CTO of Bigfix, Amrit Williams feels that security, already identified as one of the top three CIO concerns, deserves even greater attention in India. As the IT industry in the country grows, it will take on even more significant proportions, especially due to international compliance regulations. He voices his concerns and insights below:
What is Bigfix about?
Bigfix has been developing security solutions for over a decade. The idea was that we would maintain and help with security, some design objectives around decentralized management and intelligence to system cells in providing real time security to the state of the assets. We would create the place of a virtual administrator that could be pushed into any computing device. Today a lot of enterprises have become more than distributed, there is a step up in the change velocity and the dynamic nature. This itself could be a threat, so having a technology that will allow them to control these threats real time, helps. Since we provide high security systems and security management software, we constantly work on the idea of improving the security of IT devices, and providing that to enterprise and service providers.
From a CIO perspective do you think security is somewhere near the top in priority?
I do. Before joining Bigfix, I was with Gartner as a senior analyst and there, we had ascertained the top CIO concerns for 2008, and security was one of the top three concerns, along with business improvement and enterprise applications deployment. It needs to be a big issue, one because the growing threat points and secondly because there is recognition that security really is required as something that adds to the software side.
What is the status of Bigfix in India?
In India, Bigfix’s footprint has gone up significantly over the past several quarters. We have acquired a hundred thousand end point sales, and hit the 50 customer mark. We have big partners like Wipro to help establish and use our technology, so we are definitely expanding and take the Indian market seriously. About the mindset I think there is the realization that you can compete effectively in the global economy, but security has to be a basic issue because without being able to provide the trust to your customer, your business cannot work in the set of services being provided. It is very difficult to take business away from what could be big competition, and I am sure they would not compromise.
You are a CTO, how do you help CIOs to justify the investment ROI. How does Bigfix help?
We have a set of solutions that are not just security solutions, but solutions that have power management attributes, that will add to their green IT initiatives. We found that HVAC systems and power savings systems to provide security as well as drive huge cost savings. We also provide asset expansion services, where the solutions for security also help to see the other aspects, to justify the purchase. In my decade and a half of service in the security industry, people always search for the magic security solutions, they do not exist. However, I think that most CIOs are savvy enough to be able to convince their management to agree that not investing in security may be scary. They need to know that not having security can adversely affect their business, specially in critical data industries. So security configuration management — which essentially means configuring machines against a base line and having a common operating client for security to begin with, provides cost savings because you can lower support costs if there is less variability in your environment. You can turn around caches and applications delivery and other market variations in the environment faster. Therefore, there is an upside, as security professionals we should inform our executives about what the benefits are of security, that are not related to just stopping the bad guys.
However, I do concede in a security purchase, ROI is really difficult to quantify, and I think executives are not even willing to hear how many millions of dollars they would lose in the event of a security breach. But what is interesting and what I think security has failed largely is that they do not have the ability to measure. Most security professionals feel that if their space is not hacked, that is their representation of their effective security program. It really is measuring the unknown, as against in the world of storage or networking or application delivery, where we get these different methods of measuring efficiency and effectiveness. Security professionals need to look towards providing that.
Bigfix has ability to provide SLA around security delivery, how effective is the environment, how efficient is our team responding to, even changing the environment. Now it is moving away from merely ROI to how effective is my environment.
Security threats — virus, intrusions, phishing…next is what?
From the nineties have definitely seen a shift from hobby hackers to financially motivated intrusions, and that has taken roots around selling stolen data or IP addresses, so it is moving into and making IT aware of the data layer. Today its not just about the device itself, in fact if a laptop is stolen, its not the hardware that IT is concerned with, it’s the data that is important, so taking the concept of visibility ad control to the data layer. In the coming times, we shall see tremendous thrust on some old concepts like DNS. The reality, though, is that most organizations can prevent all those threats and also work on a response quickly, once these things occur.
Where do CIOs find the fine balance between accessibility and security?
This is a very interesting situation, more so now that we have a workforce that is very serious and IT-savvy. It used to be OK for IT departments to say you cannot bring these devices into the environment, but no longer. Now the workers don’t really appreciate that. What the security needs to do is to enable the technology, they need to find that fine balance between how they enable it and how they disable it. Once they have visibility into usage of the data, it is easier for them to place policies in place, but definitely there is a situation that IT department will have to enable usage of other devices.
The knowledge worker of today and tomorrow is savvy enough, if you disable I pods and 3Gs, they can use email, and it’s very easy to transfer data through email. Many organizations are trying to SaaS delivery models for applications, that’s safer since it is not even housed in the organization, so that could a solution.
Awareness levels are high — do you think solutions in the market can let CIOs be complacent? Will this effect security planning?
I think what’s caused the complacency is not the belief that IT is working, but due to what is called an orgy of disclosure, there is so much disclosure going around, every time you turn there is a bank, a company, govt, either in the US or globally, have lost information. So much so that we have got cool about it, yes, I am going to get hacked and lose information, so why bother.
It does, and even in the economies that are struggling, security spending is still strong, because clients demanded it and because of the realization that destruction of data can effect your bottom-line. But I think again that this is the realization that I need security in place because I am really scared because to maintain a profitable business. It requires me to establish and maintain proper security controls, just like I do with storage etc.
As an ex-Gartner, how does India fare?
A lot of security activity is done in the Indian market through service provider and outsourcing partners but I would imagine that for India to maintain and grow as a viable global economy and service provider in general in terms of outsourcing, BPO, it has to take security seriously. It has to go with global compliance initiatives, so the banking and infrastructure and government, manufacturing and retail have to take security seriously. I believe that since the IT market in India is supposed to grow at about 110 million in 2012, and a significant chunk of that is associated with security compliance, the government is also pushing harder to meet international compliance issues, so I see a lot happening in this field.




