cut into profits faster for a lower margin product. Develop your own solution then sell it to those who can't or don't want to. See? There's a new revenue stream!

Aug 12, 2010

ROI Can be Higher in a Private Cloud

A random white paper I read used the words, "...increase infrastructure ROI..." when discussing virtualization of servers. These words are not typically used in the context of cloud based services because everyone is so preoccupied with the benefits of using the public cloud.

In public cloud parlance, ROI us usually used in a comparison of the costs to buy infrastructure vs. the cost of using resources on demand in the cloud. In private cloud vocab, ROI means just that: return on investment. So, how does an organization "increase" the ROI for capital assets? By virtualizing and adopting cloud best practices for automated provisioning and deprovisioning-in other words, creating a private cloud. If usage of the asset is increased, then the return on the initial investment can be increased as well.

Jun 25, 2010

Fear Rogue Workloads!

"Enterprise IT is under pressure to transform from bottleneck to business enabler. The rise of public cloud services such as Amazon EC2 have provided a clear example of what enterprise IT is expected to become: A simple, self-service on-demand infrastructure provider. IT organizations that fail to make this transformation will watch in vain as rogue workloads follow the path of least resistance to the public cloud."

How's that for using fear as a marketing tool? That was the introductory paragraph for an invitation to join a webinar on transforming the IT organization into the purveyor of on-demand services.

Of course, they're right at a certain level. Anyone with a credit card can spin up an instance and have your data crunched, client information or sensitive documents stored off your secure network, or generally in an environment that has not been vetted according to your organization's security practice.

So, how then, does one go about transforming the IT organization into a 'business enabler'? It seems to me that this same question was posed a decade ago when IT budgets were running rampant and accounted for a significant chunk of an organizations expenses.

This particular situation has arisen not because IT is not a business enabler, but because of a perceived lack of flexibility, long delivery times for IT service requests, and expense policies that, while originally robust, now have loopholes that allow anyone with a credit card to acquire off net compute power.

Any potential solution should include the following:
  1. Revise IT processes to increase flexibility in meeting user requests.
  2. Review IT service metrics to determine delivery times and work to reduce them.
  3. Refresh expense policies to take into account this new reality and educate employees about the new policies and how they will help reduce risk for the organization.
In general, this requires an update of the organization's governance structure to ensure that its processes are adequate to manage this new technology, whether it is a planned introduction or not.

Another way that IT can help resolve this problem is to partner with a cloud services provider or identify an approved vendor for future demand of cloud based services. Of course, this requires that the organization have a more mature level of understanding of what cloud based services can offer as well as the will to adopt these services before such a relationship can be created.

Employees under pressure to perform and meet goals will follow the path of least resistance to achieve them. Perhaps management should consider clarifying employees' roles in this context as well and in parallel to all other efforts.

Jun 14, 2010

City of San Diego Reported to Outsource IT Services

GovTech reported that the City of San Diego is ready to outsource some IT services including help desk functions, laptop, desktop, and database server management.

Within the article, the City reportedly consolidated five email systems into one. Oddly, there is no mention of migrating any services into the cloud as various city and state governments have already. It would seem that migrating to a SaaS model, such as Google Apps, would generate a cost savings by simply reducing removing  license fees/maintenance contracts and person-hours required to maintain on-premises servers and productivity apps on upwards of 10,000 desktops and laptops.

That said, the article doesn't mention whether the City's licenses are up for renewal nor the asset lifecycle. So, it is entirely possible that such a migration is being considered. We may yet see an announcement to that effect in the near future.

Jun 9, 2010

More on ROI and the Economics of Cloud Based Services

InformationWeek::Analytics issued a report earlier this month entitled, "Cloud ROI: Calculating Costs, Benefits, Returns," which compares the costs of acquiring hardware and the costs of utilizing cloud based services and the associated ROI. While the basic analysis of the costs makes sense, the comparison is flawed: the difference between the two is cost savings, not ROI.

The spreadsheet attached to the report is fairly straightforward. All costs involved in the acquisition of capital assets vs. leased assets (i.e., on demand) and the related costs are listed and compared. A present value calculation is performed to show the total cost of ownership over a number of years. It is evident that cloud based services are cheaper than acquiring capital assets for the same purpose. This forms the basis for the ROI calculation but the report never actually calculates the ROI; it gives the reader just enough information to be misinformed...

