Solution includes dedicated hardware in the cloud for anti-spam/virus/malware, DLP, email encryption/tracking/authentication/reporting and a kitchen sink too
Cisco jumped into the cloud based hosted email security business with little fanfare about a year ago. Since then it has quietly built out its hosted email security offering to the point where it is now a major player in this space. Sometimes it is better to be late to the game I suppose, it lets you learn from others mistakes. It seems that Cisco IronPort may have done exactly that but I’ll let you be the judge. For those that aren’t familiar with hosted email security here is a basic idea. Hosted email security offers a cloud service that filters your mail traffic for spam, viruses, mailware and phishing attacks. It also provides advanced services like encrypted email messages, Data Leakage Prevention technologies, and of course email reporting and tracking among others. The general idea is to send your email through a hosted email security provider so that the email you ultimately get is clean and bug free. So now that we have a basic understanding of what email security is let’s lay out the traditional issues with a hosted email security offering. Then let’s see how the Cisco IronPort solution attempts to overcome traditional issues with their hosted offering. Finally, we’ll wrap up with some of the pitfalls of the Cisco offering compared to others out there. Let’s get right into it! A very common complaint from customers of Hosted Email Security (HEmSec –I’m going to makeup my own acronym for this article or my fingers will fall off typing this every time.☺) A very common complaint of customers using a HEmSec solution is around lack of timely control to make changes. Typical HEmSec providers run a multi-tenant environment with shared infrastructure across many customers. This allows economy of scale but also limits the ability of each customer to quickly manage their own service. Another artifact of multi-tenancy is that when a change is made in the system it needs to propagate through to all areas around the world. In some cases this can take several hours. The net is that because of this design the HEmSec providers have instituted a ticketing system for moves, adds or changes that might take a consider amount of time to deploy . If a customer wants an email security change they open a ticket and stand in line until their turn. The common complaint is that this process takes to long, is cumbersome and at worst error prone. In response to this Cisco IronPort HEmSec took a different design approach. Instead of creating a multi-tenant shared infrastructure they chose a single-tenant dedicated infrastructure design. This means that each new customer is provided a dedicated email security appliance(s) in the cloud just for them. In fact, the same on-premise Cisco IronPort email appliances in use by over 40% of fortune 500 companies are dedicated to each customer in the cloud service. Using the same Gartner recommended solution and just putting it in the cloud has allowed Cisco to quickly become a dominate player in the hosted email market. This dedicated approach has several advantages. For example, now when you issue a ticket for a change it can be propagated much quicker because the change only goes to your dedicated appliances not to all appliances like multi-tenant does. It also allows Cisco to offer you direct management and reporting of your devices, something not possible with a multi-tenant design. This means if you want to make a change yourself you can, if you want to schedule or run a report you can. In effect, this design approach offers all of the benefits of having an appliance on your site plus all of the benefits of having a managed service in the cloud. So there must be disadvantages right? Yep, there are. The dedicated design does not have the same cost savings as a shared infrastructure design does. As a result, the dedicated service doesn’t monetize well for smaller customers. In fact, because of this Cisco IronPort HEmSec is only offered to customers larger than 999 mailboxes. The second major issue reported by customers with a multi-tenant HEmSec service is around compliance and message tracking. In a multi-tenant environment all components including log databases, email storage, hardware, software, everything is shared among all service customers. It also means that you have limited or no controls over what datacenters are allowed to host your email security service. For example, not allowing a DC in china with no privacy laws to process your email. Complying with PCI standards in a shared environment is just about impossible. Your data is mixed up with all the other customers’ data in a shared environment. It would not be feasible to bring the whole service provider into PCI scope for an audit. With a dedicated hardware approach it becomes feasible to still pass compliance audits but also have a hosted service. An artifact of the shared approach is that message tracking becomes at best risky and at worst impossible. E-mail tracking is a method for monitoring the e-mail delivery to intended recipient(s). It also allows searching capabilities to find a message based on the sender, recipient, subject header, message ID and/or time of delivery. Several of the larger hosted providers are starting to offer this service but it is usually not real-time tracking. Also, in many instances in order to offer a tracking service the provider must mix your logs with all other customer logs to create a tracking database. Not always something you want to have happen. Tracking is a very useful tool for mail administrators that must be close to real-time and available. Cisco IronPort HEmSec’s dedicated offering provides the same robust message tracking features that it offers to its on-premise appliance customers. Customers can either open a ticket or do the tracking themselves real-time with no waiting. The final major problem that Cisco IronPort is attempting solve is the shared fate issue that comes with a shared infrastructure design. We’ve all seen the news talking about HEmSec providers having major outages that cause a complete system outage for some time period. Many of these outages are due to the shared infrastructure design where an outage affects everyone not just a specific user. The Cisco offering postures that a dedicated infrastructure offering will greatly diminish the amount and scope of outages. In other words, an outage should only affect a single customer most of the time. To wrap it up, Cisco IronPort’s Hosted email security offering is focused on changing the playing field, and the rules, that traditional service providers have offered in the past. It is not without its drawbacks however and it remains to be seen what Cisco IronPort will do for the sub-1000 mailbox customers in the future. But regardless, this new type of offering seems compelling and worth a look. What are your thoughts? Has Cisco stumbled onto a gem here or is this just a flash in the pan? For more info see here http://www.cisco.com/en/US/products/ps10354/index.html
The opinions and information presented here are my PERSONAL views and not those of my employer. I am in no way an official spokesperson for my employer.
More from Jamey Heary: Credit Card Skimming: How thieves can steal your card info without you knowing it Google Nexus One vs. Top 10 Phone Security RequirementsWhy you should always shred your boarding pass Video rental records are afforded more privacy protections than your online dataThe truth about new SSL attacks 2009 Top Urban Legends in IT Security/a>Go to Jamey’s Blog for more articles on security.*
*
*
*
*
*