To make the numbers make more sense, the report needs to add a revenue stream. That revenue stream would allow the reader to find the breakeven point. And, if there was enough time, the report could go further and examine the impact of asset lifecycle and the replacement of capital assets versus using leased assets over time. In this case we would see the economic value of using assets on demand instead of acquiring them.

The one statement, from Lew Moorman, Chief Strategy Officer of Rackspace, with which I agree is that organizations need to evaluate how to make cloud based services fit into their IT service catalog rather than whether they can save money by migrating everything into the cloud. The latter discussion is probably not going to be very productive since not all services can be or should be moved into the cloud though, financially, it might make perfect sense. IT and Finance often butt heads.

In previous posts (here and here) I discussed ROI of Cloud Based Services and how it is often confused for cost savings, touching briefly on the concept of breakeven.

May 25, 2010

"Cash-Starved Governments Look to Cut IT Maintenance Fees"

Interesting article at Government Technology about government organizations trying to cut costs by reducing maintenance fees. Not that this is real news since many "cash-starved" organizations are trying to cut costs. It makes you wonder how this will play out. Maintenance fees can range anywhere from 18% to 24% of net costs with the typical rate set at 20%. If vendors give in, their revenue streams suffer and they have to make up the difference elsewhere by increasing services costs or product pricing to satisfy shareholders.

On the other hand, cloud based services do not have maintenance surcharges (they're built in to the pricing model). The States of Oregon and Arizona have adopted Google Apps in their education system and the City of Los Angeles was actively debating it last year as well. But does SaaS serve government as well as on premise hardware and software?

Well, it all depends on your governance model. Cloud providers are feverishly working on securing their offerings in order to attract customers. However, it begs the question: can clouds be as secure as your own network? I suppose it is possible, but your network is secured according to your own governance and security policies. Unless the provider agrees to secure the environment according to your policies, it may not be sufficient. Add to that the fact that availability and SLAs suffer with multiple providers (99.99% telco uptime, 99.5% cloud provider uptime = 99.49% effective uptime guarantee) and we see why governance is a major issue facing cloud adopters, not the least of which is governments.

That said, it would be surprising if security and governance concerns would not be resolved. It seems to me that those organizations that would benefit most from cloud will modify their governance policies accordingly and cloud providers will improve their offerings so that the two will meet at some compromising middle ground. Is this the beginning of the end for maintenance contracts? I don't think so, but I bet they're going to change as cloud gains traction...

May 11, 2010

Cloud Computing: Nomenclature Issues

The nomenclature for cloud computing, or the model for services consumed on a utility basis, has drawn much criticism and caused much confusion.

For those of you who are not aware, cloud computing draws its name from the fact that IT resources are "in the cloud", meaning that they are somewhere on the Internet, off your network. (A stylized cloud is often used to represent the Internet in architecture diagrams.) The most common term for cloud computing is the "as-a-Service" suffix: infrastructure (IaaS), platform (PaaS), software (SaaS), and storage (such as Amazon's S3). Clearly, IaaS and PaaS are derived directly from the hardware and development platforms and provide users with instances of the underlying resources on demand while storage is the use of storage media as a resource. SaaS, however, poses a problem: is software "cloud computing"? SaaS splits the community into two distinct camps: yes, SaaS is cloud computing because it is available in the cloud; no, SaaS is not cloud computing because you are subscribing to software on a monthly basis (unlike the utility model for IaaS and PaaS).

The NIST defines cloud computing as follows:
"Cloud computing is a model for enabling convenient, on demand network access to a shared pool of configurable computing resources (e.g., networks, servers, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model promotes availability and is composed of five essential characteristics, three service models, and four deployment models."

This definition leaves a bit of room for interpretation. Because of this, I propose alternate terms: "Cloud Based Services", "Services in the Cloud", or "Cloud Services". Each of these terms indicate that the services are consumed (be they IaaS, PaaS, SaaS, or storage) are located or based in the cloud and do not confuse the issue of SaaS being a compute resource per se.

While the terms "Cloud Based Services", "Services in the Cloud", and "Cloud Services" are not revolutionary, they clarify the concept and are inclusive of the various forms of cloud computing.